SecWiki周刊(第242期)
2018/10/15-2018/10/21
安全资讯
美国选民数据再次遭到泄露,数量达3500万
https://nosec.org/home/detail/1899.html
https://nosec.org/home/detail/1899.html
加州IoT设备网络安全法对物联网法律之影响(附法案翻译)
https://www.anquanke.com/post/id/161941
https://www.anquanke.com/post/id/161941
区块链信息服务管理规定(征求意见稿)
http://zqyj.chinalaw.gov.cn/readmore?id=2708&listType=2
http://zqyj.chinalaw.gov.cn/readmore?id=2708&listType=2
2018前三季度上市网络安全公司业绩预告
https://mp.weixin.qq.com/s/dLsXvmU0ba91_9gjmvPU3w
https://mp.weixin.qq.com/s/dLsXvmU0ba91_9gjmvPU3w
安全技术
FireEye:ICS安全趋势分析
https://mp.weixin.qq.com/s/a8DRajYpeCMo_bwSKbQErA
https://mp.weixin.qq.com/s/a8DRajYpeCMo_bwSKbQErA
安大略湖畔的安全之光——ACM CCS 2018 小记(2)
https://zhuanlan.zhihu.com/p/47219624
https://zhuanlan.zhihu.com/p/47219624
智能网联汽车信息安全风险分析及实践探讨
https://www.kiwisec.com/news/detail/5bc4490ddb30c341099f272d.html
https://www.kiwisec.com/news/detail/5bc4490ddb30c341099f272d.html
安大略湖畔的安全之光——ACM CCS 2018 小记(1)
https://zhuanlan.zhihu.com/p/47087828
https://zhuanlan.zhihu.com/p/47087828
看我如何通过邮箱获取IP定位
https://mp.weixin.qq.com/s/QBLnJruKj753XY0rnmVSXg
https://mp.weixin.qq.com/s/QBLnJruKj753XY0rnmVSXg
跨平台横向移动 [ wmi利用 ]
https://mp.weixin.qq.com/s/7YidkhJvmVBxFhYcD7pIfQ
https://mp.weixin.qq.com/s/7YidkhJvmVBxFhYcD7pIfQ
Teltonika路由器存在远程命令执行漏洞(CVE-2018-17532)
https://nosec.org/home/detail/1901.html
https://nosec.org/home/detail/1901.html
Java常见通用漏洞和修复的代码以及利用payload
https://github.com/JoyChou93/java-sec-code
https://github.com/JoyChou93/java-sec-code
SoK: Security Evaluation of Home-Based IoT Deployments
https://astrolavos.gatech.edu/articles/sok_sp19.pdf
https://astrolavos.gatech.edu/articles/sok_sp19.pdf
MetInfo最新版本爆出SQL注入漏洞
https://nosec.org/home/detail/1889.html
https://nosec.org/home/detail/1889.html
智能合约游戏之殇——Dice2win安全分析
https://lorexxar.cn/2018/10/18/dice2win-safe/
https://lorexxar.cn/2018/10/18/dice2win-safe/
PHPWander: A Static Vulnerability Analysis Tool for PHP
https://www.duo.uio.no/bitstream/handle/10852/63609/master-pavelju.pdf
https://www.duo.uio.no/bitstream/handle/10852/63609/master-pavelju.pdf
如何进入Gartner报告?
https://mp.weixin.qq.com/s/uGhcnkgGNeZhGRAGlPfUWg
https://mp.weixin.qq.com/s/uGhcnkgGNeZhGRAGlPfUWg
olap2018: 易观第二届OLAP漏斗算法大赛
https://github.com/housepower/olap2018
https://github.com/housepower/olap2018
零基础如何学习 Web 安全?
