<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkxMjYyMjA3Mg.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Fri, 21 Nov 2025 15:23:03 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>从TEB开始找到WinExec函数</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485581&amp;idx=1&amp;sn=995fee84e3bee031095c2284d55fe4c8</link><description>PE结构+windbg+PE Bear + 函数地址手动解析</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-11-21T10:30:50</pubDate></item><item><title>静态地址shellcode</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485546&amp;idx=1&amp;sn=db815e2a1e83f3a2c5db5004b449e5a1</link><description>windows-shellcode 续写nasm 工具安装仅做汇编代码的工具+汇编代码+x64dbg调试+寄存器知识</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-11-20T10:40:00</pubDate></item><item><title>windows-shellcode入门</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485531&amp;idx=1&amp;sn=f43312087ecc3e594c79a624c2793013</link><description>shellcode加载器 入门+代码+分析</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-11-18T10:40:00</pubDate></item><item><title>websocket的ws与wss传输</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485517&amp;idx=1&amp;sn=3ce859797049e2019382298fdb195165</link><description>websocket的ws与wss观察，用了socket.io库的flask聊天室demo，想要观察它的ws与wss</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-11-09T08:50:00</pubDate></item><item><title>dll注入入门</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485505&amp;idx=1&amp;sn=8eec21f94231ba490b2c779ba9b73f9a</link><description>DLL注入入门</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-11-04T10:50:00</pubDate></item><item><title>云服务器部署flask+uwsgi+nginx</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485497&amp;idx=1&amp;sn=19dad8219e05c17f404fcc674754482d</link><description>云服务器部署flask+uwsgi+nginx</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-10-30T10:00:00</pubDate></item><item><title>Se8_Artificial</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485493&amp;idx=1&amp;sn=738a48be4ff8ec341ad69cdf2ef119ea</link><description>Se8_Artificial+linux(Eazy)+tensorflow-rce+restic提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-06-28T22:00:00</pubDate></item><item><title>Se8_Sorcery(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485489&amp;idx=1&amp;sn=fcc1f9e7d998433c8f71cba54982f0d6</link><description>Se8_Sorcery+linux(hard)+cypher注入+kafka协议流量+内网网段探测+ dnsmasq利用+mitmproxy拦截+钓鱼邮件发送</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-06-21T22:00:00</pubDate></item><item><title>Se8_TombWatcher</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485478&amp;idx=1&amp;sn=bc452c406ab1638d8b22b28ea3481e19</link><description>Se8_TombWatcher+windows(Med)+writeSPN+readGMSApasswd+GenericOwner+(is_deleted)certipy</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-06-14T20:00:00</pubDate></item><item><title>HTB_certificate</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485473&amp;idx=1&amp;sn=be4708b35aa2433287dd6e20837130e3</link><description>HTB_certificate+windows(hard)+zip绕过+esc3-\\x26gt;gold_cert</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-06-13T20:00:00</pubDate></item><item><title>Se8_Fluffy(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485469&amp;idx=1&amp;sn=89fa2d8cb7fa6becc85a68382f50347d</link><description>HTB8_Fluffy+windows(easy)+GenericAll+GenericWrite-\\x26gt;certipy</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-06-08T20:00:00</pubDate></item><item><title>HTB_Nocturnal</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485465&amp;idx=1&amp;sn=880b4a6d752319de5aa6959e59b7ddd7</link><description>HTB_Nocturnal+FUZZ+命令执行绕过-\\x26gt;CVE-2023-46818</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-18T20:00:00</pubDate></item><item><title>HTB_WhiteRabbit</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485461&amp;idx=1&amp;sn=33b6d4c216ace2e23c5835538b146150</link><description>HTB_WhiteRabbit+linux(Insane)+改响应码进后台发现新接口+请求构造+sqlmap+flask</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