SecWiki周刊(第84期)
2015/10/05-2015/10/11
安全资讯
Hacking Wireless Printers With Phones on Drones
http://www.wired.com/2015/10/drones-robot-vacuums-can-spy-office-printer/
http://www.wired.com/2015/10/drones-robot-vacuums-can-spy-office-printer/
What’s New with Microsoft Threat Modeling Tool 2016
http://blogs.microsoft.com/cybertrust/2015/10/07/whats-new-with-microsoft-threat-modeling-tool-2016/
http://blogs.microsoft.com/cybertrust/2015/10/07/whats-new-with-microsoft-threat-modeling-tool-2016/
Three High severity vulnerabilities of the last week
http://malwarelist.net/2015/10/06/cybersecurity-threats-2015-three-high-severity-vulnerabilities-of-the-last-week/
http://malwarelist.net/2015/10/06/cybersecurity-threats-2015-three-high-severity-vulnerabilities-of-the-last-week/
HackerOne推出免费漏洞协调成熟度模型工具
http://www.aqniu.com/tools/10582.html
http://www.aqniu.com/tools/10582.html
2015年第40&41周安全通报
http://blog.topsec.com.cn/ad_lab/2015%e5%b9%b4%e7%ac%ac40-41%e5%91%a8%e5%ae%89%e5%85%a8%e9%80%9a%e6%8a%a5/
http://blog.topsec.com.cn/ad_lab/2015%e5%b9%b4%e7%ac%ac40-41%e5%91%a8%e5%ae%89%e5%85%a8%e9%80%9a%e6%8a%a5/
Behind the NSA Details and images on almost 300 patents filed
https://medium.com/silk-stories/behind-the-nsa-e0bf2c3a40c0
https://medium.com/silk-stories/behind-the-nsa-e0bf2c3a40c0
安全技术
Financial Cryptography and Data Security 2015
http://fc15.ifca.ai/schedule.html
http://fc15.ifca.ai/schedule.html
浅析大规模DDOS防御架构-应对T级攻防
http://www.ayazero.com/?p=75
http://www.ayazero.com/?p=75
CTF主办方指南之对抗搅屎棍
http://drops.wooyun.org/tips/9405
http://drops.wooyun.org/tips/9405
PwnWiki
http://pwnwiki.io
http://pwnwiki.io
Weblogic-Weakpassword-Scnner
https://github.com/dc3l1ne/Weblogic-Weakpassword-Scnner
https://github.com/dc3l1ne/Weblogic-Weakpassword-Scnner
OpenGraphiti : Data Visualization Framework
http://www.opengraphiti.com/
http://www.opengraphiti.com/
APK decompiler online
http://www.javadecompilers.com/apk
http://www.javadecompilers.com/apk
Try Django 1.8 Tutorial 视频
http://www.bilibili.com/video/av3007483/
http://www.bilibili.com/video/av3007483/
ROP Illmatic: Exploring Universal ROP on glibc x86-64 (en)
http://www.slideshare.net/inaz2/rop-illmatic-exploring-universal-rop-on-glibc-x8664-en-41595384
http://www.slideshare.net/inaz2/rop-illmatic-exploring-universal-rop-on-glibc-x8664-en-41595384
How I Hacked Hotmail
https://www.synack.com/labs/blog/how-i-hacked-hotmail/
https://www.synack.com/labs/blog/how-i-hacked-hotmail/
Black Hat USA 2015 Video
https://www.youtube.com/playlist?list=PLwibn_3po6c9sA7_6sOCTyDWhX26eKJkd
https://www.youtube.com/playlist?list=PLwibn_3po6c9sA7_6sOCTyDWhX26eKJkd
Microsoft Threat Modeling Tool 2016
http://www.microsoft.com/en-us/download/details.aspx?id=49168
http://www.microsoft.com/en-us/download/details.aspx?id=49168
Kemoge: Another Mobile Malicious Adware Infecting Over 20 Countries
https://www.fireeye.com/blog/threat-research/2015/10/kemoge_another_mobi.html
https://www.fireeye.com/blog/threat-research/2015/10/kemoge_another_mobi.html
BadUsb----结合实例谈此类外设的风险
http://drops.wooyun.org/tips/9336
http://drops.wooyun.org/tips/9336
Duqu 2.0 Win32k Exploit Analysis
