<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzg5MDU4NjYwOQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Fri, 28 Mar 2025 07:39:34 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>护网行动倒计时：企业必须落实的七项战前准备（万字实操指南）</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484249&amp;idx=1&amp;sn=dd33237d7a65b54e4625f6a71289a1ba</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-27T19:53:40</pubDate></item><item><title>ThinkPHP 多语言本地文件包含漏洞(lang-rce)复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484245&amp;idx=1&amp;sn=72e76c0d95fc37a646ebd834a39e1be3</link><description>ThinkPHP 多语言本地文件包含漏洞(lang-rce)复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-23T21:06:15</pubDate></item><item><title>浅谈护网如何面试签约：避坑指南与血泪教训</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484244&amp;idx=1&amp;sn=2994f21fbf763c2fa8d3c6a632410582</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-21T21:43:14</pubDate></item><item><title>SRC漏洞挖掘之敏感信息泄露漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484240&amp;idx=1&amp;sn=d7532687fa54f9403d3489a824651ecb</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-20T22:10:52</pubDate></item><item><title>SRC漏洞挖掘之并发漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484236&amp;idx=1&amp;sn=5193c349b28c2433ae1e1c9799effd64</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-19T21:28:26</pubDate></item><item><title>SRC漏洞挖掘之越权漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484232&amp;idx=1&amp;sn=00bc01f6b175e96b6f09c2fdbf3ef5d0</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-18T18:19:23</pubDate></item><item><title>SRC漏洞挖掘之未授权漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484228&amp;idx=1&amp;sn=29999622ae9c6523de14419be8621253</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-17T20:59:52</pubDate></item><item><title>SRC漏洞挖掘之文件上传漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484223&amp;idx=1&amp;sn=feba755768b8f849823e57dae54399e0</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-16T22:09:47</pubDate></item><item><title>SRC漏洞挖掘之逻辑漏洞挖掘实战指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484219&amp;idx=1&amp;sn=89af4b699328ee762974eeb130ed2c58</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-15T21:29:05</pubDate></item><item><title>SRC漏洞挖掘之SQL注入漏洞挖掘</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484215&amp;idx=1&amp;sn=b3b4f0dd8ffc562c078ac4fe6cd3a90f</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-14T23:43:16</pubDate></item><item><title>SRC漏洞挖掘之XSS漏洞挖掘【文末有短期渗透项目人员需求】</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484211&amp;idx=1&amp;sn=de893c776e848281581b21f9ff2c9d9a</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-13T18:17:14</pubDate></item><item><title>服务器遭遇挖矿病毒：详细处置流程与应急响应</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484203&amp;idx=1&amp;sn=31483e47ee887dd92bd267b19c7a4f97</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-12T18:51:36</pubDate></item><item><title>《SRC漏洞挖掘实战指南：掌握这些思路月入过万不是梦》</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484199&amp;idx=1&amp;sn=408d005a7a84117200e9705d131e6cbc</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-11T20:21:41</pubDate></item><item><title>《SRC漏洞挖掘思路手法：揭秘服务器端请求伪造的危险》</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484195&amp;idx=1&amp;sn=17d0eab4f47adc638f3a6077b22cab48</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-10T18:32:26</pubDate></item><item><title>当ChatGPT突破防火墙：14亿人的数字保卫战已然打响！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484190&amp;idx=1&amp;sn=44a31fee15739d3ccc192c450ce63be9</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-09T21:18:26</pubDate></item><item><title>中国团队的 AI 创举：开启智能新时代</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484186&amp;idx=1&amp;sn=4ae18f7f4e90245fa29fc2c6e5285be5</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-06T18:33:29</pubDate></item><item><title>深度求索技术对网络安全的影响：机遇与挑战并存的数字世界</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484179&amp;idx=1&amp;sn=bf3fb569f07b77c8cdb0843e6a5e20d7</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-03-05T18:29:06</pubDate></item><item><title>《SQL注入攻击手法大揭秘！