SecWiki周刊(第236期)
2018/09/03-2018/09/09
安全资讯
美国起诉朝鲜黑客,涉索尼及WannaCry等黑客案
https://mp.weixin.qq.com/s/KaduuL0Fv-xBgr7smY_cnQ
https://mp.weixin.qq.com/s/KaduuL0Fv-xBgr7smY_cnQ
公安机关“净网2018”专项行动破刑案2.2万余起(附十大典型案例)
https://mp.weixin.qq.com/s/ZsI4LEmshKoppeeqM4nsrA
https://mp.weixin.qq.com/s/ZsI4LEmshKoppeeqM4nsrA
关于规范促进网络安全竞赛活动的通知
http://www.cac.gov.cn/2018-09/07/c_1123394579.htm
http://www.cac.gov.cn/2018-09/07/c_1123394579.htm
英国航空公司遭到攻击,攻击者窃取了38万客户的详细信息
https://nosec.org/home/detail/1816.html
https://nosec.org/home/detail/1816.html
国外著名网盘MEGA Chrome浏览器扩展程序遭黑客窃取登陆凭据和加密货币
https://nosec.org/home/detail/1814.html
https://nosec.org/home/detail/1814.html
S2-057(CVE-2018-11776)漏洞影响思科产品
https://nosec.org/home/detail/1815.html
https://nosec.org/home/detail/1815.html
安全技术
387个暗网网址
http://www.ddosi.com/t4/
http://www.ddosi.com/t4/
[VULNSPY实验] ECShop 3.0.x/3.6.x 版本远程代码执行高危漏洞利用 EXP
http://www.vulnspy.com/cn-ecshop-3.x.x-rce-exploit/ecshop_%3C=_2.x/3.6.x/3.0.x_%E7%89%88%E6%9C%AC%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8/
http://www.vulnspy.com/cn-ecshop-3.x.x-rce-exploit/ecshop_%3C=_2.x/3.6.x/3.0.x_%E7%89%88%E6%9C%AC%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8/
opencanary_web: 基于opencanary的蜜罐web服务端
https://github.com/p1r06u3/opencanary_web
https://github.com/p1r06u3/opencanary_web
KCon 2018 议题 PPT 公开
https://paper.seebug.org/697/?from=timeline&isappinstalled=0
https://paper.seebug.org/697/?from=timeline&isappinstalled=0
Tips:FOFA结合DNS/WebLOG写POC(不用修改代码)
https://nosec.org/home/detail/1812.html
https://nosec.org/home/detail/1812.html
子域名劫持指南
https://xz.aliyun.com/t/2704
https://xz.aliyun.com/t/2704
DockerXScan—Docker镜像漏洞扫描器
https://github.com/MXi4oyu/DockerXScan
https://github.com/MXi4oyu/DockerXScan
Chainspotting! Building Exploit Chains with Logic Bugs
https://labs.mwrinfosecurity.com/assets/BlogFiles/G.-Geshev-and-Rob-Miller-Chainspotting.pdf
https://labs.mwrinfosecurity.com/assets/BlogFiles/G.-Geshev-and-Rob-Miller-Chainspotting.pdf
滴滴 KDD 2018 论文详解:基于强化学习技术的智能派单模型
https://www.leiphone.com/news/201808/7ZbAz8REosn3L8kT.html?from=timeline
https://www.leiphone.com/news/201808/7ZbAz8REosn3L8kT.html?from=timeline
代码审计3-熊海cms v1.0
https://uknowsec.cn/posts/%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1/%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A13-%E7%86%8A%E6%B5%B7cms-v1-0.html
https://uknowsec.cn/posts/%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1/%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A13-%E7%86%8A%E6%B5%B7cms-v1-0.html
腾讯企业终端安全管理最佳实践
https://mp.weixin.qq.com/s/g_x_xpbyKKQkLNpYnMqaXg
https://mp.weixin.qq.com/s/g_x_xpbyKKQkLNpYnMqaXg
DesktopNaotu: 桌面版脑图(百度脑图离线版,思维导图工具)
https://github.com/NaoTu/DesktopNaotu
https://github.com/NaoTu/DesktopNaotu
Jackson反序列化漏洞简介(一):Jackson基本的工作原理
http://www.leadroyal.cn/?p=594
http://www.leadroyal.cn/?p=594
Jackson反序列化漏洞简介(二):在反序列化时进行代码执行
http://www.leadroyal.cn/?p=616
http://www.leadroyal.cn/?p=616
ECSHOP多个版本远程代码执行漏洞(非全版本)
https://nosec.org/home/detail/1770.html
https://nosec.org/home/detail/1770.html
TWCTF 2018 escapeme writeup
https://www.anquanke.com/post/id/159146
https://www.anquanke.com/post/id/159146
代码自动化扫描系统的建设(下)
https://mp.weixin.qq.com/s/4XtIWbkIeCjbNWT2VCFHZg
https://mp.weixin.qq.com/s/4XtIWbkIeCjbNWT2VCFHZg
突破限制—一份安全编写和审计Chrome扩展程序的指南(下)
https://xz.aliyun.com/t/2717
https://xz.aliyun.com/t/2717
DDoS威胁与黑灰产业调查报告
http://www.freebuf.com/news/topnews/178990.html
http://www.freebuf.com/news/topnews/178990.html
以太坊智能合约 OPCODE 逆向之调试器篇
https://paper.seebug.org/693/
https://paper.seebug.org/693/
