SecWiki周刊(第82期)
2015/09/21-2015/09/27
安全资讯
绿盟云:XcodeGhost分析及在线检测
http://blog.nsfocus.net/nsfocus-xcodeghost-online-detection/
http://blog.nsfocus.net/nsfocus-xcodeghost-online-detection/
安全技术
dzscan:discuz插件漏洞扫描框架
https://github.com/code-scan/dzscan
https://github.com/code-scan/dzscan
维基百科简体中文语料的获取
http://licstar.net/archives/262
http://licstar.net/archives/262
discuz-plugin-scan:扫discuz插件小工具
https://github.com/Tycx2ry/discuz-plugin-scan
https://github.com/Tycx2ry/discuz-plugin-scan
智普教育python就业培训视频教程
http://pan.baidu.com/s/1bnmFmAb
http://pan.baidu.com/s/1bnmFmAb
CVE-2015-2546:从补丁比对到Exploit
http://drops.wooyun.org/papers/9276
http://drops.wooyun.org/papers/9276
GSMem: Data Exfiltration from Air-Gapped Computers over GSM Frequencies
https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/guri
https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/guri
Pupy: opensource RAT written in Python
https://github.com/n1nj4sec/pupy
https://github.com/n1nj4sec/pupy
Packer templates for creating a basic malware analysis lab
https://github.com/m-dwyer/packer-malware
https://github.com/m-dwyer/packer-malware
9款国内外垂直领域的在线作图工具
http://www.csdn.net/article/2015-02-12/2823939
http://www.csdn.net/article/2015-02-12/2823939
CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
https://labs.portcullis.co.uk/blog/cve-2015-5119-flash-bytearray-uaf-a-beginners-walkthrough/
https://labs.portcullis.co.uk/blog/cve-2015-5119-flash-bytearray-uaf-a-beginners-walkthrough/
使用TaskManager爬取2万条代理IP实现自动投票功能
http://www.cnblogs.com/yanweidie/p/4800948.html
http://www.cnblogs.com/yanweidie/p/4800948.html
Xcode非官方版本恶意代码污染事件(XcodeGhost)的分析与综述
http://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=211283363&idx=1&sn=0be9595fe5e4e9e43b749f53297c2f48&scene=1
http://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=211283363&idx=1&sn=0be9595fe5e4e9e43b749f53297c2f48&scene=1
XCodeGhost详细分析报告
http://bbs.pediy.com/showthread.php?p=1393233#post1393233
http://bbs.pediy.com/showthread.php?p=1393233#post1393233
关于Python的面试题
https://github.com/taizilongxu/interview_python
https://github.com/taizilongxu/interview_python
Equation APT analysis using Security Data Science platform: BinSecSweeper
http://www.simonroses.com/2015/09/equation-apt-analysis-using-security-data-science-platform-binsecsweeper/
http://www.simonroses.com/2015/09/equation-apt-analysis-using-security-data-science-platform-binsecsweeper/
利用被入侵的路由器迈入内网
http://drops.wooyun.org/tips/9121
http://drops.wooyun.org/tips/9121
A list of IDA Plugins
https://github.com/onethawt/idaplugins-list
https://github.com/onethawt/idaplugins-list
FCatalog: Find similarities between binary functions
http://www.xorpd.net/pages/fcatalog.html
http://www.xorpd.net/pages/fcatalog.html
SoundCloud:我们最终是如何使用微服务的?
