<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkwMDMwNDgwNQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Sat, 27 Dec 2025 10:31:20 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>一款赏金猎人xss漏洞扫描工具——Mey</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485935&amp;idx=1&amp;sn=7f93536f07c81b13f416f35586d506e0</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-12-26T21:18:13</pubDate></item><item><title>【Shadowrend 斩影 1.1.5】开发日志3 — 一个集成AI大模型的渗透测试框架</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485911&amp;idx=1&amp;sn=b9b2144d8ad02a6925bb1d7d65fed686</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-12-25T11:32:42</pubDate></item><item><title>【Shadowrend 斩影 1.1】开发日志2 — 一个集成AI大模型的渗透测试框架</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485896&amp;idx=1&amp;sn=c6bd9f72b8c90b6df3692c5116f0a0ab</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-10-11T18:00:46</pubDate></item><item><title>Shadowrend 斩影 1.0 — 一个集成AI大模型的渗透测试框架</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485878&amp;idx=1&amp;sn=30f2873daaecb113fe70dfee6d6ded1b</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-08-28T19:38:06</pubDate></item><item><title>Stable-Diffusion-WebUi+ChilloutMix模型实现AI图片生成</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485864&amp;idx=1&amp;sn=09040e1705b305e83201f421229ed6e8</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-27T00:35:39</pubDate></item><item><title>Pega Infinity - 绕过身份验证[CVE-2021-27651]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485823&amp;idx=1&amp;sn=8712bd94384a346119b1be32969df1ab</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-24T11:36:26</pubDate></item><item><title>CVE-2021-27651</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485818&amp;idx=1&amp;sn=c17befd07ae5d3f03456ee7eaf802f5d</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-24T11:30:36</pubDate></item><item><title>NAS[linux虚拟机磁盘GVFS挂载转CIFS挂载]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485806&amp;idx=1&amp;sn=1a1fc06901ff2d2a067a2dc6e20c1ac1</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-19T00:33:11</pubDate></item><item><title>开源自编程智能体框架AiPy---帮你思考，更能帮你干活</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485780&amp;idx=1&amp;sn=28be95ba23b7ee06564246ae9d43c7b1</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-16T17:09:37</pubDate></item><item><title>NAS内网穿透实现虚拟机远程桌面windows系统</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485739&amp;idx=1&amp;sn=a8eddf0edb293fd73de29a4bd5a3d4fe</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-08T17:25:09</pubDate></item><item><title>NAS[vps+docker+SynologyDrive实时数据同步]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485696&amp;idx=1&amp;sn=1a641b547c714f5350459a6f342656da</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-04-01T16:37:13</pubDate></item><item><title>如何使用AI进行漏洞挖掘(最终版本)</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485669&amp;idx=1&amp;sn=c5c5aac25660a7007a041269156698b6</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-02-25T16:42:20</pubDate></item><item><title>如何使用AI进行漏洞挖掘？完结！</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485658&amp;idx=1&amp;sn=4cde13c89f470e234da4fb928192b9e2</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-02-14T14:54:55</pubDate></item><item><title>使用deepseek进行代码审计进行漏洞挖掘？</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485642&amp;idx=1&amp;sn=317337ad87d8d251fcf5450748bf9ba8</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2025-02-06T14:32:21</pubDate></item><item><title>reNgine自动化侦察框架-国内vps搭建</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485615&amp;idx=1&amp;sn=c034d354f7c0320da5a5ca5fd035e333</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-12-18T18:53:22</pubDate></item><item><title>[xss