SecWiki周刊(第301期)
2019/12/02-2019/12/08
安全资讯
卡巴斯基2019年Q3垃圾邮件与钓鱼攻击报告
https://mp.weixin.qq.com/s/JE5J6misSPhzCjyKB0MxCA
https://mp.weixin.qq.com/s/JE5J6misSPhzCjyKB0MxCA
2010年以来重大网络安全事件盘点
https://mp.weixin.qq.com/s/kv64D0fqBwJ3J3pkDFqI3A
https://mp.weixin.qq.com/s/kv64D0fqBwJ3J3pkDFqI3A
安全技术
利用SSH隧道构建多级tunnel
https://mp.weixin.qq.com/s/jg_7bKqwfeYh1ErTtljKYw
https://mp.weixin.qq.com/s/jg_7bKqwfeYh1ErTtljKYw
QBAnalyzer: automates extracting artifacts and binaries
https://github.com/bd249ce4/QBAnalyzer
https://github.com/bd249ce4/QBAnalyzer
靶场发展态势⑤美国防部企业级赛博靶场环境(DECRE)
https://mp.weixin.qq.com/s/mAeld9GbLN9Ps-M5wgelfw
https://mp.weixin.qq.com/s/mAeld9GbLN9Ps-M5wgelfw
CobaltStrike基本功能与使用
https://payloads.cn/2019/1204/cobaltstrike-basic-functions-and-use.html
https://payloads.cn/2019/1204/cobaltstrike-basic-functions-and-use.html
使用 IDA 处理 U-Boot 二进制流文件
https://paper.seebug.org/1090/
https://paper.seebug.org/1090/
我是如何拿到OSCP认证的?
https://www.anquanke.com/post/id/188582
https://www.anquanke.com/post/id/188582
Thinkphp5 RCE总结
https://www.chabug.org/audit/1078.html
https://www.chabug.org/audit/1078.html
一篇文章带你读懂 HTTP Smuggling 攻击
https://xz.aliyun.com/t/6878
https://xz.aliyun.com/t/6878
Kubernetes 下零信任安全架构分析
https://mp.weixin.qq.com/s/WybnFRHiGy1joLFyQyba0g
https://mp.weixin.qq.com/s/WybnFRHiGy1joLFyQyba0g
NJUPT CTF 天璇Writeup
https://xz.aliyun.com/t/6876
https://xz.aliyun.com/t/6876
AssetScan内网脆弱面分析工具
https://mp.weixin.qq.com/s/dCP3PsjZYDY0f2wJX4dC4w
https://mp.weixin.qq.com/s/dCP3PsjZYDY0f2wJX4dC4w
openrasp-iast: IAST 灰盒扫描工具
https://github.com/baidu-security/openrasp-iast
https://github.com/baidu-security/openrasp-iast
从0开始入门Chrome Ext安全(二) --安全的Chrome Ext
https://lorexxar.cn/2019/12/05/chrome-ext-2/
https://lorexxar.cn/2019/12/05/chrome-ext-2/
五年之后的回顾--磊科路由器后门利用情况分析
https://mp.weixin.qq.com/s/6djU9_yl8px9oimxCRQd5A
https://mp.weixin.qq.com/s/6djU9_yl8px9oimxCRQd5A
Python模板注入(SSTI)深入学习
https://xz.aliyun.com/t/6885
https://xz.aliyun.com/t/6885
SecWiki周刊(第300期)
https://www.sec-wiki.com/weekly/300
https://www.sec-wiki.com/weekly/300
BigData-Notes: 大数据入门指南
https://github.com/heibaiying/BigData-Notes
https://github.com/heibaiying/BigData-Notes
HELP: Flare-On 6 Challenge 12
https://unhere.com/2019/11/23/help-flare-on-6-challenge-12/
https://unhere.com/2019/11/23/help-flare-on-6-challenge-12/
浅谈工控CTF中网络数据分析的思路
https://mp.weixin.qq.com/s/bR1t53-YHSKWmFawT5t0Kg
https://mp.weixin.qq.com/s/bR1t53-YHSKWmFawT5t0Kg
Linux逆向之调试&反调试
https://xz.aliyun.com/t/6882
https://xz.aliyun.com/t/6882
靶场发展态势⑥欧洲典型靶场发展现状
https://mp.weixin.qq.com/s/JgPnNDixgcSd4uPgmp4itg
https://mp.weixin.qq.com/s/JgPnNDixgcSd4uPgmp4itg
漏洞验证和利用代码编写指南
https://xz.aliyun.com/t/6880
https://xz.aliyun.com/t/6880
“海莲花”组织2019年针对中国的攻击活动汇总
https://mp.weixin.qq.com/s/OA09fndsHfpLVxeo7DnjYg
https://mp.weixin.qq.com/s/OA09fndsHfpLVxeo7DnjYg
APT review: what the world’s threat actors got up to in 2019
https://securelist.com/ksb-2019-review-of-the-year/95394/
https://securelist.com/ksb-2019-review-of-the-year/95394/
网络空间测绘的生与死(三)
https://mp.weixin.qq.com/s/jffEOTF3n028USQujIzmmw
https://mp.weixin.qq.com/s/jffEOTF3n028USQujIzmmw
一文解密所有WebLogic密文
https://mp.weixin.qq.com/s/HY0X3koYVEIotYIQZi680w
https://mp.weixin.qq.com/s/HY0X3koYVEIotYIQZi680w
将MITRE ATT&CK模型应用于网络设备
https://www.freebuf.com/articles/es/220628.html
https://www.freebuf.com/articles/es/220628.html
浅析容器安全与EDR的异同
https://mp.weixin.qq.com/s/FfaeXbeVf3omO2Q8r6ztXw
https://mp.weixin.qq.com/s/FfaeXbeVf3omO2Q8r6ztXw
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第301期)
