SecWiki周刊(第246期)
2018/11/12-2018/11/18
安全资讯
腾讯安全守门人 Coolc:黑客站在旷野,他们有时孤独
https://mp.weixin.qq.com/s/bTdL34ugYJ67vIkVBmGexg
https://mp.weixin.qq.com/s/bTdL34ugYJ67vIkVBmGexg
美国公布长达35页的《2016—2045年新兴科技趋势报告》
https://mp.weixin.qq.com/s/okd_GK0-DzCDsuVB-yxoYQ
https://mp.weixin.qq.com/s/okd_GK0-DzCDsuVB-yxoYQ
安全技术
2018最新PHP漏洞利用技巧
http://zeroyu.xyz/2018/11/13/New-PHP-exploit-techniques/
http://zeroyu.xyz/2018/11/13/New-PHP-exploit-techniques/
Bellingcat's Online Investigation Toolkit
https://docs.google.com/document/d/1BfLPJpRtyq4RFtHJoNpvWQjmGnyVkfE2HYoICKOGguA/edit#heading=h.po9n93ahppok
https://docs.google.com/document/d/1BfLPJpRtyq4RFtHJoNpvWQjmGnyVkfE2HYoICKOGguA/edit#heading=h.po9n93ahppok
勒索软件种类在线检测及对应解密软件下载
https://www.nomoreransom.org/crypto-sheriff.php?lang=zh
https://www.nomoreransom.org/crypto-sheriff.php?lang=zh
CTF pwn 中最通俗易懂的堆入坑指南
https://www.anquanke.com/post/id/163971
https://www.anquanke.com/post/id/163971
Serialization flaw in wp-gdpr-compliance
https://medium.com/alertot/serialization-flaw-in-wp-gdpr-compliance-8cfc8feb4ec3
https://medium.com/alertot/serialization-flaw-in-wp-gdpr-compliance-8cfc8feb4ec3
威胁猎杀实战(三)-基于Wazuh, Snort/Suricata和Elastic Stack的SOC
https://blog.tianyulab.com/post/ty-practical-guide-to-threat-hunting-03/
https://blog.tianyulab.com/post/ty-practical-guide-to-threat-hunting-03/
深入理解Double Free:CVE-2015-2419 Exploit分析
https://www.freebuf.com/vuls/188558.html
https://www.freebuf.com/vuls/188558.html
手把手教你如何用MSF进行后渗透测试
https://www.anquanke.com/post/id/164525
https://www.anquanke.com/post/id/164525
中间人攻击框架xerosploit介绍
https://mp.weixin.qq.com/s/GdzoLZ78Gy3iTEwxsSTh3Q
https://mp.weixin.qq.com/s/GdzoLZ78Gy3iTEwxsSTh3Q
威胁猎杀实战(二): NIDS和HIDS关联
https://blog.tianyulab.com/post/ty-practical-guide-to-threat-hunting-02/
https://blog.tianyulab.com/post/ty-practical-guide-to-threat-hunting-02/
HCTF 2018 Web Write-up
http://momomoxiaoxi.com/ctf/2018/11/12/HCTF2018/
http://momomoxiaoxi.com/ctf/2018/11/12/HCTF2018/
Adobe ColdFusion最新文件上传漏洞实际利用在公网被发现(CVE-2018-15961)
https://nosec.org/home/detail/1953.html
https://nosec.org/home/detail/1953.html
Feed the tool a .nessus file and it will automatically get you MSF shell
https://github.com/DanMcInerney/msf-autoshell
https://github.com/DanMcInerney/msf-autoshell
Sandbox escape using WinHTTP Web Proxy Auto-Discovery Service
https://github.com/hacksysteam/WpadEscape
https://github.com/hacksysteam/WpadEscape
CaptfEncoder:一款跨平台网络安全工具套件
https://www.freebuf.com/sectool/188397.html
https://www.freebuf.com/sectool/188397.html
Machine Learning for Red Teams, Part 1
https://silentbreaksecurity.com/machine-learning-for-red-teams-part-1/
https://silentbreaksecurity.com/machine-learning-for-red-teams-part-1/
Privilege Escalation in gVisor, Google's Container Sandbox
https://justi.cz/security/2018/11/14/gvisor-lpe.html
https://justi.cz/security/2018/11/14/gvisor-lpe.html
企业安全建设之探索安全数据分析平台
https://xz.aliyun.com/t/3294
https://xz.aliyun.com/t/3294
使用基于浏览器的端口扫描来探测内网情况
https://nosec.org/home/detail/1954.html
https://nosec.org/home/detail/1954.html
phpinfo可以告诉我们什么
http://zeroyu.xyz/2018/11/13/what-phpinfo-can-tell-we/
http://zeroyu.xyz/2018/11/13/what-phpinfo-can-tell-we/
Google MyAccount价值7500美金的点击劫持漏洞
https://nosec.org/home/detail/1960.html