https://github.com/ohjeongwook/Publications/blob/master/Duqu%202.0%20Win32k%20Exploit%20Analysis.pdf
https://github.com/ohjeongwook/Publications/blob/master/Duqu%202.0%20Win32k%20Exploit%20Analysis.pdf
pwntools — pwntools 2.2.0 documentation
http://pwntools.readthedocs.org/en/latest/index.html
http://pwntools.readthedocs.org/en/latest/index.html
new-metasploit-tools-to-collect-microsoft-patches
https://community.rapid7.com/community/metasploit/blog/2015/10/08/new-metasploit-tools-to-collect-microsoft-patches
https://community.rapid7.com/community/metasploit/blog/2015/10/08/new-metasploit-tools-to-collect-microsoft-patches
Nmap cheat sheet相关
https://duckduckgo.com/?q=nmap+cheat+sheet&t=canonical&ia=cheatsheet
https://duckduckgo.com/?q=nmap+cheat+sheet&t=canonical&ia=cheatsheet
VB2015 Prague Slide
https://www.virusbtn.com/conference/vb2015/slides/index
https://www.virusbtn.com/conference/vb2015/slides/index
Fuzzing with american fuzzy lop [LWN.net]
http://lwn.net/Articles/657959/
http://lwn.net/Articles/657959/
Cisco Web VPNs Leveraged for Access and Persistence
http://www.volexity.com/blog/?p=179
http://www.volexity.com/blog/?p=179
ODA - onlinedisassembler
https://www.onlinedisassembler.com/odaweb/
https://www.onlinedisassembler.com/odaweb/
Big Data University
http://bigdatauniversity.com.cn/
http://bigdatauniversity.com.cn/
Writing Cisco IOS Rootkits
https://packetstormsecurity.com/files/133917/Writing-Cisco-IOS-Rootkits.html
https://packetstormsecurity.com/files/133917/Writing-Cisco-IOS-Rootkits.html
OSXCollector : Automated forensic evidence collection & analysis for OS X
http://files.brucon.org/2015/Kuba_Sendor_OSXCollector.pdf
http://files.brucon.org/2015/Kuba_Sendor_OSXCollector.pdf
A survey of insecure Flash crossdomain policies – Alexa Top 10,000
http://blog.whatever.io/2015/10/03/a-survey-of-insecure-flash-crossdomain-policies-alexa-top-10000-case-study/
http://blog.whatever.io/2015/10/03/a-survey-of-insecure-flash-crossdomain-policies-alexa-top-10000-case-study/
A Study in Bots: DiamondFox
http://blog.cylance.com/a-study-in-bots-diamondfox
http://blog.cylance.com/a-study-in-bots-diamondfox
Materials for my Pycon 2015 scikit-learn tutorial
https://github.com/jakevdp/sklearn_pycon2015
https://github.com/jakevdp/sklearn_pycon2015
WordPress 利用 system.multicall RPC进行快速爆破
http://rickgray.me/2015/10/09/wordpress-xmlrpc-brute-force-in-one-request.html
http://rickgray.me/2015/10/09/wordpress-xmlrpc-brute-force-in-one-request.html
Dradis:Effective Information Sharing
http://dradisframework.org/
http://dradisframework.org/
Dynamic Analysis Of Adobe Flash Files
http://www.securityevaluators.com/knowledge/flash/flash.pdf
http://www.securityevaluators.com/knowledge/flash/flash.pdf
cpp con2015
https://github.com/CppCon/CppCon2015
https://github.com/CppCon/CppCon2015
python 安全类目推荐
http://zone.wooyun.org/content/23255
http://zone.wooyun.org/content/23255
Viper is a binary management and analysis framework
http://viper.li/
http://viper.li/
安全专题
大数据可视化开源库
https://www.sec-wiki.com/topic/64
https://www.sec-wiki.com/topic/64
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第84期)
