4月1日-每日安全知识热点

http://p0.qhimg.com/t01f7ef32da341925d2.jpg

1、如何搭建你自己的GSM基站

https://evilsocket.net/2016/03/31/how-to-build-your-own-rogue-gsm-bts-for-fun-and-profit/

2、web应用安全基础

http://martinfowler.com/articles/web-security-basics.html

3、java和c#中的安全密码字符串

https://nvisium.com/blog/2016/03/31/secure-password-strings/

4、You Down 'Wit XPC

http://www.lifeform-labs.com/blog/2016/3/31/you-down-wit-xpc

5、64位linux ROP

http://crypto.stanford.edu/~blynn/rop/

6、对恶意欺诈软件RETYA的技术概览

https://blog.gdatasoftware.com/2016/03/28226-ransomware-petya-a-technical-review

7、可能是目前世界上体积最小的编译器了

https://github.com/thejameskyle/the-super-tiny-compiler

8、静态分析工具,用来检测二进制文件的UAF漏洞

https://github.com/montyly/gueb

9、Apache Jetspeed 任意文件上传bug

https://www.exploit-db.com/exploits/39643/

10、绕过浏览器安全策略

http://www.mediafire.com/download/g4v6vte3ludxfll/Bypassing-Browser-Security-Policies-For-Fun-And-Profit.pdf

11、Empire 1.5发行

https://github.com/PowerShellEmpire/Empire/releases/tag/1.5

12、linux x64 shellcode

https://odzhan.wordpress.com/2016/03/31/x64-shellcodes-linux/

13、oz:一款沙箱系统

https://github.com/subgraph/oz

14、介绍r Ray’s Web SHell:一款python当客户端,php当服务端的webshell

http://www.doyler.net/security-not-included/introducting-rwsh-rays-web-shell

15、巴西恶意软件的演变

https://securelist.com/blog/research/74325/the-evolution-of-brazilian-malware/

16、快速盲住的视频和PPT https://drive.google.com/file/d/0B0tBYiOD2uG7MkpxaFRWTkhOTTA/view?pref=2&pli=1

https://www.youtube.com/watch?v=7WA9Muvt4Sg&feature=youtu.be

17、利用白名单逃逸策略

https://www.insinuator.net/2016/03/mind-the-gap-exploit-free-whitelisting-evasion-tactics/

18、hacking个人无人机

https://www.blackhat.com/docs/asia-16/materials/asia-16-Rodday-Hacking-A-Professional-Drone.pdf

免责声明:文章内容不代表本站立场,本站不对其内容的真实性、完整性、准确性给予任何担保、暗示和承诺,仅供读者参考,文章版权归原作者所有。如本文内容影响到您的合法权益(内容、图片等),请及时联系本站,我们会及时删除处理。查看原文

为您推荐