SecWiki周刊(第91期)
2015/11/23-2015/11/29
安全资讯
FSI 2015 | 安全创新之未来
http://isf.cisrg.org/
http://isf.cisrg.org/
安全技术
信息安全之路--和好友共同学习[ie8t]
http://pan.baidu.com/s/1gdyhq0r
http://pan.baidu.com/s/1gdyhq0r
一步一步学ROP之gadgets和2free篇
http://drops.wooyun.org/binary/10638
http://drops.wooyun.org/binary/10638
浏览器fuzz框架介绍
http://drops.wooyun.org/papers/10590
http://drops.wooyun.org/papers/10590
360护心镜脚本分析及N种绕过方式
http://drops.wooyun.org/web/10636
http://drops.wooyun.org/web/10636
浅析安全威胁情报共享框架OpenIOC
http://www.freebuf.com/tools/86580.html
http://www.freebuf.com/tools/86580.html
新浪微博 CSRF & ClickJacking 蠕虫
http://linux.im/2015/11/23/SinaWeibo-Worm.html
http://linux.im/2015/11/23/SinaWeibo-Worm.html
从异常挖掘到CC攻击地下黑客团伙
http://weibo.com/p/1001603912771065542344
http://weibo.com/p/1001603912771065542344
Exploit Hardening Made Easy
http://users.ece.cmu.edu/~ejschwar/papers/usenix11.pdf
http://users.ece.cmu.edu/~ejschwar/papers/usenix11.pdf
is_numeric的理解和PHP 脚本多字节字符解析模式带来的安全隐患
http://k1p4ss.sinaapp.com/?p=328
http://k1p4ss.sinaapp.com/?p=328
PWNtcha – captcha decoder
http://caca.zoy.org/wiki/PWNtcha
http://caca.zoy.org/wiki/PWNtcha
揭开山寨应用的伪装面具
http://blog.avlyun.com/2015/11/2546/mask/
http://blog.avlyun.com/2015/11/2546/mask/
awesome-python: 优秀库汇总
https://github.com/vinta/awesome-python
https://github.com/vinta/awesome-python
angularjs-expression-security-internals
https://www.veracode.com/blog/2015/07/angularjs-expression-security-internals
https://www.veracode.com/blog/2015/07/angularjs-expression-security-internals
ICS/SCADA Top 10 Most Dangerous Software Weaknesses
http://www.toolswatch.org/wp-content/uploads/2015/11/ICSSCADA-Top-10-Most-Dangerous-Software-Weaknesses.pdf
http://www.toolswatch.org/wp-content/uploads/2015/11/ICSSCADA-Top-10-Most-Dangerous-Software-Weaknesses.pdf
A security scanner for HTTP response headers.
https://github.com/riramar/hsecscan
https://github.com/riramar/hsecscan
Linux工具快速教程 — Linux Tools Quick Tutorial
http://linuxtools-rst.readthedocs.org/zh_CN/latest/index.html
http://linuxtools-rst.readthedocs.org/zh_CN/latest/index.html
3-attacks-on-cisco-tacacs-bypassing
http://agrrrdog.blogspot.de/2015/11/3-attacks-on-cisco-tacacs-bypassing.html
http://agrrrdog.blogspot.de/2015/11/3-attacks-on-cisco-tacacs-bypassing.html
Tor Forensics on Windows OS
https://digital-forensics.sans.org/summit-archives/dfirprague14/Tor_Forensics_On_Windows_OS_Mattia_Epifani.pdf
https://digital-forensics.sans.org/summit-archives/dfirprague14/Tor_Forensics_On_Windows_OS_Mattia_Epifani.pdf
A king's ransom: an analysis of the CTB-locker ransomware
http://samvartaka.github.io/malware/2015/11/20/ctb-locker/
http://samvartaka.github.io/malware/2015/11/20/ctb-locker/
Exploiting JBoss with Empire and PowerShell
http://www.rvrsh3ll.net/blog/offensive/exploiting-jboss-with-powershell-and-empire/
http://www.rvrsh3ll.net/blog/offensive/exploiting-jboss-with-powershell-and-empire/
PEERING INTO GLASSRAT A Zero Detection Trojan from China
https://blogs.rsa.com/wp-content/uploads/2015/11/GlassRAT-final.pdf
https://blogs.rsa.com/wp-content/uploads/2015/11/GlassRAT-final.pdf
The Chinese Cybercriminal Underground in 2015
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-prototype-nation.pdf
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-prototype-nation.pdf
情报系列书籍(电子版)
http://pan.baidu.com/s/1eQdQmC6
http://pan.baidu.com/s/1eQdQmC6
从智能插座看智能生活的安全隐患
http://security.tencent.com/index.php/blog/msg/98
http://security.tencent.com/index.php/blog/msg/98
reko: general purpose decompiler
http://uxmal.github.io/reko/
http://uxmal.github.io/reko/
Markov Chains as a Keyed Obfuscation Method
https://bwall.github.io/markov-chains-keyed-obfuscation/
https://bwall.github.io/markov-chains-keyed-obfuscation/
The flawed crypto of Hacking Team's 'core-packer' malware crypter
http://samvartaka.github.io/malware/2015/09/13/hackingteam-crypter/
http://samvartaka.github.io/malware/2015/09/13/hackingteam-crypter/
PHP static code analysis vs ~1000 top wordpress plugins
http://blog.cinu.pl/2015/11/php-static-code-analysis-vs-top-1000-wordpress-plugins.html
http://blog.cinu.pl/2015/11/php-static-code-analysis-vs-top-1000-wordpress-plugins.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第91期)
