-->

whaust

2020年4月22日 星期三

2020 年間のセキュリティ機能トレーニング(5/15オープン登録)

1.目的
ICT安全責任レベルのA、B、およびCのレベルを持つ公的機関(組織)を支援して、ICT安全管理法の要件(ICT安全責任レベルの段階への段階的アプローチ)に準拠するには、関連する情報セキュリティ機能評価証明書が必要です。公安機関(構造)のフルタイム(責任者)の専門家のセキュリティ知識とスキルを向上させるトレーニング。
2.参加者
公安機関(構造)の常勤(責任)要員。
3.頻度
登録は5月15日10時からです。
補助金クラス:職員の研修費用は行政院の50%が助成し、残りは研修機関が助成します。
自己資金によるクラス:職員のトレーニング費用は、トレーニング組織から完全に助成されます。

シフト日付トレーニング名人数研修機関クラスサインアップ
16月11日〜12日
(木曜日〜金曜日)
セキュリティシステム開発ライフサイクル(.NET)30中国文化大学補助金開かない
27月2日〜3日
(木曜日〜金曜日)
政府情報運用アウトソーシングセキュリティ30中国文化大学補助金開かない
7月15日〜17日
(水曜〜金曜)
情報セキュリティ入門30中国文化大学補助金開かない
48月6日〜7日
(木〜金)
ICTリスク管理30中国文化大学補助金開かない
58月19日〜21日
(水曜〜金曜)
情報セキュリティ入門30中国文化大学補助金開かない
69月3日〜4日
(木曜日〜金曜日)
情報健康クリニック30中国文化大学自己負担クラス開かない
9月17日〜18日
(木〜金)
ICTリスク管理30中国文化大学自己負担クラス開かない
810月6日〜8日
(火曜日〜木曜日)
情報セキュリティ入門30中国文化大学自己負担クラス開かない
97月22日〜24日
(水曜〜金曜)
情報セキュリティ入門30ハイキング科学技術大学補助金開かない
107月29日〜31日
(水曜日〜金曜日)
情報セキュリティ入門30ハイキング科学技術大学補助金開かない
118月12日〜14日
(水曜〜金曜)
情報セキュリティ入門30ハイキング科学技術大学補助金開かない
128月26日〜28日
(水曜日〜金曜日)
Webアプリケーションのセキュリティ30ハイキング科学技術大学補助金開かない
139月9〜11日
(水曜〜金曜)
Webアプリケーションのセキュリティ30ハイキング科学技術大学自己負担クラス開かない
149月23日〜25日
(水曜〜金曜)
ネットワークアーキテクチャと展開のセキュリティ30ハイキング科学技術大学自己負担クラス開かない
1510月14日〜16日
(水曜〜金曜)
ネットワークアーキテクチャと展開のセキュリティ30ハイキング科学技術大学自己負担クラス開かない
1610月28日〜29日
(水曜日〜木曜日)
セキュリティシステム開発ライフサイクル(JAVA)30ハイキング科学技術大学自己負担クラス開かない
176月10日〜12日
(水曜日〜金曜日)
情報セキュリティ入門30逢甲大学補助金開かない
186月18日〜19日
(木曜日〜金曜日)
ICTリスク管理30逢甲大学補助金開かない
197月2日〜3日
(木曜日〜金曜日)
情報健康クリニック30逢甲大学補助金開かない
207月8日〜10日
(水曜〜金曜)
情報セキュリティ入門30逢甲大学補助金開かない
217月16日〜17日
(木曜日〜金曜日)
情報健康クリニック30逢甲大学補助金開かない
227月16日〜17日
(木曜日〜金曜日)
ICTリスク管理30逢甲大学自己負担クラス開かない
237月22日〜24日
(水曜〜金曜)
ネットワークアーキテクチャと展開のセキュリティ30逢甲大学自己負担クラス開かない
247月29日〜30日
(水曜〜木曜)
政府情報運用アウトソーシングセキュリティ30逢甲大学自己負担クラス開かない
257月1日〜3日
(水曜〜金曜)
情報セキュリティ入門30国立ZTE大学補助金開かない
26日7月16日〜17日
(木曜日〜金曜日)
ICTリスク管理30国立ZTE大学補助金開かない
27日7月30日〜31日
(木曜日〜金曜日)
政府情報運用アウトソーシングセキュリティ30国立ZTE大学補助金開かない
288月12日〜14日
(水曜〜金曜)
Webアプリケーションのセキュリティ30国立ZTE大学補助金開かない
29日8月27日〜28日
(木曜日〜金曜日)
情報健康クリニック30国立ZTE大学補助金開かない
309月2日〜4日
