SecWiki周刊(第38期)
2014/11/17-2014/11/23
安全资讯
MITMf:中间人攻击框架
http://www.91ri.org/10918.html
http://www.91ri.org/10918.html
一种自动化检测 Flash 中 XSS 方法的探讨
http://www.91ri.org/11464.html
http://www.91ri.org/11464.html
.NET远程代码执行(MS14-026/CVE-2014-1806)
http://www.91ri.org/11461.html
http://www.91ri.org/11461.html
某cms程序SQL注入(demo测试)
http://www.shellsec.com/tech/187619.html
http://www.shellsec.com/tech/187619.html
安全科普:什么是暴力破解攻击?如何检测和防御?
http://www.freebuf.com/news/special/52361.html
http://www.freebuf.com/news/special/52361.html
PHP应用安全静态代码分析工具 – WAP 2.0
http://www.freebuf.com/tools/52333.html
http://www.freebuf.com/tools/52333.html
PHP Execute Command Bypass Disable_functions
http://www.91ri.org/11321.html
http://www.91ri.org/11321.html
Exploit搜索工具 – Pompem
http://www.freebuf.com/tools/51796.html
http://www.freebuf.com/tools/51796.html
域控制器的用户尽快升级MS14-068补丁
http://blog.sina.com.cn/s/blog_e8e60bc00102v9k7.html
http://blog.sina.com.cn/s/blog_e8e60bc00102v9k7.html
在遭中国黑客攻击之后Google与NSA结盟
http://www.solidot.org/story?sid=41905
http://www.solidot.org/story?sid=41905
一周海外安全事件回顾(11.03-11.15):黑暗网络的坠落
http://www.freebuf.com/news/51974.html
http://www.freebuf.com/news/51974.html
安全技术
安卓Bug 17356824 BroadcastAnywhere漏洞分析
http://drops.wooyun.org/papers/3912
http://drops.wooyun.org/papers/3912
漏洞预警:.NET远程代码执行漏洞(含EXP)
http://www.freebuf.com/vuls/51981.html
http://www.freebuf.com/vuls/51981.html
安全科普:你的密码在谁的手里?
http://www.freebuf.com/news/special/52234.html
http://www.freebuf.com/news/special/52234.html
震网病毒Stuxnet之子 – Duqu的现身
http://www.freebuf.com/news/52249.html
http://www.freebuf.com/news/52249.html
沙虫漏洞(CVE-2014-4114)利用测试方法
http://www.freebuf.com/vuls/51735.html
http://www.freebuf.com/vuls/51735.html
战斗之旅——SSCTF(一)
http://www.91ri.org/11349.html
http://www.91ri.org/11349.html
勒索软件CoinVault:拿钱来,给你一个恢复文件的机会
http://www.freebuf.com/news/51899.html
http://www.freebuf.com/news/51899.html
ModSecurity 晋级-如何调用lua脚本进行防御快速入门
http://danqingdani.blog.163.com/blog/static/1860941952014101862337903/
http://danqingdani.blog.163.com/blog/static/1860941952014101862337903/
IE浏览器“神洞”CVE-2014-6332已经被用作定向攻击
http://blog.vulnhunt.com/index.php/2014/11/18/cve-2014-6332-used-in-targeted-attack/
http://blog.vulnhunt.com/index.php/2014/11/18/cve-2014-6332-used-in-targeted-attack/
WEB调试工具---Firebug
http://www.imooc.com/view/137?utm_source=jobboleweibo
http://www.imooc.com/view/137?utm_source=jobboleweibo
XML实体攻击-从内网探测到命令执行步步惊心
http://bobao.360.cn/course/detail/95.html
http://bobao.360.cn/course/detail/95.html
Win95+IE3 – Win10+IE11全版本执行漏洞(含POC)
http://www.freebuf.com/articles/system/51501.html
http://www.freebuf.com/articles/system/51501.html
Zero Day Initiative
http://www.zerodayinitiative.com/advisories/published/?nsukey=H3ybxI6z8vYpfXCHC7ZctZZ5WVg4BD1C0trgyAOTHU34SON%2Bfg%2FV3xdn9v95hZJGkmOFBybUHYsWQarBfBtCfQ%3D%3D
