<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkyMjY1NjI2MQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 06 Nov 2025 14:24:03 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>Nacos最新检测工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247484022&amp;idx=1&amp;sn=bd3c9637e3e6547bd9b4c905db7ec2a5</link><description>Nacos最近检测工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-11-06T09:02:49</pubDate></item><item><title>Struts2最新检测工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247484010&amp;idx=1&amp;sn=337722b29f414b469da8013ad92f8565</link><description>Struts2最近检测工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-11-04T16:12:08</pubDate></item><item><title>Webshell木马免杀工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247484007&amp;idx=1&amp;sn=4ce9a5aad08b73b041dddbc56be61e34</link><description>Struts2最近检测工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-11-04T16:06:58</pubDate></item><item><title>Webshell木马免杀工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247484001&amp;idx=1&amp;sn=b0f1609938ca1be2aa5f437b30ff1bae</link><description>Webshell木马免杀、流量加密传输工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-04-21T23:40:58</pubDate></item><item><title>大模型本地部署的“隐形炸弹”，你的数据安全吗？</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483990&amp;idx=1&amp;sn=baff53485adec1f42bf6b343740b5c28</link><description>随着DeepSeek R1等开源大模型的火爆，越来越多的开发者、企业甚至开始尝试在本地部署大语言模型，享受AI带来的便利。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-03-07T14:28:30</pubDate></item><item><title>一手体验首款通用Agent产品Manus - 唯有惊叹。</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483990&amp;idx=2&amp;sn=0ae7808b9ab17f5c54a0071c6734234e</link><description>今夜的星空属于China。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-03-07T14:28:30</pubDate></item><item><title>若依（RuoYi）漏洞利用工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483988&amp;idx=1&amp;sn=cd3ab7f8d1fbde6901eb1e9a56a11464</link><description>ruuoyi_vulnscan漏洞利用工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-03-06T17:26:22</pubDate></item><item><title>deepseek API key无法使用替代方法</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483981&amp;idx=1&amp;sn=bafdde4fc029fb2e57d173cb4d947cf6</link><description>deepseek API key无法使用替代方法</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-02-15T16:12:16</pubDate></item><item><title>jeecgBoot漏洞利用工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483972&amp;idx=1&amp;sn=95cc21cf1d38bb9e9b6468de8580c3cc</link><description>jeecgBoot漏洞利用工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-02-15T01:11:49</pubDate></item><item><title>帆软Channel反序列化工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483962&amp;idx=1&amp;sn=d7533f1eec2a3ff0bb157c3b764bd2c6</link><description>帆软Channel反序列化工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2025-02-05T10:55:01</pubDate></item><item><title>Spring框架工具（SBscan）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483955&amp;idx=1&amp;sn=1ec92e974cf3e225397187eac8c405d2</link><description>Spring框架工具（SBscan）</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-11-05T10:28:21</pubDate></item><item><title>弱口令爆破工具（week-password）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483955&amp;idx=2&amp;sn=214715e6f7eb3e868391efa9edb71545</link><description>FTP,SSH,MYSQL,MSSQL等弱口令爆破工具！</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-11-05T10:28:21</pubDate></item><item><title>利用procdump读取ToDesk连接信息</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483947&amp;idx=1&amp;sn=6555ed0b0c4abc8f241945d6898e4c24</link><description>利用procdump读取ToDesk连接信息</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-10-21T10:22:12</pubDate></item><item><title>Java代码安全扫描工具 -- chanzi</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483931&amp;idx=1&amp;sn=330841443399e903752ae92218662d65</link><description>JAVA代码审计工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-10-11T10:15:34</pubDate></item><item><title>hvv漏洞poc</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483925&amp;idx=1&amp;sn=168ee6eef1a1a555ce9bf531692cf5fa</link><description>hvv常用漏洞poc整理</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-08-27T11:28:54</pubDate></item><item><title>内网敏感信息收集工具——searchall</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483925&amp;idx=2&amp;sn=4be974baa64585a9b845eca0a13341bb</link><description>searchall3.5可以快速搜索服务器中的有关username，passsword,账号，口令的敏感信息还有浏览器的账户密码。