信息安全技术文章汇总 | 20180822
22 Aug 2018- An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring: Kemon
- honggfuzz漏洞挖掘技术深究系列(2)—— Persistent Fuzzing
- 在线生成key地址转发别人来IP定位
- Compromising Online Accounts by Cracking Voicemail Systems: VoiceMailAutomator
- Open source memory scanner written in C++: XenoScan
- The x86 Processor Fuzzer: sandsifter
- Defending Elections from Foreign Adversaries: Election Buster
- Security Competition Infrastructure Automation Framework: Laforge
- Backdooring and Breaking Signatures: SMBetray
- Apache Struts2 S2-057漏洞分析预警
- ghostscript命令执行漏洞预警
- UEditor编辑器两个版本任意文件上传漏洞分析
- Blackhat议题解读 | phar反序列化
- CVE-2018-11776: How to find 5 RCEs in Apache Struts with Semmle QL
- GET请求-Referer限制绕过总结
- Black Hat议题解读 | 滴滴出行王宇Black Hat 2018&DEFCON 26现场议题详解
- Hussarini:一个正将菲律宾作为攻击目标的后门
- 从一道Crypto题目认识z3
- 技术分享 | 如何使用BtleJuice黑入BLE智能电灯泡
- 谈谈我所了解的WEB代理
- Windows下反反调试技术汇总
- SQLServer攻击姿势与防护总结
- 基于DNS通信的Powershell恶意软件DNSMessenger分析
- 批量勒索挖矿常用漏洞利用工具Jexboss的简单分析
- 2018网鼎杯-第二场-writeup
- 对某webmail的渗透测试
- 针对某IDC站点的一次测试(拿下数百服务器)
- 中间人攻击教程全套
- Wker_代码审计工具
- China H.L.B “网鼎杯” 部分WriteUp
- IQY and PowerShell Abused by Spam Campaign to Infect Users in Japan with BEBLOH and URSNIF
- A few notes on WordPress Security
- Juicy Potato (abusing the golden privileges)
- 以太坊合约审计 CheckList 之“以太坊智能合约设计缺陷问题”影响分析报告
- ColdFusion再爆远程代码执行漏洞 CVE-2018-4939
- 机器学习在Windows RDP版本和后门检测上的应用