(水曜〜金曜)
情報セキュリティ入門30国立ZTE大学自己負担クラス開かない
319月10日〜11日
(木曜日〜金曜日)
ICTリスク管理30国立ZTE大学自己負担クラス開かない
3211月5日〜6日
(木〜金)
情報健康クリニック30国立ZTE大学自己負担クラス開かない
337月13日〜15日
(月曜日〜水曜日)
情報セキュリティ入門30朝陽科学技術大学補助金開かない
348月11日〜13日
(火曜日〜木曜日)
ネットワークアーキテクチャと展開のセキュリティ30朝陽科学技術大学補助金開かない
358月18日〜20日
(火曜日〜木曜日)
情報セキュリティ入門30朝陽科学技術大学補助金開かない
369月23日〜25日
(水曜〜金曜)
ネットワークアーキテクチャと展開のセキュリティ30朝陽科学技術大学
(中国科学部)
補助金開かない
379月28日〜29日
(月曜日〜火曜日)
情報健康クリニック30朝陽科学技術大学
(中国科学部)
自己負担クラス開かない
3810月12日〜13日
(月曜日〜火曜日)
情報健康クリニック30朝陽科学技術大学
(中国科学部)
自己負担クラス開かない
3910月14日〜16日
(水曜〜金曜)
ネットワークアーキテクチャと展開のセキュリティ30朝陽科学技術大学
(中国科学部)
自己負担クラス開かない
406月29日〜30日
(月曜日〜火曜日)
ICTリスク管理30ジンイ大学補助金開かない
417月6日〜8日
(月〜水)
情報セキュリティ入門30ジンイ大学補助金開かない
427月22日〜23日
(水曜日〜木曜日)
ICTリスク管理30ジンイ大学補助金開かない
437月28日〜30日
(火曜日〜木曜日)
ネットワークアーキテクチャと展開のセキュリティ30ジンイ大学補助金開かない
448月4日〜5日
(火曜日〜水曜日)
政府情報運用アウトソーシングセキュリティ30ジンイ大学補助金開かない
458月10日〜12日
(月曜日〜水曜日)
Webアプリケーションのセキュリティ30ジンイ大学自己負担クラス開かない
468月17日〜19日
(月〜水)
ネットワークアーキテクチャと展開のセキュリティ30ジンイ大学自己負担クラス開かない
477月20日〜22日
(月曜日〜水曜日)
Webアプリケーションのセキュリティ30昆山理工大学補助金開かない
487月28日〜29日
(火曜日〜水曜日)
政府情報運用アウトソーシングセキュリティ30昆山理工大学補助金開かない
498月25日〜27日
(火曜日〜木曜日)
情報セキュリティ入門30昆山理工大学補助金開かない
509月3日〜4日
(木曜日〜金曜日)
セキュリティシステム開発ライフサイクル(.NET)30昆山理工大学補助金開かない
519月24日〜25日
(木曜〜金曜)
情報健康クリニック30昆山理工大学補助金開かない
5210月14日〜16日
(水曜〜金曜)
情報セキュリティ入門30昆山理工大学自己負担クラス開かない
5311月5日〜6日
(木〜金)
ICTリスク管理30昆山理工大学自己負担クラス開かない
5411月11日〜13日
(水曜〜金曜)
情報セキュリティ入門30昆山理工大学自己負担クラス開かない
556月2日〜4日
(火曜日〜木曜日)
ネットワークアーキテクチャと展開のセキュリティ30機能開発専門学校補助金開かない
566月8日〜10日
(月曜日〜水曜日)
情報セキュリティ入門30機能開発専門学校補助金開かない
576月9日〜11日
(火曜日〜木曜日)
ネットワークアーキテクチャと展開のセキュリティ30機能開発専門学校補助金開かない
586月17日〜19日
(水曜〜金曜)
Webアプリケーションのセキュリティ30機能開発専門学校補助金開かない
598月4日〜5日
(火曜日〜水曜日)
政府情報運用アウトソーシングセキュリティ30機能開発専門学校自己負担クラス開かない
608月6日〜7日
(木〜金)
情報健康クリニック30機能開発専門学校自己負担クラス開かない
618月17日〜18日
(月〜火)
ICTリスク管理30機能開発専門学校自己負担クラス開かない
628月20日〜21日
(木曜日〜金曜日)
安全システム開発ライフサイクル30機能開発専門学校自己負担クラス開かない
638月24日〜26日
(月〜水)
Webアプリケーションのセキュリティ30機能開発専門学校自己負担クラス開かない
648月27日〜28日
(木曜日〜金曜日)
政府情報運用アウトソーシングセキュリティ30機能開発専門学校自己負担クラス開かない

