<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkxNjc0ODA3NQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Mon, 23 Mar 2026 23:29:50 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>CSP绕过工具：cspbypass</title><link>https://mp.weixin.qq.com/s/YcVpH_5U_1uVNPA9PZvRRg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-03-23T22:25:40</pubDate></item><item><title>预接管账号：结合 OTP 校验分离与空格绕过注册内部管理员邮箱</title><link>https://mp.weixin.qq.com/s/KT_PYLtH5v2QYgwEQ1ooyA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-03-22T00:16:14</pubDate></item><item><title>逻辑漏洞：邮箱注册 tips #11</title><link>https://mp.weixin.qq.com/s/N5q10Kxa6L-pdaXoXtHfQA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-03-01T15:46:49</pubDate></item><item><title>个人资料/配置页检查清单</title><link>https://mp.weixin.qq.com/s/QzyFqnsEEIATyYJHWkI3dg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-26T08:03:46</pubDate></item><item><title>缓存投毒玩坏头像：Unix 时间戳预测 + 4小时 404 DoS 实战</title><link>https://mp.weixin.qq.com/s/7WOJRipH17N5uv_4obMySg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-25T17:52:05</pubDate></item><item><title>深度解析：在 Rails 中通过结构化代码消灭 IDOR 漏洞</title><link>https://mp.weixin.qq.com/s/oMqK4nCnXVBH8IguGzfq3Q</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-24T09:19:58</pubDate></item><item><title>Bug Bounty 实战：CSRF 如何升级成针对用户的 DoS</title><link>https://mp.weixin.qq.com/s/gxqPZ54SnjjZeWnToVLgIg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-20T08:33:13</pubDate></item><item><title>第三方集成崩盘：Salesforce 可预测 ID 枚举 + Zendesk 前端 admin token 泄露 265 万记录</title><link>https://mp.weixin.qq.com/s/V8vJ_7IwPqJasFk3DdSDFg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-18T10:26:12</pubDate></item><item><title>业务逻辑缺陷：同时 Archive &amp;amp; Trash，消息瞬间隐身 + 委托滥用</title><link>https://mp.weixin.qq.com/s/u2thIjVFZisr7ulNiCxqtQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-16T07:36:28</pubDate></item><item><title>GatewayToHeaven：在 GCP Apigee 中发现跨租户漏洞</title><link>https://mp.weixin.qq.com/s/WO82jQmN8mzZLdINYs6vCQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-15T11:52:50</pubDate></item><item><title>单请求经典 DoS：一个请求干掉目标的艺术</title><link>https://mp.weixin.qq.com/s/XQ5VUa99w_2j-wjd_yHDag</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-14T08:17:44</pubDate></item><item><title>技术干货：详解 Host Header 导致的逻辑越权与防护方案</title><link>https://mp.weixin.qq.com/s/xALL2HuwgqXTSA2YHOfziw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-10T09:24:19</pubDate></item><item><title>【实战复盘】通过监控调试模式获取 15,000 美元的远程代码执行收益</title><link>https://mp.weixin.qq.com/s/gb2Qc7AVTC8W11VOknMkvw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-07T10:05:34</pubDate></item><item><title>漏洞实战：怎么利用 XSS、BAC 和 CSRF 实现平台级接管的</title><link>https://mp.weixin.qq.com/s/IlyyCCU-SeusEZBxdPImQg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-06T10:16:05</pubDate></item><item><title>【实战分享】抽丝剥茧：记一次导致全站用户信息泄露的严重 IDOR 漏洞挖掘</title><link>https://mp.weixin.qq.com/s/aaxbzbgTukRYI_sZfTTozw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-05T08:47:22</pubDate></item><item><title>【实战复盘】利用 URL 路径混淆绕过认证：记一次价值 $4500 的企业后台接管</title><link>https://mp.weixin.qq.com/s/1DGqQdGiA7wf93qiV3ciWQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-04T09:25:36</pubDate></item><item><title>使用 Frida 在运行时拦截 OkHttp - 