<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzIzMDM2MjY5NA.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Mon, 26 Jan 2026 08:43:22 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>国密tls双向认证“首例公开”研究过程分享</title><link>https://mp.weixin.qq.com/s/lPrZIq0Cr3bJsnXJxyp1jw</link><description>前文    最近在测试过程中，发现某家金融机构采用双向国密证书校验，和团队成员云舒共同研究，成功解决抓包问题。</description><author>安全边角料</author><category>安全边角料</category><pubDate>2026-01-25T19:59:58</pubDate></item><item><title>\"storm\"团队荣获\"360众测巅峰赛\"总榜第一</title><link>https://mp.weixin.qq.com/s/vA0Inq0lWeNdOt0-Nc9ihg</link><description>恭喜\\x26quot;storm\\x26quot;团队荣获\\x26quot;360众测巅峰赛\\x26quot;总榜第一</description><author>安全边角料</author><category>安全边角料</category><pubDate>2026-01-05T21:10:04</pubDate></item><item><title>一次不一样的“任意用户密码重置”</title><link>https://mp.weixin.qq.com/s/9pocQqfz-8uorsMQqWMi5g</link><description>一次攻防中核心系统的密码重置漏洞，带你开启不一样的视角。附带demo环境，可以自己实践一下</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-12-06T08:48:02</pubDate></item><item><title>补天白帽黑客城市沙龙长沙站“个人议题ppt分享”</title><link>https://mp.weixin.qq.com/s/wP-51NPfQHo7T4gTGVnJQA</link><description>内容    分享补天沙龙个人议题ppt，后续应该也会公开在奇安信社区    放到腾讯文档，自行下载 https</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-11-16T17:32:12</pubDate></item><item><title>金融业-“react native app”测试指南</title><link>https://mp.weixin.qq.com/s/47iziv0o6g2Re9Or7NDTew</link><description>金融业react native app测试指南</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-10-08T10:05:48</pubDate></item><item><title>金融业“强制国密tls”实践应用之yakit</title><link>https://mp.weixin.qq.com/s/AL6IU9qc3sUAKuB2ykH91w</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-09-19T09:15:10</pubDate></item><item><title>“postMessage”漏洞</title><link>https://mp.weixin.qq.com/s/2O8A89_h3gvy9QpDM3zazQ</link><description>“postMessage”漏洞，你挖到过吗？</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-09-02T11:14:41</pubDate></item><item><title>关于“客户端强制国密tls”的回复</title><link>https://mp.weixin.qq.com/s/n_dmNTdZq2tXDWIR6O6WHg</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-30T08:15:33</pubDate></item><item><title>金融业app抓包“强制国密tls”基础概念</title><link>https://mp.weixin.qq.com/s/yFMl3zC0V-ukgvNjCPPoyw</link><description>客户端强制国密tls了解过吗？这篇文章可能可以给你的没法抓包做出解释</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-29T12:17:46</pubDate></item><item><title>chrome “0day”讲解一二</title><link>https://mp.weixin.qq.com/s/DowR3oMqC7BdqFHAXVU0ZQ</link><description>前文    想写这篇文章已经很久很久了，感觉快拖一个月之久，今天刚好有时间将这篇文章输出一下，供大家参考。</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-23T17:37:10</pubDate></item><item><title>“人脸安全”之图生视频ai模型</title><link>https://mp.weixin.qq.com/s/SY256m0gR1uTXqek9bBdGg</link><description>安全测试人脸之新时代大模型选择尝试</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-22T16:41:25</pubDate></item><item><title>金融业“解析差异”漏洞后续-POC</title><link>https://mp.weixin.qq.com/s/J6iSLyWa6Qj9_npRPLyiYA</link><description>接着上一篇文章，本篇文章将会给出具体可行的操作方法，如未看上一篇文章，传送门如下：金融业“解码差异”漏洞上一篇</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-15T09:05:49</pubDate></item><item><title>金融业“解码差异”漏洞</title><link>https://mp.weixin.qq.com/s/5Ug9tLthXq1st1hrrSHwUA</link><description>“”不一致”也能出严重漏洞？