2020年4月21日 星期二

2020年4月19日 星期日

BlackArch Linux Penetration Testing 2020.01.01 Complete install

BlackArch Linux is an Arch Linux-based penetration testing distribution for penetration testers and security researchers. The repository contains 2521 tools. In this article, I’m going to show you how to install BlackArch. A Step-by-Step walkthrough..!

Video:
Article:

2020年4月16日 星期四

Threat Signatures


There are three types of Palo Alto Networks threat signatures, each designed to detect different types of threats as the firewall scans network traffic:

  • Antivirus signatures—Detect viruses and malware found in executables and file types.
  • Anti-spyware signatures—Detects command-and-control (C2) activity, where spyware on an infected client is collecting data without the user's consent and/or communicating with a remote attacker.
  • Vulnerability signatures—Detects system flaws that an attacker might otherwise attempt to exploit.
A signature's severity indicates the risk of the detected event, and a signature's default action (for example, block or alert) is how Palo Alto Networks recommends that you enforce matching traffic.
You must Set Up Antivirus, Anti-Spyware, and Vulnerability Protection to tell the firewall what action to take when it detects a threat, and you can easily use the default security profiles to start blocking threats based on Palo Alto Networks recommendations. For each signature type, category, and even specific signatures you can continue to modify or create new profiles to more granularly enforce potential threats.
The following table lists all possible signature categories by type—Antivirus, Spyware, and Vulnerability—and includes the content update (Applications and Threats, Antivirus, or WildFire) that provides the signatures in each category. You can also go to the Palo Alto Networks Threat Vault to Learn More About Threat Signatures.
THREAT CATEGORY
CONTENT UPDATE THAT PROVIDES THESE SIGNATURES
DESCRIPTION
Antivirus Signatures
apk
Antivirus
WildFire or WildFire Private
Malicious Android Application (APK) files.
dmg
Antivirus
Wildfire or WildFire Private
Malicious Apple disk image (DMG) files, that are used with Mac OS X.
flash
Antivirus
Wildfire or WildFire Private
Adobe Flash applets and Flash content embedded in web pages.
java-class
Antivirus
Java applets (JAR/class file types).
macho
Antivirus
Wildfire or WildFire Private
Mach object files (Mach-O) are executables, libraries, and object code that are native to Mac OS X.
office
Antivirus
Wildfire or WildFire Private
Microsoft Office files, including documents (DOC, DOCX, RTF), workbooks (XLS, XLSX), and PowerPoint presentations (PPT, PPTX).
openoffice
Antivirus
Wildfire or WildFire Private
Office Open XML (OOXML) 2007+ documents.
pdf
Antivirus
Wildfire or WildFire Private
Portable Document Format (PDF) files.
pe
Antivirus
Wildfire or WildFire Private
Portable executable (PE) files can automatically execute on a Microsoft Windows system and should be only allowed when authorized. These files types include:

