SecWiki周刊(第21期)
2014/07/21-2014/07/27
安全资讯
Forensic scientist identifies suspicious back doors' running on every iOS device
http://www.zdnet.com/forensic-scientist-identifies-suspicious-back-doors-running-on-every-ios-device-7000031795/
http://www.zdnet.com/forensic-scientist-identifies-suspicious-back-doors-running-on-every-ios-device-7000031795/
安全技术
《安全参考》HACKCTO-201407-19
http://pan.baidu.com/s/1c0eoN8c
http://pan.baidu.com/s/1c0eoN8c
Toward Scalable Systems for Big Data Analytics: A Technology Tutorial
http://ieeexplore.ieee.org/xpl/articleDetails.jsp?reload=true&arnumber=6842585
http://ieeexplore.ieee.org/xpl/articleDetails.jsp?reload=true&arnumber=6842585
简单修改了cve-2011-3402的内核提权ShellCode
http://debugwar.com/archives/313/change_shellcode_cve-2011-3402
http://debugwar.com/archives/313/change_shellcode_cve-2011-3402
DOM Clobbering
http://www.thespanner.co.uk/2013/05/16/dom-clobbering/
http://www.thespanner.co.uk/2013/05/16/dom-clobbering/
Attacks on Android Clipboard
http://www.cis.syr.edu/~wedu/Research/paper/clipboard_attack_dimva2014.pdf
http://www.cis.syr.edu/~wedu/Research/paper/clipboard_attack_dimva2014.pdf
Machine Learning Surveys
http://www.mlsurveys.com/
http://www.mlsurveys.com/
2014年澳大利亚信息安全挑战 CySCA CTF 官方write up Crypto篇
http://drops.wooyun.org/tips/2618
http://drops.wooyun.org/tips/2618
wireshark 实用技巧
https://community.emc.com/message/827199#827199
https://community.emc.com/message/827199#827199
SyScan360 2014 Program
http://www.syscan360.org/en/schedule.html
http://www.syscan360.org/en/schedule.html
playweb:基于分布式网络安全扫描系统实现
http://yaseng.me/yaseng-graduation-thesis-playweb.html
http://yaseng.me/yaseng-graduation-thesis-playweb.html
内网渗透之-域渗透基础
http://www.91ri.org/10154.html
http://www.91ri.org/10154.html
配置ModSecurity防火墙与OWASP规则
http://drops.wooyun.org/tips/2614
http://drops.wooyun.org/tips/2614
GNU/Linux安全基线与加固
https://raw.githubusercontent.com/citypw/DNFWAH/master/4/d4_0x02_DNFWAH_gnu-linux_security_baseline_hardening.txt
https://raw.githubusercontent.com/citypw/DNFWAH/master/4/d4_0x02_DNFWAH_gnu-linux_security_baseline_hardening.txt
TSRC挑战赛: PHP防御绕过挑战实录
http://security.tencent.com/index.php/blog/msg/58
http://security.tencent.com/index.php/blog/msg/58
TSRC挑战赛: PHP场景中getshell防御思路分享
http://security.tencent.com/index.php/blog/msg/57
http://security.tencent.com/index.php/blog/msg/57
无声杯 xss 挑战赛 writeup
http://drops.wooyun.org/tips/2671
http://drops.wooyun.org/tips/2671
Academic Universe:A Platform for Exploring Linked Academic Objects
http://soscholar.com/universe/
http://soscholar.com/universe/
CVE-2014-3153 Exploit
http://www.clevcode.org/cve-2014-3153-exploit/
http://www.clevcode.org/cve-2014-3153-exploit/
Advanced Exploitation of VirtualBox 3D Acceleration VM Escape Vulnerability
http://www.vupen.com/blog/20140725.Advanced_Exploitation_VirtualBox_VM_Escape.php
http://www.vupen.com/blog/20140725.Advanced_Exploitation_VirtualBox_VM_Escape.php
McAfee Advanced Threat Defense Test
http://www.mcafee.com/us/resources/reports/rp-advanced-threat-defense-test.pdf
http://www.mcafee.com/us/resources/reports/rp-advanced-threat-defense-test.pdf
后现代艺术:解构主义APT
http://0x.557.im/swan/201407/23_73.html
http://0x.557.im/swan/201407/23_73.html
chopshop:Protocol Analysis/Decoder Framework
https://github.com/MITRECND/chopshop
https://github.com/MITRECND/chopshop
Wordpress XML-RPC Brute Force Scanning
http://blog.spiderlabs.com/2014/07/honeypot-alert-wordpress-xml-rpc-brute-force-scanning.html
http://blog.spiderlabs.com/2014/07/honeypot-alert-wordpress-xml-rpc-brute-force-scanning.html
2014H1绿盟科技DDoS威胁报告
http://www.nsfocus.com/report/H1_2014_DDoS_THEATS_REPORT.pdf
http://www.nsfocus.com/report/H1_2014_DDoS_THEATS_REPORT.pdf
Python教程网络安全篇
http://drops.wooyun.org/tips/2568
http://drops.wooyun.org/tips/2568
Hacking Clients with WPAD (Web Proxy Auto-Discovery) Protocol
http://resources.infosecinstitute.com/hacking-clients-wpad-web-proxy-auto-discovery-protocol/
http://resources.infosecinstitute.com/hacking-clients-wpad-web-proxy-auto-discovery-protocol/
Samples from the conflict in Syria
http://syrianmalware.com/
http://syrianmalware.com/
Threat Research, Analysis, and Mitigation
http://www.fireeye.com/blog/
http://www.fireeye.com/blog/
我是如何”黑掉”91Ri的
http://www.91ri.org/10085.html
http://www.91ri.org/10085.html
x64_dbg:An open-source x64/x32 debugger for windows
http://x64dbg.com/#start
http://x64dbg.com/#start
RPC 库 grpc
https://bitbucket.org/seewind/grpc
https://bitbucket.org/seewind/grpc
如何建立高效的安全测试
http://www.freebuf.com/video/38608.html
http://www.freebuf.com/video/38608.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第21期)