你的数据库正在被黑客这样掏空》</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484169&amp;idx=1&amp;sn=d2773984743ee20d74305e3c2810c9bc</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-02-21T22:15:49</pubDate></item><item><title>他发现了一个隐藏在代码中的秘密，这改变了一切！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484163&amp;idx=1&amp;sn=c2ce09fc2a49782cd282071e6c156920</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2025-02-19T15:42:17</pubDate></item><item><title>【踩坑日记】来看看那些自欺欺人的 Typora \"破解\"</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484155&amp;idx=1&amp;sn=039f8bc08ccf98899d3f44582a1ce80e</link><description>周末闲来无事想着搞个方便记笔记的东西（没错，问了周围一圈师傅，最终决定使用Typora~）然后就是被开屏暴击！</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2024-07-28T17:56:03</pubDate></item><item><title>【2024HVV】截止7-26所有漏洞情报</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484119&amp;idx=1&amp;sn=5826f2c7f62732d65f95607fb3f43d14</link><description>周五了，来总结一下到目前为止所收集到的漏洞情报，漏洞不多，也就一百多个，希望蓝队的师傅们今晚可以睡个好觉~~</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2024-07-26T22:02:53</pubDate></item><item><title>【情报】2024HVV木马样本情报</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484119&amp;idx=4&amp;sn=4207bf41f4af5cebb298edbde2e57dbc</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2024-07-26T22:02:53</pubDate></item><item><title>【情报】2024HVV木马样本情报</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484084&amp;idx=1&amp;sn=dec453101b6a968fd3bc0f83a84197e0</link><description></description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2024-07-24T11:36:25</pubDate></item><item><title>Jeecg-Boot 未授权SQL注入漏洞（CVE-2023-1454）验证脚本</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247484004&amp;idx=1&amp;sn=5c60f50c27e76d238f825814713a3219</link><description>Jeecg-Boot 未授权SQL注入漏洞（CVE-2023-1454）验证脚本</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-04-25T21:07:18</pubDate></item><item><title>分享一个自己编的CVE-2023-23752验证脚本</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483965&amp;idx=1&amp;sn=6776b9856466a3421606d2256131143d</link><description>分享一个自己编的CVE-2023-23752验证脚本</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-04-24T20:57:29</pubDate></item><item><title>QVD-2023-6271 Nacos身份绕过漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483959&amp;idx=1&amp;sn=948c3904018edaa0643f2dad67b73196</link><description>QVD-2023-6271 Nacos身份绕过漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-04-23T19:14:15</pubDate></item><item><title>CVE-2023-21839漏洞本地复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483940&amp;idx=1&amp;sn=c8723b23e9d17f0895244347ff2e5cd8</link><description>CVE-2023-21839漏洞本地复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-04-22T19:42:36</pubDate></item><item><title>HMS v1.0 三处SQL注入合集</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483924&amp;idx=1&amp;sn=5a307fb317b46f24c74faf722541f796</link><description>HMS v1.0 三处SQL注入合集</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-03-06T16:51:33</pubDate></item><item><title>taocms代码注入 （CVE-2022-25578）</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483914&amp;idx=1&amp;sn=74e160f91f04a0ca191858fe12da28b8</link><description>taocms代码注入 （CVE-2022-25578）</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-10T18:07:24</pubDate></item><item><title>CVE-2022-23131 Zabbix身份认证绕过漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483896&amp;idx=1&amp;sn=d3c8921bfcaa6e51a4c0c474ba1ec3d1</link><description>描述：Zabbix对客户端提交的Cookie会话存在不安全的存储方式，导致在启动SAML SSO认证模式的前</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-07T14:22:42</pubDate></item><item><title>centos7下的vulfocus本地靶场搭建</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483881&amp;idx=1&amp;sn=15a555f9d8601b5c9d1f11e91e1187f5</link><description>centos7下的vulfocus本地靶场搭建</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-06T18:04:25</pubDate></item><item><title>CNVD-2022-10270向日葵远程代码执行漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483868&amp;idx=1&amp;sn=60289181a5b524edc46babd5828af3ff</link><description>CNVD-2022-10270向日葵远程代码执行漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-05T16:25:53</pubDate></item><item><title>ThinkPHP 