  • Object code.
  • Fonts (FONs).
  • System files (SYS).
  • Driver files (DRV).
  • Windows control panel items (CPLs).
  • DLLs (dynamic-link libraries).
  • OCXs (libraries for OLE custom controls, or ActiveX controls).
  • SCRs (scripts that can be used to execute other files).
  • Extensible Firmware Interface (EFI) files, which run between an OS and firmware in order to facilitate device updates and boot operations.
  • Program information files (PIFs).
pkg
Antivirus
Wildfire or WildFire Private
Apple software installer packages (PKGs), used with Mac OS X.
Spyware Signatures
adware
Applications and Threats
Detects programs that display potentially unwanted advertisements. Some adware modifies browsers to highlight and hyperlink the most frequently searched keywords on web pages-these links redirect users to advertising websites. Adware can also retrieve updates from a command-and-control (C2) server and install those updates in a browser or onto a client system.
Newly-released protections in this category are rare.
autogen
Antivirus
These payload-based signatures detect command-and-control (C2) traffic and are automatically-generated. Importantly, autogen signatures can detect C2 traffic even when the C2 host is unknown or changes rapidly.
backdoor
Applications and Threats
Detects a program that allows an attacker to gain unauthorized remote access to a system.
botnet
Applications and Threats
Indicates botnet activity. A botnet is a network of malware-infected computers (“bots”) that an attacker controls. The attacker can centrally command every computer in a botnet to simultaneously carry out a coordinated action (like launching a DoS attack, for example).
browser-hijack
Applications and Threats
Detects a plugin or software that is modifying browser settings. A browser hijacker might take over auto search or track users’ web activity and send this information to a C2 server.
Newly-released protections in this category are rare.
data-theft
Applications and Threats
Detects a system sending information to a known C2 server.
Newly-released protections in this category are rare.
dns
Antivirus
Detects DNS requests to connect to malicious domains.
dns and dns-wildfire signatures detect the same malicious domains; however, dns signatures are included in the daily Antivirus content update and dns-wildfire signatures are included in the WildFire updates that release protections every 5 minutes.
dns-wildfire
Wildfire or WildFire Private
Detects DNS requests to connect to malicious domains.
dns and dns-wildfire signatures detect the same malicious domains; however, dns signatures are included in the daily Antivirus content update and dns-wildfire signatures are included in the WildFire updates that release protections every 5 minutes.
keylogger
Applications and Threats
Detects programs that allow attackers to secretly track user activity, by logging keystrokes and capturing screenshots.
Keyloggers use various C2 methods to periodically sends logs and reports to a predefined e-mail address or a C2 server. Through keylogger surveillance, an attacker could retrieve credentials that would enable network access.
networm
Applications and Threats
Detects a program that self-replicates and spreads from system to system. Net-worms might use shared resources or leverage security failures to access target systems.
phishing-kit
Applications and Threats
Detects when a user attempts to connect to a phishing kit landing page (likely after receiving an email with a link to the malicious site). A phishing website tricks users into submitting credentials that an attacker can steal to gain access to the network.
In addition to blocking access to phishing kit landing pages, enable Multi-Factor Authentication and Credential Phishing Prevention to prevent phishing attacks at all stages.
post-exploitation
Applications and Threats
Detects activity that indicates the post-exploitation phase of an attack, where an attacker attempts to assess the value of a compromised system. This might include evaluating the sensitivity of the data stored on the system, and the system’s usefulness in further compromising the network.
web shell
Applications and Threats
Detects systems that are infected with a web shell. A web shell is a script that enables remote administration of a web server; attackers can use web shell-infected web servers (the web servers can be both internet-facing or internal systems) to target other internal systems.
spyware
Applications and Threats
Detect outbound C2 communication. These signatures are either auto-generated or are manually created by Palo Alto Networks researchers.
Spyware and autogen signatures both detect outbound C2 communication; however, autogen signatures are payload-based and can uniquely detect C2 communications with C2 hosts that are unknown or change rapidly.
Vulnerability Signatures
brute force
Applications and Threats
A brute-force signature detects multiple occurrences of a condition in a particular time frame. While the activity in isolation might be benign, the brute-force signature indicates that the frequency and rate at which the activity occurred is suspect. For example, a single FTP login failure does not indicate malicious activity. However, many failed FTP logins in a short period likely indicate an attacker attempting password combinations to access an FTP server.
You can tune the action and trigger conditions for brute force signatures.
code execution
Applications and Threats
Detects a code execution vulnerability that an attacker can leverage to run code on a system with the privileges of the logged-in user.
code-obfuscation
Applications and Threats
Detects code that has been transformed to conceal certain data while retaining its function. Obfuscated code is difficult or impossible to read, so it’s not apparent what commands the code is executing or with which programs its designed to interact. Most commonly, malicious actors obfuscate code to conceal malware. More rarely, legitimate developers might obfuscate code to protect privacy, intellectual property, or to improve user experience. For example, certain types of obfuscation (like minification) reduce file size, which decreases website load times and bandwidth usage.
dos
Applications and Threats
Detects a denial-of-service (DoS) attack, where an attacker attempts to render a targeted system unavailable, temporarily disrupting the system and dependent applications and services. To perform a DoS attack, an attacker might flood a targeted system with traffic or send information that causes it to fail. DoS attacks deprive legitimate users (like employees, members, and account holders) of the service or resource to which they expect access.
exploit-kit
Applications and Threats
Detects an exploit kit landing page. Exploit kit landing pages often contain several exploits that target one or many common vulnerabilities and exposures (CVEs), for multiple browsers and plugins. Because the targeted CVEs change quickly, exploit-kit signatures trigger based on the exploit kit landing page, and not the CVEs.
When a user visits a website with an exploit kit, the exploit kit scans for the targeted CVEs and attempts to silently deliver a malicious payload to the victim’s computer.
info-leak
Applications and Threats
Detects a software vulnerability that an attacker could exploit to steal sensitive or proprietary information. Often, an info-leak might exist because comprehensive checks do not exist to guard the data, and attackers can exploit info-leaks by sending crafted requests.
overflow
Applications and Threats
Detects an overflow vulnerability, where a lack of proper checks on requests could be exploited by an attacker. A successful attack could lead to remote code execution with the privileges of the application, server or operating system.
phishing
Applications and Threats
Detects when a user attempts to connect to a phishing kit landing page (likely after receiving an email with a link to the malicious site). A phishing website tricks users into submitting credentials that an attacker can steal to gain access to the network.
In addition to blocking access to phishing kit landing pages, enable Multi-Factor Authentication and Credential Phishing Prevention to prevent phishing attacks at all stages.
protocol-anomaly
Applications and Threats
Detects protocol anomalies, where a protocol behavior deviates from standard and compliant usage. For example, a malformed packet, poorly-written application, or an application running on a non-standard port would all be considered protocol anomalies, and could be used as evasion tools. It is a best practice to block protocol anomalies of any severity.
sql-injection
Applications and Threats
Detects a common hacking technique where an attacker inserts SQL queries into an application’s requests, in order to read from or modify a database. This type of technique is often used on websites that do not comprehensively sanitize user input.

