SecWiki周刊(第25期)
2014/08/18-2014/08/24
安全资讯
NSA黑客团队手抖,叙利亚举国断网三日
http://www.freebuf.com/news/41021.html
http://www.freebuf.com/news/41021.html
Black Hat USA安全隐患盘点及黑客奥斯卡颁奖
http://www.csdn.net/article/2014-08-14/2821195-the-top-10-leaks-exposed-on-black-hat-2014
http://www.csdn.net/article/2014-08-14/2821195-the-top-10-leaks-exposed-on-black-hat-2014
安全技术
recon 2014 video
http://recon.cx/2014/video/
http://recon.cx/2014/video/
开源运维堡垒机(跳板机)系统 python
http://laoguang.blog.51cto.com/6013350/1540080
http://laoguang.blog.51cto.com/6013350/1540080
《安全参考》HACKCTO-201408-20
http://pan.baidu.com/s/1eQzkhUy
http://pan.baidu.com/s/1eQzkhUy
短域名进化史,XSS,短网址,长度限制绕过
http://lcx.cc/?i=4416
http://lcx.cc/?i=4416
A Large-Scale Analysis of the Security of Embedded Firmwares
https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-costin.pdf
https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-costin.pdf
Network Forensics Puzzle Contest 2014 Walkthrough
http://forensicscontest.com/2014/08/14/network-forensics-puzzle-contest-2014-walkthrough#more-1221
http://forensicscontest.com/2014/08/14/network-forensics-puzzle-contest-2014-walkthrough#more-1221
Android Whitepapers
https://github.com/droidsec/droidsec.github.io/wiki/Android-Whitepapers
https://github.com/droidsec/droidsec.github.io/wiki/Android-Whitepapers
虚拟身份信息分析系统20080615-辽宁省
http://www.doc88.com/p-5156184304925.html
http://www.doc88.com/p-5156184304925.html
Youtobe Burp-Suite 入门视频
https://www.youtube.com/playlist?list=PLZOToVAK85MorLmAqD3117C0s9h7ccxaV
https://www.youtube.com/playlist?list=PLZOToVAK85MorLmAqD3117C0s9h7ccxaV
Forensic Analysis of Windows Shellbags
http://www.magnetforensics.com/forensic-analysis-of-windows-shellbags/
http://www.magnetforensics.com/forensic-analysis-of-windows-shellbags/
Web Server Attack Investigation
https://isc.sans.edu/forums/diary/Web+Server+Attack+Investigation+-+Installing+a+Bot+and+Reverse+Shell+via+a+PHP+Vulnerability/18543
https://isc.sans.edu/forums/diary/Web+Server+Attack+Investigation+-+Installing+a+Bot+and+Reverse+Shell+via+a+PHP+Vulnerability/18543
Getting Started with Android Forensics
http://resources.infosecinstitute.com/getting-started-android-forensics/
http://resources.infosecinstitute.com/getting-started-android-forensics/
三菱Q系列PLC以太网识别脚本(ICS Discovery Tools Releases)
http://plcscan.org/blog/2014/08/melsecq-plc-discover-tools-releases/
http://plcscan.org/blog/2014/08/melsecq-plc-discover-tools-releases/
53th-刘颖-基于互联网数据的社会经济预测
http://pan.baidu.com/s/1sjz3Kip
http://pan.baidu.com/s/1sjz3Kip
Hex-Rays Decompiler plugin (v1.5) and patch for IDA Pro6.5
http://www.h4ck.org.cn/2014/08/hex-rays-decompiler-plugin-v1-5-0-110408-and-patch-for-ida-pro6-5/
http://www.h4ck.org.cn/2014/08/hex-rays-decompiler-plugin-v1-5-0-110408-and-patch-for-ida-pro6-5/
Analyzing heap objects with mona.py
https://www.corelan.be/index.php/2014/08/16/analyzing-heap-objects-with-mona-py/
https://www.corelan.be/index.php/2014/08/16/analyzing-heap-objects-with-mona-py/
下一代远程控制木马的思路探讨
http://www.freebuf.com/articles/system/41241.html
http://www.freebuf.com/articles/system/41241.html
Password dictionaries
https://wiki.skullsecurity.org/Passwords
https://wiki.skullsecurity.org/Passwords
FireEye Cyber Threat Map
http://www.fireeye.com/cyber-map/threat-map.html
http://www.fireeye.com/cyber-map/threat-map.html
ModSecurity CRS 笔记
http://danqingdani.blog.163.com/blog/static/186094195201472304841643
http://danqingdani.blog.163.com/blog/static/186094195201472304841643