http://www.zerodayinitiative.com/advisories/published/?nsukey=H3ybxI6z8vYpfXCHC7ZctZZ5WVg4BD1C0trgyAOTHU34SON%2Bfg%2FV3xdn9v95hZJGkmOFBybUHYsWQarBfBtCfQ%3D%3D
使用Pfsense+Snorby构建入侵检测系统
http://www.freebuf.com/articles/network/51473.html
http://www.freebuf.com/articles/network/51473.html
CVE-2014-1767_Afd.sys_double-free_漏洞分析与利用
http://bbs.pediy.com/showthread.php?p=1331045#post1331045
http://bbs.pediy.com/showthread.php?p=1331045#post1331045
2014中华架构师大会PPT
http://vdisk.weibo.com/s/A2SbHmu4fAWi/1416472883
http://vdisk.weibo.com/s/A2SbHmu4fAWi/1416472883
安全研究进阶_yuange1975
http://blog.sina.com.cn/s/blog_85e506df0102v9o8.html
http://blog.sina.com.cn/s/blog_85e506df0102v9o8.html
Trigger the ms14-066
http://blog.beyondtrust.com/triggering-ms14-066
http://blog.beyondtrust.com/triggering-ms14-066
IE远程代码执行漏洞(CVE-2014-6332)利用测试方法
http://www.freebuf.com/vuls/51628.html
http://www.freebuf.com/vuls/51628.html
开源跳板机(堡垒机)Jumpserver
http://laoguang.blog.51cto.com/6013350/1576502
http://laoguang.blog.51cto.com/6013350/1576502
chm文件执行任意代码
http://xiaonieblog.com/?post=128
http://xiaonieblog.com/?post=128
战斗之旅——SSCTF(二)
http://www.91ri.org/11390.html
http://www.91ri.org/11390.html
免费开源相册Piwigo <= v2.6.0 SQL注入漏洞(0day)
http://www.freebuf.com/vuls/51401.html
http://www.freebuf.com/vuls/51401.html
PHP WDDX Serializier Data Injection Vulnerability
http://drops.wooyun.org/tips/3911
http://drops.wooyun.org/tips/3911
IRMA在线分析系统
http://irma.quarkslab.com/
http://irma.quarkslab.com/
关于重复发包的防护与绕过
http://drops.wooyun.org/web/3910
http://drops.wooyun.org/web/3910
博客安全:如何为WordPress做安全防护?
http://www.freebuf.com/articles/web/49210.html
http://www.freebuf.com/articles/web/49210.html
SSLStrip 终极版:Location 瞒天过海
http://www.freebuf.com/articles/web/50771.html
http://www.freebuf.com/articles/web/50771.html
一些Malware、Virus、Worm相关的文档和电子书
http://m.weibo.cn/1684840802/3778153060791056/weixin?sourceType=weixin&from=1046295010&wm=5091_0008
http://m.weibo.cn/1684840802/3778153060791056/weixin?sourceType=weixin&from=1046295010&wm=5091_0008
Pullcore-永久免费的新闻标题核心词提取API
http://pullcore.com/
http://pullcore.com/
Smashing_The_Browser
https://github.com/demi6od/Smashing_The_Browser
https://github.com/demi6od/Smashing_The_Browser
Debugging and reverse engineering: Stuxnet
http://bsodanalysis.blogspot.sg/2014/11/stuxnet-kernel-analysis.html
http://bsodanalysis.blogspot.sg/2014/11/stuxnet-kernel-analysis.html
Mongodb注入攻击
http://drops.wooyun.org/tips/3939
http://drops.wooyun.org/tips/3939
Radare - Forensic Android Tool
http://www.radare.org/y/?p=download
http://www.radare.org/y/?p=download
PHP绕过open_basedir列目录的研究
http://drops.wooyun.org/tips/3978
http://drops.wooyun.org/tips/3978
Optimizing Disk IO and Memory for Big Data Vector Analysis
http://blogs.teradata.com/data-points/optimizing-disk-io-and-memory-for-big-data-vector-analysis/