实用指南</title><link>https://mp.weixin.qq.com/s/KMqS2kM6vF5ar2RimJi8ng</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-02-02T20:20:14</pubDate></item><item><title>密码重置漏洞检查清单</title><link>https://mp.weixin.qq.com/s/3dBX4ZdJIdvbSJU6Ld_M3Q</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-31T10:44:12</pubDate></item><item><title>一种PHP PDO 预处理语句中的新型 SQL 注入技术</title><link>https://mp.weixin.qq.com/s/fRvF0SH6BtJVj5YnTIlqrg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-30T00:04:22</pubDate></item><item><title>注册功能漏洞检查清单</title><link>https://mp.weixin.qq.com/s/23f7itDcmeDixxIF9ZTtsQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-28T22:18:11</pubDate></item><item><title>一种利用 HTTP 重定向循环的新型 SSRF 技术</title><link>https://mp.weixin.qq.com/s/GwlZy-KB9epxVtt_-S8fmw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-27T20:28:11</pubDate></item><item><title>干货：如何利用自动化工具绕过谷歌验证码实现XSS攻击链</title><link>https://mp.weixin.qq.com/s/j7ynlnjH31IkKV8giCuhhA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-24T19:29:35</pubDate></item><item><title>利用 WAF 窃取 Salesforce OAuth 令牌</title><link>https://mp.weixin.qq.com/s/eKC2GH7qNRWHD9z_xEkqCw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-23T19:36:45</pubDate></item><item><title>【实战】利用 Salesforce ID 格式特性实现用户遍历</title><link>https://mp.weixin.qq.com/s/piPYyb2z20u4jfiy5iyP2w</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-22T09:04:04</pubDate></item><item><title>常见OAuth 漏洞：未验证token</title><link>https://mp.weixin.qq.com/s/BMcWmEx-eOHcnxLR7adA9g</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-21T22:38:35</pubDate></item><item><title>TOCTOU 与信任链断裂:DNS Rebinding</title><link>https://mp.weixin.qq.com/s/hWV18NkjGn4-hgXI2rXazw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-20T21:49:02</pubDate></item><item><title>API 渗透实战：从 JSON 响应倒推隐藏的高危路由</title><link>https://mp.weixin.qq.com/s/jczC5QHZqOZMkclH0qHVaw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2026-01-19T18:07:28</pubDate></item><item><title>【深度复盘】Trust Wallet 惊魂24小时：当官方插件变成“内鬼”，一行代码如何盗走600万美元？</title><link>https://mp.weixin.qq.com/s/-puuLDHaEl7d1N4S4yFxKg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-26T14:11:05</pubDate></item><item><title>从源码泄露到 RCE：某 AI 平台沙箱逃逸实战复盘</title><link>https://mp.weixin.qq.com/s/McKkLJ4NkOs4ixbcFf-33Q</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-23T17:12:14</pubDate></item><item><title>不触发预检的 CSRF 攻击：Content-Type:text/plain 的魔法</title><link>https://mp.weixin.qq.com/s/ZZfvYGhvAdhVTQJVbbNMJQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-21T13:40:55</pubDate></item><item><title>谷歌登录也防不住？实战劫持 GIS SDK 实现无感账号接管</title><link>https://mp.weixin.qq.com/s/Mnyt3Yuwdvg6mkHqK5waVg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-19T11:17:58</pubDate></item><item><title>【漏洞挖掘Tips】一种新的 GraphQL 绕过角度</title><link>https://mp.weixin.qq.com/s/Cz_SWDIMD8iQyx_1xyrzqg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-17T14:53:37</pubDate></item><item><title>【从公开报告到私有神器】：如何通过漏洞报告制作字典</title><link>https://mp.weixin.qq.com/s/DO22QC7SBHKFk-87W9vUcA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-11T22:57:05</pubDate></item><item><title>如何发现 OpenAI Atlas的 OAuth泄漏漏洞</title><link>https://mp.weixin.qq.com/s/jtDPaa1hCXZl94fNqndavg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-09T22:22:06</pubDate></item><item><title>嵌套解析器情况下的XSS</title><link>https://mp.weixin.qq.com/s/2ofBOAfGNWpRpSLyu1aSZQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-08T14:55:25</pubDate></item><item><title>伪造注释状态下的XSS</title><link>https://mp.weixin.qq.com/s/iIQ2HmVB02Z5iIoXH3oNew</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-07T18:14:24</pubDate></item><item><title>用 