<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk0Mjg4MTQxMw.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Mon, 12 Jan 2026 18:19:54 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>OSCP/OSEP一对一私教直通车：协议保障，直通高级渗透测试专家</title><link>https://mp.weixin.qq.com/s/URjyp6kF_h-PO0avaFOz7Q</link><description>课程由具备八年一线红队经验的泷老师领衔，教学和助教团队均具备OSEP级别实力，提供一对一专属教学，全程协议保障，费用全包（含考试报名费），承诺包教包会包通过。帮助学员快速掌握实战技能，顺利通过认证。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2026-01-12T16:31:55</pubDate></item><item><title>在Kali-Linux如何破解kdb文件</title><link>https://mp.weixin.qq.com/s/NzN5LWBksMegaf4iA8hRFQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2026-01-11T19:32:22</pubDate></item><item><title>HexStrike AI：渗透测试助手部署与配置全指南</title><link>https://mp.weixin.qq.com/s/P0c75O16pBFC6imBd_9Uiw</link><description>HexStrike AI 是一款基于人工智能的进攻性安全框架。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2026-01-09T18:12:25</pubDate></item><item><title>Hack The Box：TombWatcher</title><link>https://mp.weixin.qq.com/s/718XN7T-MFhOBlUxwtY9Bw</link><description>TombWatcher是Hack The Box平台上的一个中等难度靶机，模拟了一个真实的Windows Active Directory域环境。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-08-20T17:12:21</pubDate></item><item><title>Hack The Box：Fluffy</title><link>https://mp.weixin.qq.com/s/Ub652Espn_qKkG4eDvOFSQ</link><description>在 Active Directory (AD) 域环境中，一个看似普通的共享目录权限、一个未修复的已知漏洞，往往能成为攻击者撕开整个防御体系的突破口。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-07-30T00:33:47</pubDate></item><item><title>Hack The Box：Artificial</title><link>https://mp.weixin.qq.com/s/Pa8OcYNZBscZpBPQ6Wg9QA</link><description>本文将详细解析HTB平台中人工靶机的渗透过程，从信息收集到权限提升，带你体验AI安全的有趣挑战。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-07-05T20:06:09</pubDate></item><item><title>2025最新渗透测试靶场推荐</title><link>https://mp.weixin.qq.com/s/iWXyEdY1CpD-4uqQrd-3eA</link><description>靶场都玩不明白，还搞个锤子渗透？2025把这26个靶场刷了，才配称得上黑客！</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-06-23T18:06:42</pubDate></item><item><title>零基础也能成为网络安全高手？揭秘渗透测试与免杀的终极奥秘！</title><link>https://mp.weixin.qq.com/s/2w0yKWgTDzL4kPHBf1LgkA</link><description>卷不死就往死里卷</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-06-20T17:48:30</pubDate></item><item><title>靶场奇妙记之Vulnhub sar 靶场练习</title><link>https://mp.weixin.qq.com/s/f6K_PQJAQ--elvk2qfuimA</link><description>在网络安全领域，渗透测试是发现和修复漏洞的关键手段。本文通过一次模拟实战，详细解析如何从主机发现、漏洞利用到最终提权，揭示常见安全风险及防御思路。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-05-07T19:07:27</pubDate></item><item><title>红日靶场(一)：从外网到域控</title><link>https://mp.weixin.qq.com/s/WZDC1GfQyHe3THiknjvBJg</link><description>本文基于红日靶场(一)的内网渗透演练场景，完整复现攻击者从外网突破到域控接管的完整攻击链条。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-04-05T23:41:12</pubDate></item><item><title>守护网络安全的另一种战场：为什么我们选择「笨方法」</title><link>https://mp.weixin.qq.com/s/3BesamEQi2WvrsPclndETQ</link><description>写在前面：我们为何要「卷」漏洞提交？近期补天漏洞榜单的竞争引发热议，当一家安全团队单月提交超2000个漏洞时，难免会被质疑“是否在刷洞”。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-04-03T15:06:30</pubDate></item><item><title>恭喜榜首！来聊聊刷榜“漏洞”背后的技术坚持</title><link>https://mp.weixin.qq.com/s/9GmGuEF9Rs6cwySNemPcxw</link><description>挖洞快：掌握高效漏洞挖掘方法论🔹xa0质量高：提交报告自带厂商复现指南🔹xa0学得深：每个漏洞都吃透原理和修复👉 点击了解《泷羽SRC漏洞挖掘实战学习》</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-04-02T10:48:07</pubDate></item><item><title>还在SQL注入里当脚本小子？破解特斯拉的男人配叫黑客！