https://www.zhihu.com/question/21606800
https://www.zhihu.com/question/21606800
net-creds:从网络接口或PCAP文件中嗅探敏感信息
https://nosec.org/home/detail/1905.html
https://nosec.org/home/detail/1905.html
甲方安全建设的一些思路和思考
https://mp.weixin.qq.com/s/quwaJMVHYpBAXpkgtR12Kw
https://mp.weixin.qq.com/s/quwaJMVHYpBAXpkgtR12Kw
2018护网杯calendar详析
https://www.anquanke.com/post/id/162121
https://www.anquanke.com/post/id/162121
D-Link 850L&645路由漏洞分析
https://xz.aliyun.com/t/2941
https://xz.aliyun.com/t/2941
Malware Families & Actors 恶意家族查询
https://malpedia.caad.fkie.fraunhofer.de/families
https://malpedia.caad.fkie.fraunhofer.de/families
记一次安全应急响应中遇到的利用SSH日志触发的后门分析
http://www.freebuf.com/articles/system/185942.html?from=timeline
http://www.freebuf.com/articles/system/185942.html?from=timeline
风险评估服务能力成熟度模型研究
https://mp.weixin.qq.com/s/y9Qx4htmcoWgC96G2sWvpw
https://mp.weixin.qq.com/s/y9Qx4htmcoWgC96G2sWvpw
Finding Related ATT&CK Techniques
https://medium.com/mitre-attack/finding-related-att-ck-techniques-f1a4e8dfe2b6
https://medium.com/mitre-attack/finding-related-att-ck-techniques-f1a4e8dfe2b6
Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE
https://dragos.com/media/CRASHOVERRIDE2018.pdf
https://dragos.com/media/CRASHOVERRIDE2018.pdf
Analyzing WebAssembly binaries
https://www.forcepoint.com/blog/security-labs/analyzing-webassembly-binaries
https://www.forcepoint.com/blog/security-labs/analyzing-webassembly-binaries
一步步教你轻松学主成分分析PCA降维算法
http://www.52nlp.cn/10738-2
http://www.52nlp.cn/10738-2
浅谈重放漏洞与竞态条件漏洞
https://mp.weixin.qq.com/s/oN_AvF7luMNvwB3GDyk_PA
https://mp.weixin.qq.com/s/oN_AvF7luMNvwB3GDyk_PA
Git Submodule 漏洞(CVE-2018-17456)分析
https://paper.seebug.org/716/
https://paper.seebug.org/716/
old-school-evil-excel-4-0-macros-xlm
https://outflank.nl/blog/2018/10/06/old-school-evil-excel-4-0-macros-xlm/
https://outflank.nl/blog/2018/10/06/old-school-evil-excel-4-0-macros-xlm/
Detecting Malicious Campaigns with Machine Learning
https://researchcenter.paloaltonetworks.com/2018/10/unit42-detecting-malicious-campaigns-machine-learning/
https://researchcenter.paloaltonetworks.com/2018/10/unit42-detecting-malicious-campaigns-machine-learning/
分析基于RTF恶意文档的攻击活动
https://www.anquanke.com/post/id/162105
https://www.anquanke.com/post/id/162105
SecWiki周刊(第241期)
https://www.sec-wiki.com/weekly/241
https://www.sec-wiki.com/weekly/241
使用QEMU chroot进行固件本地调试
http://blog.nsfocus.net/qemu-chroot/
http://blog.nsfocus.net/qemu-chroot/
Another link between Equation Group and Stuxnet?
https://www.a12d404.net/security/2018/08/10/another-link-between-eqgrp-and-stuxnet.html
https://www.a12d404.net/security/2018/08/10/another-link-between-eqgrp-and-stuxnet.html
IoT时代,“白帽子”以网为剑捍卫安全
https://mp.weixin.qq.com/s/9t36Z_8exZwI_rpG-P57Yw
https://mp.weixin.qq.com/s/9t36Z_8exZwI_rpG-P57Yw
负载恶意软件HawkEye的VB Inject样本分析
http://www.freebuf.com/articles/paper/186050.html
http://www.freebuf.com/articles/paper/186050.html
正解HTTPS与中间人攻击
https://mp.weixin.qq.com/s/E0_NRjpsyCCZtNgzuXU5Jw
https://mp.weixin.qq.com/s/E0_NRjpsyCCZtNgzuXU5Jw
DarkPulsa (apt)
https://securelist.com/darkpulsar/88199/
https://securelist.com/darkpulsar/88199/
The dark side of WebAssembly
https://www.virusbulletin.com/virusbulletin/2018/10/dark-side-webassembly/
https://www.virusbulletin.com/virusbulletin/2018/10/dark-side-webassembly/
The release of Dmp2Json & Querying Memory Images through JSON format
https://blog.comae.io/the-release-of-dmp2json-querying-memory-images-through-json-format-11fa01fd86ae
https://blog.comae.io/the-release-of-dmp2json-querying-memory-images-through-json-format-11fa01fd86ae
Flare-on Challenge 2018 Write-up
https://bruce30262.github.io/flare-on-challenge-2018-write-up/
https://bruce30262.github.io/flare-on-challenge-2018-write-up/
某CMS 排行页面存储型XSS漏洞分析
https://xz.aliyun.com/t/2899
https://xz.aliyun.com/t/2899
The Problems and Promise of WebAssembly
https://googleprojectzero.blogspot.com/2018/08/the-problems-and-promise-of-webassembly.html
https://googleprojectzero.blogspot.com/2018/08/the-problems-and-promise-of-webassembly.html
Struts2 漏洞exp从零分析
https://www.anquanke.com/post/id/161690
https://www.anquanke.com/post/id/161690
Forrester 威胁情报服务厂商评估报告
https://mp.weixin.qq.com/s/1O5KU5O95s_naz5MKKpYow
https://mp.weixin.qq.com/s/1O5KU5O95s_naz5MKKpYow
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第242期)
