SecWiki周刊(第225期)
2018/06/18-2018/06/24
安全资讯
颜新兴:一个安全老兵眼里的中国信息安全技能竞赛
https://mp.weixin.qq.com/s/VQKyx-hQaqgwjzMm3NdszA
https://mp.weixin.qq.com/s/VQKyx-hQaqgwjzMm3NdszA
姜开达:安全需要耐得住寂寞,日积月累地做下去
https://mp.weixin.qq.com/s/MbGGNZhnDk9s_29_NwPnEA
https://mp.weixin.qq.com/s/MbGGNZhnDk9s_29_NwPnEA
2018年以色列网络周内塔尼亚胡总理演讲实录
https://mp.weixin.qq.com/s/UVsGnhCaoMQv_snvXKx5xw
https://mp.weixin.qq.com/s/UVsGnhCaoMQv_snvXKx5xw
安全技术
金融企业数据安全建设实践系列(一)
https://mp.weixin.qq.com/s/fiQqdARZ9NBeKI85mUPJOQ
https://mp.weixin.qq.com/s/fiQqdARZ9NBeKI85mUPJOQ
以太坊智能合约call注入攻击
https://mp.weixin.qq.com/s/l3QBZwacLjIzu6KlpUvuWw
https://mp.weixin.qq.com/s/l3QBZwacLjIzu6KlpUvuWw
GraphQL安全总结与测试技巧
https://www.anquanke.com/post/id/147455
https://www.anquanke.com/post/id/147455
先知白帽大会2018 议题下载
https://paper.seebug.org/625/
https://paper.seebug.org/625/
Fuxi-Scanner: 开源的网络安全检测工具
https://github.com/jeffzh3ng/Fuxi-Scanner
https://github.com/jeffzh3ng/Fuxi-Scanner
mail_fishing: 甲方安全系统-内部钓鱼系统
https://github.com/MSG-maniac/mail_fishing
https://github.com/MSG-maniac/mail_fishing
Game-of-Thrones-CTF-1.0靶机实战演练
http://www.freebuf.com/articles/web/175048.html
http://www.freebuf.com/articles/web/175048.html
LFIboomCTF: 本地文件包含漏洞&&PHP利用协议&&实践源码
https://github.com/Go0s/LFIboomCTF
https://github.com/Go0s/LFIboomCTF
SOCKS5代理-ew 正向、反向、多级级联
https://www.bodkin.ren/index.php/archives/677/
https://www.bodkin.ren/index.php/archives/677/
RCTF 2018 Magic题目详解
http://www.freebuf.com/articles/others-articles/174311.html
http://www.freebuf.com/articles/others-articles/174311.html
利用PHP脚本从浏览器中获得Net-NTLM hash
https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%88%A9%E7%94%A8PHP%E8%84%9A%E6%9C%AC%E4%BB%8E%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E8%8E%B7%E5%BE%97Net-NTLM-hash/
https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%88%A9%E7%94%A8PHP%E8%84%9A%E6%9C%AC%E4%BB%8E%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E8%8E%B7%E5%BE%97Net-NTLM-hash/
天枢CTF线下赛-2018
http://momomoxiaoxi.com/awd/2018/06/11/TSCTF/
http://momomoxiaoxi.com/awd/2018/06/11/TSCTF/
ip2region - 最自由的ip地址查询库
https://gitee.com/lionsoul/ip2region
https://gitee.com/lionsoul/ip2region
honeytrap: Advanced Honeypot framework
https://github.com/honeytrap/honeytrap
https://github.com/honeytrap/honeytrap
记一次初级渗透测试模拟过程
https://www.secpulse.com/archives/72738.html
https://www.secpulse.com/archives/72738.html
Beginner Malware Reversing Challenges
http://www.malwaretech.com/beginner-malware-reversing-challenges
http://www.malwaretech.com/beginner-malware-reversing-challenges
以太坊智能合约call注入攻击
https://blog.csdn.net/u011721501/article/details/80757811
https://blog.csdn.net/u011721501/article/details/80757811
Hash-Buster: 集成多API的hash查询工具
https://github.com/s0md3v/Hash-Buster
https://github.com/s0md3v/Hash-Buster
敏信审计系列之EOS开发框架
https://mp.weixin.qq.com/s/4Ejshk7x71L9INB0grj5mw
https://mp.weixin.qq.com/s/4Ejshk7x71L9INB0grj5mw
金融企业数据安全建设实践系列(二)
https://mp.weixin.qq.com/s/k1dmW2UBLYLrrOpmtaAoag
https://mp.weixin.qq.com/s/k1dmW2UBLYLrrOpmtaAoag
Modern Linux Malware Exposed
http://s3.eurecom.fr/~invano/slides/recon18_linux_malware.pdf
http://s3.eurecom.fr/~invano/slides/recon18_linux_malware.pdf
以太坊智能合约Owner相关CVE漏洞分析
http://0x48.pw/2018/06/19/0x43/
http://0x48.pw/2018/06/19/0x43/
EuroS&P 2018 论文录用列表
https://mp.weixin.qq.com/s/36DRLvoM0VyXKMbdIf1OLA
https://mp.weixin.qq.com/s/36DRLvoM0VyXKMbdIf1OLA
PRISM-AP: An automated Wireless RogueAP MITM attack framework
https://github.com/1N3/PRISM-AP
https://github.com/1N3/PRISM-AP
容器管理利器:Web Terminal 简介
https://mp.weixin.qq.com/s/zlHJTxDeHgjn9A9XuYp9fQ
https://mp.weixin.qq.com/s/zlHJTxDeHgjn9A9XuYp9fQ
Open Source Datasets with Kaggle
