SecWiki周刊(第83期)
2015/09/28-2015/10/04
安全资讯
2015 HITCON CTF
http://ctf.hitcon.org/
http://ctf.hitcon.org/
500 million users at risk of compromise via unpatched WinRAR bug
http://www.net-security.org/secworld.php?id=18914
http://www.net-security.org/secworld.php?id=18914
Black Hat Arsenal Europe 2015 Line-Up
http://www.toolswatch.org/2015/10/black-hat-arsenal-europe-2015-line-up/
http://www.toolswatch.org/2015/10/black-hat-arsenal-europe-2015-line-up/
Volkswagen and Cheating Software
https://www.schneier.com/blog/archives/2015/09/volkswagen_and_.html
https://www.schneier.com/blog/archives/2015/09/volkswagen_and_.html
Cyber Security Conferences India
https://www.concise-courses.com/security/cybersecurity-conferences-india/
https://www.concise-courses.com/security/cybersecurity-conferences-india/
Black Hat Europe 2015 Briefings
https://www.blackhat.com/eu-15/briefings.html
https://www.blackhat.com/eu-15/briefings.html
Scottrade Breach Hits 4.6 Million Customers
http://krebsonsecurity.com/2015/10/scottrade-breach-hits-4-6-million-customers/
http://krebsonsecurity.com/2015/10/scottrade-breach-hits-4-6-million-customers/
安全技术
relative path overwrite
http://www.mbsd.jp/Whitepaper/rpo.pdf
http://www.mbsd.jp/Whitepaper/rpo.pdf
qark:Quick Android Review Kit
https://github.com/linkedin/qark
https://github.com/linkedin/qark
Concise Courses Hacker Tools Videos
https://www.concise-courses.com/hacking-tools/videos/
https://www.concise-courses.com/hacking-tools/videos/
Lpk.dll劫持+ 飞客蠕虫病毒取证
http://drops.wooyun.org/tips/9106
http://drops.wooyun.org/tips/9106
Gitrob: Putting the Open Source in OSINT
http://michenriksen.com/blog/gitrob-putting-the-open-source-in-osint/
http://michenriksen.com/blog/gitrob-putting-the-open-source-in-osint/
Derbycon 2015 Videos
http://www.irongeek.com/i.php?page=videos/derbycon5/mainlist
http://www.irongeek.com/i.php?page=videos/derbycon5/mainlist
10 种机器学习算法的要点(附 Python 和 R 代码)
http://blog.jobbole.com/92021/
http://blog.jobbole.com/92021/
Android应用程序通用自动脱壳方法研究
http://drops.wooyun.org/papers/9214
http://drops.wooyun.org/papers/9214
黑客防线2015年第6期杂志
http://www.hacker.com.cn/show-7-2749-1.html
http://www.hacker.com.cn/show-7-2749-1.html
TrendMicro CTF 2015 : Poison Ivy (Defense 300) write-up
https://blog.0xbadc0de.be/archives/256
https://blog.0xbadc0de.be/archives/256
ICS 工业控制系统安全风险分析
http://ftps.zdnet.com.cn/files/3/22758.pdf
http://ftps.zdnet.com.cn/files/3/22758.pdf
Revisiting Apple IPC: (1) Distributed Objects
http://googleprojectzero.blogspot.com/2015/09/revisiting-apple-ipc-1-distributed_28.html
http://googleprojectzero.blogspot.com/2015/09/revisiting-apple-ipc-1-distributed_28.html
a list of crypto libs/APIs
https://cryptocoding.net/index.php/References#Libraries_and_toolkits
https://cryptocoding.net/index.php/References#Libraries_and_toolkits
美团Android资源混淆保护实践
http://tech.meituan.com/mt-android-resource-obfuscation.html
http://tech.meituan.com/mt-android-resource-obfuscation.html
实例详解机器学习如何解决问题
http://mp.weixin.qq.com/s?__biz=MjM5ODIzNDQ3Mw==&mid=208693972&idx=1&sn=96ad4367776df79ec64b6ffc16865cd4&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MjM5ODIzNDQ3Mw==&mid=208693972&idx=1&sn=96ad4367776df79ec64b6ffc16865cd4&scene=0#rd
