SecWiki周刊(第243期)
2018/10/22-2018/10/28
安全资讯
雅虎数据泄露时隔两年和解,向2亿用户赔偿3.5亿元
https://nosec.org/home/detail/1916.html
https://nosec.org/home/detail/1916.html
8个成人网站上泄露了120万私密用户数据
https://nosec.org/home/detail/1917.html
https://nosec.org/home/detail/1917.html
信息战部队:美国海军的新型作战力量
https://mp.weixin.qq.com/s/xq2Yoba8UPvZG6Hlv51rNQ
https://mp.weixin.qq.com/s/xq2Yoba8UPvZG6Hlv51rNQ
海康威视总裁胡扬忠:安防市场的虚与实
https://mp.weixin.qq.com/s/7NfXcNC4bEtdT2RJ6vl3Ww
https://mp.weixin.qq.com/s/7NfXcNC4bEtdT2RJ6vl3Ww
DARPA:60岁的“创新偶像”
https://mp.weixin.qq.com/s/xFRR5tJBc2C_SLxOIhlHaw
https://mp.weixin.qq.com/s/xFRR5tJBc2C_SLxOIhlHaw
Ex-Dream Market Vendor 'OxyMonster' Sentenced to 20 Years in Prison
https://darkwebnews.com/law-enforcement/20yrs-sentenced-for-oxymonster/
https://darkwebnews.com/law-enforcement/20yrs-sentenced-for-oxymonster/
安全技术
TenSec 2018 安全议题 ppt 公开
https://paper.seebug.org/726/
https://paper.seebug.org/726/
jQuery-File-Upload <= 9.x 远程命令执行漏洞 (ImageMagick/Ghostscript)
https://blog.vulnspy.com/2018/10/23/jQuery-File-Upload-9-x-Remote-Code-Execution-With-ImageMagick-Ghostscript-CN/
https://blog.vulnspy.com/2018/10/23/jQuery-File-Upload-9-x-Remote-Code-Execution-With-ImageMagick-Ghostscript-CN/
安大略湖畔的安全之光——ACM CCS 2018 小记(3)
https://zhuanlan.zhihu.com/p/47333518
https://zhuanlan.zhihu.com/p/47333518
安大略湖畔的安全之光——ACM CCS 2018 小记(4)
https://zhuanlan.zhihu.com/p/47481683
https://zhuanlan.zhihu.com/p/47481683
Platypus 反弹 Shell 构建僵尸网络
https://github.com/WangYihang/Platypus
https://github.com/WangYihang/Platypus
2018年中国网络安全产业报告
https://mp.weixin.qq.com/s/t54wFWBxA1iKr74LB_KFRg
https://mp.weixin.qq.com/s/t54wFWBxA1iKr74LB_KFRg
利用C++和C#绕过AV检测
https://xz.aliyun.com/t/3008
https://xz.aliyun.com/t/3008
Linux应急响应(一):SSH暴力破解
https://mp.weixin.qq.com/s/1I0MpWXcyJoe5zGFLnv8gw
https://mp.weixin.qq.com/s/1I0MpWXcyJoe5zGFLnv8gw
Available Artifacts - Evidence of Execution
https://blog.1234n6.com/2018/10/available-artifacts-evidence-of.html
https://blog.1234n6.com/2018/10/available-artifacts-evidence-of.html
Rapid Anomaly Detection Via Ransom Note File Classification
https://www.endgame.com/blog/technical-blog/stop-and-step-away-data-rapid-anomaly-detection-ransom-note-file-classification
https://www.endgame.com/blog/technical-blog/stop-and-step-away-data-rapid-anomaly-detection-ransom-note-file-classification
Linux应急响应(三):挖矿病毒
https://mp.weixin.qq.com/s/0q1XXqqQZiux3jvrP9zUOg
https://mp.weixin.qq.com/s/0q1XXqqQZiux3jvrP9zUOg
D-Link多型号路由器存在任意文件下载漏洞(CVE-2018-10822)
https://nosec.org/home/detail/1913.html
https://nosec.org/home/detail/1913.html
Udp2raw-Tunnel:一款功能强大的UDP隧道工具
https://www.freebuf.com/sectool/187069.html
https://www.freebuf.com/sectool/187069.html
二十年以来对 RSA 密码系统攻击综述
https://paper.seebug.org/727/
https://paper.seebug.org/727/
CVE-2018–8414: A Case Study in Responsible Disclosure
https://posts.specterops.io/cve-2018-8414-a-case-study-in-responsible-disclosure-ff74c39615ba
https://posts.specterops.io/cve-2018-8414-a-case-study-in-responsible-disclosure-ff74c39615ba
深入分析MikroTik RouterOS CVE-2018-14847 & Get bash shell
