SecWiki周刊(第426期)
2022/04/25-2022/05/01
安全资讯
国资委:将网络安全纳入央企负责人经营业绩考核
http://www.sasac.gov.cn/n2588035/n2588320/n2588335/c10652592/content.html
http://www.sasac.gov.cn/n2588035/n2588320/n2588335/c10652592/content.html
安全技术
记一次Discuz X3.4后台getshell
https://mp.weixin.qq.com/s/KngycYJ7nnirHkNXAlMVKw
https://mp.weixin.qq.com/s/KngycYJ7nnirHkNXAlMVKw
利用ProxyShell漏洞获取域控所有Hash
https://mp.weixin.qq.com/s/ACTLX6LUdZRevHJHiOnlSg
https://mp.weixin.qq.com/s/ACTLX6LUdZRevHJHiOnlSg
xray联动crawlergo自动化扫描爬坑记
https://mp.weixin.qq.com/s/aJ7UvZmACNSEF1zCrntxow
https://mp.weixin.qq.com/s/aJ7UvZmACNSEF1zCrntxow
链上追踪:洗币手法科普之波场 TRON
https://mp.weixin.qq.com/s/xuK94UW1ZNcxwE12qJLutA
https://mp.weixin.qq.com/s/xuK94UW1ZNcxwE12qJLutA
记一次护网漏洞发现到域控全过程
https://mp.weixin.qq.com/s/_b43Pj6rszcKvZhrVlsS7g
https://mp.weixin.qq.com/s/_b43Pj6rszcKvZhrVlsS7g
回顾 2021 年在野利用的 0day 漏洞
https://paper.seebug.org/1886/
https://paper.seebug.org/1886/
软件成分安全分析(SCA)能力的建设与演进
https://mp.weixin.qq.com/s/2tu27ZLzd3kEyk5lrXeytQ
https://mp.weixin.qq.com/s/2tu27ZLzd3kEyk5lrXeytQ
无需免杀获取域控hash小技巧
https://mp.weixin.qq.com/s/fQdb-DY9yBdjcCAbUR73fw
https://mp.weixin.qq.com/s/fQdb-DY9yBdjcCAbUR73fw
利用远程进程分叉转存Lsass凭据
https://mp.weixin.qq.com/s/67SghGobegFUC2td3az5qQ
https://mp.weixin.qq.com/s/67SghGobegFUC2td3az5qQ
从源代码的控制流图中学习特性以定位缺陷
https://mp.weixin.qq.com/s/jzQy2KmCiLmJ_RHaPVc4ew
https://mp.weixin.qq.com/s/jzQy2KmCiLmJ_RHaPVc4ew
CodeQL进阶知识(Java)
https://mp.weixin.qq.com/s/ZCl9kaMsZLqc74VzErHCGw
https://mp.weixin.qq.com/s/ZCl9kaMsZLqc74VzErHCGw
针对移动支付的道德反欺诈系统
https://mp.weixin.qq.com/s/t1-kQ4wpH0wf0gIceV0xzw
https://mp.weixin.qq.com/s/t1-kQ4wpH0wf0gIceV0xzw
《软件分析》课程实验作业平台概述
https://tai-e.pascal-lab.net/intro/overview.html
https://tai-e.pascal-lab.net/intro/overview.html
Pentest_Note: 渗透测试常规操作记录
https://github.com/xiaoy-sec/Pentest_Note
https://github.com/xiaoy-sec/Pentest_Note
Smarty 模板注入与沙箱逃逸
https://www.anquanke.com/post/id/272393
https://www.anquanke.com/post/id/272393
A blueprint for evading industry leading endpoint protection in 2022
https://vanmieghem.io/blueprint-for-evading-edr-in-2022/
https://vanmieghem.io/blueprint-for-evading-edr-in-2022/
SecWiki周刊(第425期)
https://www.sec-wiki.com/weekly/425
https://www.sec-wiki.com/weekly/425
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第426期)