https://nosec.org/home/detail/1960.html
Simplifying API Pentesting With Swagger Files
https://rhinosecuritylabs.com/application-security/simplifying-api-pentesting-swagger-files/
https://rhinosecuritylabs.com/application-security/simplifying-api-pentesting-swagger-files/
以太坊智能合约审计 CheckList
https://paper.seebug.org/741/
https://paper.seebug.org/741/
Adobe ColdFusion远程命令执行漏洞预警(CVE-2018-15961)
https://nosec.org/home/detail/1958.html
https://nosec.org/home/detail/1958.html
“以太坊智能合约编码隐患”影响分析报告
https://lorexxar.cn/2018/11/08/haotian-s-5/
https://lorexxar.cn/2018/11/08/haotian-s-5/
phpmyadmin getshell姿势
https://xz.aliyun.com/t/3283
https://xz.aliyun.com/t/3283
4 种常见“无文件”攻击技术解析
https://mp.weixin.qq.com/s/eHsa0DgeogZN-tO5r3FeLg
https://mp.weixin.qq.com/s/eHsa0DgeogZN-tO5r3FeLg
从一个iCloud钓鱼网站挖掘幕后人信息
https://zhuanlan.zhihu.com/p/49422034
https://zhuanlan.zhihu.com/p/49422034
PHP 运行时漏洞检测
http://blog.fatezero.org/2018/11/11/prvd/
http://blog.fatezero.org/2018/11/11/prvd/
Privacy Online Test And Resource Compendium (POTARC)
https://github.com/CHEF-KOCH/Online-Privacy-Test-Resource-List
https://github.com/CHEF-KOCH/Online-Privacy-Test-Resource-List
JBoss RichFaces EL Injection RCE Analysis(CVE-2018-14667)
https://mp.weixin.qq.com/s/aB9eKXy5OUaivhAPRnzM0w
https://mp.weixin.qq.com/s/aB9eKXy5OUaivhAPRnzM0w
HCTF2018 部分 web 题目 Writeup
https://paper.seebug.org/744/
https://paper.seebug.org/744/
疑似Group 123 APT团伙利用HWP软件未公开漏洞的定向攻击分析
https://www.freebuf.com/vuls/188846.html
https://www.freebuf.com/vuls/188846.html
被遗漏的0day ? —APT-C-06组织另一网络武器库分析揭秘
https://paper.seebug.org/743/
https://paper.seebug.org/743/
Basic shellcoding for linux on x86
https://rayoflightz.github.io/shellcoding/linux/x86/2018/11/15/Shellcoding-for-linux-on-x86.html
https://rayoflightz.github.io/shellcoding/linux/x86/2018/11/15/Shellcoding-for-linux-on-x86.html
我是如何发现影响约20个Uber子域的XSS漏洞的
https://nosec.org/home/detail/1964.html
https://nosec.org/home/detail/1964.html
SecWiki周刊(第245期)
https://www.sec-wiki.com/weekly/245
https://www.sec-wiki.com/weekly/245
(C)0ld Case : From Aerospace to China’s interests
https://cyberthreatintelligenceblog.wordpress.com/2018/11/16/c0ld-case-from-aerospace-to-chinas-interests/
https://cyberthreatintelligenceblog.wordpress.com/2018/11/16/c0ld-case-from-aerospace-to-chinas-interests/
关键信息基础设施重要信息资产漏洞治理的实践和思考
https://mp.weixin.qq.com/s/eQyc2jye-mrKBLhba_JP3g
https://mp.weixin.qq.com/s/eQyc2jye-mrKBLhba_JP3g
恶意挖矿攻击的现状、检测及处置
https://www.anquanke.com/post/id/164447
https://www.anquanke.com/post/id/164447
Bettercap Using in Penetration Tests
https://www.prismacsi.com/en/bettercap-using-in-penetration-tests/
https://www.prismacsi.com/en/bettercap-using-in-penetration-tests/
机器翻译学术论文写作方法和技巧
https://mp.weixin.qq.com/s/Th1ESj8WLZVFLzholoAC1g
https://mp.weixin.qq.com/s/Th1ESj8WLZVFLzholoAC1g
FCL (Fileless Command Lines) - Known command lines of fileless malicious executi
https://github.com/chenerlich/FCL
https://github.com/chenerlich/FCL
BabySploit Beginner Pentesting Framework Written in Python
https://github.com/M4cs/BabySploit
https://github.com/M4cs/BabySploit
西门子通信协议S7COMM(Part 2)
https://www.freebuf.com/articles/ics-articles/188606.html
https://www.freebuf.com/articles/ics-articles/188606.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第246期)