-15T20:00:00</pubDate></item><item><title>电话诈骗</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485446&amp;idx=1&amp;sn=035960fc71763f6bf57c16fed1108f1d</link><description>诈骗电话</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-12T20:00:42</pubDate></item><item><title>HTB_Haze</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485450&amp;idx=1&amp;sn=f13270028c1bb3b000d1b44134723442</link><description>HTB_Haze+Windows(hard)-\\x26gt;cve-2024-36991-\\x26gt;gMSA组-\\x26gt;WriteOnwer权限+ForceChangePassword权限利用-\\x26gt;Splunk-shell+SeImpersonatePrivilege</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-12T20:00:00</pubDate></item><item><title>HTB_Code</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485432&amp;idx=1&amp;sn=edc502ff3b0aaa3209384f64a4ba23e8</link><description>HTB_Code+linux(eazy)+python-继承链-\\x26gt;ln软链接</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-10T20:00:00</pubDate></item><item><title>HTB_TheFrizz</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485428&amp;idx=1&amp;sn=7d5f1fd567e891076b8de521d6fef962</link><description>HTB_TheFrizz+Windows(Insane)+CVE-2023-45878-\\x26gt;kerberos登录ssh-\\x26gt;回收站-\\x26gt;洪范配合GPO滥用提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-09T00:10:43</pubDate></item><item><title>HTB_Dog(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485423&amp;idx=1&amp;sn=1da8ef3edbc8fc4d227441472dd39314</link><description>HTB_Dog+linux(Eazy)+.git泄露+dropback-1.27.1-rce+php调试环境搭建vscode+xdebug+phpstudy</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-06T22:35:00</pubDate></item><item><title>HTB_Checker(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485417&amp;idx=1&amp;sn=b3f0a2e5b246b1c4371f87047afb08d6</link><description>HTB_Checker+linux(hard)+CVE-2023-1545-\\x26gt;CVE-2023-6199</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-05T22:05:00</pubDate></item><item><title>HTB_Cypher</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485413&amp;idx=1&amp;sn=f1fcedf1e0ede56405e7883497ccc491</link><description>HTB_Cypher+linux(Med)+目录爆破-\\x26gt;jd-gui分析jar-\\x26gt;cypher-inject+sudo提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-05T22:00:44</pubDate></item><item><title>HTB_Titanic</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485409&amp;idx=1&amp;sn=cc619244e24a1cb7fac2bc790e748e69</link><description>HTB_Titanic+linux(Eazy)+子域名+任意文件下载-\\x26gt;cve-2024-41817</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-04-04T22:30:57</pubDate></item><item><title>HTB_DarkCorp</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485405&amp;idx=1&amp;sn=9c0c38dd9a7e9c6e5c2298e811d61a19</link><description>linux-windows混合AD+CVE-2024-42009+postgresql注入-\\x26gt;postgres弹shell-\\x26gt;内网横向-\\x26gt;krbrelayx-\\x26gt;dpapi-\\x26gt;pywhisker-\\x26gt;upn欺骗-\\x26gt;gpo_abuse</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-03-19T21:10:17</pubDate></item><item><title>HTB_Bigbang(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485401&amp;idx=1&amp;sn=5bbd93a61ed45ffd0c73e96b7e64105b</link><description>HTB_Bigbang+CVE_2023-26326+CVE-2024-2961+app逆向</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-02-07T20:00:18</pubDate></item><item><title>HTB_Cat(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485396&amp;idx=1&amp;sn=87356740064eca47baf980b1b66c3f75</link><description>HTB_Cat+linux(Medium)+代码审计+xss+sql盲注-\\x26gt;端口转发+gitea_xss</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-02-06T20:03:14</pubDate></item><item><title>HTB_Backfire(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485388&amp;idx=1&amp;sn=74e685a7639e0314856454b95462a187</link><description>HTB_Backfire+linux(Med)+Havoc_poc+Hardhatc2_poc+sudo+ssh私钥</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-01-23T20:00:25</pubDate></item><item><title>CE了解</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485392&amp;idx=1&amp;sn=a3204187202136c21f954c939c9d6a3d</link><description>CE基础知识了解</