<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzg5NjY4NDg1Nw.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 31 Jul 2025 17:59:10 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>[真实案例] 有趣的文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483979&amp;idx=1&amp;sn=6a2c1f2109595a27d133f417dd31991b</link><description>有趣的文件读取漏洞</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-07-31T15:03:32</pubDate></item><item><title>内推|江苏某运营商安全岗招聘</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483968&amp;idx=1&amp;sn=399699a5578bab86cf7acb03a2a168e3</link><description>内推|江苏某运营商安全岗招聘</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-03-12T12:53:35</pubDate></item><item><title>公众号+满血deepseek实现公众服务PLUS</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483961&amp;idx=1&amp;sn=7295e8413f46fb72d93820ac0fcbecac</link><description>🚀探索DeepSeek：公众号智能化的新纪元！🚀</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-02-19T09:25:02</pubDate></item><item><title>太丢人了</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483948&amp;idx=1&amp;sn=c78c4f6b64f4e732bb3fcbe3684d3819</link><description>抖音一堆人声称“红客联盟”，打着爱国的名义圈流量。\\x0a其实一看不是做安全的，只是群为了流量装13的小孩。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-01-30T10:20:47</pubDate></item><item><title>大年初一的赛博零食</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483941&amp;idx=1&amp;sn=efaa292f8cff392bda854d11b79bff12</link><description>“遵纪守法”</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-01-29T20:51:18</pubDate></item><item><title>AI-小肥羊新年贺词！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483918&amp;idx=1&amp;sn=3f545e8664083850f43da076087b61cc</link><description>使用豆包和deepseek生成的新年贺词！</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-01-28T19:58:49</pubDate></item><item><title>震惊-国际黑客组织竟...</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483914&amp;idx=1&amp;sn=efada6fd45a7603f4396c3045970f331</link><description>谨防诈骗！</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-01-03T16:42:00</pubDate></item><item><title>[武器库]-WExploit漏洞综合利用工具</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483907&amp;idx=1&amp;sn=e64a7eb7fb8ecb4ffba0df92f7de2cb0</link><description>兵者,诡道也,故能而示之不能,用而示之不用</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2025-01-02T15:02:29</pubDate></item><item><title>我们做安全的都很有礼貌，也从不装杯</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483898&amp;idx=1&amp;sn=faf604fbed1a477f573cf05c3308415a</link><description></description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-12-26T16:34:03</pubDate></item><item><title>平安夜，给大家发浮力啦！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483892&amp;idx=1&amp;sn=2aa79eff9b3fa8b19e760a7e18390051</link><description>我是补蛋老人，今晚我会给每一个研究生（第四声）宝宝补个蛋。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-12-24T22:56:12</pubDate></item><item><title>[fscan2.0] fscan更新！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483873&amp;idx=1&amp;sn=7322b31c4a8c3c8c5ad7bd49a9eccdde</link><description>[fscan2.0] fscan更新！</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-12-20T17:00:07</pubDate></item><item><title>fscan存在命令注入漏洞[doge][doge]</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483861&amp;idx=1&amp;sn=5c201134f7e14bd55bdd5d4923f0a60c</link><description>标题dang：fscan存在命令注入漏洞[doge][doge]</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-12-16T17:36:19</pubDate></item><item><title>[bypass] 迅雷下载功能bypass 403 | waf</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483857&amp;idx=1&amp;sn=746d9af2c466c45b93d6ce5075adb01a</link><description>迅雷的bypass应用</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-10-17T19:06:14</pubDate></item><item><title>[AWVS] 定制你的AWVS</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483843&amp;idx=1&amp;sn=92f2567c652423f47920d3293c95330e</link><description></description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-10-15T16:25:08</pubDate></item><item><title>[惊觉] 做安全的我每天竟然在贴钱上班！