SecWiki周刊(第268期)
2019/04/15-2019/04/21
安全资讯
维基解密公开的数千份可下载敏感文件
https://nosec.org/home/detail/2487.html
https://nosec.org/home/detail/2487.html
腾讯云鼎实验室掌门人Killer谈网络安全
https://mp.weixin.qq.com/s/MLvd1AmxE9YnkWWmB9L9VQ
https://mp.weixin.qq.com/s/MLvd1AmxE9YnkWWmB9L9VQ
企业海外机构信息安全保密风险分析及对策建议
https://mp.weixin.qq.com/s/jJyq7bYuq1xxGXpfnmKP3g
https://mp.weixin.qq.com/s/jJyq7bYuq1xxGXpfnmKP3g
互联网个人信息安全保护指南
http://www.beian.gov.cn/portal/topicDetail?id=88
http://www.beian.gov.cn/portal/topicDetail?id=88
国家安全机关公布三起境外网络攻击窃密案件
http://www.xinhuanet.com/legal/2019-04/18/c_1124383501.htm
http://www.xinhuanet.com/legal/2019-04/18/c_1124383501.htm
全球最大网络安全演习北约“锁盾”:法国夺冠
https://mp.weixin.qq.com/s/uY9EzJAg7OtJKgcFYwOVEA
https://mp.weixin.qq.com/s/uY9EzJAg7OtJKgcFYwOVEA
安全技术
Netsparker5.3破解版 Netsparker Pro 5.3.0.23162[cracked]
https://www.ddosi.com/b170/
https://www.ddosi.com/b170/
FuzzScanner:自研信息搜集开源小工具
https://mp.weixin.qq.com/s/qy_iunNY1DNnrnAsCpB3mw
https://mp.weixin.qq.com/s/qy_iunNY1DNnrnAsCpB3mw
Web弱口令通用检测方法探究
https://mp.weixin.qq.com/s/R0M1V0X4eG_GnSyZK3Fz_A
https://mp.weixin.qq.com/s/R0M1V0X4eG_GnSyZK3Fz_A
针对VxWorks设备的分析工具VxHunter介绍
https://mp.weixin.qq.com/s/RPLGCwb6do2LbIodFGoGBQ
https://mp.weixin.qq.com/s/RPLGCwb6do2LbIodFGoGBQ
真真假假的创新 - RSAC2019之三
https://mp.weixin.qq.com/s/pWZ3rRrRHOVMpxUc_vWgAg
https://mp.weixin.qq.com/s/pWZ3rRrRHOVMpxUc_vWgAg
2019年僵尸网络主动监测报告(第一期)
https://mp.weixin.qq.com/s/ptimjyH9wlamO83nPZMa-Q
https://mp.weixin.qq.com/s/ptimjyH9wlamO83nPZMa-Q
客串逆向工程,一瞬获悬镜WAF规则
https://drivertom.blogspot.com/2019/04/waf.html?m=1
https://drivertom.blogspot.com/2019/04/waf.html?m=1
VxWorks固件逆向:WRT54Gv8
https://www.anquanke.com/post/id/176481
https://www.anquanke.com/post/id/176481
一文洞悉DAST、SAST、IAST —Web应用安全测试技术对比浅谈
https://mp.weixin.qq.com/s/EWn9ktce3KB4P6zi4slnTA
https://mp.weixin.qq.com/s/EWn9ktce3KB4P6zi4slnTA
iSCSI未授权访问漏洞,数万iSCSI可能受影响
https://nosec.org/home/detail/2491.html
https://nosec.org/home/detail/2491.html
Confluence 未授权 RCE 分析(CVE-2019-3396)
https://paper.seebug.org/893/
https://paper.seebug.org/893/
数据分析与可视化:谁是安全圈的吃鸡第一人
https://www.freebuf.com/articles/web/199925.html
https://www.freebuf.com/articles/web/199925.html
Exposed: Cyberattacks on Cloud Honeypots
http://www.sophos.com/CloudHoneypotsReport
http://www.sophos.com/CloudHoneypotsReport
下一代SIEM@AI:从UEBA到SOAR
https://mp.weixin.qq.com/s/OYPooeIZp8hq4JebOHDJMg
https://mp.weixin.qq.com/s/OYPooeIZp8hq4JebOHDJMg
理清弄透:加密&解密、签名&验签
https://mp.weixin.qq.com/s/aw5V95kelBslFv-ScxUVMw
https://mp.weixin.qq.com/s/aw5V95kelBslFv-ScxUVMw
Spring Cloud Config Server 路径穿越与任意文件读取漏洞分析
