SecWiki周刊(第241期)
2018/10/08-2018/10/14
安全资讯
焦点访谈20181007 信息安全:防内鬼 防黑客
http://tv.cctv.com/2018/10/07/VIDEHBYLGmnR5LoYZawu3dZc181007.shtml
http://tv.cctv.com/2018/10/07/VIDEHBYLGmnR5LoYZawu3dZc181007.shtml
华夏银行技术处长编写病毒植入系统,盗窃700余万受审
https://nosec.org/home/detail/1886.html
https://nosec.org/home/detail/1886.html
安全技术
2018护网杯线上赛 Writeup by Whitzard
https://xz.aliyun.com/t/2893
https://xz.aliyun.com/t/2893
Logan:美团点评的开源移动端基础日志库
https://tech.meituan.com/logan_open_source.html
https://tech.meituan.com/logan_open_source.html
2018护网杯线上赛 Writeup by 天枢
https://xz.aliyun.com/t/2897
https://xz.aliyun.com/t/2897
基于DREAD模型的漏洞等级计算
https://mp.weixin.qq.com/s/-gHMhj1Qdl1N5rCne61m4Q
https://mp.weixin.qq.com/s/-gHMhj1Qdl1N5rCne61m4Q
利用FOFA做些有趣的事
https://nosec.org/home/detail/1858.html
https://nosec.org/home/detail/1858.html
运维安全之应用发布安全隐患
https://mp.weixin.qq.com/s/SykbwlIuNJUHf2Ch_PE3ow
https://mp.weixin.qq.com/s/SykbwlIuNJUHf2Ch_PE3ow
吾爱破解论坛-爱盘源码
https://github.com/ganlvtech/down_52pojie_cn
https://github.com/ganlvtech/down_52pojie_cn
打开JBoss的潘多拉魔盒——JBoss高危漏洞分析
https://mp.weixin.qq.com/s/Kjw_abH6a-ifXdQmbc5Pug
https://mp.weixin.qq.com/s/Kjw_abH6a-ifXdQmbc5Pug
2018护网杯-web部分题解
https://www.anquanke.com/post/id/161849
https://www.anquanke.com/post/id/161849
Behinder: “冰蝎”动态二进制加密网站管理客户端
https://github.com/rebeyond/Behinder/releases
https://github.com/rebeyond/Behinder/releases
渗透基础——端口转发与代理
http://www.4hou.com/technology/13970.html
http://www.4hou.com/technology/13970.html
看我是如何利用升级系统一键GetShell
https://bbs.ichunqiu.com/thread-46603-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-46603-1-1.html?from=sec
TheDAO悲剧重演,SpankChain重入漏洞分析
https://nosec.org/home/detail/1884.html
https://nosec.org/home/detail/1884.html
全球超过30万路由器变矿机,现每日递增1万
https://nosec.org/home/detail/1841.html
https://nosec.org/home/detail/1841.html
Fuzzing技术总结与工具列表
https://blog.csdn.net/wcventure/article/details/82085251
https://blog.csdn.net/wcventure/article/details/82085251
2018 XJNU CTF Web Writeup
https://imlonghao.com/54.html
https://imlonghao.com/54.html
利用NodeJS SSRF漏洞获取AWS完全控制权限
https://xz.aliyun.com/t/2871
https://xz.aliyun.com/t/2871
红队技术从零到一 part 2
http://www.4hou.com/technology/13476.html
http://www.4hou.com/technology/13476.html
APT组织ZooPark V3版移动样本分析
http://www.freebuf.com/articles/terminal/185500.html
http://www.freebuf.com/articles/terminal/185500.html
Top 10 Web Hacking Techniques of 2017
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
Security researchers find solid evidence linking Industroyer to NotPetya
https://www.zdnet.com/article/security-researchers-find-solid-evidence-linking-industroyer-to-notpetya/
https://www.zdnet.com/article/security-researchers-find-solid-evidence-linking-industroyer-to-notpetya/
QiboCMS从SQL注入到getshell
https://xz.aliyun.com/t/2879
https://xz.aliyun.com/t/2879
PHP代码审计中的一些Tips
http://zeroyu.xyz/2018/10/13/php-audit-tips/
http://zeroyu.xyz/2018/10/13/php-audit-tips/
EmpireCMS_V7.5的一次审计
https://bbs.ichunqiu.com/thread-46685-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-46685-1-1.html?from=sec
A timing attack with CSS selectors and Javascript
https://blog.sheddow.xyz/css-timing-attack/
https://blog.sheddow.xyz/css-timing-attack/
A Malware Campaign Targeting the Tibetan Diaspora Resurfaces
https://citizenlab.ca/2018/08/familiar-feeling-a-malware-campaign-targeting-the-tibetan-diaspora-resurfaces/
https://citizenlab.ca/2018/08/familiar-feeling-a-malware-campaign-targeting-the-tibetan-diaspora-resurfaces/
区块链安全风险白皮书第二版
https://www.knownsec.com/media/upload/the_whitepaper_of_blockchain_security_risks_by_Knownsec_V2.0.pdf
https://www.knownsec.com/media/upload/the_whitepaper_of_blockchain_security_risks_by_Knownsec_V2.0.pdf
币早知道夺宝题--以太坊题解题方法
https://www.cnblogs.com/xiaoxiaoleo/p/9729142.html
https://www.cnblogs.com/xiaoxiaoleo/p/9729142.html
AWS takeover through SSRF in JavaScript
http://10degres.net/aws-takeover-ssrf-javascript/
http://10degres.net/aws-takeover-ssrf-javascript/
Analysis and Detection of Spying Browser Extensions
https://mp.weixin.qq.com/s/D1si0cYJ8kIh4nACBY_4bQ
https://mp.weixin.qq.com/s/D1si0cYJ8kIh4nACBY_4bQ
Glibc堆块的向前向后合并与unlink原理机制探究
https://bbs.ichunqiu.com/thread-46614-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-46614-1-1.html?from=sec
互联网企业为什么必须关注应用安全能力建设
http://www.polaris-lab.com/index.php/archives/599/
http://www.polaris-lab.com/index.php/archives/599/
开源软件源代码安全缺陷分析报告 —人工智能类开源软件专题
https://www.anquanke.com/post/id/161526
https://www.anquanke.com/post/id/161526
使用ESP8266信标垃圾邮件发送者来跟踪智能手机用户
https://nosec.org/home/detail/1878.html
https://nosec.org/home/detail/1878.html
基于goahead 的固件程序分析
https://xz.aliyun.com/t/2835
https://xz.aliyun.com/t/2835
红队技术从零到一 part 1
http://www.4hou.com/technology/13350.html
http://www.4hou.com/technology/13350.html
知己知彼之新型勒索Viro Botnet Ransomware的功能分析
http://www.freebuf.com/articles/terminal/185735.html
http://www.freebuf.com/articles/terminal/185735.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第241期)
