百度统计js被劫持用来DDOS Github Full Open Source Car Hacking Kit For The Masses 国内漏洞奖励计划大盘点 Millions of computers left vulnerable to BIOS chip hack Study reveals We are being tracked by Our Smartphones Fei-Fei Li: How we're teaching computers to understand pictures Stealing Data From Computers Using Heat 谷歌发现用于中间人攻击的证书
列举些Android SDK的国内镜像和相关资源 websocket-injection:WebSocket 中转注入工具 大数据分析与机器学习领域Python兵器谱 GTC2015 deep learning session vedio web日志取证分析工具 Python Programming Tutorials Video CVE-2014-4487 – IOHIDLibUserClient堆溢出漏洞 BCTF 2015 CamlMaze命題報告及CTF題目鏡像準備方法 对JiaThis Flash XSS的挖掘与分析 大华监控设备存在弱口令的全网统计报告 Ad-Fraud Malware Hijacks Router DNS – Injects Ads Via Google Analytics Smart COM Fuzzing - Auditing IE Sandbox Bypass in COM Objects honggfuzz:A general-purpose fuzzer with simple, command-line interface 揭秘:钓鱼攻击工具包Angler Exploit Kit初探 IROS 2014 Aerial Open Source Robotics Workshop 【流量劫持】躲避 HSTS 的 HTTPS 劫持 MongoDB vs. Elasticsearch: The Quest of the Holy Performances easyPass:字典生成和整理工具 Firefox 31~34远程命令执行漏洞的分析 机器学习的一些通俗易懂的tutorial BCTF 2015 - weak_enc Crypto challenge Detection of JavaScript-based Malware Flash in 2015 Deep Dive Into Stageless Meterpreter Payloads dns recon & research, find & lookup dns records Introducing Elastichoney - an Elasticsearch Honeypot XCTF联赛—2015_BCTF_Writeup Threat Spotlight: PoSeidon, A Deep Dive Into Point of Sale Malware 左右互博:站在攻击者的角度来做防护 Adventures in Browser Exploitation: Firefox 32.0 - 35.0.1 RCE 这些年做安全的一点心得 Cisco 2015 Annual Security Report 从技术细节看美团的架构 Android 签名验证机制 在未越狱的 iPhone 6上盗取支付宝和微信支付的帐号密码 IE安全系列:IE的自我介绍 (I) Android平台的SQL注入漏洞浅析 Bypassing Control Flow Guard on Windows 8 Unmasked: An Analysis of 10 Million Passwords 八种最常见Docker开发模式 未来 Docker 的安全 PowerSpy: Location Tracking using Mobile Device Power Analysis Cryptographic Backdooring
本期原文地址: SecWiki周刊(第56期)