bypass]补0绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485596&amp;idx=1&amp;sn=9bcab7bba8abc52e5dcaf5baafbd2a64</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-12-16T14:32:10</pubDate></item><item><title>关于新版本gowitness/snap强制占用磁盘解决方案</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485586&amp;idx=1&amp;sn=8a7a7997dc5dc4c510a96dd9abcddfa0</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-11-12T15:51:42</pubDate></item><item><title>【赏金猎人之路5】shodan(网络空间搜索引擎)常规用法及脚本编写</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485572&amp;idx=1&amp;sn=9a8dde663e264f674102b9df4355d0de</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-10-14T12:28:40</pubDate></item><item><title>【赏金猎人之路4】fofa+oneforall+gowitness自动化资产发现</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485549&amp;idx=1&amp;sn=bb6007d4a39fc5e31f8cdfa2e706c168</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-10-11T11:38:32</pubDate></item><item><title>【赏金猎人之路3】gowitness+oneforall自动化资产发现</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485533&amp;idx=1&amp;sn=be964caf466ab312a0033e56573df468</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-10-10T14:07:58</pubDate></item><item><title>【赏金猎人之路2】gowitness实现钉钉推送</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485523&amp;idx=1&amp;sn=fe07dad5ef5d3740391daf7ef012db6a</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-10-09T17:00:25</pubDate></item><item><title>我如何获得第一个赏金【翻】—sql注入工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485499&amp;idx=1&amp;sn=f19850418e1ff9fb682c13f71b9bb08e</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-09-30T16:47:58</pubDate></item><item><title>gowitness网站截屏+半自动去重</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485483&amp;idx=1&amp;sn=c2cffabd2d2eed21c808cd3902dd6b36</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-09-27T11:37:37</pubDate></item><item><title>全民都能用上\"ChatGPT\"—【本地部署Llama3.1 AI模型】</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485465&amp;idx=1&amp;sn=b348ed780a826686146d0f3c31972d62</link><description>您可以在任何地方微调、提取和部署的开源 AI 模型。我们最新的指令调谐模型有 8B、70B 和 405B 版本。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-09-13T16:40:50</pubDate></item><item><title>Windows TCP/IP 远程执行代码漏洞(CVE-2024-38063)</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485417&amp;idx=1&amp;sn=bfd13d51fb8810151ba53d6f7f679cdc</link><description>作为对无法立即安装本周 Windows 安全更新的用户的缓解措施，Microsoft 建议禁用 IPv6 以消除攻击面。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-08-15T16:33:05</pubDate></item><item><title>Web缓存中毒</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485378&amp;idx=1&amp;sn=3a746e943abc2e0e0e8742006acc13a9</link><description></description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-06-28T10:13:35</pubDate></item><item><title>JWT 身份验证绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485185&amp;idx=1&amp;sn=27353d24bd2643dbb7236594fb97f5fb</link><description>知彼知己者，百战不殆</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-03-13T17:06:43</pubDate></item><item><title>红队手册[2]——心脏滴血(Heartbleed)</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485093&amp;idx=1&amp;sn=a2d175cd6cad0a3cd69b8d24e39ea465</link><description>故能而示之不能，用而示之不用，近而示之远，远而示之近；利而诱之，乱而取之，实而备之，强而避之，怒而挠之，卑而骄之，佚而劳之，亲而离之。攻其无备，出其不意。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-03-09T21:31:32</pubDate></item><item><title>红队手册[1]——准备篇</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485052&amp;idx=1&amp;sn=80638f767f0c8444bab0fb8427031813</link><description>兵者，诡道，利而诱之，乱而取之，实而备之，强而避之，怒而挠之，卑而骄之，逸而劳之，亲而离之。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2024-03-07T15:50:25</pubDate></item><item><title>[漏洞复现] Apache Struts2 文件上传 CVE-2023-50164</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247485019&amp;idx=1&amp;sn=2ab0b59d51bdf2d1d51f2eb7a7d17613</link><description>漏洞源于文件上传逻辑存在缺陷，攻击者可利用上传文件参数启动路径遍历，成功利用该漏洞可以上传恶意文件到服务器的非预期位置，最终导致远程代码执行。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-12-13T16:42:44</pubDate></item><item><title>Apache Ofbiz XML-RPC RCE  (CVE-2023-49070) [漏洞复现]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484985&amp;idx=1&amp;sn=8f1da351f25d033d8f4e30489af46d23</link><description>2020年，为修复 CVE-2020-9496 增加权限校验，存在绕过。