</title><link>https://mp.weixin.qq.com/s/CkjroU48-Iys5hoXbeOrww</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-03-14T12:29:50</pubDate></item><item><title>WebDeveloper靶机：从Web渗透到Root提权</title><link>https://mp.weixin.qq.com/s/t2PvQpEi4c7CIsyUJdwgng</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-03-09T11:52:47</pubDate></item><item><title>渗透测试新利器！EZ漏洞扫描器全面解析</title><link>https://mp.weixin.qq.com/s/G7CPLE03tVMdeeFAXHnEjA</link><description>集信息收集、端口扫描、服务暴破、URL爬虫、指纹识别、被动扫描为一体的跨平台漏洞扫描器</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-28T19:06:41</pubDate></item><item><title>Wintermute-v1靶机实战：从外网渗透到内网横向移动</title><link>https://mp.weixin.qq.com/s/ZiZz2WC_axqzPhDw2K81EQ</link><description>Wintermute-v1是一台模拟真实环境的渗透测试靶机，综合考察信息收集、漏洞利用、权限提升及内网横向移动能力。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-23T12:00:12</pubDate></item><item><title>Hooka：新一代Shellcode加载器生成工具，多重规避技术助力安全测试</title><link>https://mp.weixin.qq.com/s/jG8QZpNEtxijYyDixLfIqA</link><description>基于Golang开发的开源工具，集成了多种规避技术，专为安全研究者和红队测试设计。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-22T01:39:57</pubDate></item><item><title>靶场奇妙记之pWnOS v2.0</title><link>https://mp.weixin.qq.com/s/XAc5-ss4LCWZiwEZn7bjOQ</link><description>pWnOS v2.0是一款经典的渗透测试靶机，适合练习Web漏洞利用和权限提升。本文将详细解析实战过程，带你一步步从发现主机到获取Root权限。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-17T16:05:23</pubDate></item><item><title>SpiderX：一键绕过前端JS加密，安全测试效率翻倍</title><link>https://mp.weixin.qq.com/s/DDukMIvhHzCpHP2RbH_Bqw</link><description>利用爬虫技术实现前端JS加密自动化绕过的渗透测试工具，通过模拟浏览器点击实现前端加密爆破。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-15T16:50:10</pubDate></item><item><title>Linux 32位Crossfire游戏缓冲区溢出</title><link>https://mp.weixin.qq.com/s/f5-HGZ4WMrWsl-tRT9ZSwQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-13T17:21:31</pubDate></item><item><title>多服务弱口令爆破工具-week-passwd</title><link>https://mp.weixin.qq.com/s/_0VKVTyLKR526NzyjwcmkQ</link><description>图形化的多服务弱口令爆破工具</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-11T18:48:42</pubDate></item><item><title>靶场奇妙记之Pinkys-Palace2缓冲溢出</title><link>https://mp.weixin.qq.com/s/Uvx-feqoqXTvyADJ8B6Ypw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-10T21:01:15</pubDate></item><item><title>靶场奇妙记之HackLAB</title><link>https://mp.weixin.qq.com/s/EFgNr0hrcMEMyIDdxkzgvA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-09T15:42:55</pubDate></item><item><title>EasyTools-简单集成的渗透测试工具箱</title><link>https://mp.weixin.qq.com/s/uow0XhmzEG33U26nAscPzw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-08T16:09:36</pubDate></item><item><title>对移动端信息收集的渗透测试工具</title><link>https://mp.weixin.qq.com/s/COdO8LZqHBKi88TR6jKqFw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-07T16:03:35</pubDate></item><item><title>Brainpan从缓冲区溢出到提权</title><link>https://mp.weixin.qq.com/s/7anvo1p0G3yJNJyiYIOT0Q</link><description>从缓冲区溢出到提权练习</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-02-06T12:03:35</pubDate></item><item><title>一款好用的笔记软件-Obsidian</title><link>https://mp.weixin.qq.com/s/xDQe-IHD_He1Qeen9LHyww</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-26T15:29:43</pubDate></item><item><title>缓冲区溢出到getshell提权</title><link>https://mp.weixin.qq.com/s/ah5pLHvlAX6VvWa7B3C3QQ</link><description>我们的爱，像不断填充的缓冲区，终是溢出了界限，漫过心房的堤岸，泛滥成无法收拾的悲伤，淹没了我所有温柔的期待。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-24T17:28:38</pubDate></item><item><title>Spear工具箱重大更新！！！