<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzg3Mzg5MTc1OA.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Fri, 27 Feb 2026 18:29:10 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>青龙面板存在鉴权绕过：可获取面板账户密码、执行任意命令</title><link>https://mp.weixin.qq.com/s/yb0FNEOImFDp2TDqoXijgA</link><description>青龙面板存在鉴权绕过：可获取面板账户密码、执行任意命令漏洞概述近日，发现青龙面板存在严重安全漏洞。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2026-02-27T16:26:02</pubDate></item><item><title>冰蝎二开从0到1-3-behinder4流量魔改及免杀</title><link>https://mp.weixin.qq.com/s/PWSuIL5ltDJm18lycpZiZQ</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2026-01-30T09:31:03</pubDate></item><item><title>AI供应链攻击设想——mcp server投毒</title><link>https://mp.weixin.qq.com/s/ph-Pnbnolmlx8kDATG3Y1w</link><description>AI供应链攻击设想—mcp server投毒</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2026-01-23T14:45:31</pubDate></item><item><title>靶机-No-CVE-Range系列靶场B</title><link>https://mp.weixin.qq.com/s/nWgYjrxGGX2qk-v8ML3ZUg</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-12-11T11:36:52</pubDate></item><item><title>2025某集团ctf决赛-RATTRACER-AsyncRAT通信解密</title><link>https://mp.weixin.qq.com/s/DR_77fXCrB7u5RqYshwV8w</link><description>电信小伙伴给了两道ctf说帮忙看看，感觉挺有意思的，这里简单记录一下。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-12-09T09:20:57</pubDate></item><item><title>2025某集团ctf决赛-谁知盘中餐</title><link>https://mp.weixin.qq.com/s/LlYRfj09ePKY6k8FI_Illg</link><description>电信的小伙伴给了两道ctf说帮忙看看，感觉挺有意思的，这里简单记录一下。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-12-05T10:22:13</pubDate></item><item><title>2025年Solar应急响应公益月赛-11月wp</title><link>https://mp.weixin.qq.com/s/h-K5GQcnarObuz2dpr7DPQ</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-12-01T09:20:32</pubDate></item><item><title>第二届“数证杯”电子数据取证分析大赛-服务器取证wp</title><link>https://mp.weixin.qq.com/s/4pcSKdyOcy04-FV6TvGXrA</link><description>服务器取证上篇文章已经讲过怎么仿真e01软件，不会的同学去公众号看一下。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-11-19T09:30:21</pubDate></item><item><title>第二届“数证杯”电子数据取证分析大赛-计算机取证wp</title><link>https://mp.weixin.qq.com/s/kAJOxlDVp3FEu0CW7xnqqQ</link><description>题开局给到一个什么后缀也不是文件，也没说使用啥打开，这里简单讲一下，怎么将环境运行起来，再进行做题。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-11-07T09:30:41</pubDate></item><item><title>XXL-Job默认AccessToken漏洞</title><link>https://mp.weixin.qq.com/s/nOLVqWKC2MejXSdZ2ji-eg</link><description>最近遇到一个执行器默认token漏洞，但是不出网，无法直接反弹shell。也没找到调度中心面板，所以研究了下不出网利用及打filter内存马。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-09-22T13:43:20</pubDate></item><item><title>某单位ctf部分wp</title><link>https://mp.weixin.qq.com/s/aHNbVWTTJutQo7q7PTIOyw</link><description>前两天，大师傅说，有个比赛让我看看，这里记录以下。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-09-05T15:31:24</pubDate></item><item><title>《起因是一个基础的常识问题》</title><link>https://mp.weixin.qq.com/s/2P6rhVUzM5IQeG__LG4EMQ</link><description>《起因是一个基础的常识问题》</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-07-30T14:20:21</pubDate></item><item><title>冰蝎二开从0到1-2(免杀)</title><link>https://mp.weixin.qq.com/s/8UOpNd-GQ_Am8fwHxjmD-A</link><description>前言有小伙伴提议说，我们上个文章改了一下冰蝎的流量，但是在实际的应用中，我们打战肯定要先传木马落地，如果不能</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-07-21T09:00:39</pubDate></item><item><title>冰蝎二开从0到1</title><link>https://mp.weixin.qq.com/s/tPxzjVBqpJJ1JyD0EUeWwA</link><description>最近学习了一下冰蝎和哥斯拉的二开，这里简单记录一下冰蝎二开的过程。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-07-08T09:30:14</pubDate></item><item><title>苕皮哥2.0</title><link>https://mp.weixin.qq.com/s/1snp6zNXkxu3pp4j-VrMhQ</link><description>拉练开始了，苕皮哥又出动了。先生大义，卧底到参演单位给好兄弟送分已经拿下面试初级？