是的没错</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-14T23:24:16</pubDate></item><item><title>红队攻防之“C2” 重定向</title><link>https://mp.weixin.qq.com/s/7e2n_gv1u9g5ovsprLw68w</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-06-02T16:22:12</pubDate></item><item><title>“脚本小子”-之恶意poc投毒事件</title><link>https://mp.weixin.qq.com/s/DLz8Izy6yftAuQW9HT6D3w</link><description>来看看你中招了吗？</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-04-20T13:31:57</pubDate></item><item><title>金融业\"服务端签名伪造\"漏洞</title><link>https://mp.weixin.qq.com/s/43WK-AcAuDnFJ6iV72xj7w</link><description>金融业”服务端签名伪造“漏洞</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-03-31T07:29:13</pubDate></item><item><title>恭喜自己获得雷神众测\"年榜第一\"</title><link>https://mp.weixin.qq.com/s/oY55KNTKUOm9YpFvquh8IA</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-03-25T19:03:41</pubDate></item><item><title>金融业“隐藏content-type”漏洞</title><link>https://mp.weixin.qq.com/s/yLGgmuF9nDjHhpOVf6_V3Q</link><description>金融业隐藏的content-type相关漏洞</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-03-23T23:11:21</pubDate></item><item><title>金融业“时序竞争”越权漏洞</title><link>https://mp.weixin.qq.com/s/g464H6gmtl61l3EwUAARHA</link><description>“时序竞争”越权漏洞</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-03-16T23:11:44</pubDate></item><item><title>“金融项目渗透测试指南”beta版本完成啦</title><link>https://mp.weixin.qq.com/s/3j03Sih6puPUnIO_cLGUeg</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-03-08T19:02:34</pubDate></item><item><title>客户端路径遍历(CSPT)漏洞详解</title><link>https://mp.weixin.qq.com/s/caljmJD8XTtU8rSeyvdWBg</link><description>客户端路径遍历（CSPT）漏洞，一种你没关注过但是却能高危的漏洞，适合想赚大钱的人研究。</description><author>安全边角料</author><category>安全边角料</category><pubDate>2025-01-22T08:03:47</pubDate></item><item><title>“点击劫持”已死？百万赏金案例分享</title><link>https://mp.weixin.qq.com/s/TG64f7xRSoiehwtBC7laWA</link><description>让点击劫持再一次强大起来</description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-12-06T18:31:22</pubDate></item><item><title>pdfjs cve-2024-4367多种利用方式分析</title><link>https://mp.weixin.qq.com/s/V5sw_U9jVNlVlUS_XjsvzQ</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-11-23T09:09:53</pubDate></item><item><title>不一样的ssrf[征求思路]</title><link>https://mp.weixin.qq.com/s/UcExaFftwQ-17Ui54QRZWw</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-11-11T12:31:45</pubDate></item><item><title>「网络安全」你差的不是技术，而是手机</title><link>https://mp.weixin.qq.com/s/GQfavnXimlNeAcG248AIQQ</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-10-22T12:10:33</pubDate></item><item><title>solr CVE-2024-45216 身份认证绕过漏洞</title><link>https://mp.weixin.qq.com/s/vODXknpneazcoSJBQBo6vg</link><description>solr CVE-2024-45216 身份认证绕过漏洞</description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-10-19T23:10:50</pubDate></item><item><title>jjwt稍旧版本bug及密钥爆破工具</title><link>https://mp.weixin.qq.com/s/grhA50u77HCtzM1_CbFzsQ</link><description></description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-10-15T22:40:33</pubDate></item><item><title>本地js测试神器-JsInfoMiner</title><link>https://mp.weixin.qq.com/s/DQCyYLyuJTm4S5YpgTvXTA</link><description>非传统的本地js测试方法，提高安全漏洞的发现效率和全面性</description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-04-14T12:36:20</pubDate></item><item><title>ssrf漏洞</title><link>https://mp.weixin.qq.com/s/pbb6jCh6821jrmw9x1jHfw</link><description>一次有趣的ssrf之旅</description><author>安全边角料</author><category>安全边角料</category><pubDate>2024-04-12T22:52:58</pubDate></item></channel></rss>