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-08-27T11:28:54</pubDate></item><item><title>[HVV情报] 第四弹</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483911&amp;idx=1&amp;sn=4c17747a8fcbf9f2c218a99f67b451c3</link><description>2024hw情报</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-08-08T12:34:07</pubDate></item><item><title>亿赛通NoticeConfigAjax接口存在SQL注入漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483911&amp;idx=3&amp;sn=4f8841f93b4cab8ee66fd1b9c8ee066c</link><description>亿赛通NoticeAjax接口存在任意文件上传漏洞，攻击者通过漏洞可以上传任意文件到服务器中，获取主机权限。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-08-08T12:34:07</pubDate></item><item><title>亿赛通NoticeAjax接口存在SQL注入漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483911&amp;idx=4&amp;sn=cff57f49bdac2d4d79d3a1070bd887a1</link><description>亿赛通NoticeAjax接口存在任意文件上传漏洞，攻击者通过漏洞可以上传任意文件到服务器中，获取主机权限。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-08-08T12:34:07</pubDate></item><item><title>[HVV情报] 第三弹</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483899&amp;idx=1&amp;sn=923fc9d7e2fccf23c07a81b614cf31af</link><description>2024hw情报</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-26T20:55:56</pubDate></item><item><title>[HVV情报] 第二弹</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483892&amp;idx=1&amp;sn=8ccb10e04ff6833f48385bcb7db38ca2</link><description>2024hw情报</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-25T20:54:06</pubDate></item><item><title>用友NC系统querygoodsgridbycode接口sql注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483881&amp;idx=1&amp;sn=c9fac069c615187c8f33fd7174da63e6</link><description>由于code参数由于输入验证不严格，存在注入漏洞。利用该漏洞执行任意SQL语句，如查询数据、下载数据、写入webshell、执行系统命令以及绕过登录限制等。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-23T19:28:41</pubDate></item><item><title>ServiceNowUI Jelly模板注入漏洞(CVE-2024-4879)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483861&amp;idx=1&amp;sn=7b09c06d150200c8e0d9e251d4feb820</link><description>Bricks Builder是一款用于WordPress的开发主题，提供直观的拖放界面，用于设计和构建WordPress网站。WordPress配置安装的Brick Builder主题在低于\\x26lt;= 1.9.6版本中存在远程代码执行漏洞。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-18T10:03:14</pubDate></item><item><title>（0day）Nacos RCE复现及分析</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483853&amp;idx=1&amp;sn=c8eb21ad40c337e4b37a71020e1bab4d</link><description>nacos rce复现及分析</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-16T10:44:06</pubDate></item><item><title>通达OA最新工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483853&amp;idx=2&amp;sn=e28241902feb64ebe83e2aad91f527af</link><description>通达OA42个漏洞利用工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-16T10:44:06</pubDate></item><item><title>NACOS RCE 0day细节</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483833&amp;idx=1&amp;sn=ac365c584fd3e3c074e3efd738c631c0</link><description>海康威视漏洞利用工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-07-15T20:57:46</pubDate></item><item><title>Burp 指纹识别插件</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483828&amp;idx=1&amp;sn=cbe5f89d4639fcf55ad48f310f7488c6</link><description>Burp 指纹识别插件</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-06-28T11:26:11</pubDate></item><item><title>【红队武器库|漏洞利用工具】2024HVV准备均收集来源于Github（包含海康威视、大华等等一把梭）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483828&amp;idx=2&amp;sn=f0bc294e8505476ebc757d32cce85bc2</link><description>免责声明❝「此公众号所分享的网络安全知识、信息及工具皆来源互联网公开收集整理，仅供学习和研究使用，请勿用于非</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-06-28T11:26:11</pubDate></item><item><title>免费送服务器 预装Kali渗透测试工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483812&amp;idx=1&amp;sn=b602711dc86955f2c3a7442a337ca100</link><description>点击上方蓝字 关注【渗透测试】不迷路0x00 免费送服务器访问网址：https://shell.segf</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-06-17T16:48:17</pubDate></item><item><title>海康威视扫描工具--Rookie</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483810&amp;idx=1&amp;sn=94495ff948778d8c1dc2dc5d6d9300e0</link><description>海康威视漏洞利用工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-05-22T13:11:23</pubDate></item><item><title>DecryptTools-综合解密</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483803&amp;idx=1&amp;sn=a8940327508b8afd1fc34e8e4187905e</link><description>拿下靶标不仅需要获取服务器权限还需要登录网站后台这时候很多系统要么数据库连接字符串加密，要么登陆用户加密而这款工具就是为了解决问题</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-04-30T10:47:44</pubDate></item><item><title>GO语言免杀工具-GoBypassAV</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483794&amp;idx=1&amp;sn=aacf2160ffaae632016e559928b24baa</link><description>GoBypassAV是一款用Go语言编写的免杀工具，支持自动化随机加解密，使用方便，简单易上手。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-04-16T17:01:30</pubDate></item><item><title>密探渗透工具测试版</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483787&amp;idx=1&amp;sn=c13585a734a93b248e4ae35384348bb9</link><description>域名信息查询，IP端口查询，备案信息查询，搜索引擎语法自动生成（FOFA,Hunter,google,github），文件扫描（包含目录，备份文件，spring信息泄漏，自定义字典等）、渗透技能路线备忘录，常用网络安全网站导航等功能。