SecWiki周刊(第56期)
2015/03/23-2015/03/29
安全资讯
百度统计js被劫持用来DDOS Github Full Open Source Car Hacking Kit For The Masses 国内漏洞奖励计划大盘点 Millions of computers left vulnerable to BIOS chip hack Study reveals We are being tracked by Our Smartphones Fei-Fei Li: How we're teaching computers to understand pictures Stealing Data From Computers Using Heat 谷歌发现用于中间人攻击的证书
安全技术
列举些Android SDK的国内镜像和相关资源 websocket-injection:WebSocket 中转注入工具 大数据分析与机器学习领域Python兵器谱 GTC2015 deep learning session vedio web日志取证分析工具 CVE-2014-4487 – IOHIDLibUserClient堆溢出漏洞 Python Programming Tutorials Video BCTF 2015 CamlMaze命題報告及CTF題目鏡像準備方法 对JiaThis Flash XSS的挖掘与分析 大华监控设备存在弱口令的全网统计报告 Smart COM Fuzzing - Auditing IE Sandbox Bypass in COM Objects Ad-Fraud Malware Hijacks Router DNS – Injects Ads Via Google Analytics honggfuzz:A general-purpose fuzzer with simple, command-line interface 揭秘:钓鱼攻击工具包Angler Exploit Kit初探 IROS 2014 Aerial Open Source Robotics Workshop 【流量劫持】躲避 HSTS 的 HTTPS 劫持 MongoDB vs. Elasticsearch: The Quest of the Holy Performances easyPass:字典生成和整理工具 Firefox 31~34远程命令执行漏洞的分析 机器学习的一些通俗易懂的tutorial BCTF 2015 - weak_enc Crypto challenge Detection of JavaScript-based Malware Flash in 2015 Deep Dive Into Stageless Meterpreter Payloads Introducing Elastichoney - an Elasticsearch Honeypot dns recon & research, find & lookup dns records XCTF联赛—2015_BCTF_Writeup Threat Spotlight: PoSeidon, A Deep Dive Into Point of Sale Malware 左右互博:站在攻击者的角度来做防护 这些年做安全的一点心得 Adventures in Browser Exploitation: Firefox 32.0 - 35.0.1 RCE Cisco 2015 Annual Security Report 从技术细节看美团的架构 Android 签名验证机制 在未越狱的 iPhone 6上盗取支付宝和微信支付的帐号密码 IE安全系列:IE的自我介绍 (I) Android平台的SQL注入漏洞浅析 Bypassing Control Flow Guard on Windows 8 Unmasked: An Analysis of 10 Million Passwords 八种最常见Docker开发模式 未来 Docker 的安全 PowerSpy: Location Tracking using Mobile Device Power Analysis Cryptographic Backdooring
安全专题
国内NLP相关公司产品
https://www.sec-wiki.com/topic/61
https://www.sec-wiki.com/topic/61
-----微信ID:SecWiki-----
SecWiki,12年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第56期)