多语言本地文件包含漏洞(lang-rce)复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483859&amp;idx=1&amp;sn=ab8d84388f0b30affc56898176eccc9a</link><description>ThinkPHP 多语言本地文件包含漏洞(lang-rce)复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-04T20:31:24</pubDate></item><item><title>CVE_2022_22890 Spring Data MongoDB SpEL表达式注入漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483854&amp;idx=1&amp;sn=97f755fa15470e6ccc1f8426b6256ea7</link><description>CVE_2022_22890 Spring Data MongoDB SpEL表达式注入漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-02T22:33:23</pubDate></item><item><title>VSFTP2.3.4  笑脸漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483830&amp;idx=1&amp;sn=e2fe22c721ff1c1209961687e08236d8</link><description>在vsftpd2.3.4中在6200端口存在一个shell,使得任何人都可以进行连接，并且VSFTPD v2.3.4 服务，是以 root 权限运行的，最终获取到的权限也是root</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-02-01T17:35:34</pubDate></item><item><title>PHP8.1.0dev后门命令执行漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483801&amp;idx=1&amp;sn=a88322df2f4e623562cf5e9f3059115b</link><description>PHP8.1.0dev后门命令执行漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-30T20:56:59</pubDate></item><item><title>CVE-2022-29464 WSO2 文件上传 漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483790&amp;idx=1&amp;sn=778b66e38d2fd417ddc71606ee581a6b</link><description>描述：WSO2是一家成立于 2005 年的开源技术提供商。它提供了一个企业平台，用于在本地和整个 Inter</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-29T20:57:34</pubDate></item><item><title>weblogic  CVE-2020-14882漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483775&amp;idx=1&amp;sn=422557e098494436df5aef49427ee785</link><description>描述：未经身份验证的远程攻击者可能通过构造特殊的 HTTP GET请求，利用该漏洞在受影响的 WebLogi</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-26T20:46:00</pubDate></item><item><title>windows7  CVE-2018-8174漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483764&amp;idx=1&amp;sn=6b875348e9f3282ca734cb102e2041a7</link><description>windows7  CVE-2018-8174漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-25T19:55:31</pubDate></item><item><title>solr 命令执行 （CVE-2017-12629）</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483751&amp;idx=1&amp;sn=0543f79288eae54bd2170392b46f7bae</link><description>solr 命令执行 （CVE-2017-12629）</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-24T11:16:43</pubDate></item><item><title>CVE-2022-22916  O2OA RCE 远程命令执行</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483735&amp;idx=1&amp;sn=253f1e299721942e533b4e132e340802</link><description>CVE-2022-22916  O2OA RCE 远程命令执行</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-23T12:48:57</pubDate></item><item><title>CVE-2022-0824 Webmin 远程代码执行漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483722&amp;idx=1&amp;sn=af51dc59a92c7a0e2b9d42d3ede80b84</link><description>CVE-2022-0824 Webmin 远程代码执行漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-22T17:54:28</pubDate></item><item><title>CVE-2022-25237 Bonitasoft Platform RCE漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483709&amp;idx=1&amp;sn=0ba927216e7ce811181c55641e61b4c1</link><description>CVE-2022-25237 Bonitasoft Platform RCE漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-21T17:47:49</pubDate></item><item><title>CVE-2022-28346 Django SQL注入漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483691&amp;idx=1&amp;sn=25fb0e0441f5d65cf8cbe1a4530a96fc</link><description>CVE-2022-28346 Django SQL注入漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-20T19:21:07</pubDate></item><item><title>CVE_2022_0543  redis漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5MDU4NjYwOQ==&amp;mid=2247483679&amp;idx=1&amp;sn=ee805c08e1c7dcf130a24f095a239917</link><description>CVE_2022_0543  redis漏洞复现</description><author>炽汐安全屋</author><category>炽汐安全屋</category><pubDate>2023-01-19T20:47:50</pubDate></item></channel></rss>