Windows 8 Kernel Memory Protections Bypass
https://labs.mwrinfosecurity.com/blog/2014/08/15/windows-8-kernel-memory-protections-bypass/
https://labs.mwrinfosecurity.com/blog/2014/08/15/windows-8-kernel-memory-protections-bypass/
对象的种群隔离与大小隔离之思考
http://weibo.com/p/1001603747202920018411
http://weibo.com/p/1001603747202920018411
WOOT '14 Papers ZIP
http://t.cn/RPueoZA
http://t.cn/RPueoZA
cve-2014-1767漏洞分析与讨论
http://binvul.com/viewthread.php?tid=450&extra=page%3D1
http://binvul.com/viewthread.php?tid=450&extra=page%3D1
跨终端实践-天猫试戴的解决方案
https://github.com/tmallfe/tmallfe.github.io/issues/4
https://github.com/tmallfe/tmallfe.github.io/issues/4
Secure Planet WIKI
https://www.securepla.net/wiki/index.php?title=Main_Page
https://www.securepla.net/wiki/index.php?title=Main_Page
Tracking Attackers: Honeypot, Part 1 (Honeyd)
http://resources.infosecinstitute.com/tracking-attackers-honeypot-part-1-honeyd/
http://resources.infosecinstitute.com/tracking-attackers-honeypot-part-1-honeyd/
darshak:Detecting any suspicious activity of being tracked
https://github.com/darshakframework/darshak
https://github.com/darshakframework/darshak
meterpreter之pivot
http://www.coolhacker.org/?p=1669
http://www.coolhacker.org/?p=1669
安防IP Camera固件分析
http://drops.wooyun.org/papers/2792
http://drops.wooyun.org/papers/2792
Amaze UI:中国首个开源 HTML5 跨屏前端框架
http://amazeui.org/
http://amazeui.org/
调用域名注册api,查询所有域名组合脚本
http://laoguang.blog.51cto.com/6013350/1531198
http://laoguang.blog.51cto.com/6013350/1531198
How To Set Up mod_security with Apache on Debian/Ubuntu
https://www.digitalocean.com/community/tutorials/how-to-set-up-mod_security-with-apache-on-debian-ubuntu
https://www.digitalocean.com/community/tutorials/how-to-set-up-mod_security-with-apache-on-debian-ubuntu
用程序生成word文档(DOC)
http://haoluobo.com/2014/08/gen-word-doc/
http://haoluobo.com/2014/08/gen-word-doc/
RTFM 0day in iOS apps: G+, Gmail, FB Messenger, etc.
http://algorithm.dk/posts/rtfm-0day-in-ios-apps-g-gmail-fb-messenger-etc
http://algorithm.dk/posts/rtfm-0day-in-ios-apps-g-gmail-fb-messenger-etc
HTML5 App的代码注入攻击
http://phpsec.sinaapp.com/?p=152
http://phpsec.sinaapp.com/?p=152
日志管理平台 Logentries
https://github.com/logentries
https://github.com/logentries
Obfuscation in Android malware, and how to fight back
https://www.virusbtn.com/pdf/magazine/2014/vb201407-Android-obfuscation.pdf
https://www.virusbtn.com/pdf/magazine/2014/vb201407-Android-obfuscation.pdf
The UCSB iCTF
http://ictf.cs.ucsb.edu/framework#/
http://ictf.cs.ucsb.edu/framework#/
Routards Team Blog: Defcon 22 CTF
http://www.routards.org/2014/08/defcon-22-ctf-badger.html
http://www.routards.org/2014/08/defcon-22-ctf-badger.html
ByWaf: a web application penetration testing framework (WAPTF)
https://github.com/depasonico/OWASP-ByWaf
https://github.com/depasonico/OWASP-ByWaf
Browser Intranet Hacking [video]
http://blog.whitehatsec.com/browser-intranet-hacking-video/
http://blog.whitehatsec.com/browser-intranet-hacking-video/
WeRoBot:微信机器人框架
https://werobot.readthedocs.org/en/latest/
https://werobot.readthedocs.org/en/latest/
Discuz 5.x/6.x/7.x投票SQL注入分析
http://www.freebuf.com/articles/web/41287.html
http://www.freebuf.com/articles/web/41287.html
Laravel From Scratch
https://laracasts.com/series/laravel-from-scratch
https://laracasts.com/series/laravel-from-scratch
美团通用性能监控平台和WEB性能分析框架
http://share.csdn.net/slides/7171
http://share.csdn.net/slides/7171
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第25期)
