2017年1月1日 星期日

2017/1/1 資安晨摘

資安趨勢:

1.Security attacks on industrial control systems by IBM

2.Sundown Exploit Kit now leverages on the steganography by Pierluigi Paganini


社工姿勢:

1.黑客Only_guest 親身講述的三個“非主流詐騙”故事 by 謝么


PT姿勢:

1.PHP htaccess injection cheat sheet by sektioneins


漏洞分析:

1.CVE-2016-7255:分析挖掘Windows內核提權漏洞 by Stanley Zhu;翻譯:overXsky

2.Zend Framework (zend-mail) < 2.4.11 Remote Code Execution (CVE-2016-10034) by Dawid Golunski

3.Using MBAE To Disable MBAE, and Subverting ASLR/DEP by Abdulellah Alsaheel

4.Be Careful with Python's New-Style String Format by Armin Ronacher

5.Digging Into a Windows Kernel Privilege Escalation Vulnerability: CVE-2016-7255 by Stanley Zhu


POC:

1.CVE-2016-1003 Zend-mail PoC RCE Exploit by Dawid Golunski


概念教學:

1.SSD資料恢復技術探究 by OSSLab


學習資源:

1.Deep Learning Security Papers by Jason Trost


工具:

1.awesome-hacking - awesome collection of hacking tools by jekil

2.Penetration Testers Framework - a way for modular support for up-to-date tools by trustedsec

沒有留言:

張貼留言