<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkxMzY5NDUyMQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 12 Mar 2026 11:36:12 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>CC 链（Commons Collections 链）</title><link>https://mp.weixin.qq.com/s/aaCBnTjkCDM7UyC3Qm020A</link><description>一、认识 CC 链1.1 基本定义CC 链全称为 「Apache Commons Collections 链」</description><author>hutututu</author><category>hutututu</category><pubDate>2026-03-12T09:05:07</pubDate></item><item><title>CDN 验证与真实 IP 查找</title><link>https://mp.weixin.qq.com/s/g1l7S8CZv8wBeEi-xxbktA</link><description>转自渐怀的博客一、CDN 存在性验证验证核心逻辑为：若域名解析对应 IP 不唯一，则大概率使用 CDN，主要通</description><author>hutututu</author><category>hutututu</category><pubDate>2026-03-10T17:05:10</pubDate></item><item><title>FastcmsV0.1.5代码审计</title><link>https://mp.weixin.qq.com/s/kFYTn0FQVO3RcOO2rJ2-Ew</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2026-01-30T15:03:17</pubDate></item><item><title>tarzan-cms：snakeyaml反序列化(ScriptEngineManager利用链)</title><link>https://mp.weixin.qq.com/s/MMWUP-TasKJZ1HdArV5HNg</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2026-01-23T16:41:05</pubDate></item><item><title>halo博客系统代码审计</title><link>https://mp.weixin.qq.com/s/0Ws8r4TrVgBjPIZzRlMi9w</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2026-01-22T14:45:09</pubDate></item><item><title>tarzan-cms：snakeyaml反序列化(ScriptEngineManager利用链)</title><link>https://mp.weixin.qq.com/s/xc-kXLgLE0UPB6qPIsPJyw</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2026-01-14T20:04:20</pubDate></item><item><title>若依最新版本4.8.1漏洞 SSTI绕过获取ShiroKey至RCE</title><link>https://mp.weixin.qq.com/s/S4u141OeazuNxhEeCWLbTw</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-12-26T11:59:25</pubDate></item><item><title>记一次edu证书挖掘案例</title><link>https://mp.weixin.qq.com/s/_qtBnR9oR-eHaub7kVa_bg</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-10-16T00:30:30</pubDate></item><item><title>用友U8 Cloud系统</title><link>https://mp.weixin.qq.com/s/JmehmZA_I3S4AZB0VtieVQ</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-10-15T17:27:49</pubDate></item><item><title>用友 u8-cloud VouchFormulaCopyAction sql注入分析</title><link>https://mp.weixin.qq.com/s/2ihFHNOUa8rd_-Bub_jM_g</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-10-14T13:37:32</pubDate></item><item><title>EDUSRC信息收集</title><link>https://mp.weixin.qq.com/s/zre3yY8EY-d2jLxPOXjVgg</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-09-09T15:15:57</pubDate></item><item><title>vulntarget-e</title><link>https://mp.weixin.qq.com/s/L-2z7TNUo7gwrj88dO1TVg</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-07-23T02:57:56</pubDate></item><item><title>vulntarget-a（writeup）</title><link>https://mp.weixin.qq.com/s/U1iBAUmZaKV0404e6kRc0w</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-05-31T11:04:00</pubDate></item><item><title>Communication</title><link>https://mp.weixin.qq.com/s/FOF9Y3hEXjyk6NVCDjALww</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-05-19T22:26:08</pubDate></item><item><title>不寻常的vulnhub靶机-DeathStar</title><link>https://mp.weixin.qq.com/s/e2-LdkWu0uP4r-8FSBcudA</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-05-19T17:26:17</pubDate></item><item><title>安全设备</title><link>https://mp.weixin.qq.com/s/Ni4QnTNcyNldoY626PkM3g</link><description>一名合格的安服仔也能在拓扑图中了解各类设备IDS入侵检测系统“常通过旁路方式，部署在核心交换、路由位置。</description><author>hutututu</author><category>hutututu</category><pubDate>2025-05-17T19:25:00</pubDate></item><item><title>安服面试笔记（上）</title><link>https://mp.weixin.qq.com/s/byDLaYigiyQ7uFxr1HLPNw</link><description></description><author>hutututu</author><category>hutututu</category><pubDate>2025-05-06T21:45:53</pubDate></item><item><title>内存取证例题练习</title><link>https://mp.weixin.qq.com/s/2GJa2fSjIdySWb4fvhDgvQ</link><description>四道取证习题，回顾内存取证知识点和vol.py工具的使用</description><author>hutututu</author><category>hutututu</category><pubDate>2025-04-26T23:44:50</pubDate></item><item><title>ThermalPower</title><link>https://mp.weixin.qq.com/s/4cfUcgcQmRchdQl8-OGLMA</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2025-01-17T00:06:50</pubDate></item><item><title>2022网鼎杯半决赛复盘详细打靶笔记</title><link>https://mp.weixin.qq.com/s/qTDwwo3auJdQfgehc95Nmw</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2025-01-08T00:11:06</pubDate></item><item><title>2022网鼎杯半决赛复盘</title><link>https://mp.weixin.qq.com/s/N8olPirCku7vvRtk51T-dA</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-31T00:16:08</pubDate></item><item><title>春秋云境-GreatWall综合渗透</title><link>https://mp.weixin.qq.com/s/22PwMTF34kuYlvOdnoR5rw</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-22T18:15:52</pubDate></item><item><title>第二届长城杯&amp;CISCN 