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-01-22T20:00:46</pubDate></item><item><title>WebSocket了解</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485387&amp;idx=1&amp;sn=cd63395d61608fa0e0fa3a453a6b9eb3</link><description>Websocket了解</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-01-21T20:00:42</pubDate></item><item><title>S7_HTB_EscapeTwo(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485368&amp;idx=1&amp;sn=74ddd25dde102efbcdb5039899f102d1</link><description>S7_HTB_EscapeTwo+windows(Easy)+smbclient+mssql利用+bloodyAD+CA模板漏洞利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-01-16T20:00:44</pubDate></item><item><title>frida搭建+使用</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485367&amp;idx=1&amp;sn=dc03aa1898daa66f43405c5cf951f4df</link><description>frida环境搭建+HTB_APKey+apk反编译+frida_hook</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2025-01-14T20:00:23</pubDate></item><item><title>HTB_Unrested(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485355&amp;idx=1&amp;sn=1daf8e542791e21a08caefb9ce458e5d</link><description>HTB-Unrested+linux(Med)+CVE-2024-42327(时间盲注)-\\x26gt;RCE-\\x26gt;sudo -l(nmap)</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-12-22T20:31:43</pubDate></item><item><title>HTB_Vintage（思路）</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485349&amp;idx=1&amp;sn=a329b52351dc5b9a272eb4450c1df369</link><description>HTB_Vintage（思路）+ windows(hard)+pre2k+krb5票据(getTGT)+bloodyAD+asreproast+dpapi</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-12-08T20:00:10</pubDate></item><item><title>thm_pwn110</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485343&amp;idx=1&amp;sn=11f1ac8a85a3a280a2cebafc70dde1ac</link><description>pwn110+mprotect+__libc_stack_end</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-24T00:01:26</pubDate></item><item><title>pwn109-ret2libc</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485333&amp;idx=1&amp;sn=ea4483585e0169afbf783b1640ad7a74</link><description>THM_pwn109+ret2libc+rop gadgets</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-23T20:00:21</pubDate></item><item><title>HTB_BlockBlock</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485311&amp;idx=1&amp;sn=259b559254467b7b3dcee850a4b4cb07</link><description>HTB_BlockBlock+fetch_xss+json-rpc信息泄露+sudo提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-21T20:00:27</pubDate></item><item><title>pwn109-ret2libc</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485279&amp;idx=1&amp;sn=5a364b58f2dc06c59b6e2a98fc20c669</link><description>THM_pwn109+NX+libc+ROP</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-19T20:00:48</pubDate></item><item><title>thm_pwn108</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485256&amp;idx=1&amp;sn=c270089dff0d99f2cb4bf45522e27d55</link><description>thm_pwn108+GOT覆盖+printf格式化字符串%n利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-16T20:00:15</pubDate></item><item><title>THM_pwn107(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485233&amp;idx=1&amp;sn=7ad0cf32c05e5ab37fb5ab3388f3f029</link><description>thm_pwn107+格式化字符串溢出+PIE绕过+canary获取+动态基址获取</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-15T21:30:18</pubDate></item><item><title>HTB_Administrator</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485207&amp;idx=1&amp;sn=91ad667a36ec73349dd30451f7cafd32</link><description>HTB_Administrator+bloodhound+GeneriAll+Genericwrite+DCSync</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-14T20:01:00</pubDate></item><item><title>thm_pwn103</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485180&amp;idx=1&amp;sn=34b285e609745d187170243e1bebccfa</link><description>THM_pwn103+scanf缓冲区溢出+栈对齐</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-13T22:30:23</pubDate></item><item><title>HTB_Certified</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485124&amp;idx=1&amp;sn=cf1807878af914dbcc449bb1e46cf8fd</link><description>HTB之Certified+windows(Med)+smb服务利用+bloodhound+ADCS利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-10T20:00:36</pubDate></item><item><title>记一次应急记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485089&amp;idx=1&amp;sn=d2e489a897e9a58424c208f7e5a20d32</link><description>记一次应急响应排除挖矿病毒记录+root密码重置+进程cpu占用率异常+找到相关路径，计划任务，服务进行排查</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-06T20:00:43</pubDate></item><item><title>HTB 