国家千人计划教授任奎:数据安全的现状与趋势
https://mp.weixin.qq.com/s/G0lLc4PZtomkBd5s3l5qgw
https://mp.weixin.qq.com/s/G0lLc4PZtomkBd5s3l5qgw
ISG 2018 Web Writeup
https://bbs.ichunqiu.com/thread-45213-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-45213-1-1.html?from=sec
Oceanus:美团HTTP流量定制化路由的实践
https://tech.meituan.com/Oceanus_Custom_Traffic_Routing.html
https://tech.meituan.com/Oceanus_Custom_Traffic_Routing.html
代码自动化扫描系统的建设(上)
https://mp.weixin.qq.com/s/tSbWhBh9RQQ5Wduoo18MEg
https://mp.weixin.qq.com/s/tSbWhBh9RQQ5Wduoo18MEg
快速找出网站中可能存在的XSS漏洞实践(一)
https://bbs.ichunqiu.com/thread-44668-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-44668-1-1.html?from=sec
A glimpse into the dark underbelly of cryptocurrency markets
https://medium.com/@nic__carter/a-glimpse-into-the-dark-underbelly-of-cryptocurrency-markets-d1690b761eaf
https://medium.com/@nic__carter/a-glimpse-into-the-dark-underbelly-of-cryptocurrency-markets-d1690b761eaf
安装Python安装包时执行任意代码
https://nosec.org/home/detail/1813.html
https://nosec.org/home/detail/1813.html
MiningGitlog: 采集Github仓库mail地址
https://github.com/omg2hei/MiningGitlog/
https://github.com/omg2hei/MiningGitlog/
Google Dataset Search 数据集搜索专用引擎
https://toolbox.google.com/datasetsearch
https://toolbox.google.com/datasetsearch
态势感知攻击链分析-Redis未授权访问检测
http://www.4hou.com/technology/13479.html
http://www.4hou.com/technology/13479.html
情报困局-探索如何解决发现未知风险问题 —降维
https://weibo.com/ttarticle/p/show?id=2309404280480668196655
https://weibo.com/ttarticle/p/show?id=2309404280480668196655
一款轻量级Web漏洞教学演示系统(DSVW)
http://mykings.me/2017/02/04/%E4%B8%80%E6%AC%BE%E8%BD%BB%E9%87%8F%E7%BA%A7Web%E6%BC%8F%E6%B4%9E%E6%95%99%E5%AD%A6%E6%BC%94%E7%A4%BA%E7%B3%BB%E7%BB%9F-DSVW/
http://mykings.me/2017/02/04/%E4%B8%80%E6%AC%BE%E8%BD%BB%E9%87%8F%E7%BA%A7Web%E6%BC%8F%E6%B4%9E%E6%95%99%E5%AD%A6%E6%BC%94%E7%A4%BA%E7%B3%BB%E7%BB%9F-DSVW/
SecWiki周刊(第235期)
https://www.sec-wiki.com/weekly/235
https://www.sec-wiki.com/weekly/235
AI Challenger 全球AI挑战赛
https://challenger.ai/
https://challenger.ai/
代码自动化扫描系统的建设
https://www.anquanke.com/post/id/158929
https://www.anquanke.com/post/id/158929
Using tidytext to find document similarity
http://varianceexplained.org/r/op-ed-text-analysis/
http://varianceexplained.org/r/op-ed-text-analysis/
论Elasticsearch数据建模的重要性
https://mp.weixin.qq.com/s/LXhE-D0FlT_hOns1s1rBmg
https://mp.weixin.qq.com/s/LXhE-D0FlT_hOns1s1rBmg
koadic-pen-testing-pivoting-javascripting-part-ii
https://blog.varonis.com/koadic-pen-testing-pivoting-javascripting-part-ii/
https://blog.varonis.com/koadic-pen-testing-pivoting-javascripting-part-ii/
HITB Gsec sg2018
https://gsec.hitb.org/materials/sg2018/
https://gsec.hitb.org/materials/sg2018/
突破限制—一份安全编写和审计Chrome扩展程序的指南(上)
https://xz.aliyun.com/t/2706
https://xz.aliyun.com/t/2706
what-is-it-that-makes-a-microsoft-executable
https://posts.specterops.io/what-is-it-that-makes-a-microsoft-executable-a-microsoft-executable-b43ac612195e
https://posts.specterops.io/what-is-it-that-makes-a-microsoft-executable-a-microsoft-executable-b43ac612195e
Malware Analysis using Osquery Part 2
https://www.alienvault.com/blogs/labs-research/malware-analysis-using-osquery-part-2
https://www.alienvault.com/blogs/labs-research/malware-analysis-using-osquery-part-2
koadic-lol-malware-meets-python-based-command-and-control-c2-server-part-i
https://blog.varonis.com/koadic-lol-malware-meets-python-based-command-and-control-c2-server-part-i/
https://blog.varonis.com/koadic-lol-malware-meets-python-based-command-and-control-c2-server-part-i/
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第236期)
