SecWiki周刊(第359期)
2021/01/11-2021/01/17
安全资讯
公安部网安局公布一批网络黑产案例
https://mp.weixin.qq.com/s/uXupT3yeeOA9NWVjQORgDQ
https://mp.weixin.qq.com/s/uXupT3yeeOA9NWVjQORgDQ
安全技术
通过 OpenVPN 实现流量审计
https://green-m.me//2021/01/12/audit-traffic-through-openvpn/
https://green-m.me//2021/01/12/audit-traffic-through-openvpn/
Netgear固件分析与后门植入
https://mp.weixin.qq.com/s/o9v4V673ayyMTY1vGjveFg
https://mp.weixin.qq.com/s/o9v4V673ayyMTY1vGjveFg
自动化渗透测试系统技术路径分析
https://mp.weixin.qq.com/s/gtXfPvT8Yatp3IMVdCID7Q
https://mp.weixin.qq.com/s/gtXfPvT8Yatp3IMVdCID7Q
局域网监控软件WFilter ICF 鸡肋0day RCE漏洞挖掘
https://drivertom.blogspot.com/2021/01/wfilter-icf-0day-rce.html
https://drivertom.blogspot.com/2021/01/wfilter-icf-0day-rce.html
Real World CTF 2020 DBaaSadge Writeup
https://www.hetianlab.com/specialized/20210112133159
https://www.hetianlab.com/specialized/20210112133159
基于机器学习的Web管理后台识别方法探索
https://mp.weixin.qq.com/s/vccQcK2GNqWkGuxEGe22Zg
https://mp.weixin.qq.com/s/vccQcK2GNqWkGuxEGe22Zg
Js文件追踪到未授权访问
https://www.sec-in.com/article/806
https://www.sec-in.com/article/806
开源包托管服务存在的供应链安全问题
https://mp.weixin.qq.com/s/DjfldjeqJY786nqdcsXzBg
https://mp.weixin.qq.com/s/DjfldjeqJY786nqdcsXzBg
BORG :一个快速进化的僵尸网络
https://security.tencent.com/index.php/blog/msg/175
https://security.tencent.com/index.php/blog/msg/175
关于PDD员工发帖溯源联想到的相关技术与实现
https://mp.weixin.qq.com/s/coRsNLMT_FAr6xSHwPgOUg
https://mp.weixin.qq.com/s/coRsNLMT_FAr6xSHwPgOUg
SecWiki安全周刊-年卷-2020
https://mp.weixin.qq.com/s/pI495N48AYbA3gYkf4zlqQ
https://mp.weixin.qq.com/s/pI495N48AYbA3gYkf4zlqQ
NDSS 2021 论文录用列表
https://mp.weixin.qq.com/s/6QVEJP-Z8s-NgrbNoAiH2Q
https://mp.weixin.qq.com/s/6QVEJP-Z8s-NgrbNoAiH2Q
G.O.S.S.I.P 安全学术会议排行榜(2020版)
https://feysh.com/ranking/2020/
https://feysh.com/ranking/2020/
在XML中测试Fastjson反序列化
https://www.sec-in.com/article/810
https://www.sec-in.com/article/810
子域名枚举的艺术——主动子域枚举
https://www.sec-in.com/article/793
https://www.sec-in.com/article/793
Cobalt Strike4.0远控木马分析
https://mp.weixin.qq.com/s/Sv0lR4G2eQf4_L8W4CqRYw
https://mp.weixin.qq.com/s/Sv0lR4G2eQf4_L8W4CqRYw
初探 Python Flask+Jinja2 SSTI
https://www.anquanke.com/post/id/226900
https://www.anquanke.com/post/id/226900
组策略限制3389登录的绕过方式
https://mp.weixin.qq.com/s/4eDNmiiXp7afLKdYzHeb3Q
https://mp.weixin.qq.com/s/4eDNmiiXp7afLKdYzHeb3Q
深度探索:解除文件占用那些坑
https://anhkgg.com/unlockfile/
https://anhkgg.com/unlockfile/
JSON DataSet for macOS mapped to MITRE ATT&CK Tactics
https://github.com/sbousseaden/macOS-ATTACK-DATASET
https://github.com/sbousseaden/macOS-ATTACK-DATASET
incaseformat来袭,针对病毒进行分析
https://mp.weixin.qq.com/s/EwExVZqmiLLZ5R3172d2wQ
https://mp.weixin.qq.com/s/EwExVZqmiLLZ5R3172d2wQ
SecWiki周刊(第358期)
https://www.sec-wiki.com/weekly/358
https://www.sec-wiki.com/weekly/358
SharePoint Rce 系列分析(三)
https://mp.weixin.qq.com/s/Z2hDtlsu0zgKY8YWhDBS7g
https://mp.weixin.qq.com/s/Z2hDtlsu0zgKY8YWhDBS7g
SharePoint Rce 系列分析(二)
https://mp.weixin.qq.com/s/ZLSFXUoNNAFxqeiD9RpYZg
https://mp.weixin.qq.com/s/ZLSFXUoNNAFxqeiD9RpYZg
浅谈绕过disable_functions的部分方法的原理
https://www.anquanke.com/post/id/228712
https://www.anquanke.com/post/id/228712
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第359期)