部分WP</title><link>https://mp.weixin.qq.com/s/k2XGeqhMGEemtmlxcbPx6g</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-18T19:52:13</pubDate></item><item><title>关于内网代理、vm、frp、proxifier全局流量转发等问题</title><link>https://mp.weixin.qq.com/s/Cq-DdH1DseOJIcEGwb0RWg</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-09T01:27:03</pubDate></item><item><title>关于内网代理、横向移动技巧</title><link>https://mp.weixin.qq.com/s/vSNa3yECLL-pQbVuQ5zofg</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-09T01:17:44</pubDate></item><item><title>关于内网代理、横向移动技巧</title><link>https://mp.weixin.qq.com/s/tDjmeosqfHVeNVhnIkiTzA</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-09T00:39:17</pubDate></item><item><title>ATT&amp;CK红队评估实战靶场二</title><link>https://mp.weixin.qq.com/s/a4VByLOCH-X8D-BOcCYV_w</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-12-06T00:29:49</pubDate></item><item><title>CTF之web基础</title><link>https://mp.weixin.qq.com/s/9sUJMus1k_W_gYu8G4pU5Q</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-11-16T19:33:51</pubDate></item><item><title>一文讲懂蓝队面试shiro漏洞知识点</title><link>https://mp.weixin.qq.com/s/PytxxCfCcAyDkolvZTGN_Q</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-11-08T13:15:20</pubDate></item><item><title>PHP反序列化</title><link>https://mp.weixin.qq.com/s/TlgEAb8iwVGRV_Mj6vXaCA</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-10-19T00:04:08</pubDate></item><item><title>CTF 第八届御网杯线上赛</title><link>https://mp.weixin.qq.com/s/VWE5oIsGenrIcJoJoj5ozw</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-10-10T21:09:58</pubDate></item><item><title>记一次内网实战渗透，拿下域/主机</title><link>https://mp.weixin.qq.com/s/10d8kc0WJC82YrOur2rp-g</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-09-29T17:23:57</pubDate></item><item><title>等保-Linux</title><link>https://mp.weixin.qq.com/s/s1ZcMPneRotUfSBUxLWTvg</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-08-26T12:40:54</pubDate></item><item><title>welcome</title><link>https://mp.weixin.qq.com/s/mG6YMNp0GQDZ8BUoT1kqMQ</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-08-18T16:50:23</pubDate></item><item><title>linux后门教程</title><link>https://mp.weixin.qq.com/s/sI1V9GNlUuka8bXIZP6BLg</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-07-16T19:09:56</pubDate></item><item><title>应急响应</title><link>https://mp.weixin.qq.com/s/2tLx3_7trjEQAxEmrAvnXw</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-07-13T11:26:56</pubDate></item><item><title>Fastjson反序列化漏洞</title><link>https://mp.weixin.qq.com/s/jIn1uqyozj0xs89zUTkaEQ</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-07-09T23:02:04</pubDate></item><item><title>Log4j2远程代码执行漏洞</title><link>https://mp.weixin.qq.com/s/oR9W5gX4YOlkZsat21Gyjw</link><description></description><author>flowers-boy</author><category>flowers-boy</category><pubDate>2024-07-08T11:35:21</pubDate></item><item><title>u200bCTF入门知识点</title><link>https://mp.weixin.qq.com/s/m8CnScEG37dIhpkBhcWuDw</link><description>CTF入门知识点</description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-07-05T23:03:16</pubDate></item><item><title>struts2框架漏洞</title><link>https://mp.weixin.qq.com/s/nLwKxjGyrhVlK3DfwwHxpA</link><description>title: struts2框架漏洞\\x0d\\x0acategories:漏洞复现\\x0d\\x0aabbrlink: 48203\\x0d\\x0adate</description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-06-16T23:41:58</pubDate></item><item><title>webshell工具流量特征</title><link>https://mp.weixin.qq.com/s/1_og6CkD_KdCr8WbkIuzrg</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-06-05T16:51:13</pubDate></item><item><title>CTF线下AWD攻防经验总结</title><link>https://mp.weixin.qq.com/s/Z6rX2FYVdnA_0_KkU4magQ</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-06-03T11:36:55</pubDate></item><item><title>Prime1 - 提权的另一种解法，彻底搞懂OpenSSL解密渗透提权，超强思路版。</title><link>https://mp.weixin.qq.com/s/EMNelhJvG3jnkHnmDEL-Bg</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-06-02T01:30:46</pubDate></item><item><title>SickOS1.1 - Shellshock原理和利用过程精讲</title><link>https://mp.weixin.qq.com/s/EOnlL9e5NpE0iQbm9mc0DA</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-06-01T01:16:24</pubDate></item><item><title>JARBAS - Jenkins渗透原理详解</title><link>https://mp.weixin.qq.com/s/tBjZV3f96lOaA_0irxw-DA</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-05-31T00:13:14</pubDate></item><item><title>打靶笔记w1r3s.v1.0</title><link>https://mp.weixin.qq.com/s/kD7EkxLLYHr3ckKS8GtXcA</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-05-29T16:26:13</pubDate></item><item><title>打靶笔记Connect the dots</title><link>https://mp.weixin.qq.com/s/VllnCvKYP5jPEGMCI5Vm6A</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-05-27T21:37:55</pubDate></item><item><title>ISCC比赛2024</title><link>https://mp.weixin.qq.com/s/7XFuRqtTcmTOzJGRQhIaoQ</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-05-25T19:33:13</pubDate></item><item><title>sudo风暴</title><link>https://mp.weixin.qq.com/s/aq5bHuLHdbhKERR9JrjBmg</link><description></description><author>汉堡安全</author><category>汉堡安全</category><pubDate>2024-05-23T19:02:40</pubDate></item></channel></rss>