</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-07-02T15:00:37</pubDate></item><item><title>LLM护栏demo</title><link>https://mp.weixin.qq.com/s/hYrXJHIcIiUKyMYysscY1A</link><description>LLM Guard Agent项目地址https://github.com/qncosfh/llm-guard</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-07-01T17:30:49</pubDate></item><item><title>哥斯拉二开从0到1-6(jspx免杀)</title><link>https://mp.weixin.qq.com/s/4dDhad62s4FpY84SmJUy-w</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-02-08T15:41:26</pubDate></item><item><title>哥斯拉二开从0到1-5(Asmx免杀)</title><link>https://mp.weixin.qq.com/s/1-aRbrzX5FzFo9Q0WtLerg</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-01-27T09:30:28</pubDate></item><item><title>哥斯拉二开从0到1-4(流量优化)</title><link>https://mp.weixin.qq.com/s/Jr3HJcg97e7lsXonjH6XyQ</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-01-23T15:06:19</pubDate></item><item><title>哥斯拉二开从0到1-3(动态密钥)</title><link>https://mp.weixin.qq.com/s/VKv2EH3DcWkF85-4HNHxzg</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-01-14T09:48:00</pubDate></item><item><title>cockcrow_0.0.1测试版本</title><link>https://mp.weixin.qq.com/s/izCosH9O6z4fhNVQdhabFw</link><description>嘿，你丫瞅啥。要不要来我的妙妙屋？</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2025-01-06T15:09:27</pubDate></item><item><title>哥斯拉二开从0到1-2(免杀)</title><link>https://mp.weixin.qq.com/s/G5MduvgPRWH0Yyt1KOeGAA</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-12-13T11:28:40</pubDate></item><item><title>哥斯拉二开从0到1</title><link>https://mp.weixin.qq.com/s/mRlMhi7Zy2fvCdvuQmJh2g</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-11-14T14:09:24</pubDate></item><item><title>【漏洞复现】nacos_sqli_RCE</title><link>https://mp.weixin.qq.com/s/WZ4y_V8GjL3_JUmyU0Mhyw</link><description>【漏洞复现】nacos_sqli_RCE</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-07-16T15:37:59</pubDate></item><item><title>nuclei_poc编写</title><link>https://mp.weixin.qq.com/s/RG2ki5e-XMDKadXPLYfDiA</link><description>nuclei_poc编写</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-07-09T11:23:51</pubDate></item><item><title>[禅道PMS] &lt;*.12小版本_身份认证_绕过漏洞</title><link>https://mp.weixin.qq.com/s/W16zGTvpdFRAJrHrfGDe0w</link><description>[禅道PMS] \\x26lt;*.12小版本_身份认证_绕过漏洞</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-04-27T17:34:23</pubDate></item><item><title>[kkFileView]4.2.0-4.4.0任意文件上传上传getshell 续</title><link>https://mp.weixin.qq.com/s/KvOpRN2_KmCqvCb6ypdgJA</link><description>这个洞就到此为止，大家不要去搞破坏，自己本地搭环境玩一玩就行了。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-04-22T15:35:37</pubDate></item><item><title>[kkFileView]4.2.0-4.4.0任意文件上传上传getshell</title><link>https://mp.weixin.qq.com/s/keWYMOu5SIFZ-AsdGb9mpQ</link><description>[kkFileView]4.2.0-4.4.0任意文件上传上传getshell</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-04-19T12:26:21</pubDate></item><item><title>【漏洞挖掘】一个不起眼的存储XSS利用</title><link>https://mp.weixin.qq.com/s/rAHXMrP2WfmeDKzD9Opo9Q</link><description>闲来无事，互联网上偶然看到一个代码片段。代码如下：一眼看过去，这不妥妥的可以未授权。测试了一番后，存在存储型XSS。</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-02-27T15:27:11</pubDate></item><item><title>app抓不到数据？换个打开方式试试！</title><link>https://mp.weixin.qq.com/s/mU5Ee85824WsYYPAdiY7Eg</link><description>app抓不到数据？换个打开方式试试！</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2024-01-13T17:57:11</pubDate></item><item><title>CVE-2023-38831 WINRAR漏洞分析</title><link>https://mp.weixin.qq.com/s/0Y56gc_kKaCIdFvwJ1anJw</link><description>原文地址：https://b1tg.github.io/post/cve-2023-38831-winrar</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-12-23T21:51:23</pubDate></item><item><title>uniview某接口未授权泄漏用户账密</title><link>https://mp.weixin.qq.com/s/YuDD0MT9hEqnAgKL2Z0tsQ</link><description>未授权访问特定接口可下载敏感信息Config.xml 查看到用户账号密码等敏感信息_____________</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-12-12T16:29:25</pubDate></item><item><title>见证雷池成为 GitHub 全球第一的 WAF 项目</title><link>https://mp.weixin.qq.com/s/gtmV3HKdwbCPwt_RAetysQ</link><description>雷池（SafeLine）是长亭科技耗时近 10 年打造的 WAF，由长亭独创的智能语义分析算法驱动。