http://blogs.teradata.com/data-points/optimizing-disk-io-and-memory-for-big-data-vector-analysis/
小窥杀软主防+某杀软反注入exp
http://bbs.pediy.com/showthread.php?p=1332925#post1332925
http://bbs.pediy.com/showthread.php?p=1332925#post1332925
PHP Session 序列化及反序列化处理器设置使用不当带来的安全隐患
http://drops.wooyun.org/tips/3909
http://drops.wooyun.org/tips/3909
Google与NSA(美国国安局)结盟,共同对抗黑客
http://www.freebuf.com/news/51956.html
http://www.freebuf.com/news/51956.html
2014 WOT全球软件技术峰会PPT
http://down.51cto.com/zt/6814/1
http://down.51cto.com/zt/6814/1
PHP Execute Command Bypass Disable_functions With Shellshock
http://www.secpulse.com/archives/2300.html
http://www.secpulse.com/archives/2300.html
CVE-2014-6332 ie漏洞利用分析
http://xteam.baidu.com/?p=104
http://xteam.baidu.com/?p=104
老掉牙的12306根证书问题可导致中间人攻击
http://www.wooyun.org/bugs/wooyun-2014-082725
http://www.wooyun.org/bugs/wooyun-2014-082725
PHP Execute Command Bypass Disable_functions
http://zone.wooyun.org/content/16631
http://zone.wooyun.org/content/16631
Deobfuscation and beyond (ZeroNights, 2014)
http://www.slideshare.net/ReCrypt/deobfuscation-and-beyond
http://www.slideshare.net/ReCrypt/deobfuscation-and-beyond
Static-DOM-XSS-Scanner
https://github.com/ajinabraham/Static-DOM-XSS-Scanner
https://github.com/ajinabraham/Static-DOM-XSS-Scanner
Android Hacking and Security, Part 13: Introduction to Drozer
http://resources.infosecinstitute.com/android-hacking-security-part-13-introduction-drozer/
http://resources.infosecinstitute.com/android-hacking-security-part-13-introduction-drozer/
APT事件技术文档索引库
http://git.oschina.net/superme/APTnotes
http://git.oschina.net/superme/APTnotes
Data Mining in Social Science
http://lingfeiw.gitbooks.io/data-mining-in-social-science/
http://lingfeiw.gitbooks.io/data-mining-in-social-science/
XCTF HCTF Reverse Writeup
http://www.programlife.net/xctf-hctf-reverse-writeup.html
http://www.programlife.net/xctf-hctf-reverse-writeup.html
不只是搜索引擎:10个鲜为人知谷歌搜索功能
http://www.shellsec.com/tech/187536.html
http://www.shellsec.com/tech/187536.html
社会信息学2014巴塞罗那会议报告
http://www.jianshu.com/p/81075168240e
http://www.jianshu.com/p/81075168240e
捣毁Tor网络黑市:400个匿名站点被关,丝绸之路2.0经营者被捕
http://www.freebuf.com/news/50903.html
http://www.freebuf.com/news/50903.html
NoSuchCon 2014 大会资料
http://www.nosuchcon.org/talks/2014/
http://www.nosuchcon.org/talks/2014/
Advanced Exploitation of Mozilla Firefox Use-After-Free Vulnerability
http://www.vupen.com/blog/20140520.Advanced_Exploitation_Firefox_UaF_Pwn2Own_2014.php?nsukey=9s%2BGDLjFM2hq51rKHzOfJbHEZ6vfVkIcD4bFMXkcMfYm2msBPSzpn5ErG7MIq6Ljh8F3jSt7ksTOZu6wm6VbMA%3D%3D
http://www.vupen.com/blog/20140520.Advanced_Exploitation_Firefox_UaF_Pwn2Own_2014.php?nsukey=9s%2BGDLjFM2hq51rKHzOfJbHEZ6vfVkIcD4bFMXkcMfYm2msBPSzpn5ErG7MIq6Ljh8F3jSt7ksTOZu6wm6VbMA%3D%3D
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第38期)