</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483832&amp;idx=1&amp;sn=8f011f9f73ac2a7ade90caf39922cc78</link><description>惊觉！我发现网络安全是少见的需要我贴钱上班的职业。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-10-14T17:32:41</pubDate></item><item><title>[fscan插件] 一个用于fscan的VNC爆破插件</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483822&amp;idx=1&amp;sn=163df58243c093b88fb41e0a339be8d0</link><description>VNC的爆破插件</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-10-10T09:56:39</pubDate></item><item><title>[审计] 用友U8C-ReleaseRepMngAction</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483811&amp;idx=1&amp;sn=ec466b22fe5a5de529685ef3ba55169f</link><description>U8Cloud-ReleaseRepMngAction接口的SQL注入问题审计分析</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-07-22T17:08:20</pubDate></item><item><title>用友NC-1day源码审计</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483798&amp;idx=1&amp;sn=9ed5d502ce57ea28243ccae6a96252ef</link><description>看到用友官方的一则通告，还是个0day。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-07-18T21:10:41</pubDate></item><item><title>yonyou-uap-saveXmlToFileServlet-upload-file</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483769&amp;idx=1&amp;sn=f74d95256210b48ee992a2bca985b92b</link><description>用友nc存在文件上传漏洞，攻击者可通过上传jsp文件获取服务器权限。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-03-25T10:57:21</pubDate></item><item><title>用友NC-未公开RCE</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483762&amp;idx=1&amp;sn=53f9399bb7effc80ed8f9d631e14b11e</link><description>yonyou-nc-saveXXXXXServlet-upload-file</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-03-22T23:22:22</pubDate></item><item><title>用友UAP-0Day</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483747&amp;idx=1&amp;sn=e8c2744815aba1b9fabdd323f1391521</link><description>《0day》yonyou-uap-lfw_chart-xxe</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-03-20T14:58:50</pubDate></item><item><title>OSSFinder - 本地文件的Findomething</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483736&amp;idx=1&amp;sn=03dfe08f3233624a5f69f347a9a0ebec</link><description>OSSFinder - 本地文件的Findomething</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-02-22T17:31:07</pubDate></item><item><title>Nacosplay（nacos配置一键获取工具）</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483724&amp;idx=1&amp;sn=44ecb6a1152d9e24abca99365d5acd52</link><description>Nacosplay（nacos配置一键获取工具_我爱说实话）</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-02-06T21:47:03</pubDate></item><item><title>用友的反序列化链</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483716&amp;idx=1&amp;sn=bd23ee7a7233e7fc0968bb17d669881f</link><description>从goby中找了用友的CC6和CC7的生成规则。结合用友的反序列化路径可以执行无回显命令。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2024-01-24T14:08:09</pubDate></item><item><title>P-Shell：PHP免杀+绕过阿里云waf实战</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483709&amp;idx=1&amp;sn=ac13126faf15021bce3f099c9193df39</link><description>Webshell免杀+阿里云waf绕过实战</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2023-09-19T17:01:42</pubDate></item><item><title>省护的一些东西</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483690&amp;idx=1&amp;sn=7b05fe0afce0251554d574b1ae0ab661</link><description>省护这一天的东西</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2023-09-12T21:29:06</pubDate></item><item><title>OSSFinder-云存储凭据查找工具（2）</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483681&amp;idx=1&amp;sn=5f59447a8946bfe76b25a3ff4b78d132</link><description>OSSFinder内网专用版！全盘查找OSS凭据！资产自查/红蓝攻防</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2023-09-03T03:02:03</pubDate></item><item><title>OSSFinder-云存储凭据查找工具</title><link>https://mp.weixin.qq.com/s?__biz=Mzg5NjY4NDg1Nw==&amp;mid=2247483673&amp;idx=1&amp;sn=2de7b140eacf81e4ce33f2db317f45c2</link><description>在渗透测试的过程中，经常会遇到一些云上资产。寻找类似AK/SK这样的凭证可以快速控制云上存储/ECS等资产。</description><author>小肥羊安全</author><category>小肥羊安全</category><pubDate>2023-09-02T23:11:54</pubDate></item></channel></rss>