之 University(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485076&amp;idx=1&amp;sn=724e31274c73dd3386945c370ddd9dfb</link><description>赛季6HTB之University+Window(Insane)+CVE-2023-33733-\\x26gt;socks代理+文件上传+?</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-11-03T20:00:20</pubDate></item><item><title>HTB之Chemistry</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485024&amp;idx=1&amp;sn=6303195c52d52e780850d663fb733cb3</link><description>赛季6HTB之Chemistry+linux(eazy)+cif文件伪造+python解析db文件+CVE-2024-23334</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-10-26T20:01:41</pubDate></item><item><title>HTB之Chemistry(思路)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485016&amp;idx=1&amp;sn=f021c2e152d21341258619cf550200b1</link><description>HTB之Chemistry(思路)+cif文件伪造+CVE</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-10-20T21:00:21</pubDate></item><item><title>HTB之Yummy</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247485000&amp;idx=1&amp;sn=e8b15fa2e4b133af54008e9ab43ca078</link><description>HTB之Yummy+linxu(hard)+本地文件包含-\\x26gt;jwt伪造-\\x26gt;sudo提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-10-15T11:32:17</pubDate></item><item><title>HTB之Cicada</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484979&amp;idx=1&amp;sn=cb17a35d6a87462fdc38d0f6197769bd</link><description>赛季6HTB之Cicada+Windows(Eazy)+smb漏洞利用+SeBackup提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-10-03T20:00:08</pubDate></item><item><title>HTB之Cicada</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484961&amp;idx=1&amp;sn=21fc262f5a82b6283b93b63da6dd3570</link><description>HTB之Cicada+Windows(Eazy)+SMB漏洞利用-\\x26gt;SeBackup权限/Backup Operators组利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-29T20:00:46</pubDate></item><item><title>HTB之trickster(root补充)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484953&amp;idx=1&amp;sn=dc36d59912d8feb43794612e1f078037</link><description>赛季6HTB之Trickster(root补充)</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-25T23:33:52</pubDate></item><item><title>HTB之trickster</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484943&amp;idx=1&amp;sn=8f8508fe73979b3d41bfa0a452e98fcd</link><description>赛季6HTB之linux(Med)+CVE-2024-34716-\\x26gt;docker端口转发-\\x26gt;CVE-2024-32651</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-23T22:14:38</pubDate></item><item><title>HTB之Caption(User解法二)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484907&amp;idx=1&amp;sn=0ac39cbc4216db244aacd21738d74898</link><description>赛季6HTB之Caption(User解法二)+linux(hard)-\\x26gt;FUZZ+XSS+SSRF+LFI</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-21T21:28:30</pubDate></item><item><title>HTB之Caption</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484876&amp;idx=1&amp;sn=adbcd5a38c9272be55162f3a43d4069d</link><description>赛季6HTB之Caption+linux(hard)+H2-RCE-\\x26gt;thrift客户端服务端RPC通信</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-17T21:12:24</pubDate></item><item><title>HTB之Sightless</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484843&amp;idx=1&amp;sn=0b318b3e806f00cddf9dcd9646448759</link><description>赛季6HTB之Sightless+linux(Eazy)+CVE-2022-0944+shadow密码爆破+ssh-\\x26gt;端口转发+chrome远程调用+命令执行</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-09-11T22:20:48</pubDate></item><item><title>HTB之MonitorsThree</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484812&amp;idx=1&amp;sn=ecbb5a87666714c7a00fcc75cdfddb15</link><description>赛季6HTB之monitorsthree+linux(med)+SQL注入+子域名爆破+CVE-2024-25641反弹webshell+敏感配置文件,密码爆破+横向shell+ssh端口转发+Duplicati-bypass+计划备份任务</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-27T19:06:39</pubDate></item><item><title>HTB之Lantern（root部分）</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484770&amp;idx=1&amp;sn=f3ea2f42f62db78fd52a388f7d9f77c7</link><description>赛季6HTB之Lantern+db文件BLOB数据查看</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-24T11:56:21</pubDate></item><item><title>HTB之Lantern(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484741&amp;idx=1&amp;sn=35168965b6fc445052e86b53ae1073b5</link><description>赛季6HTB之Lantern+linux(hard)+ssrf+dll反编译+dll反弹shell</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-22T01:29:16</pubDate></item><item><title>HTB之Compiled(root部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484696&amp;idx=1&amp;sn=e399186f7629b515cd91d800d7a133d7</link><description>HTB之Compiled(root部分)+windows(Med)+CVE-2024-20656</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-14T15:56:32</pubDate></item><item><title>HTB之Compiled(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484685&amp;idx=1&amp;sn=af7fa8f7cdb5e261b7746793480e0ffa</link><description>HTB之Compiled(user部分)+Windows(Med)+CVE-2024-32002+密码爆破+winrm远程连接</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-13T23:43:41</pubDate></item><item><title>HTB之Sea</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484659&amp;idx=1&amp;sn=69bbe38891c7f95a1784e08cb2a7204c</link><description>赛季6HTB之Sea+linux(eazy)+cms_nday利用+hash爆破+端口转发+命令执行</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-11T21:44:27</pubDate></item><item><title>HTB之Resource(user部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484613&amp;idx=1&amp;sn=db3f2b448d5294fe2d4cd1bc6885c9c9</link><description>Season6+HTB之Resource+本地文件包含+敏感信息泄露(zipgrep)+CA签名登录</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-07T18:46:40</pubDate></item><item><title>说点什么</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484584&amp;idx=1&amp;sn=30b73729de0eb6798bf0b8d4a3f77648</link><description>搜狗输入法绕锁屏密码漏洞</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-08-02T13:03:01</pubDate></item><item><title>HTB之PermX</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484580&amp;idx=1&amp;sn=a63d6be72bba56381a083bea5bb61f6f</link><description>赛季靶5HTB之permx+linux(eazy)+CVE-2023-4220+配置文件数据库凭证泄露+ssh密码重用+sudo提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-07-08T16:09:33</pubDate></item><item><title>Blazorized</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484568&amp;idx=1&amp;sn=50ca9b979d3bbeb80685a888145de3ab</link><description>赛季5之Blazorized+windows(Med)+DLL反编译+jwt伪造+MSSQL注入+powerview使用与bloodhound分析</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-07-02T23:28:57</pubDate></item><item><title>HTB之Axlle</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484539&amp;idx=1&amp;sn=7a7e87f2123378e24ade8f5550f0a40e</link><description>赛季靶HTB之Axlle+钓鱼邮件xll-exec反弹shell+hta反弹shell</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-06-27T17:52:11</pubDate></item><item><title>HTB之editorial</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484522&amp;idx=1&amp;sn=1ff3a128f2648a99de78348c1f0c9e0f</link><description>赛季5HTB之Editorial+linux(Eazy)+SSRF+.git敏感信息泄露+CVE-2022-24439</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-06-17T18:05:42</pubDate></item><item><title>HTB之Blurry</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484507&amp;idx=1&amp;sn=ce95c2a5a2d12a1771858d418b411929</link><description>赛季5之HTB-Blurry+linux(Medium)+CVE漏洞利用+sudo提权/恶意文件构造</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-06-12T11:10:31</pubDate></item><item><title>HTB之Freelancer</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484495&amp;idx=1&amp;sn=c63e7f161283221088d8e36fb2a94064</link><description>赛季靶HTB之HTB之Freelancer+windows(hard)+任意注册+越权+约束委派利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-06-10T09:57:05</pubDate></item><item><title>HTB之BoardLight</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484476&amp;idx=1&amp;sn=b171af11ec47f65533791bd2da4d176f</link><description>赛季靶5HTB之boardlight+子域名爆破+CVE-2023-30253+CVE-2022-37706</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-05-27T21:55:14</pubDate></item><item><title>HTB之MagicGardens</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484461&amp;idx=1&amp;sn=2c4acfc241bf636c446cacdc80e2c026</link><description>HTB之MagicGardens+linux(ins)+smtp用户枚举+5000端口密码爆破+drg.py脚本利用获得敏感文件+ssh连接+端口转发+cdp利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-05-21T18:03:36</pubDate></item><item><title>HTB之SolarLab</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484436&amp;idx=1&amp;sn=5e32ea5633d793723cc72ed2014fe21d</link><description>赛季5HTB之scholarlab+smb用户枚举+smbclient敏感信息泄露+CVE-2023-33733+端口转发+CVE-2023-32315+openfire解密爆破</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-05-14T15:33:21</pubDate></item><item><title>HTB之Mailing</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484397&amp;idx=1&amp;sn=07e5201b3641914b5384e0d59ad6057d</link><description>赛季5_HTB之Mailing+windows(eazy)+任意文件下载+第三方组件漏洞利用+sam哈希导出</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-05-11T21:19:18</pubDate></item><item><title>HTB之Intuition</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484386&amp;idx=1&amp;sn=814902e662e2f395c4b13c2b99896db9</link><description>HTB之Intuition+linux(hard)+xss弹cookie+ssrf读取文件+(敏感信息泄露+ftp)+逆向代码分析</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-05-01T11:50:46</pubDate></item><item><title>HTB之Runner</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484368&amp;idx=1&amp;sn=4c8863db41a0f1da293aff9186b35904</link><description>赛季5HTB之Runner+子域名扫描+未授权api调用+敏感信息收集+端口转发+runc逃逸</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-04-23T19:59:59</pubDate></item><item><title>webshell流量一览</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484342&amp;idx=1&amp;sn=5e82034b835fddf7638e1c0c57d56ed9</link><description>webshell流量的记录</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-04-19T18:04:02</pubDate></item><item><title>HTB之IClean</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484285&amp;idx=1&amp;sn=bc4605628c29abea99cd92fa760f7fa6</link><description>HTB之Iclean+linux(Med)+xss反弹cookie+ssti注入反弹shell+数据库信息泄露+sudo -l提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-04-15T19:54:37</pubDate></item><item><title>HTB之Ouija</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484269&amp;idx=1&amp;sn=d96f2d6e02f28b977f44c73f19876f70</link><description>HTB之Ouija+linux(insane)+请求夹带bypass+哈希长度扩展攻击+软链接的任意文件读取</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-26T11:49:57</pubDate></item><item><title>HTB之Headless</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484251&amp;idx=1&amp;sn=9c9345ef67b74965e4f56ac1cfa1d9d0</link><description>赛季靶HTB之Headless+linux(eazy)+xss+命令执行+sudo提取</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-24T14:09:58</pubDate></item><item><title>HTB之WifineticTwo</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484241&amp;idx=1&amp;sn=f8633555025425dfe9ad9bd72426c38e</link><description>赛季靶HTB之WifineticTwo+linux(Med)+openplc漏洞+wlan密码爆破+有关配置</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-18T17:21:28</pubDate></item><item><title>HTB之FormulaX</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484218&amp;idx=1&amp;sn=ce91c655d979affbf561fe05d8b82bcb</link><description>HTB赛季靶之FormulaX+linux(hard)+xss敏感信息获取+simple-git漏洞利用+mongodb数据库信息泄露+ssh -L端口转发+webshell获取+敏感配置文件信息获取+OpenOffice漏洞利用</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-16T14:36:36</pubDate></item><item><title>vulnhub之Brainpan: 1</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484178&amp;idx=1&amp;sn=950fb5140de480ac54160181ab0ee977</link><description>vulnhub之Brainpan：1+linux+缓冲区溢出(eip+jmp