技术类:
opensshd – user enumeration 用户列举漏洞
中文讨论在http://zone.wooyun.org/content/28516
http://seclists.org/fulldisclosure/2016/Jul/51
httpoxy:PHP,GO,Pyhton以及其他语言可能包含的CGI应用漏洞
中文分析在 http://bobao.360.cn/learning/detail/2903.html,
技术讨论在 http://zone.wooyun.org/content/28537,
POC在 https://github.com/httpoxy/php-fpm-httpoxy-poc
浏览器中的恶意软件,你的chrome扩展是如何被黑的
https://kjaer.io/extension-malware/
Meinberg NTP 时间服务器的RCE漏洞
https://www.securifera.com/blog/2016/07/17/time-to-patch-rce-on-meinberg-ntp-time-server/
Joomla的CVE-2015-8562漏洞,被用于挂马
https://blog.sucuri.net/2016/07/new-realstatistics-attack-vector-compromising-joomla-sites.html
Runtime DirectX Hooking
http://www.codereversing.com/blog/archives/282
50 Shades of Fuzzing
https://speakerdeck.com/marcograss/50-shades-of-fuzzing
安全评估7款手环设备
https://www.av-test.org/fileadmin/pdf/avtest_2016-07_fitness_tracker_english.pdf
了解Kovter恶意软件的维持权限(persistence )的方法
https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/
通过行为分析检测 Neutrino EK
http://capstarforensics.com/?p=713
新的ERNW白皮书,讨论Xenpwn层的安全漏洞
https://www.ernw.de/download/newsletter/ERNW_Newsletter_54_Xenpwn_v.1.0_signed.pdf
python的openvas酷,可以支持openvas 6,7,8
https://github.com/golismero/openvas_lib
word宏病毒使用WMI检测VM环境
https://www.vmray.com/word-macro-detects-vm-environments/
WiReboot-Keep:可以让你的wifi路由器,每24小时自动重启一次
https://www.kickstarter.com/projects/786298545/wireboot-keep-your-wifi-on-24-7-automatically-rebo
B-Sides London伦敦会议的视频:通过源码静态分析寻找BUG
https://www.youtube.com/watch?v=Sb011qfbMkQ
资讯类:
黑客花费46个月猜测对手球队的密码
http://www.theregister.co.uk/2016/07/19/hacker_46_months_db_breach/?mt=1468894136585
收购信息:
奇虎 360花费6 亿美元购买Opera 浏览器
https://www.engadget.com/2016/07/18/opera-browser-sold-to-a-chinese-consortium-for-600-million/
签协议了!软银320亿美元正式收购ARM
http://tech.ifeng.com/a/20160719/42579773_0.shtml
数据泄露信息:
前段时间的泄露的恐怖主意人员的信息在暗网售卖