http://blog.kaggle.com/2018/06/21/open-source-datasets-with-kaggle/
http://blog.kaggle.com/2018/06/21/open-source-datasets-with-kaggle/
Obscure-IP-Obfuscator: obscure any IP address
https://github.com/C-REMO/Obscure-IP-Obfuscator
https://github.com/C-REMO/Obscure-IP-Obfuscator
一文概览机器学习面临的所有攻击类型
https://mp.weixin.qq.com/s/ixdE3ld0qOOpj7F_kLmmSg
https://mp.weixin.qq.com/s/ixdE3ld0qOOpj7F_kLmmSg
Pentester's Windows NTFS Tricks Collection
https://www.sec-consult.com/en/blog/2018/06/pentesters-windows-ntfs-tricks-collection/
https://www.sec-consult.com/en/blog/2018/06/pentesters-windows-ntfs-tricks-collection/
信息安全知识库 2018全站离线打包
https://pan.baidu.com/s/1gf4Brb1#list/path=%2F
https://pan.baidu.com/s/1gf4Brb1#list/path=%2F
深度学习在文本领域的应用
https://tech.meituan.com/deep_learning_doc.html
https://tech.meituan.com/deep_learning_doc.html
利用定时任务(Cronjobs)进行Linux提取
https://xz.aliyun.com/t/2401
https://xz.aliyun.com/t/2401
Default passwords from CIRT website
https://gist.github.com/PaulSec/26251d56134c7fedb2176f2290202546
https://gist.github.com/PaulSec/26251d56134c7fedb2176f2290202546
利用wmic调用xsl文件的分析与利用
https://3gstudent.github.io/%E5%88%A9%E7%94%A8wmic%E8%B0%83%E7%94%A8xsl%E6%96%87%E4%BB%B6%E7%9A%84%E5%88%86%E6%9E%90%E4%B8%8E%E5%88%A9%E7%94%A8/
https://3gstudent.github.io/%E5%88%A9%E7%94%A8wmic%E8%B0%83%E7%94%A8xsl%E6%96%87%E4%BB%B6%E7%9A%84%E5%88%86%E6%9E%90%E4%B8%8E%E5%88%A9%E7%94%A8/
SecWiki周刊(第224期)
https://www.sec-wiki.com/weekly/224
https://www.sec-wiki.com/weekly/224
通过MySQL-Proxy实现MySQL数据库的认证、授权与审计
http://www.freebuf.com/articles/database/174712.html
http://www.freebuf.com/articles/database/174712.html
CTF中格式化字符串漏洞快速利用
https://www.anquanke.com/post/id/147666
https://www.anquanke.com/post/id/147666
我的WAF Bypass实战系列
https://mp.weixin.qq.com/s/3_l-Zi7EH6D_N1imY61nsg
https://mp.weixin.qq.com/s/3_l-Zi7EH6D_N1imY61nsg
auto_ml: Automated machine learning for analytics & production
https://github.com/ClimbsRocks/auto_ml
https://github.com/ClimbsRocks/auto_ml
MEDIACODER 0.8.43.5852 - .M3U缓冲区溢出漏洞
http://whereisk0shl.top/post/2018-06-23
http://whereisk0shl.top/post/2018-06-23
SOC日志收集实践:企业邮件服务日志收集
http://www.freebuf.com/articles/es/174281.html
http://www.freebuf.com/articles/es/174281.html
工业控制系统(ICS)安全专家必备的测试工具和安全资源
http://www.freebuf.com/sectool/174567.html
http://www.freebuf.com/sectool/174567.html
Struts-S2-xxx: 整理收集Struts2漏洞环境
https://github.com/sie504/Struts-S2-xxx
https://github.com/sie504/Struts-S2-xxx
先知议题 Java反序列化实战 解读
https://mp.weixin.qq.com/s/ohga7Husc9ke5UYuqR92og
https://mp.weixin.qq.com/s/ohga7Husc9ke5UYuqR92og
Android Ransomware Dataset
http://csp.whu.edu.cn/RansomProber/
http://csp.whu.edu.cn/RansomProber/
JIS-CTF_VulnUpload靶机攻略
http://www.freebuf.com/vuls/175057.html
http://www.freebuf.com/vuls/175057.html
Malware Analysis Report (AR18-165A)
https://www.us-cert.gov/ncas/analysis-reports/AR18-165A
https://www.us-cert.gov/ncas/analysis-reports/AR18-165A
MalwLess: MalwLess Simulation Tool (MST)
https://github.com/n0dec/MalwLess
https://github.com/n0dec/MalwLess
Analyzing Shellcode of GrandSoft's CVE-2018-8174
https://www.nao-sec.org/2018/06/analyzing-shellcode-of-grandsofts-cve.html
https://www.nao-sec.org/2018/06/analyzing-shellcode-of-grandsofts-cve.html
ATN 抵御合约攻击的报告—基于ERC223与DS-AUTH的混合漏洞
https://paper.seebug.org/621/
https://paper.seebug.org/621/
区块链安全思考
https://xz.aliyun.com/t/2395
https://xz.aliyun.com/t/2395
Open-Source Intelligence Gathering and Social Engineering
https://docs.google.com/presentation/d/1cYYg_VfG3pmTnQl9Ek4Pi5M9oK72vbHcEQOsfMb-bd8/edit#slide=id.p1
https://docs.google.com/presentation/d/1cYYg_VfG3pmTnQl9Ek4Pi5M9oK72vbHcEQOsfMb-bd8/edit#slide=id.p1
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第225期)
