SecWiki周刊(第346期)
2020/10/12-2020/10/18
安全技术
momo-code-sec-inspector-java: IDEA静态代码安全审计插件
https://github.com/momosecurity/momo-code-sec-inspector-java
https://github.com/momosecurity/momo-code-sec-inspector-java
电报(telegram)开源情报工具及技巧
https://mp.weixin.qq.com/s/9HLP4Gcgo0yx3WVB-odK9A
https://mp.weixin.qq.com/s/9HLP4Gcgo0yx3WVB-odK9A
Adminer≤4.6.2任意文件读取漏洞
https://mp.weixin.qq.com/s/ZYGN8WceT2L-P4yF6Z8gyQ
https://mp.weixin.qq.com/s/ZYGN8WceT2L-P4yF6Z8gyQ
Goby自定义漏洞之EXP
https://mp.weixin.qq.com/s/J1JW66Uh_6Nc0x2YY_5V6Q
https://mp.weixin.qq.com/s/J1JW66Uh_6Nc0x2YY_5V6Q
Hacking All The Cars之Tesla API分析与利用(上)
https://bacde.me/post/hacking-all-the-cars-tesla-api-exploit-part-one/
https://bacde.me/post/hacking-all-the-cars-tesla-api-exploit-part-one/
Pickle反序列化源码分析与漏洞利用
https://xz.aliyun.com/t/8342
https://xz.aliyun.com/t/8342
Tomcat 内存马检测
https://www.anquanke.com/post/id/219177
https://www.anquanke.com/post/id/219177
IAST安全测试如何防止数据污染
https://mp.weixin.qq.com/s/VeUscKDI0o1jL9uDYywgow
https://mp.weixin.qq.com/s/VeUscKDI0o1jL9uDYywgow
Xcheck之Golang安全检查引擎
https://mp.weixin.qq.com/s/VzjcXp3O8zc97aIppy4LUA
https://mp.weixin.qq.com/s/VzjcXp3O8zc97aIppy4LUA
browser-pwn cve-2020-6418 漏洞分析
https://paper.seebug.org/1358/
https://paper.seebug.org/1358/
最右sign-v2签名算法追踪及逆向还原
https://mp.weixin.qq.com/s/5hmsU_CNGp7habqwSVVckg
https://mp.weixin.qq.com/s/5hmsU_CNGp7habqwSVVckg
网络访问权限检查工具PropertyScanner
https://www.anquanke.com/post/id/219093
https://www.anquanke.com/post/id/219093
利用不安全的JSONP绕过SSO实现账户接管(分析+实践)
https://xz.aliyun.com/t/8350
https://xz.aliyun.com/t/8350
Nautilus:一款基于语法的反馈式模糊测试工具
https://mp.weixin.qq.com/s/LrSFAX_WQEPQQvhhOrXWgA
https://mp.weixin.qq.com/s/LrSFAX_WQEPQQvhhOrXWgA
针对中东石油和天然气供应链的攻击
https://paper.seebug.org/1368/
https://paper.seebug.org/1368/
2019 BDCI互联网金融新实体发现
https://github.com/light8lee/2019-BDCI-FinancialEntityDiscovery
https://github.com/light8lee/2019-BDCI-FinancialEntityDiscovery
《透视APT》读书笔记
https://xz.aliyun.com/t/8335
https://xz.aliyun.com/t/8335
折腾MobSF APP隐私合规如何与技术检查结合(一)
https://blog.csdn.net/bloodzero_new/article/details/109105051
https://blog.csdn.net/bloodzero_new/article/details/109105051
SecWiki周刊(第345期)
https://www.sec-wiki.com/weekly/345
https://www.sec-wiki.com/weekly/345
详尽的 HTTPS 原理详解图
https://segmentfault.com/a/1190000021494676
https://segmentfault.com/a/1190000021494676
DependencyTrack: 开源软件成分分析平台
https://github.com/DependencyTrack/dependency-track
https://github.com/DependencyTrack/dependency-track
从RSA创新沙盒决赛产品ShiftLeft浅谈DevSecOps
https://mp.weixin.qq.com/s/WyxhX4tuMOSBCF1R9obLKg
https://mp.weixin.qq.com/s/WyxhX4tuMOSBCF1R9obLKg
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第346期)
