•HFL: Hybrid Fuzzing on the Linux Kernel
https://chungkim.io/doc/ndss20-hfl.pdfNdss2020 linux內核漏洞挖掘論文•On Measuring and Visualizing Fuzzer Performance
https://hexgolems.com/2020/08/on-measuring-and-visualizing-fuzzer-performance/提升fuzzer評估效率的方法•Everything Old is New Again: Binary Security of WebAssembly
https://www.usenix.org/system/files/sec20-lehmann.pdfUsenix2020WebAssembly漏洞論文•Responsible and Effective Bugfinding
https://blog.regehr.org/archives/2037漏洞挖掘的有效方法IOT漏洞相關•A PRACTICAL GUIDE FOR CRACKING AES-128 ENCRYPTED FIRMWARE UPDATES
https://gethypoxic.com/blogs/technical/a-practical-guide-for-cracking-aes-128-encrypted-firmware-updates實戰破解AES-128加密的固件升級包•Breaking the D-Link DIR3060 Firmware Encryption - Recon - Part 1
https://0x434b.dev/breaking-the-d-link-dir3060-firmware-encryption-recon-part-1/D-Link DIR3060固件加密解析漏洞利用相關•Buffer-Overflow-Exploit-Development-Practice
https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice棧溢出實戰練習倉庫作業系統漏洞相關•SassyKitdi: Kernel Mode TCP Sockets + LSASS Dump
https://zerosum0x0.blogspot.com/2020/08/sassykitdi-kernel-mode-tcp-sockets.htmlwindows通用kernel payload•CVE-2020-1571 Windows Setup Elevation of Privileges Bypass 0day
https://github.com/klinix5/Windows-Setup-EoPCVE-2020-1571 windows提權漏洞exp•Windows AppX Deployment Service Local Privilege Escalation (CVE-2020-1488)
https://www.activecyber.us/activelabs/windows-appx-deployment-service-local-privilege-escalation-cve-2020-1488CVE-2020-1488WindowsAppXDeployment服務提權漏洞分析•BLIZZARD JAILBREAK
https://geosn0w.github.io/getblizzard/開源的越獄工具IOS 11.0至 IOS 13.5•CVE-2020-1337: my two cents
https://blog.hiveminds.es/en/posts/cve-2020-1337_my_two_cents/CVE-2020-1337漏洞分析應用程式漏洞相關•List of bug bounty writeups
https://pentester.land/list-of-bug-bounty-writeups.html#bug-bounty-writeups-published-in-2020bounty 報告•Bludit Auth BF mitigation bypass exploit / PoC
https://github.com/noraj/Bludit-auth-BF-bypassExploit/ PoCfor CVE-2019-17240•Understanding and Preventing LDAP Injection
https://www.securecoding.com/understanding-and-preventing-ldap-injection/LDAP注入及防禦機制分析•A SmorgasHORDE of Vulnerabilities :: A Comparative Analysis of Discovery
https://srcincite.io/blog/2020/08/19/a-smorgashorde-of-vulnerabilities-a-comparative-analysis-of-discovery.htmlSmorgasHORDE漏洞挖掘分析•Struts2 S2-059 漏洞分析
https://wxn.qq.com/cmsid/20200816A03TC200其它•PowerShell Commands for Incident Response
https://www.securityinbits.com/incident-response/powershell-commands-for-incident-response/powershell 奇淫技巧命令•Why you should always scan UDP ports (part 1/2)
https://medium.com/@securityshenaningans/why-you-should-always-scan-udp-ports-part-1-2-d8ee7eb26727掃描UDP埠的作用往期推薦
2020.7.13-7.19一周知識動態
2020.7.20-7.6一周知識動態
2020.7.27-8.2一周知識動態
2020.8.3-8.9一周知識動態
【平凡路上】是一個致力於二進位漏洞分析與利用交流與分享的圈子,做純粹的技術分享,與大家共同進步。如果大家覺得公眾號不錯的話,幫忙推薦給身邊的朋友,你的分享是我們的動力。同時歡迎掃描下方二維碼加入【平凡路上】知識星球,在星球裡面與各位師傅分享自己的經驗與心得以及提出自己的疑問,與大家共同進步。