2020年4月15日 星期三

滿滿的 svhost.xml (fully svhost.xml)

Hacker要攻 , 然後EternalBlue配置檔一直被Cisco AMP for Endpoint 隔離, 
所以打不成功, 就一直try, try 到懷疑人生, 因為之前可能都成功, 為何最近不成功 , 怎麼會這樣  ?
因為被擋了 ... 
經判斷是 Backdoor.XJC








原來是這些殘部



5G網絡的核心技術暨SDN網路實驗與Wireshark診斷分析

  1. Macro cell sites with a smaller number of fronthaul fiber links
  2. Distributed antenna systems (DAS) with a high number of fronthaul fiber links
  3. Centralized radio access network (C-RAN) with a high number of fronthaul fiber links


(A)5G的關鍵技術:下一代革命性的網路(SDN)雲ISP、電信運營商、企業面臨的問題
(B)OpenFlow1.x交換器必須懂的規格
(C) OpenFlow訊息類型
(D) OpenFlow交換器與控制器
(E) Linux與Mininet基礎
(F)OpenFlow實驗環境與mininet操作
(G)交換器類型的選擇與實現
(H) SDN乙太網集線器實現與Wireshark分析
(I) OpenFlow流記錄顯示與流加入方法
(J) SDN交換器的實現方式
SDN學習型交換器:l2_learning.py實作分析
MiniEdit繪圖與實作分析

Popular