JADX 静态分析，反手挖出两个高危 ATO</title><link>https://mp.weixin.qq.com/s/x0nmGjdAVz_0Sqd4tnnEAQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-05T09:41:10</pubDate></item><item><title>工具流教学：Gau + Uro + Dorking，一套组合拳挖到星巴克的XSS漏洞</title><link>https://mp.weixin.qq.com/s/JOgOXWqYYVJxz5yvsOmHRw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-04T17:15:47</pubDate></item><item><title>攻防演练中的“降维打击”：逃逸出内网边界的影子资产与SaaS供应链挖掘</title><link>https://mp.weixin.qq.com/s/ZzeCujgzqbXdeAgoLcretg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-03T15:39:03</pubDate></item><item><title>信息收集最强OSINT姿势：Google一搜，全球程序员的密码、API Key、邮箱全裸奔</title><link>https://mp.weixin.qq.com/s/bSNgMNdAmLGdeXT1WBUqgA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-12-01T14:49:53</pubDate></item><item><title>【漏洞挖掘Tips】将JS伪造为 PDF 的一些方法</title><link>https://mp.weixin.qq.com/s/segiaTbEeRRpm6iEaEvRWg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-29T17:54:22</pubDate></item><item><title>【漏洞挖掘Tips】将 JSON payload 伪装为 PDF 或图像文件</title><link>https://mp.weixin.qq.com/s/Gvv-uaA64OrtaV-Y5bud4w</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-28T10:13:10</pubDate></item><item><title>【漏洞挖掘Tips】Web应用常见鉴权机制及其漏洞</title><link>https://mp.weixin.qq.com/s/IRXQ6ISaORerh7IyVDFRiQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-25T09:41:21</pubDate></item><item><title>【快讯】Cloudflare 突发全球大范围宕机！</title><link>https://mp.weixin.qq.com/s/2xuGHo1rNPMDIBprT-4kFA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-18T22:30:26</pubDate></item><item><title>【漏洞挖掘Tips】模糊测试和绕过AWS WAF</title><link>https://mp.weixin.qq.com/s/Ej1Oz52gyzpBwP-eRiBTUA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-14T17:56:28</pubDate></item><item><title>【工具推荐】绕过 Cloudflare 针对的burpsuite代理的识别</title><link>https://mp.weixin.qq.com/s/444-TPlLZYc5Iwh8hxKFPQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-13T15:14:10</pubDate></item><item><title>【移动安全】现代 iOS 渗透测试：无需越狱</title><link>https://mp.weixin.qq.com/s/wz5O4h6amgRuFxGsEUhHyg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-10T11:31:58</pubDate></item><item><title>【工具推荐】AI+Fuzz，一键挖掘隐藏目录！</title><link>https://mp.weixin.qq.com/s/bKN5EtTlFV9qxwj4YwsGog</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-11-04T17:48:16</pubDate></item><item><title>【漏洞挖掘Tips】IDOR 终极技巧清单</title><link>https://mp.weixin.qq.com/s/-mIIqw-y6kNcQP0uz4x2bg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-31T15:41:21</pubDate></item><item><title>【后渗透Tips】一种常见但是不容易想到的伪提权方式</title><link>https://mp.weixin.qq.com/s/qxcqLAXomuVUxWBoIeHGdw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-29T18:07:41</pubDate></item><item><title>【漏洞挖掘Tips】关于OTP的常见漏洞和处理方式</title><link>https://mp.weixin.qq.com/s/Q5Dopm1Qb4Jr1MEwTegFyQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-27T16:28:43</pubDate></item><item><title>【漏洞挖掘Tips】一种小众的边缘资产收集方式</title><link>https://mp.weixin.qq.com/s/hP0frs64QNAJGO8yMPji9w</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-22T11:38:31</pubDate></item><item><title>Lubian矿池被盗？美执法没收12WBTC！带你理清最近的127,271 BTC事件；</title><link>https://mp.weixin.qq.com/s/iJz7kq1KWLAcSpnOz74Wyg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-17T15:25:48</pubDate></item><item><title>【漏洞挖掘Tips】二次上下文路径遍历攻击</title><link>https://mp.weixin.qq.com/s/0qrhzJkf6QBcj3mhTKHO1g</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-10-13T15:25:03</pubDate></item><item><title>【漏洞挖掘Tips】postMessage注入实现RCExa0获取xa0Google $22,500</title><link>https://mp.weixin.qq.com/s/fJtZekvaBqjtRXwSCsBwMA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-29T11:06:43</pubDate></item><item><title>【漏洞挖掘Tips】关于头像上传存储在s3的漏洞挖掘方法</title><link>https://mp.weixin.qq.com/s/PkML8SfN_nl7Uv2VoDKeFA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-25T11:13:31</pubDate></item><item><title>【漏洞挖掘Tips】一种新的2FA 绕过方式</title><link>https://mp.weixin.qq.com/s/gG_yER9pHVA5Yq2webcKYw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-24T16:52:25</pubDate></item><item><title>从“发送失败”到任意账号接管</title><link>https://mp.weixin.qq.com/s/y7CnGoPT8uL23-bSi2QndQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-22T17:06:58</pubDate></item><item><title>【漏洞挖掘tips】通过批量分配实现权限提升</title><link>https://mp.weixin.qq.com/s/sP432lqjcQgcKBDDvtCxIw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-17T11:33:12</pubDate></item><item><title>狂挖5000$赏金并且登入apple 的名人堂</title><link>https://mp.weixin.qq.com/s/45PbCTrZg1sL-wCiEavLzg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-08T15:50:44</pubDate></item><item><title>微软含泪打钱6000$！一条\"中文\"CRLF冲进 Hall of Fame</title><link>https://mp.weixin.qq.com/s/xjiCFzJ8ce3UpATxKlskHw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-05T11:47:48</pubDate></item><item><title>【0day 预警】Atlassian Jira Service Management Cloud 曝出 “一接管任意账户”</title><link>https://mp.weixin.qq.com/s/Q9e6zdxCR6eeIbKLBcULKQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-09-02T11:51:31</pubDate></item><item><title>腾讯云曝出严重安全漏洞，内部敏感信息等持续数月暴露于公网</title><link>https://mp.weixin.qq.com/s/dnbUfvMEgpzNyoOvMQOXUw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-28T11:49:57</pubDate></item><item><title>【技术干货】三连杀！用“并发”连续薅出3个高危漏洞</title><link>https://mp.weixin.qq.com/s/i07kfc8XBzhJ21DhLfPM5A</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-19T09:23:42</pubDate></item><item><title>【逻辑漏洞】一次价格篡改实战复盘</title><link>https://mp.weixin.qq.com/s/Q317LBsoZDLIoC-YjaB9Lg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-18T14:23:58</pubDate></item><item><title>【0-Click！一键接管任意 Facebook 账户】</title><link>https://mp.weixin.qq.com/s/E7k9MZhaka_ndJXfikoWzw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-17T15:31:01</pubDate></item><item><title>【扩大影响】把用户枚举玩出花：一个参数引发的 0-Click 账户接管</title><link>https://mp.weixin.qq.com/s/QMH967bwUvGvYqVboDe4xg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-16T10:06:16</pubDate></item><item><title>【新思路】把注册接口换成 WebSocket，UUID 一改直接接管全场账号</title><link>https://mp.weixin.qq.com/s/uS3OZUx_CnAuIvtaBBAwcA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-15T10:29:51</pubDate></item><item><title>【技术干货】一条 Google Dork 捡到的 高危存储型 XSS → 完整钓鱼链拿下管理员账号</title><link>https://mp.weixin.qq.com/s/a3YSFUmBTFXNe87zaC3igg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-14T16:41:14</pubDate></item><item><title>一条斜杠 “%2f” 狂赚 500€</title><link>https://mp.weixin.qq.com/s/jtXXQGUufGEJ4fgoTvkrIA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-13T11:09:42</pubDate></item><item><title>突发：字节 CDN 正式挂出“讣告”</title><link>https://mp.weixin.qq.com/s/utG-KktYeLnm18kDmx-jkw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-12T14:56:20</pubDate></item><item><title>喜提€1500赏金！仅凭一个Cookie绕过403，拿下整个内网CRM管理权！