</title><link>https://mp.weixin.qq.com/s/HXQG60tTRsVxcmB0jrtUgw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-23T20:59:55</pubDate></item><item><title>BeEF-XSS介绍指南</title><link>https://mp.weixin.qq.com/s/y6V1SHiDw3TWPDqS9AOXZg</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-21T18:22:21</pubDate></item><item><title>SQL注入的入门指南</title><link>https://mp.weixin.qq.com/s/EdRj6--I2CIbIDPlUNKxEA</link><description>介绍SQL注入的基本概念、原理、常见手法，帮助初学者理解SQL注入</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-20T18:23:16</pubDate></item><item><title>渗透测试信息收集指南</title><link>https://mp.weixin.qq.com/s/fE6EY7DsDtWPgnKeRTuHqg</link><description>帮助渗透测试人员系统地收集目标信息，包括域名、子域名、技术栈、开放端口等，为后续的安全评估与漏洞挖掘提供全面、准确的数据支持。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-19T17:35:56</pubDate></item><item><title>SerializeJava-反序列图形化工具</title><link>https://mp.weixin.qq.com/s/45srvG_zgsggAsWEHHcFAQ</link><description>用Go语言+GUI库Fyne开发的反序列化图形化工具。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-18T16:22:49</pubDate></item><item><title>Vcenter：综合的渗透工具包</title><link>https://mp.weixin.qq.com/s/gYgpDhJAkOE7uSsbpxb5dA</link><description>一款针对Vcenter的综合利用工具，提供一键上传webshell，命令执行或者上传公钥使用SSH免密连接</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-17T17:12:34</pubDate></item><item><title>Viper国内自主编写的一款红队服务器</title><link>https://mp.weixin.qq.com/s/8o7Rv3w4zqf-KsM3229H4g</link><description>国内自主编写的一款红队服务器，提供图形化的操作界面，可以使用浏览器即可进行内网渗透</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-16T17:25:44</pubDate></item><item><title>靶场奇妙记之lin.security_v1.0</title><link>https://mp.weixin.qq.com/s/Gwf5Ur0HM6zgRePhu9rjAw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-15T18:32:07</pubDate></item><item><title>CodeScan-代码扫描审计工具</title><link>https://mp.weixin.qq.com/s/HPjexNvYttFhkCeCALMm7A</link><description>对大多数不完整的代码以及依赖快速进行Sink点匹配来帮助红队完成快速代码审计</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-14T18:12:04</pubDate></item><item><title>burp被动路径扫描-RouteVulScan插件</title><link>https://mp.weixin.qq.com/s/haAw1-_1vJzUu20DcfncVg</link><description>Burpsuite - Route Vulnerable scanning 递归式被动检测脆弱路径的burp插件</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-13T17:15:26</pubDate></item><item><title>Kunlun-Mirror源代码审计工具</title><link>https://mp.weixin.qq.com/s/aHCy88Qiylssm30QQVmFZA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-12T17:33:12</pubDate></item><item><title>fsacn工具及二开</title><link>https://mp.weixin.qq.com/s/Apss8LktQ8HKYamukE44pw</link><description>都说她的内心仿佛布满了许多弱点，如同一个错综复杂的内网，等待着被洞察与触碰，可是，即便我动用了如同fscan内网扫描工具般的细腻与敏锐，试图探寻那些隐藏的缝隙，却终究还是找不到她真正的弱点所在</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-11T18:24:27</pubDate></item><item><title>ShellcodeLoader免杀加载器</title><link>https://mp.weixin.qq.com/s/e3CPQPZ2wXZQUHmzDzJ8sA</link><description>你的免杀技术精妙绝伦，巧妙绕过了所有检测与拦截的防线，却终究未能逃脱她指尖轻触的删除键，一抹之间，化为虚无。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-10T17:06:21</pubDate></item><item><title>js之敏感信息扫描工具</title><link>https://mp.weixin.qq.com/s/kB3C8Isb9HnnVm8vKHaNcg</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-09T16:58:45</pubDate></item><item><title>Pwntools工具</title><link>https://mp.weixin.qq.com/s/ZDO3Vjfdt5DlgeqzzXZqMg</link><description>专为漏洞利用开发和安全研究设计的 Python 库，尤其在 CTF 竞赛中保持着广泛的应用。