SecWiki周刊(第89期)
2015/11/09-2015/11/15
安全资讯
The clock is ticking that could blow up a free internet: the TPP
http://www.theguardian.com/commentisfree/2015/nov/06/clock-ticking-time-bomb-blow-up-free-internet-tpp
http://www.theguardian.com/commentisfree/2015/nov/06/clock-ticking-time-bomb-blow-up-free-internet-tpp
安全技术
TensorFlow: Large-scale machine learning on heterogeneous systems
https://github.com/tensorflow/tensorflow
https://github.com/tensorflow/tensorflow
Jenkins漏洞探测、用户抓取爆破
https://github.com/blackye/Jenkins
https://github.com/blackye/Jenkins
OS-X-Security-and-Privacy-Guide
https://github.com/drduh/OS-X-Security-and-Privacy-Guide
https://github.com/drduh/OS-X-Security-and-Privacy-Guide
Python安全编码指南
http://drops.wooyun.org/tips/10383
http://drops.wooyun.org/tips/10383
绿盟科技网络攻防赛决赛Write-ups
http://blog.nsfocus.net/nsctf-network-attack-defence-finals/
http://blog.nsfocus.net/nsctf-network-attack-defence-finals/
Violent Python中文版全本
http://pan.baidu.com/s/1qW5VdDE
http://pan.baidu.com/s/1qW5VdDE
二进制漏洞人员的五个技能方向
http://weibo.com/p/1001603907896629983260
http://weibo.com/p/1001603907896629983260
第六季极客大挑战writeup
http://blog.sycsec.com/?p=725
http://blog.sycsec.com/?p=725
域渗透—Local Administrator Password Solution
http://drops.wooyun.org/tips/10496
http://drops.wooyun.org/tips/10496
Redis CrackIT 入侵事件分析
http://static.nosec.org/download/redis_crackit_v1.0.pdf
http://static.nosec.org/download/redis_crackit_v1.0.pdf
GeekPwn 2015 视频
http://v.qq.com/vplus/e659025cdd238151b188a15948ea99e1
http://v.qq.com/vplus/e659025cdd238151b188a15948ea99e1
使用graphviz绘制流程图(2015版)
http://icodeit.org/2015/11/using-graphviz-drawing
http://icodeit.org/2015/11/using-graphviz-drawing
Big data stories in seconds: Hacker News and BigQuery
https://medium.com/google-cloud/big-data-stories-in-seconds-hacker-news-abe52bc5caad
https://medium.com/google-cloud/big-data-stories-in-seconds-hacker-news-abe52bc5caad
使用FINS协议攻击欧姆龙(Omron)PLC的物理(I/O)输出
http://plcscan.org/blog/2015/11/attacks-omron-plc-coils-output/
http://plcscan.org/blog/2015/11/attacks-omron-plc-coils-output/
Black Hat EU-15 day two
http://pan.baidu.com/s/1eQExtSm
http://pan.baidu.com/s/1eQExtSm
XSS to RCE in Atlassian Hipchat
http://maustin.net/2015/11/12/hipchat_rce.html
http://maustin.net/2015/11/12/hipchat_rce.html
行走在网格之间:微博用户关系模型
http://www.wbrecom.com/?p=605
http://www.wbrecom.com/?p=605
All-Natural, Organic, Free Range, Sustainable, Whitelisting Evasion - Regsvcs
http://subt0x10.blogspot.jp/2015/11/all-natural-organic-free-range.html
http://subt0x10.blogspot.jp/2015/11/all-natural-organic-free-range.html
POC2015 & RUXCON2015 盘古团队议题
http://blog.pangu.io/poc2015-ruxcon2015/
http://blog.pangu.io/poc2015-ruxcon2015/
Chinese Conferences Slide
https://drive.google.com/folderview?id=0B_thUFNIy8TdfjJMRDN3V05MVlpjOEF4VDJSY2V0YXRoZlhkem1NWDFZM3I5ZVZBLUV5OUE&usp=sharing#list
https://drive.google.com/folderview?id=0B_thUFNIy8TdfjJMRDN3V05MVlpjOEF4VDJSY2V0YXRoZlhkem1NWDFZM3I5ZVZBLUV5OUE&usp=sharing#list
Hacking Smartwatches - the TomTom Runner, part 1
http://grangeia.io/2015/11/09/hacking-tomtom-runner-pt1/
http://grangeia.io/2015/11/09/hacking-tomtom-runner-pt1/
Shadow Daemon:a web application firewall
https://github.com/zecure/shadowd_ui
https://github.com/zecure/shadowd_ui
Android Inline Hook
http://secauo.com/Android-Inline-Hook.html
http://secauo.com/Android-Inline-Hook.html
Black Hat EU-15 Day 1
http://pan.baidu.com/s/1dDt07ux
http://pan.baidu.com/s/1dDt07ux
BadBarcode: How to hack a starship with a piece of paper
http://www.slideshare.net/PacSecJP/hyperchem-ma-badbarcode-en1109nocommentfinal
http://www.slideshare.net/PacSecJP/hyperchem-ma-badbarcode-en1109nocommentfinal
android-vts:Android Vulnerability Test Suite
https://github.com/nowsecure/android-vts
https://github.com/nowsecure/android-vts
Defeating Pass-the-Hash
https://dfirblog.wordpress.com/2015/11/08/protecting-windows-networks-defeating-pass-the-hash/
https://dfirblog.wordpress.com/2015/11/08/protecting-windows-networks-defeating-pass-the-hash/
Iranian Cyber-Espionage Group Exposed
http://blog.checkpoint.com/wp-content/uploads/2015/11/rocket-kitten-report.pdf
http://blog.checkpoint.com/wp-content/uploads/2015/11/rocket-kitten-report.pdf
Jenkins CommonCollections Exploit
https://github.com/CaledoniaProject/jenkins-cli-exploit
https://github.com/CaledoniaProject/jenkins-cli-exploit
PowerCat - A PowerShell version of NetCat
https://github.com/secabstraction/PowerCat
https://github.com/secabstraction/PowerCat
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第89期)
