SecWiki周刊(第90期)
2015/11/16-2015/11/22
安全资讯
[其它]  FreeBuf全球安全事件纵览(2015年10月):追着光影奔跑
http://www.freebuf.com/news/85800.html
[运维安全]  关于下一代防火墙的几个思考
http://weibo.com/p/1001603909874978310484
安全技术
[运维安全]  翻墙路由器的原理与实现
http://drops.wooyun.org/papers/10177
[数据挖掘]  SecRepo:Samples of Security Related Data
http://www.secrepo.com/#3p_malware
[移动安全]  RCTF2015-Mobile-出题思路及Writeup
http://drops.wooyun.org/mobile/10557
[数据挖掘]  Security Data Analysis
https://github.com/sooshie/Security-Data-Analysis
[文档]  我的通行你的证:cookie安全
http://pan.baidu.com/share/link?shareid=4177846603&uk=4077087174
[Web安全]  XSS 攻击利用代码收集平台
http://www.xss-payloads.com/
[漏洞分析]   funder = Format-UNDERstander
https://code.google.com/p/funder/
[比赛]  RCTF Web100, Web150 Writeup
http://insight-labs.org/?p=1987
[取证分析]  Xplico:Open Source Network Forensic Analysis Tool (NFAT)
http://www.xplico.org/
[恶意分析]  OllyDbg 2.01 简明帮助手册
http://vdisk.weibo.com/s/zmw3AF3wa5ObF/1447817229
[移动安全]  “蜥蜴之尾”——长老木马四代分析报告
http://blogs.360.cn/360mobile/2015/11/16/analysis_of_fakedebuggerd_d/
[漏洞分析]  Forensic analysis of a Sony PlayStation 4: A first look
http://www.sciencedirect.com/science/article/pii/S1742287615000146
[运维安全]  HoneyPy:A low interaction honeypot
https://github.com/foospidy/HoneyPy
[恶意分析]  Swimming in the Sea of ELF
https://www.slideshare.net/secret/c0pBeVJcrqw2pc
[Web安全]  joomlavs:Joomla vulnerability scanner
https://github.com/rastating/joomlavs
[恶意分析]  VolatilityBot – An automated malicious code dumper
http://blog.fightingmalware.com/blog/?p=221
[Web安全]  spring-social-core-vulnerability-disclosure
https://blog.srcclr.com/spring-social-core-vulnerability-disclosure/
[取证分析]  awesome-incident-response
https://github.com/meirwah/awesome-incident-response
[漏洞分析]  Bypassing SMEP Using vDSO Overwrites
http://itszn.com/blog/?p=21
[Web安全]  Nishang: A Post-Exploitation Framework
http://resources.infosecinstitute.com/nishang-a-post-exploitation-framework/
[Web安全]  DZ 6.x getshell [20151117]
http://www.unhonker.com/bug/1856.html
[恶意分析]  Linux/FileCoder (Linux.Encoder)
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=4097&p=27253#p27253
[运维安全]  Redis事件综合分析
http://weibo.com/p/1001603909861770434271
[文档]  The Landscape of Internet Threats
http://netsec.ccert.edu.cn/course/Tsinghua-Landscape.Nov15.pdf
[运维安全]  Powershell Hids DEMO
http://www.xtiger.net/2015/11/18/powershell-hids-demo/
[恶意分析]  Manual and Automatic Program Analysis/
https://isis.poly.edu/pa/
[漏洞分析]  (browser narly) - browser exploitation/exploration tool
https://github.com/d0c-s4vage/bnarly
[Web安全]  Bug Bounty Web List
http://hackersonlineclub.com/bug-bounty-web-lists/
[论文]  How to Write a Great Research Paper
https://www.youtube.com/watch?v=g3dkRsTqdDA
[工具]  APK Studio by vaibhavpandeyvpz
http://github.vaibhavpandey.com/apkstudio/
[漏洞分析]  Getting started with TSK & Autopsy pt. 2
http://digitalresidue.blogspot.tw/2015/11/getting-started-with-tsk-autopsy-pt-2.html
[漏洞分析]  Inspecting Heap Objects with LLDB
http://rotlogix.com/2015/11/19/inspecting-heap-objects-with-lldb/
[漏洞分析]  CANAPE Network Testing Tool
https://github.com/ctxis/canape
-----微信ID:SecWiki-----
SecWiki,12年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com

本期原文地址: SecWiki周刊(第90期)