针对Windows的Java反序列化攻击

https://isc.sans.edu/forums/diary/Java+Deserialization+Attack+Against+Windows/23513/

 

越过 XSS: Edge Side Include Injection

http://gosecure.net/2018/04/03/beyond-xss-edge-side-include-injection/

 

新的Android恶意软件——KevDroid调查与分析

http://blog.talosintelligence.com/2018/04/fake-av-investigation-unearths-kevdroid.html

 

CSRF攻击与防御

https://www.cnblogs.com/phpstudy2015-6/p/6771239.html

 

小心!恶意的游戏扩展

Malicious gaming extensions: a child’s play to infection

 

A root cause analysis of CVE-2018-0797 – Rich Text Format Stylesheet Use-After-Free vulnerability

https://www.fortinet.com/blog/threat-research/a-root-cause-analysis-of-cve-2018-0797—rich-text-format-styles.html

 

CloudFront劫持

CloudFront Hijacking

 

Oracle EBS Penetration testing tool

https://erpscan.com/press-center/blog/oracle-ebs-penetration-testing-tool/

 

badtouch——一个可编写脚本的网络身份验证破解程序

https://github.com/kpcyrd/badtouch