2021年，增加 Filter 用于拦截 XMLRPC 中的恶意请求，存在绕过。2023年四月，彻底删除xmlrpc handler 以避......</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-12-09T01:50:46</pubDate></item><item><title>华为Auth-Http服务器任意文件读取漏洞 [漏洞复现]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484956&amp;idx=1&amp;sn=13de1fec6406d80f81d9b1a54a7ac971</link><description>Huawei Auth-Http Server1.0任意文件读取</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-12-07T23:05:25</pubDate></item><item><title>大华DSS信息泄露 [漏洞复现]</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484936&amp;idx=1&amp;sn=27f63e48affb21603ef313bebeb4d9e7</link><description>大华DSS安防监控系统某版本存在信息泄露漏洞，用户可以轻易获取到用户名密码进入系统后台。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-12-02T20:42:04</pubDate></item><item><title>亲手打造黑客《看门狗2》马可仕 同款手机</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484833&amp;idx=1&amp;sn=5e60e6cf09a55c7d58d598b542a660ae</link><description>马可仕是在奥克兰长大的优秀黑客，在孩童时期，升级后的ctOS系统ctOS2.0连接了他的个人信息，向他错误地指控了一项自己未曾犯下的罪行他意识到该系统会给旧金山的无辜平民带来危害于是决定加入黑客组织DedSec亲身经历腐败系统带来的不公不义</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-11-18T15:00:35</pubDate></item><item><title>移动安全[3] burpsuite抓包环境搭建</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484406&amp;idx=1&amp;sn=235e159d8dcf3c4c6f1accda5fca03cf</link><description>burpsuite抓包+浏览器去除警告本次环境：Nox(夜神模拟器)版本：7.0.5.9模拟器：Androi</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-11-17T15:18:55</pubDate></item><item><title>快速漏洞扫描器nuclei</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484322&amp;idx=1&amp;sn=cf68fd9024669be833dbee84caed7213</link><description>基于YAML语法模板的定制化快速漏洞扫描器</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-05-12T18:50:50</pubDate></item><item><title>移动安全[2] 安卓反编译</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484170&amp;idx=1&amp;sn=b77756095e90092e5ac03c635f0ea796</link><description>安卓逆向反编译必经之路</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-04-19T13:50:26</pubDate></item><item><title>移动安全[1] Xposed搭建</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484157&amp;idx=1&amp;sn=45fda3a6ebcf31efbe748dfefe974621</link><description>Xposed框架(Xposed Framework)是一套开源的、在Android高权限模式下运行的框架服务，可以在不修改APK文件的情况下影响程序运行（修改系统）的框架服务，基于它可以制作出许多功能强大的模块且在功能不冲突的情况下同时运作</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2023-04-11T19:05:54</pubDate></item><item><title>如何打造《看门狗》马可仕 同款手机</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484141&amp;idx=1&amp;sn=343400871de74c69c1aed71f5c7ff348</link><description>你也想拥有马可仕·哈洛威同款手机么，欢迎来到旧金山湾区。</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2022-12-10T19:50:08</pubDate></item><item><title>【红队、赏金猎人】golang多工具联动快速资产搜集</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247484043&amp;idx=1&amp;sn=7b795f4caa15332391d085fcb17690cb</link><description>【红队、赏金猎人】golang工具联动快速资产搜集</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2022-12-07T22:25:32</pubDate></item><item><title>web安全基础①</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247483965&amp;idx=1&amp;sn=d1e36d253c8a8be6875a61cb6ca03512</link><description>①：目录遍历②：信息收集③：子域枚举④：身份验证绕过⑤：IDOR( Insecure Direct Obje</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2022-10-24T22:01:44</pubDate></item><item><title>WSH、HTA、VBA(word、excel宏钓鱼)、powershell基础</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247483869&amp;idx=1&amp;sn=750471eeb4d1581ad221ba1d073aa097</link><description>WSH、HTA、VBA(word、excel宏钓鱼)、powershell基础</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2022-10-23T23:28:24</pubDate></item><item><title>google hack(Google Dorks)&amp;(Github Dorks)&amp;().().().</title><link>https://mp.weixin.qq.com/s?__biz=MzkwMDMwNDgwNQ==&amp;mid=2247483774&amp;idx=1&amp;sn=b6265a07e2339f37441fb4b4dc051584</link><description>Dorks-collections-list</description><author>偏远酒馆</author><category>偏远酒馆</category><pubDate>2022-10-14T16:14:14</pubDate></item></channel></rss>