<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk2NDE3NTc0Ng.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Sun, 30 Mar 2025 23:42:23 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>intelligence</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483910&amp;idx=1&amp;sn=eed5f306d1ff24fbb2e7fda8961053fc</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-30T12:49:14</pubDate></item><item><title>Flight（超多知识点，超难）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483825&amp;idx=1&amp;sn=6cabd093b0a33f4b60d2f1171f1de80f</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-29T19:44:30</pubDate></item><item><title>BoardLight（难度偏低，可以盲打)</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483706&amp;idx=1&amp;sn=b3dbccfc5b022c45dcf592273cf26797</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-28T00:59:50</pubDate></item><item><title>CozyHosting（难）(这个靶机必须要懂)</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483699&amp;idx=1&amp;sn=c1f7c190cc91ff25079a80f953f7c8ec</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-28T00:57:27</pubDate></item><item><title>Editorial</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483688&amp;idx=1&amp;sn=cdf0fc8bf8bf9a2959bf69e6b6092468</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-28T00:51:20</pubDate></item><item><title>Keeper</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483684&amp;idx=1&amp;sn=e3fb026f89eda00be81fe7e7b2663c51</link><description></description><author>泷羽sec-siznwaa</author><category>泷羽sec-siznwaa</category><pubDate>2025-03-28T00:01:08</pubDate></item><item><title>mimikatz与hash</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483679&amp;idx=1&amp;sn=08be6295181283b549db62f94c46cb51</link><description></description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-28T17:59:41</pubDate></item><item><title>更优雅的nignx内存马后门 | ebpf 内核马</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483671&amp;idx=1&amp;sn=eaacd0f7f00918544a6559f980874846</link><description>更优雅的nignx内存马后门，ebpf 内核马\\x0d\\x0a\\x0d\\x0a全链路内存马系列之 nginx 内存马和ebpf 内核使用\\x0d\\x0a\\x0d\\x0a本项目不含有完整的利用工具，仅提供无害化测试程序、防御加固方案，以及研究思路讨论</description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-20T16:05:13</pubDate></item><item><title>抓包神器，特别是APP，Android和iOS | API调试+API测试一站化解决方案，Reqable介绍+使用</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483669&amp;idx=1&amp;sn=cc2477515de4ad11a40075859f8b2a16</link><description>Reqable是新一代API调试 + API测试一站化解决方案。Reqable具有全平台、免登录、轻量级、高性能、无广告等优点，理念是让API更快更简单，现已支持Windows、Mac、Linux、Android和iOS五大平台。</description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-14T20:58:17</pubDate></item><item><title>BurpSuite插件自动化发现：未授权/敏感信息/越权隐匿漏洞 | BurpAPIFinder安装+使用</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483667&amp;idx=1&amp;sn=9daefc005715b510c4832af84a8a9c70</link><description>攻防演练过程中，我们通常会用浏览器访问一些资产，但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等，通过该未授权/敏感信息/越权隐匿我们可以：\\x0d\\x0a\\x0d\\x0a1、发现通过某接口可以进行未授权/越权获取到所有的账号密码、私钥、凭证</description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-13T11:02:40</pubDate></item><item><title>灵兔宝盒二开 | 286渗透工具合集，新增OneCS-49_尊享版、vshell4.9.3破解版、Godzilla特战版等24款</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483664&amp;idx=1&amp;sn=7ba6dbb66f98b8cfce56e0a9b46a2011</link><description>最近使用了一下灵兔宝盒，介绍： 开箱即用！265种windows渗透工具合集--灵兔宝盒，。不过用起来不太顺手，首先burpsuite_pro V2024.4不能正常使用，然后又试了一下xshell，发现也不行。干脆多添加一些工具进去二开</description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-12T12:03:22</pubDate></item><item><title>红队微信聊天记录快速取证工具</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDE3NTc0Ng==&amp;mid=2247483660&amp;idx=1&amp;sn=6a77e78a183da35fe17ede360c8c2253</link><description>ChatViewTools是一款微信聊天工具搜刮工具，可以用于红队微信聊天记录快速取证。是逆向Ormicron/chatViewTool后更改而来\\x0d\\x0a\\x0d\\x0a做了大量的更新和性能优化，与原版相比优化了</description><author>泷羽Sec-siznwaa</author><category>泷羽Sec-siznwaa</category><pubDate>2025-01-11T11:34:58</pubDate></item></channel></rss>