https://mp.weixin.qq.com/s/6FZqeG3ys2rYpuz7nXr_Lw
https://mp.weixin.qq.com/s/6FZqeG3ys2rYpuz7nXr_Lw
A Deep Dive into Cobalt Strike Malleable C2
http://threatexpress.com/2018/09/a-deep-dive-into-cobalt-strike-malleable-c2/
http://threatexpress.com/2018/09/a-deep-dive-into-cobalt-strike-malleable-c2/
基于时间的高效的SQL盲注-使用MySQL的位运算符
https://xz.aliyun.com/t/3054
https://xz.aliyun.com/t/3054
安全运维中基线检查的自动化之ansible工具巧用
https://bbs.ichunqiu.com/thread-46896-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-46896-1-1.html?from=sec
Linux应急响应(四):盖茨木马
https://mp.weixin.qq.com/s/-T9wupsSfW1Q73ocPgvMBg
https://mp.weixin.qq.com/s/-T9wupsSfW1Q73ocPgvMBg
2018达观杯文本智能处理挑战赛 Top10解决方案
https://github.com/moneyDboat/data_grand
https://github.com/moneyDboat/data_grand
ReShellAAS: Reverse Shell as a Service 反弹shell即服务
https://github.com/omg2hei/ReShellAAS
https://github.com/omg2hei/ReShellAAS
Twitter 公开俄罗斯伊朗机器人账号的推文存档
https://www.solidot.org/story?sid=58279
https://www.solidot.org/story?sid=58279
Focus Training欺诈意识培训和调查培训的课程简介
https://mp.weixin.qq.com/s/4eusVprYSyxjQHR9GpFB3A
https://mp.weixin.qq.com/s/4eusVprYSyxjQHR9GpFB3A
利用硬件性能计数器(HPCs) 检测嵌入式系统中的固件修改
http://www.arkteam.net/?p=4087
http://www.arkteam.net/?p=4087
Linux应急响应(二):捕捉短连接
https://mp.weixin.qq.com/s/tu3c0l_2Bu4kNGqp3tlxKw
https://mp.weixin.qq.com/s/tu3c0l_2Bu4kNGqp3tlxKw
phpStudy 批量入侵的分析与溯源
https://www.anquanke.com/post/id/162787
https://www.anquanke.com/post/id/162787
A profiling method for SSH Clients and Servers
https://engineering.salesforce.com/open-sourcing-hassh-abed3ae5044c?gi=a71f99d6cf2f
https://engineering.salesforce.com/open-sourcing-hassh-abed3ae5044c?gi=a71f99d6cf2f
Improve Security Analytics with the Elastic Stack, Wazuh, and IDS
https://www.elastic.co/cn/blog/improve-security-analytics-with-the-elastic-stack-wazuh-and-ids
https://www.elastic.co/cn/blog/improve-security-analytics-with-the-elastic-stack-wazuh-and-ids
triton-attribution-russian-government-owned-lab-most-likely-built-tools
https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html
https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html
WebExec之技术纲要(权限提升&代码执行)
https://xz.aliyun.com/t/3043
https://xz.aliyun.com/t/3043
SIEM中基于多层网络分析引擎的安全威胁预警研究
https://www.freebuf.com/articles/es/186617.html
https://www.freebuf.com/articles/es/186617.html
SecWiki周刊(第242期)
https://www.sec-wiki.com/weekly/242
https://www.sec-wiki.com/weekly/242
iOS渗透测试工具Part 1:App Decryption以及class-dump
http://www.4hou.com/mobile/13188.html
http://www.4hou.com/mobile/13188.html
Detecting Fake Videos
https://www.schneier.com/blog/archives/2018/10/detecting_fake_.html
https://www.schneier.com/blog/archives/2018/10/detecting_fake_.html
Dissecting Malicious Office Documents with Linux
https://isc.sans.edu/forums/diary/Dissecting+Malicious+Office+Documents+with+Linux/24248/
https://isc.sans.edu/forums/diary/Dissecting+Malicious+Office+Documents+with+Linux/24248/
NSA新型APT框架曝光:DarkPulsar
http://www.freebuf.com/articles/network/187424.html
http://www.freebuf.com/articles/network/187424.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第243期)