http://dockone.io/article/695
http://dockone.io/article/695
打造一个自动检测页面是否存在XSS的插件Ⅲ
http://www.freebuf.com/articles/web/79013.html
http://www.freebuf.com/articles/web/79013.html
Remote code execution via PHP [Unserialize]
https://www.notsosecure.com/2015/09/24/remote-code-execution-via-php-unserialize/
https://www.notsosecure.com/2015/09/24/remote-code-execution-via-php-unserialize/
PowerShell Memory Scraping for Credit Cards
http://www.shellntel.com/blog/2015/9/16/powershell-cc-memory-scraper
http://www.shellntel.com/blog/2015/9/16/powershell-cc-memory-scraper
XcodeGhost截胡攻击和服务端的复现
http://drops.wooyun.org/papers/9024
http://drops.wooyun.org/papers/9024
时间图:长时间内离散事件的可视化
http://card.weibo.com/article/h5/s?from=timeline&isappinstalled=0#cid=1001603889475154487219&from=1054093010&wm=3333_2001&ip=27.38.4.33
http://card.weibo.com/article/h5/s?from=timeline&isappinstalled=0#cid=1001603889475154487219&from=1054093010&wm=3333_2001&ip=27.38.4.33
GITS 2015 CTF 'aart' writeup
https://kitctf.de/writeups/gits2015/aart/
https://kitctf.de/writeups/gits2015/aart/
Dotabuff Bbs Worm
http://linux.im/2015/09/20/Dotabuff-Worm.html
http://linux.im/2015/09/20/Dotabuff-Worm.html
Reversing Mobile Traffic Lights
http://www.bastibl.net/traffic-lights/
http://www.bastibl.net/traffic-lights/
Password_Storage_Cheat_Sheet
https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet
https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet
CSAW15 solution videos
https://www.dgsec.net/csaw15-solution-videos/
https://www.dgsec.net/csaw15-solution-videos/
XCodeGhost:信息分享及企业防护建议
http://weibo.com/p/1001603889454044583522
http://weibo.com/p/1001603889454044583522
awesome-malware-analysis:恶意分析资料
https://github.com/rshipp/awesome-malware-analysis
https://github.com/rshipp/awesome-malware-analysis
CSAW CTF 2015 - Web 200 Writeup
http://jordan-wright.com/blog/2015/09/21/csaw-ctf-2015-web-200-writeup/
http://jordan-wright.com/blog/2015/09/21/csaw-ctf-2015-web-200-writeup/
DEFCON 23 Badge Challenge
http://potatohatsecurity.tumblr.com/post/126411303994/defcon-23-badge-challenge
http://potatohatsecurity.tumblr.com/post/126411303994/defcon-23-badge-challenge
Japanese Banking Trojan Shifu Combines Malware Tools
https://blogs.mcafee.com/mcafee-labs/japanese-banking-trojan-shifu-combines-malware-tools/
https://blogs.mcafee.com/mcafee-labs/japanese-banking-trojan-shifu-combines-malware-tools/
Kaspersky: Mo Unpackers, Mo Problems
http://googleprojectzero.blogspot.com/2015/09/kaspersky-mo-unpackers-mo-problems.html
http://googleprojectzero.blogspot.com/2015/09/kaspersky-mo-unpackers-mo-problems.html
基于Spark和Flask的一个可伸缩的电影推荐系统
http://python.jobbole.com/82207/
http://python.jobbole.com/82207/
malcontrol:Malware Control Monitor
https://github.com/marcoramilli/malcontrol
https://github.com/marcoramilli/malcontrol
SQL profiling and introspection for applications using sqlalchemy
https://github.com/inconshreveable/sqltap
https://github.com/inconshreveable/sqltap
一次移动记账 App 的设计探索
http://isux.tencent.com/finance-mobile-app-design.html
http://isux.tencent.com/finance-mobile-app-design.html
外卖O2O App安全性分析:App漏洞评估平台技术细节
http://www.freebuf.com/articles/terminal/78699.html
http://www.freebuf.com/articles/terminal/78699.html
XCodeGhost 'Materializes' on App Store
https://labs.opendns.com/2015/09/21/xcodeghost-materializes/
https://labs.opendns.com/2015/09/21/xcodeghost-materializes/
Domain name permutation engine
https://github.com/elceef/dnstwist
https://github.com/elceef/dnstwist
Ways To Load Kerberos Tickets
http://carnal0wnage.attackresearch.com/2015/09/ways-to-load-kerberos-tickets.html
http://carnal0wnage.attackresearch.com/2015/09/ways-to-load-kerberos-tickets.html
WordPress Vulnerability Analysis
http://drops.wooyun.org/papers/8988
http://drops.wooyun.org/papers/8988
Detect potentially malicious PHP files
https://github.com/nbs-system/php-malware-finder
https://github.com/nbs-system/php-malware-finder
儿童智能手表行业安全问题报告
http://drops.wooyun.org/papers/9164
http://drops.wooyun.org/papers/9164
UnityGhost的检测和回溯
http://xteam.baidu.com/?p=351
http://xteam.baidu.com/?p=351
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第82期)