esp)+sudo提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-06T23:28:18</pubDate></item><item><title>HTB之Perfection</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484147&amp;idx=1&amp;sn=2b7c8df6d557b354d1b1f1dc224a979c</link><description>赛季靶HTB之Perfection+ssti注入+ssh爆破</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-03-05T13:17:48</pubDate></item><item><title>HTB之Jab</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484138&amp;idx=1&amp;sn=09f7085733d30cf29f2e9fb491cb59f2</link><description>赛季靶HTB之Jab+Windows(Med)+第三方软件利用+ASREP Roast+135端口远程登录+端口转发+CVE-2023-32315</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-02-29T00:19:58</pubDate></item><item><title>HTB之Office</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484122&amp;idx=1&amp;sn=c9980eb739095c1602100eecf9ebd2de</link><description>赛季靶HTB之Office+windows(hard)+cms漏洞利用+smb信息泄露+kerberos流量破解+内网：多用户横向渗透+GPO提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-02-24T10:24:53</pubDate></item><item><title>HTB之Pov</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484057&amp;idx=1&amp;sn=ba13fa12f0f73639fdeeffd12c4ec3f6</link><description>HTB赛季靶之pov+windows(Med)+本地文件包含漏洞+VIEWSTATE漏洞利用+PScredential+Runascs工具+msf</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-02-01T15:37:04</pubDate></item><item><title>HTB之analysis</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484049&amp;idx=1&amp;sn=f881af1d6d3ba1755ac793fff80e5488</link><description>HTB赛季4-analysis+windows(hard)+fuzz+kerbrute+ldap注入+dll劫持提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-24T15:24:57</pubDate></item><item><title>HTB之Clicker</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484041&amp;idx=1&amp;sn=40d29db7f9c1f9e5b50f60469e909521</link><description>HTB之Clicker+linux(Med)+nfs协议漏洞+代码审计+perl提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-19T12:04:41</pubDate></item><item><title>HTB之monitored</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247484026&amp;idx=1&amp;sn=8b1b1ba08aa7319c85088f267378368f</link><description>赛季靶HTB之monitored+snmp泄露+接口访问+信息收集</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-18T14:29:15</pubDate></item><item><title>HTB之Visual</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483996&amp;idx=1&amp;sn=f4431b3402427976ea1e150158752fb2</link><description>HTB之Visual+windows(Mid)+本地git+NET项目编译+恢复权限+提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-12T19:27:30</pubDate></item><item><title>HTB之Bizness</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483901&amp;idx=1&amp;sn=921ca648a3833272bd4624b93b05f7b5</link><description>HTB之Bizness cve漏洞利用+derby数据库+grep信息处理</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-11T01:17:30</pubDate></item><item><title>vulnhub-socnet</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483859&amp;idx=1&amp;sn=b3c8b4808ace8ffc3943f8a7b80e8563</link><description>vulnhub之socnet，代码反弹shell+内网穿透+uname提权</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2024-01-09T16:11:43</pubDate></item><item><title>HTB之Authority</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483809&amp;idx=1&amp;sn=b1734f1c031b62d68fa130e482b16503</link><description>主要为凭证盗取；思路：smb信息泄露、ldap监听、ADCS证书漏洞提权；工具：smbclient、certipy、evil-winrm、impacket</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2023-12-11T16:30:18</pubDate></item><item><title>HTB之Broker</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483767&amp;idx=1&amp;sn=b600816aee6b6a4862bbc1b530ae0aaa</link><description>Broker之ActiveMQ漏洞</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2023-12-06T16:03:08</pubDate></item><item><title>vulnhub-DERPNSTINK: 1</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483746&amp;idx=1&amp;sn=5c1bf32dd4d7e459ba347c732adba676</link><description>vulnhub-DERPNSTINK: 1 弱口令+文件上传</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2023-12-02T22:12:04</pubDate></item><item><title>渗透测试第一篇</title><link>https://mp.weixin.qq.com/s?__biz=MzkxMjYyMjA3Mg==&amp;mid=2247483657&amp;idx=1&amp;sn=bfddb408ca05b204e1759f69b14c1262</link><description>渗透测试基础知识分享</description><author>羽泪云小栈</author><category>羽泪云小栈</category><pubDate>2023-12-01T20:08:01</pubDate></item></channel></rss>