Attacking ZigBee and IEEE 802.15.4 networks: KillerBee
https://n0where.net/attacking-zigbee/
https://n0where.net/attacking-zigbee/
DUKES----持续七年的俄罗斯网络间谍组织大起底
http://drops.wooyun.org/papers/9292
http://drops.wooyun.org/papers/9292
决策树模型组合之随机森林与GBDT
http://mp.weixin.qq.com/s?__biz=MjM5ODIzNDQ3Mw==&mid=208679963&idx=1&sn=f43df65e2c5d274c27bfcfe55177364b&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MjM5ODIzNDQ3Mw==&mid=208679963&idx=1&sn=f43df65e2c5d274c27bfcfe55177364b&scene=0#rd
awesome pentest collection
https://github.com/enaqx/awesome-pentest
https://github.com/enaqx/awesome-pentest
Bypassing IE's XSS Filter with HZ-GB-2312 escape sequence
http://mksben.l0.cm/2015/09/bypassing-xss-filter-hzgb2312.html
http://mksben.l0.cm/2015/09/bypassing-xss-filter-hzgb2312.html
[Part 1][EN] Hacking NETGEAR JWNR2010v5 Router
http://www.shellshocklabs.com/2015/09/part-1en-hacking-netgear-jwnr2010v5.html
http://www.shellshocklabs.com/2015/09/part-1en-hacking-netgear-jwnr2010v5.html
Abusing GDI for ring0 exploit primitives
https://blog.coresecurity.com/2015/09/28/abusing-gdi-for-ring0-exploit-primitives/
https://blog.coresecurity.com/2015/09/28/abusing-gdi-for-ring0-exploit-primitives/
syscall graphs include linux,windox,os x bsd
https://w3challs.com/syscalls/
https://w3challs.com/syscalls/
使用cProfile分析Python程序性能
http://xianglong.me/article/analysis-python-application-performance-using-cProfile/
http://xianglong.me/article/analysis-python-application-performance-using-cProfile/
3,000 High-Profile Japanese Sites Hit By Massive Malvertising Campaign
http://blog.trendmicro.com/trendlabs-security-intelligence/3000-high-profile-japanese-sites-hit-by-massive-malvertising-campaign/
http://blog.trendmicro.com/trendlabs-security-intelligence/3000-high-profile-japanese-sites-hit-by-massive-malvertising-campaign/
基础数据与 威胁情报实战应⽤ 基础数据部分
http://874998.l18.yunpan.cn/lk/cH2QHnFYFthyk
http://874998.l18.yunpan.cn/lk/cH2QHnFYFthyk
Full Reddit Submission Corpus now available (2006 thru August 2015)
https://www.reddit.com/r/datasets/comments/3mg812/full_reddit_submission_corpus_now_available_2006/
https://www.reddit.com/r/datasets/comments/3mg812/full_reddit_submission_corpus_now_available_2006/
安卓动态调试七种武器之离别钩 – Hooking(上)
http://drops.wooyun.org/papers/9300
http://drops.wooyun.org/papers/9300
OS X平台的Dylib劫持技术(上)
http://drops.wooyun.org/tips/9249
http://drops.wooyun.org/tips/9249
How I hacked my IP camera, and found this backdoor account
http://jumpespjump.blogspot.tw/2015/09/how-i-hacked-my-ip-camera-and-found.html
http://jumpespjump.blogspot.tw/2015/09/how-i-hacked-my-ip-camera-and-found.html
[Part 2][EN] Hacking NETGEAR JWNR2010v5 Router
http://www.shellshocklabs.com/2015/09/part-2en-hacking-netgear-jwnr2010v5.html
http://www.shellshocklabs.com/2015/09/part-2en-hacking-netgear-jwnr2010v5.html
Open-Source Phishing Toolkit
https://github.com/jordan-wright/gophish
https://github.com/jordan-wright/gophish
如何写好一份设计文档
http://www.jianshu.com/p/6eb0125b6518
http://www.jianshu.com/p/6eb0125b6518
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第83期)
