SecWiki周刊(第88期)
2015/11/02-2015/11/08
安全资讯
[其它]  Is Internet Security getting better or worse
http://zombiecodekill.com/2015/11/02/is-internet-security-getting-better-or-worse/
[其它]  天融信在新三板成功挂牌
http://weibo.com/p/1001603904663517831260
[其它]  网络安全的时代和机会
http://weibo.com/p/1001603905410934433798
[会议]  JSRC电商与智能安全沙龙
http://www.huodongxing.com/event/8307270934200
[其它]  Details of UK website visits 'to be stored for year'
http://www.bbc.com/news/uk-politics-34715872
[恶意分析]  CyberSecurity 2015 Q3报告(一):市场形势一派大好
http://www.freebuf.com/news/83465.html
[恶意分析]  【专访吴恩达】百度人工智能杀毒,探索深度神经网络查杀技术
http://mp.weixin.qq.com/s?__biz=MzI3MTA0MTk1MA==&mid=400323118&idx=1&sn=3b403af3c0b25f2491f0bd7310b612aa
安全技术
[Web安全]  vBulletin 5 PreAuth RCE writeup
http://pastie.org/pastes/10527766/text?key=wq1hgkcj4afb9ipqzllsq
[数据挖掘]  CS259D: Data Mining for Cyber Security
http://web.stanford.edu/class/cs259d/#hw
[Web安全]  利用Powershell快速导出域控所有用户Hash
http://drops.wooyun.org/tips/10181
[移动安全]  Research on Open Socket Apps
http://vdisk.weibo.com/s/zo_33fRAzXCZK
[恶意分析]  C&C控制服务的设计和侦测方法综述
http://drops.wooyun.org/tips/10232
[设备安全]  Cisco IOS Rootkit工具该怎么写
http://drops.wooyun.org/papers/10045
[数据挖掘]  使用docker安装部署Spark集群来训练CNN(含Python实例)
http://blog.csdn.net/cyh_24/article/details/49683221
[漏洞分析]  ELF反调试初探
http://www.freebuf.com/tools/83509.html
[Web安全]  vBulletin 5 远程命令执行(无需登录)
http://zone.wooyun.org/content/23777
[设备安全]  Firmware dumping technique for an ARM Cortex-M0 SoC
http://blog.includesecurity.com/2015/11/NordicSemi-ARM-SoC-Firmware-dumping-technique.html
[数据挖掘]  从数据挖掘的角度看草榴
http://1024data.sinaapp.com/
[漏洞分析]  一个PC上的“WormHole”漏洞
http://weibo.com/p/1001603905821401598674
[移动安全]  ​BetaBot 木马分析报告
http://weibo.com/p/1001603906188252214814
[Web安全]  unserialize() 实战之 vBulletin 5.x.x 远程代码执行
http://rickgray.me/2015/11/06/unserialize-attack-with-vbulletin-5-x-x-rce.html
[编程技术]  程序员的自我修养
https://leohxj.gitbooks.io/a-programmer-prepares/content/
[移动安全]  Android SO逆向1-ARM介绍
http://drops.wooyun.org/mobile/10009
[移动安全]  Remote arbitrary file read on Huawei CPEs
https://github.com/ud2/advisories/tree/master/embedded/huawei/cve-2015-7254
[比赛]  华山杯|web ak write up|收获
http://www.math1as.com/index.php/archives/131/
[比赛]  Practice CTF List
http://captf.com/practice-ctf/
[运维安全]  How I nearly almost saved the Internet, starring afl-fuzz and dnsmasq
https://blog.skullsecurity.org/2015/how-i-nearly-almost-saved-the-internet-starring-afl-fuzz-and-dnsmasq
[文档]  2015 Ruxcon Security Conference Slides
https://ruxcon.org.au/slides/?year=2015
[文档]  SecTor 2015 Presentations
http://sector.ca/presentations
[Web安全]  Check Point Discovers Critical vBulletin 0-Day
http://blog.checkpoint.com/2015/11/05/check-point-discovers-critical-vbulletin-0-day/
[Web安全]  利用joomla 3.2.0 – 3.4.4 注入漏洞到getshell
http://www.cngrayhat.org/archives/562
[恶意分析]  恶意代码清除实战
http://blog.nsfocus.net/malicious-code-clear/
[Web安全]  webshell sample for WebShell Log Analysis
https://github.com/tanjiti/webshellSample
[Web安全]  Revolver: An Automated Approach to the Detection of Evasive Web-based Malware
https://www.lastline.com/papers/revolver.pdf
[文档]  高校网络信息安全研讨会议题
http://sec.sjtu.edu.cn/challenges
[Web安全]  A few things about Redis security
http://antirez.com/news/96
[设备安全]  Rooting the Cisco Linksys x2000 router: system() strikes again
http://meat.pisto.horse/2015/11/rooting-linksys-x2000-router-system.html
[移动安全]  WormHole虫洞漏洞分析报告
http://drops.wooyun.org/papers/10061
[书籍]  Data Mining Tools for Malware Detection
http://pan.baidu.com/s/1pJszBWf
[恶意分析]  Data Science Driven Malware Detection
http://www.slideshare.net/Pivotal/data-science-driven-malware-detection
[数据挖掘]  Dive into Machine Learning with Jupyter and scikit-learn
https://github.com/hangtwenty/dive-into-machine-learning
-----微信ID:SecWiki-----
SecWiki,12年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com

本期原文地址: SecWiki周刊(第88期)