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-08T16:50:08</pubDate></item><item><title>命令执行绕过技巧</title><link>https://mp.weixin.qq.com/s/hxQPVVzzW79mGFJcELi_rQ</link><description>绕过了WAF却绕不过她对你的防护</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-07T18:07:20</pubDate></item><item><title>一款全自动APT威胁情报拓线工具</title><link>https://mp.weixin.qq.com/s/wUwAJ2NoIjdnN8dln3wf_Q</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-06T17:09:32</pubDate></item><item><title>RapidCMS代码审计</title><link>https://mp.weixin.qq.com/s/eWQ_qlK2b_GIqO3KvWwgBw</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-05T17:37:22</pubDate></item><item><title>和Netcat不相上下的渗透工具</title><link>https://mp.weixin.qq.com/s/R5qt4QHQTQZs4ZdkPBrTnw</link><description>Pwncat是一个功能强大的命令和控制框架，专为渗透测试专家和红队成员设计。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-04T18:17:56</pubDate></item><item><title>常用的网络搜索引擎</title><link>https://mp.weixin.qq.com/s/0rw3ha46MxKIawvjl04tbA</link><description>找到你想看的资源</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-03T16:18:55</pubDate></item><item><title>内存注入免杀</title><link>https://mp.weixin.qq.com/s/A6IUWM_IVL3jNqywf70rdA</link><description>规避EDR（端点检测与响应）系统和防病毒保护</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-02T17:06:19</pubDate></item><item><title>内网权限维持</title><link>https://mp.weixin.qq.com/s/sDzIHyCOa3hQ4rdkNgVJRg</link><description>内网渗透之权限维持</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2025-01-01T16:10:12</pubDate></item><item><title>分布式web漏洞检测系统WDScanner</title><link>https://mp.weixin.qq.com/s/He17CrMKoItb4gcOET_11Q</link><description>漏洞爆发后快速形成漏洞检测能力，同时能对网站或主机进行全面快速的安全检测，开发了一套简单易用的分布式web漏洞检测系统WDScanner。</description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-31T19:14:59</pubDate></item><item><title>靶场奇妙记之SickOs1.2</title><link>https://mp.weixin.qq.com/s/yCrvbDXBl7Vk6lDfSuWpqQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-29T23:16:59</pubDate></item><item><title>靶场奇妙记之VulnOSv2</title><link>https://mp.weixin.qq.com/s/k1WRYEmruqqwGe8UK4OnIA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-28T20:26:31</pubDate></item><item><title>靶场奇妙记之Stapler</title><link>https://mp.weixin.qq.com/s/3cW_to3UzUqbYu9lI8W9RA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-26T23:25:38</pubDate></item><item><title>靶场奇妙记之FristiLeaks1.3</title><link>https://mp.weixin.qq.com/s/d-ONgYtv0Hg0iy_qQZLrNQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-24T23:12:54</pubDate></item><item><title>靶场奇妙记之SolidState</title><link>https://mp.weixin.qq.com/s/OWzyidGl20Vywbzqx4HjZA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-19T22:06:36</pubDate></item><item><title>靶场奇妙记之Kioptrix-Level 5(系列完结)</title><link>https://mp.weixin.qq.com/s/2HVQTLMyfmKQ_CSmbUAAYQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-15T22:03:05</pubDate></item><item><title>靶场奇妙记之Kioptrix-Level4</title><link>https://mp.weixin.qq.com/s/WB_1Rd0AkiAgXu7-XrnAEg</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-12T21:30:03</pubDate></item><item><title>靶场奇妙记之Kioptrix-Level3</title><link>https://mp.weixin.qq.com/s/4iWAGONj_6gHyczX_Hm7zg</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-10T19:39:16</pubDate></item><item><title>靶场奇妙记之Kioptrix-Level2</title><link>https://mp.weixin.qq.com/s/ybJREkzdbF91sNlLDQqAiQ</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-08T20:22:35</pubDate></item><item><title>Burp Suite进行验证码识别</title><link>https://mp.weixin.qq.com/s/LN12SAAgUKjCiKPjZ78mbA</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-06T19:55:48</pubDate></item><item><title>靶场奇妙记之Kioptrix-Level1</title><link>https://mp.weixin.qq.com/s/maeN_3PCUQnQNvocJV8t9Q</link><description></description><author>泷羽Sec-Ceo</author><category>泷羽Sec-Ceo</category><pubDate>2024-12-05T20:22:40</pubDate></item></channel></rss>