http://esevece.github.io/2016/06/01/taking-over-heroku-accounts.html
接管Heroku帳號
https://www.nccgroup.trust/globalassets/our-research/us/whitepapers/2016/june/container_whitepaperpdf/
linux容器的許可權和非許可權的濫用
https://bogner.sh/2016/03/mitm-attack-against-keepass-2s-update-check/
通過中間人攻擊,可以在keepass更新時,擷取明文
http://blog.talosintel.com/2016/06/ropmemu.html
ROPMEMU:分析代碼重用攻擊的架構
https://grsecurity.net/SSTIC2016.pdf
SSTIC 2016 KEYNOTE
http://www.phdays.com/program/
phdays會議PPT開始提供下載
https://github.com/ANSSI-FR/polichombr
polichombr:惡意軟體協同分析架構
https://github.com/wg/arc
用GO編寫的安全檔案打包程式
https://github.com/gentilkiwi/mimikatz/releases
mimikatz 20160602 (oe.eo) edition 發行
https://adaclscan.codeplex.com/
ADACLScan4.3.ps1 發行
https://olivierbeg.com/finding-xss-vulnerabilities-in-flash-files/
如果在flash檔案中尋找xss漏洞
https://cyber-defense.sans.org/blog/2016/06/01/powershell-function-to-send-udp-syslog-message-packets
使用powershell發送udp syslog訊息包
https://blogs.technet.microsoft.com/windowsserver/2016/05/26/securing-privileged-access-preventing-and-detecting-attacks/
為什麼說許可權訪問重要:阻止和檢測攻擊
http://bitcoinist.net/sandjacking-ios-bitcoin-ethereum/
Sandjacking ios利用威脅比特幣錢包
https://isc.sans.edu/diary/21123
針對DSHELL的網路取證第二部分
http://blog.securelayer7.net/mongodb-security-injection-attacks-with-php/
MongoDB安全,php中的注入攻擊
http://www.slideshare.net/phdays/ss-62570233
WAF繞過
本文由 360安全播報 原創發布,如需轉載請註明來源及本文地址。本文地址:http://bobao.360.cn/news/detail/3121.html