</title><link>https://mp.weixin.qq.com/s/v0nodIvTUp5JHXOTHhgT2A</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-12T12:00:08</pubDate></item><item><title>Frida Hook 实战：一次 WhatsApp 从安卓到 Windows 的跨平台 DoS 漏洞挖掘</title><link>https://mp.weixin.qq.com/s/_KLheZMAFHNkP2R0tkU4aw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-08T10:05:38</pubDate></item><item><title>如何通过一个逻辑漏洞爆赚9000$</title><link>https://mp.weixin.qq.com/s/YlBJcDmUFQqC9dzl7jajXQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-07T17:32:44</pubDate></item><item><title>我把麦当劳从Uber Eats上“下架”了，Uber还奖励了我一笔赏金</title><link>https://mp.weixin.qq.com/s/e8zMDK2EQpzqqhWePTGG_Q</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-06T17:59:05</pubDate></item><item><title>就点了一下，Yandex给了他赏金。这个P4漏洞简单到离谱</title><link>https://mp.weixin.qq.com/s/JDCRrS7UxdHKvgbDP2B-RQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-08-04T11:50:50</pubDate></item><item><title>他随手点开一个失效链接，几分钟后，100欧元赏金到账了</title><link>https://mp.weixin.qq.com/s/Qn66zNP-YDTmENXGeuz7Ig</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-31T10:37:57</pubDate></item><item><title>弱口令爆破总失败？那我建议您试下这招</title><link>https://mp.weixin.qq.com/s/Tehg2ojMyJMEJD9bm8gKWw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-29T11:55:48</pubDate></item><item><title>我震惊了！知名交易所的MFA，竟然只是一行JS代码？</title><link>https://mp.weixin.qq.com/s/Ho3uJm4pMEdpoA1HzAjorQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-28T10:21:47</pubDate></item><item><title>逻辑漏洞 | “邀请功能”：一个被严重低估的攻击面”</title><link>https://mp.weixin.qq.com/s/y8MQUtJBq7RgCJqC-9OWlQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-25T14:07:20</pubDate></item><item><title>无需点击，一张图片就能“偷”走你的GitLab账号！</title><link>https://mp.weixin.qq.com/s/Szd4gTmSmvrKHRFm7cjOAQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-23T16:31:07</pubDate></item><item><title>紧急预警！你的电脑版微信，可能已被“监控”！一键自查，立刻修复！</title><link>https://mp.weixin.qq.com/s/m6mDwzi9EZa5hwH0By27gA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-22T17:25:04</pubDate></item><item><title>就改了一个参数，喜提$3000</title><link>https://mp.weixin.qq.com/s/1aZ4duiXuN-ISMJkWQuXaw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-22T09:58:46</pubDate></item><item><title>他是如何靠“复制粘贴”拿到自己第一个$150漏洞赏金的</title><link>https://mp.weixin.qq.com/s/cWeC3DeuY01UII1yA--3_w</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-21T17:12:06</pubDate></item><item><title>只需一个请求，就能搞垮整个论坛？</title><link>https://mp.weixin.qq.com/s/x_wG14MIgvdh3q53zQEUcQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-17T09:15:35</pubDate></item><item><title>一个被判“重复”的CSRF漏洞，如何最终斩获赏金？</title><link>https://mp.weixin.qq.com/s/r-4PTvzi16LsgVdRMMPDZw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-16T10:30:09</pubDate></item><item><title>就因API没做权限校验，他把别人的任务列表给删了，还赚了$5000</title><link>https://mp.weixin.qq.com/s/ojRMbyS4JPp1M7OF5g01oQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-15T15:14:20</pubDate></item><item><title>最近刷屏的“微信XSS漏洞”原理是什么？</title><link>https://mp.weixin.qq.com/s/4pGiN3CDk3B_9D6A9NxBRQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-14T15:16:45</pubDate></item><item><title>价值$1,000的XSS</title><link>https://mp.weixin.qq.com/s/DPPh1shn-mioaTDuw9Gg3g</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-14T09:12:55</pubDate></item><item><title>$3000 on TikTok Bug Bounty</title><link>https://mp.weixin.qq.com/s/zx4uLJXRovhE8iUOZjeATg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-13T06:24:21</pubDate></item><item><title>逻辑漏洞之皇帝的新衣</title><link>https://mp.weixin.qq.com/s/aF31HMPJDjh83KHeUq4PAw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-11T08:58:39</pubDate></item><item><title>WhatsApp登录绕过</title><link>https://mp.weixin.qq.com/s/edC0DNvhl_tgopnm_F-xkw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-10T14:47:46</pubDate></item><item><title>【真·生产力工具】白嫖一年 JetBrains 全家桶</title><link>https://mp.weixin.qq.com/s/zCzEK27V0aR315EeVJxKXw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-07-01T14:25:19</pubDate></item><item><title>深度揭秘：你点的“我不是机器人”，可能正在喂养一个庞大的黑暗广告科技帝国！