SecWiki周刊(第366期)
2021/03/01-2021/03/07
安全技术
趋势科技 2020 年度网络安全报告
https://mp.weixin.qq.com/s/6pnaFU5PfYGs4d0oLmRkJA
https://mp.weixin.qq.com/s/6pnaFU5PfYGs4d0oLmRkJA
VMware vCenter RCE (CVE-2021-21972) 漏洞复现与 Exp 编写
https://mp.weixin.qq.com/s/2pvaQborwMM8UHnWS_CeXA
https://mp.weixin.qq.com/s/2pvaQborwMM8UHnWS_CeXA
Firm-AFL:高效的IoT固件灰盒fuzz
https://mp.weixin.qq.com/s/-s5GGA70vcHAVfyz1QeBtQ
https://mp.weixin.qq.com/s/-s5GGA70vcHAVfyz1QeBtQ
Node.js原型链污染的利用
https://www.freebuf.com/articles/web/264966.html
https://www.freebuf.com/articles/web/264966.html
sqlinjection-detect: C语言编写的基于语义分析的SQL注入检测库
https://github.com/peter-cui1221/sqlinjection-detect
https://github.com/peter-cui1221/sqlinjection-detect
Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities
https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
红蓝对抗中的云原生漏洞挖掘及利用实录
https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g
https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g
SonicWall SSL-VPN 远程命令执行
https://www.sec-in.com/article/899
https://www.sec-in.com/article/899
游戏安全评审的技术进阶之路
https://mp.weixin.qq.com/s/ZIzjIZziM6inUNlr2CKBCg
https://mp.weixin.qq.com/s/ZIzjIZziM6inUNlr2CKBCg
关于近期Microsoft Exchange多个高危漏洞——ProxyLogon
https://mp.weixin.qq.com/s/cmgY6W_cGtGacfYgiac5qQ
https://mp.weixin.qq.com/s/cmgY6W_cGtGacfYgiac5qQ
IOT安全(二)——再探stm32
https://www.anquanke.com/post/id/231440
https://www.anquanke.com/post/id/231440
PHP反序列化 — 字符逃逸
https://xz.aliyun.com/t/9213
https://xz.aliyun.com/t/9213
SecWiki周刊(第365期)
https://www.sec-wiki.com/weekly/365
https://www.sec-wiki.com/weekly/365
以蓝军视角跟踪和分析CANVAS攻击框架泄露事件
https://mp.weixin.qq.com/s/eQ-KDMoirOwx-pFxUcNjtQ
https://mp.weixin.qq.com/s/eQ-KDMoirOwx-pFxUcNjtQ
浅谈如何有效落地DevSecOps
https://mp.weixin.qq.com/s/5eX3-SCfvFfRitb9_onjvw
https://mp.weixin.qq.com/s/5eX3-SCfvFfRitb9_onjvw
智能化时代的代码缺陷检查探索
https://juejin.cn/post/6935413169271603208
https://juejin.cn/post/6935413169271603208
PCAP-ATTACK: PCAP Samples for Different Post Exploitation Techniques
https://github.com/sbousseaden/PCAP-ATTACK
https://github.com/sbousseaden/PCAP-ATTACK
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第366期)
