2020.9.28-10.04一周安全知识动态

转自image-20200929114557052

浏览器漏洞相关

•This is my first bug hunting in this life

1
http://ufo.stealien.com/r&d/2020/09/25/bug_hunting.html研究员ohjin关于chrome漏洞挖掘日记

•ductf2020 pwn-or-web v8 challenge

1
https://seb-sec.github.io/2020/09/28/ductf2020-pwn-or-web.htmlductf2020 v8 writeup

IOT漏洞相关

•mikrot8over

1
https://github.com/vulnersCom/mikrot8overFast exploitation tool forMikrotikRouterOS up to 6.38.4

•IoT-Pentest-devices-and-purpose

1
https://github.com/IoTSecurity101/IoT-Pentest-devices-and-purposeIoT设备渗透研究工具收集仓库

•List-of-Tools

1
https://github.com/IoT-PTv/List-of-ToolsIoT安全研究工具

•Cisco Issues Patches For 2 High-Severity IOS XR Flaws Under Active Attacks

1
https://thehackernews.com/2020/09/cisco.htmlCisco修复了IOS XR两个高危漏洞CVE-2020-3566以及CVE-2020-3569

•Hardware-Hacking-Experiments

1
https://github.com/koutto/hardware-hacking/blob/master/Hardware-Hacking-Experiments-Jeremy-Brun-Nouvion-2020.pdfNetGear N300 WNR2000v4通过硬件提取固件

漏洞挖掘相关

•SSD Lil’ Bits - Episode 3 - Fuzzing & Code Review

1
https://www.youtube.com/watch?v=kkHh2bBP3g4&feature=youtu.beSSD关于fuzz以及代码审计的视频

操作系统漏洞相关

•iOS Application Security

1
https://speakerdeck.com/vashchenko/ios-application-securityiOS app安全研究

•Jailbreaking iOS without a Mac (1/4): The Plan

1
https://medium.com/bugbountywriteup/jailbreaking-ios-without-a-mac-1-4-the-plan-b49c0edc1759iOS越狱系列文章第一篇

应用程序漏洞相关

•MS.SharePoint.CVE-2019-0604.Remote.Code.Execution

1
2
https://www.fortiguard.com/encyclopedia/ips/47918https://securityaffairs.co/wordpress/98043/hacking/sharepoint-rce.htmlSharePoint 
CVE-2019-0604远程代码执行漏洞

•A Hacker’s perspective on AEM applications security

1
https://speakerdeck.com/0ang3el/a-hackers-perspective-on-aem-applications-securityadaptTo 2020安全大会上《从黑客的角度看AdobeExperienceManager应用安全》slide

工具相关

•checksec.py

1
2
https://github.com/Wenzel/checksec.py
跨平台支持多架构的`checksec`工具

•rasengan - extract various firmware blobs from iBoot

1
2
https://github.com/b1n4r1b01/rasengan
从iBoot提取固件的工具rasengan

其它

•Programming with the PowerPC branch processor

1
2
https://www.ibm.com/developerworks/library/l-powasm3/index.html
PowerPC branch processor 编程
⬆︎UP