</title><link>https://mp.weixin.qq.com/s/5FTbEsvQGfuLC1cb-GqpTg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-06-14T17:06:18</pubDate></item><item><title>如何通过BAC绕过邀请流程，并获得管理员权限的</title><link>https://mp.weixin.qq.com/s/Wz_eeH3aJ30WeU_6rX7J3w</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-06-03T11:22:17</pubDate></item><item><title>Bypass 2FA，最终斩获6000美金</title><link>https://mp.weixin.qq.com/s/ZNwuMCMYV5P6lveKq6hBbw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-06-02T13:49:57</pubDate></item><item><title>价值12000美元 的GitLab 中的 Git flag注入漏洞</title><link>https://mp.weixin.qq.com/s/2MTJ_SWaq87TGUnNfVisQw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-06-01T14:46:32</pubDate></item><item><title>价值€3500 的 SQL 注入</title><link>https://mp.weixin.qq.com/s/W9IVIC1Eo7M5vVVfY6iduw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-05-31T15:15:30</pubDate></item><item><title>预接管漏洞挖掘：条件竞争与逻辑缺陷的组合利用</title><link>https://mp.weixin.qq.com/s/-rnHsNXY36pfAev4HXqKZA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-05-30T16:56:55</pubDate></item><item><title>如何通过一个SSRF漏洞挖出百万用户数据</title><link>https://mp.weixin.qq.com/s/jWahktKF3kF_JA-gD-l_eQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-05-29T15:39:32</pubDate></item><item><title>如何通过XSS接管 Microsoft 账户</title><link>https://mp.weixin.qq.com/s/mmVn_yi7EXGgulhc39Qc3A</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-05-09T20:39:31</pubDate></item><item><title>一封“Google官方邮件”背后的真相：你可能也收到过！</title><link>https://mp.weixin.qq.com/s/4voFdD8gpcKJrkSgsH2FUA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-04-22T09:18:22</pubDate></item><item><title>如何发现AI chatbot 中的RCE</title><link>https://mp.weixin.qq.com/s/0NCEV7dB8bJUrTn-deZo8g</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-04-14T22:59:25</pubDate></item><item><title>价值 $25,000 的hackerone 漏洞</title><link>https://mp.weixin.qq.com/s/B6ChUvw3CWJd6RNZ2s4IWQ</link><description>“一次升级，引发一场严重的数据泄露；一位研究者，在漏洞公开90分钟内精准捕捉异常，换来$25,000赏金。”</description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-04-13T18:57:08</pubDate></item><item><title>价值2500$ 的 缓存投毒与 XSS  联动</title><link>https://mp.weixin.qq.com/s/EtWMB-rvwltwSLlZo1M2fg</link><description>漏洞详情话不多说，我们直接深入了解这个漏洞。我受邀参加了HackerOne上的一个私人项目，这里我们暂且称其为company.com。</description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-04-01T11:32:04</pubDate></item><item><title>单个Web应用程序的4500美元漏洞赏金（API Hacking）</title><link>https://mp.weixin.qq.com/s/Waa2zZCwisImD-5isjA1Tw</link><description>引言嗨，又是我。在这篇文章中，我将讲述两个月前我在一个Web应用程序上发现的四个漏洞（一个严重漏洞和三个中等严重程度的漏洞）。</description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-03-30T09:37:40</pubDate></item><item><title>2500 美元漏洞赏金：破解 GraphQL</title><link>https://mp.weixin.qq.com/s/dXFRqCqY5iUq4orX7JE8Yw</link><description>在这篇文章中，我将分享自己在 GraphQL API 应用中发现多个漏洞的学习过程和经验。