雷池与开</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-12-05T15:35:09</pubDate></item><item><title>【ChatGPT4】速度嫖</title><link>https://mp.weixin.qq.com/s/dOXRKJapNf_AEsAiyOWLVw</link><description>登录ChatGPT后，访问https://chat.openai.com/?model=gpt-4-gizm</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-11-16T15:15:23</pubDate></item><item><title>【新年快乐】又到了一年一度坐牢的时间了。</title><link>https://mp.weixin.qq.com/s/0sYXiVqj5yIQezS5mqoIlg</link><description>什么是JWT？JSON网络令牌（JWT）是一种用于在系统之间发送加密签名的JSON数据的标准化格式。从理论上</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-08-08T13:24:10</pubDate></item><item><title>[mitmproxy]</title><link>https://mp.weixin.qq.com/s/RUJ58fkIe_3Fr5Ll3NowIg</link><description>mitmproxy（https://mitmproxy.org/）：MITM 的 proxy，MIT</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-08-01T22:06:40</pubDate></item><item><title>利用openssl反弹shell</title><link>https://mp.weixin.qq.com/s/XlfL2vbY6TydvBHVo-y6UA</link><description>null</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-28T16:07:28</pubDate></item><item><title>某友任意文件上传RCE</title><link>https://mp.weixin.qq.com/s/e7EQ5fwT80lDQCTDr8no7g</link><description></description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-25T23:00:46</pubDate></item><item><title>[邮件安全] 0x01签名验证</title><link>https://mp.weixin.qq.com/s/rgNQV0CdfQJjWECfwsMPFQ</link><description>[邮件安全] 0x01签名验证</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-13T13:14:25</pubDate></item><item><title>nginxWebUI 远程命令执行漏洞</title><link>https://mp.weixin.qq.com/s/hbtKtLuwe1UJfTU4T0YCYA</link><description>nginxWebUI 远程命令执行漏洞</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-12T11:31:33</pubDate></item><item><title>【邮件安全】0x01 协议介绍</title><link>https://mp.weixin.qq.com/s/j7t6f4uAqKvTtNIYUpWoWw</link><description>null\\x0anull\\x0adone</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-11T11:43:00</pubDate></item><item><title>畅捷通T+ Plus 审计 （超详细）</title><link>https://mp.weixin.qq.com/s/qLl7-Nom0FOUXbYO5v0Iyw</link><description>0x00 前言FOFA: app=\\x26quot;畅捷通-TPlus\\x26quot;           使用量:10W畅捷通T+这套系</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-10T10:35:29</pubDate></item><item><title>防守方要准备哪些</title><link>https://mp.weixin.qq.com/s/ryseA_Lw5CWC4SdTZD7P9A</link><description>null。。。\\x0anull。。。\\x0adone！！！</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-07-07T09:27:16</pubDate></item><item><title>【  】</title><link>https://mp.weixin.qq.com/s/WYVG36lr0dv3k43d3jo6NQ</link><description>某次面试某云安全厂商，被问到的一个问题让我大脑停止了转动。讲一下fastjson？心想，肯定先做个介绍吗，我</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-02-20T13:10:10</pubDate></item><item><title>【隧道隐蔽】</title><link>https://mp.weixin.qq.com/s/JikbvbRqEgpQMRyL9VlI4g</link><description>一般的网络通信，需要先建立TCP链接，然后进行通讯。但是在实际的网络环境中，通常存在各种边界设备、软/硬件防</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-02-16T12:10:49</pubDate></item><item><title>一文了解base编码</title><link>https://mp.weixin.qq.com/s/DxM1KfuH5efQopWE64FNDg</link><description>相信大多数从事it行业的人都听过base编码/解码。base编/解码系列主要分为base16、base32、</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-02-08T14:40:44</pubDate></item><item><title>golang黑帽渗透编程</title><link>https://mp.weixin.qq.com/s/joO-XRLt4hLqQGZHiOUcZA</link><description>闲来无事，看了下Go黑帽子渗透测试编程之道。简单记录下…………</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-01-10T16:20:29</pubDate></item><item><title>初识Shellcode加载器</title><link>https://mp.weixin.qq.com/s/i0wDyttFmA3nGlLyuHSf2A</link><description>概念:	作为一个接触安全时间不久的小小白,我对\\x26quot;免杀\\x26quot;这门技术很感兴趣。今天就站在新手的角度和大家聊一聊如何</description><author>Cloud Security lab</author><category>Cloud Security lab</category><pubDate>2023-01-09T14:26:20</pubDate></item></channel></rss>