Aggregator
一个漏洞技术分析文章带来的思考
4 years 2 months ago
今天在某技术群里看到大家都在讨论一个技术文章,然后就点击去看了下。
Freebsd jail设计解读
4 years 2 months ago
Freebsd的jail模型是一个纯粹的沙箱模型,用来限制进程的一些行为,是一种安全机制。
阿里云盾反爬虫(Anti-Bot)产品方案浅析
4 years 2 months ago
阿里云爬虫风险管理(Anti-Bot Service,简称Anti-Bot)针对原生App端提供安全SDK解决方案。为App提供可信通信、防机器脚本滥刷等安全防护,有效识别高风险手机、猫池、牧场等特征。
FIN7 APT组织有趣的另类样本
4 years 2 months ago
漏洞复现|Apache Flink(CVE-2020-17519)漏洞分析
4 years 2 months ago
在昨日(2021/1/5),Apache Flink发布安全更新,修复了由蚂蚁安全非攻实验室发现的2个高危漏洞
F5 Labs’ Cybersecurity Predictions for 2021
4 years 2 months ago
We considered the shape of the coming year in cybersecurity. Phishing, APTs, malware, old vulnerabilities… it’s not all bad … well, actually, it is.
阿里云盾反爬虫(Anti-Bot)产品方案浅析 - 我是小三
4 years 2 months ago
目录: 一、行业背景 二、Anti-Bot简介 三、Anti-Bot安全SDK SGAVMP逆向分析 四、总结 一、行业背景 爬虫最早源于搜索引擎,它是一种按照一定的规则,自动从互联网上抓取信息数据的脚本程序,“爬虫本身不生产数据,它只是数据的搬运工”。搜索引擎是善意的爬虫,它爬取网站的所有页面,提
我是小三
一个普通网安从业人员的2020
4 years 2 months ago
从云上攻防入手剖析攻击者的利用手法,进而站在攻击者的视角去思考防御改进,再从体系化的角度谈谈如何建立蓝军(Red Team)并在企业内部付诸实践,最后站在基础架构安全层面介绍一些业界最佳实践及如何从根本上解决常见的攻击风险。
Keeping Emissions in Check During Unprecedented Internet Use
4 years 2 months ago
As I reflect on 2020 and the way in which the pandemic affected the business world, what stands out to me is the incredible increase in streaming content consumed on the internet. We've seen launches of some of the highest-profile streaming services to date between late 2019 and 2020. People are continuously streaming content and we need to consider the impact that increased viewership is having on the world. When you sit down to catch a movie or binge watch that latest series, do you consider the effect that streamed content has on the rest of the world? We will continue to see an uptick in carbon emissions from the power required to serve online content: servers, network hardware, and the energy needed to keep it all cool.
Mike Mattera
Tree-Tracker: Auditing a Log Harvest Using IoT Edge Connect and Node-Red
4 years 2 months ago
At long last, Blue Water Farm is generating revenue! Around 20 acres of our land consists of dense, mature hardwood of oak, maple, and beech, and we were able to contract to sell 65 maple and 25 oak trees to a logging company. I won't be retiring from Akamai any time soon from our logging windfall, but it's nice to see some revenue from our land, and clearing mature trees is a part of good responsible forest management.
Brian Apley
教你实现自己的DNS隧道远控
4 years 2 months ago
“我”的信息安全规划,望指正
4 years 2 months ago
如果团队成员连自己在做的事情都无法清晰理解,就极其容易陷入一种不知道方向何在的迷失中去——你可能根本不知道自己除了手边那些琐碎的工作还需要去思考什么,还需要积累学习什么,以及未来你的方向何在。
January 2021 Security Releases
4 years 2 months ago
ATT&CK 2020更新指南
4 years 2 months ago
ATT&CK框架更新的速度较快,在一年的时间内发布了三次大的更新.
基于Outlook邮件的持久化技术
4 years 2 months ago
Tomcat容器攻防笔记之Listener内存马
4 years 2 months ago
“少年的梦发烫,晒过月与太阳,随风自生自长”
针对CobaltStrike中出现的Stager监听端口特征后门分析 - don0t
4 years 2 months ago
针对CobaltStrike中出现的Stager监听端口特征后门分析和处理方式
don0t
Winrm远程命令/端口复用后门复现运用 - admin-神风
4 years 2 months ago
一、简介 WinRM是WindowsRemoteManagementd(win远程管理)的简称。基于Web服务管理(WS-Management)标准,使用80端口或者443端口。这样一来,我们就可以在对方有设置防火墙的情况下远程管理这台服务器了。 Server2008R2及往上的系统中默认中都开启该
admin-神风
WSUS攻击Part2:CVE-2020-1013 Windows 10本地权限升级
4 years 2 months ago