</description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-03-29T21:40:13</pubDate></item><item><title>$3362 ——远程代码执行漏洞</title><link>https://mp.weixin.qq.com/s/P3VBLnAXaeOQ7rmnPYfPhg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-27T12:08:01</pubDate></item><item><title>$1020  IDOR漏洞</title><link>https://mp.weixin.qq.com/s/pecvwFb4tv4JBu8EN2c9zg</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-25T13:23:25</pubDate></item><item><title>WhatsApp  bugbunty 1000$</title><link>https://mp.weixin.qq.com/s/oLJ_CNL_U_RpHyNl1YYV3Q</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-19T12:04:52</pubDate></item><item><title>轻而易举的两个赏金漏洞 $200</title><link>https://mp.weixin.qq.com/s/OmwbtG81XJfTD9oYJYiFng</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-18T13:32:44</pubDate></item><item><title>Applexa0漏洞bugbuntyxa0 $ 15K</title><link>https://mp.weixin.qq.com/s/mwVbwfN4WCg_rDnV4yNUEA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-17T13:43:57</pubDate></item><item><title>Paypal漏洞 $10K</title><link>https://mp.weixin.qq.com/s/2jGwjJtR8ztKYzx3VnD5Gw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-15T12:33:02</pubDate></item><item><title>价值1000$的SQL注入漏洞</title><link>https://mp.weixin.qq.com/s/9Wq-X3BDMI8QIvk0DdM7zA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-13T14:42:33</pubDate></item><item><title>$100 轻松赏金 p4 漏洞 :)</title><link>https://mp.weixin.qq.com/s/rrohcGeedo_smjoANEzpyQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-02T16:50:33</pubDate></item><item><title>API中不当的访问控制导致订单篡改漏洞，获得$3,900赏金</title><link>https://mp.weixin.qq.com/s/IStvrCwnoGAzQguSSnonPw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-02-01T10:29:45</pubDate></item><item><title>绕过HackerOne的2FA要求及报告者黑名单漏洞</title><link>https://mp.weixin.qq.com/s/LPb1F0gTM__Hl_x9zFNMnA</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-01-31T16:42:23</pubDate></item><item><title>如何发现图片中的EXIF元数据泄漏</title><link>https://mp.weixin.qq.com/s/iTZSfUznu734UTPUrr6Dmw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-01-30T12:05:57</pubDate></item><item><title>简单的GraphQL SSRF漏洞赚取了3,000美元</title><link>https://mp.weixin.qq.com/s/NfQ5sPG-vsB7nx-JkgwgLw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-01-27T14:29:42</pubDate></item><item><title>通过 PNG 和奇怪的内容类型在 Facebook 上实现 XSS</title><link>https://mp.weixin.qq.com/s/CHKacNf20I1p3a-k0iLnSQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-01-03T10:31:12</pubDate></item><item><title>Uber平台的漏洞连环攻防战</title><link>https://mp.weixin.qq.com/s/Mx3Zu2j1EefsiKzumeEdRw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2025-01-01T22:39:28</pubDate></item><item><title>如何用一个漏洞删除Google Gallery的数据</title><link>https://mp.weixin.qq.com/s/EnJX8u4T4OCkcXfE5pFWaw</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2024-12-31T19:24:07</pubDate></item><item><title>如何通过跨站脚本攻击（XSS）发现账号接管（ATO）漏洞</title><link>https://mp.weixin.qq.com/s/ADj6s2HQ33UK98EtlcNrzQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2024-12-30T19:56:55</pubDate></item><item><title>发现谷歌的 IDOR 漏洞，并获得了3133.70 美元赏金</title><link>https://mp.weixin.qq.com/s/oyNh9uKj6taDDjTxndeN-A</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2024-12-29T17:34:38</pubDate></item><item><title>如何在漏洞赏金计划中发现关键漏洞并赚取$4,000</title><link>https://mp.weixin.qq.com/s/wn55fcSfqkjtuRFTYPzfzQ</link><description></description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2024-12-28T06:06:27</pubDate></item><item><title>价值1200$的访问控制失效漏洞</title><link>https://mp.weixin.qq.com/s/zwHFEtRPcOTkwg_rk3Sb8A</link><description>安全声明：本公众号文章中涉及的技术（漏洞）仅用于安全研究与教学，若读者将其作他用，将由读者承担全部法律及连带责</description><author>漏洞集萃</author><category>漏洞集萃</category><pubDate>2024-08-24T16:34:30</pubDate></item></channel></rss>