https://xz.aliyun.com/t/4844
https://xz.aliyun.com/t/4844
阿里巴巴被发现了一个可以绕过waf的漏洞
https://nosec.org/home/detail/2483.html
https://nosec.org/home/detail/2483.html
个人PWN入坑常见方法总结
https://www.freebuf.com/articles/rookie/200207.html
https://www.freebuf.com/articles/rookie/200207.html
Multiple Vulnerabilities + WAF bypass to Account Takeover
https://medium.com/@y.shahinzadeh/chaining-multiple-vulnerabilities-waf-bypass-to-account-takeover-in-almost-all-alibabas-websites-f8643eaa2855
https://medium.com/@y.shahinzadeh/chaining-multiple-vulnerabilities-waf-bypass-to-account-takeover-in-almost-all-alibabas-websites-f8643eaa2855
DNScat2工具:通过DNS进行C&C通信
https://www.4hou.com/tools/17226.html
https://www.4hou.com/tools/17226.html
Red Team从0到1的实践与思考
https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg
https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg
osquery源码解读之分析shell_history
http://www.polaris-lab.com/index.php/archives/634/
http://www.polaris-lab.com/index.php/archives/634/
Bypass XSS Protection with xmp, noscript, noframes.. etc..
https://www.hahwul.com/2019/04/bypass-xss-protection-with-xmp-noscript-etc....html
https://www.hahwul.com/2019/04/bypass-xss-protection-with-xmp-noscript-etc....html
Revisiting TTPs: TimeStomper
https://posts.specterops.io/revisiting-ttps-timestomper-622d4c28a655
https://posts.specterops.io/revisiting-ttps-timestomper-622d4c28a655
基于Flink构建用户实时基础行为工程
https://www.infoq.cn/article/rQ*fI3BN9mWGsDcTjAHf
https://www.infoq.cn/article/rQ*fI3BN9mWGsDcTjAHf
osquery源码解读之分析process_open_socket
http://www.polaris-lab.com/index.php/archives/638/
http://www.polaris-lab.com/index.php/archives/638/
Virgilio: Your new Mentor for Data Science E-Learning
https://github.com/clone95/Virgilio
https://github.com/clone95/Virgilio
Reverse-engineering Broadcom wireless chipsets
https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
CRYPTOPOKEMON: Simple C++ cryptolocker Blowfish CBC
https://github.com/PokemonGoTeam/CRYPTOPOKEMON
https://github.com/PokemonGoTeam/CRYPTOPOKEMON
刘知远:NLP研究入门之道(一)
https://mp.weixin.qq.com/s/PVoQI85YkDSzlA46FRU1OQ
https://mp.weixin.qq.com/s/PVoQI85YkDSzlA46FRU1OQ
Android Cloak and Dagger Attack
https://medium.com/@targetpractice/cloak-and-dagger-malware-techniques-demystified-c4d8a035b94e
https://medium.com/@targetpractice/cloak-and-dagger-malware-techniques-demystified-c4d8a035b94e
浅析基于人格特征的内部高风险用户识别方法
https://www.freebuf.com/articles/network/200564.html
https://www.freebuf.com/articles/network/200564.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第268期)