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-04-07T16:32:31</pubDate></item><item><title>【漏扫更新三连】Nessus、AWVS 、Invicti（Netsparker）最新版Crack（附下载）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483772&amp;idx=1&amp;sn=f6d74cfb431eeea420f4b2f65af6cb4d</link><description>点击上方蓝字关注我们免责声明❝本公众号所发布的文章及工具只限交流学习，本公众号不承担任何责任！如有侵权，请告</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-04-01T15:43:17</pubDate></item><item><title>一款集成化的Web渗透测试工具 DudeSuite</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483770&amp;idx=1&amp;sn=8d80bcb845fb9cb8b2a65f4cd0f4f32c</link><description>对于刚入门网络安全的小伙伴而言。前期要掌握很多的基础知识，如Linux相关的命令和各种web工具的使用。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-27T22:40:13</pubDate></item><item><title>网安干货 | Cuckoo沙箱安装及使用</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483768&amp;idx=1&amp;sn=6dac5116d920f454b6e3e79e4870099b</link><description>分享一篇文章。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-24T03:25:59</pubDate></item><item><title>用友系列全漏洞检测工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483766&amp;idx=1&amp;sn=840a12bf82335743a1f624334cbaa623</link><description>用友系列全漏洞检查工具plus版</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-21T19:49:11</pubDate></item><item><title>记一次智慧停车场管理系统的绕过登录通杀</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483759&amp;idx=1&amp;sn=81ad991d5ca63c7a323008f94742e08d</link><description>一次智慧停车场的登录绕过通杀</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-18T16:22:31</pubDate></item><item><title>一款好用的社工字典生成工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483748&amp;idx=1&amp;sn=464b6f4d500c351718c077d2b6b164e3</link><description>针对指定用户名、公司名等生成社工字典</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-13T15:41:24</pubDate></item><item><title>《2024年网络与信息安全行业全景图》正式发布</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483743&amp;idx=1&amp;sn=9d73c9ffed58a58e9b5d00f47ebe4a7a</link><description>前言点击下方 \\x26quot;深圳市网络与信息安全行业协会\\x26quot;公众号关注, 设为星标。后台回复：2024全景图，即可下载高清</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-12T20:08:27</pubDate></item><item><title>一款好用的Thinkphp漏洞利用工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483741&amp;idx=1&amp;sn=23001fc66dac706df300048b74794ea1</link><description>针对Thinkphp2.x-6.x版本的Thinkphp图形化工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-11T20:33:02</pubDate></item><item><title>Shiro反序列化复杂请求利用工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483732&amp;idx=1&amp;sn=d028f5a2b58d96ef5a0e25644d65d091</link><description>复杂请求下Shiro利用</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-07T19:47:45</pubDate></item><item><title>webshell免杀工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483727&amp;idx=1&amp;sn=f32324f11a75b5f4187fbd47de60e6e5</link><description>各种语言免杀马生成</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-06T11:00:21</pubDate></item><item><title>常用漏洞集合工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483722&amp;idx=1&amp;sn=edfcd872113cbfe7796748e6c6309950</link><description>常用java漏洞利用工具，其中包含Struts2、Fastjson、Weblogic（xml）、Shiro、Log4j、Jboss、SpringCloud</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-05T15:27:52</pubDate></item><item><title>社工字典生成</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483716&amp;idx=1&amp;sn=81dfe7b204c5c6ac90343b30188c7280</link><description>社工字典生成图形化工具</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-04T16:03:25</pubDate></item><item><title>若依定时任务-哥斯拉</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483710&amp;idx=1&amp;sn=fe64400d6458e4a9a54f7f7f55bc4079</link><description>ruoyi 后台定时任务注入哥斯拉内存马</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-03-01T22:11:47</pubDate></item><item><title>Nacos图形化工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483697&amp;idx=1&amp;sn=346b2ffaa16f3adfe389775f6256a2a5</link><description>Nacos漏洞综合利用GUI工具，集成了默认口令漏洞、SQL注入漏洞、身份认证绕过漏洞、反序列化漏洞的检测及其利用。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-02-29T16:34:57</pubDate></item><item><title>WordPres RCE(CVE-2024-25600)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483688&amp;idx=1&amp;sn=211faf3739838a4c0b894dc1fe3c3095</link><description>Bricks Builder是一款用于WordPress的开发主题，提供直观的拖放界面，用于设计和构建WordPress网站。WordPress配置安装的Brick Builder主题在低于\\x26lt;= 1.9.6版本中存在远程代码执行漏洞。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-02-28T21:16:24</pubDate></item><item><title>用友畅捷通T+任意文件上传getshell遇到的坑</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483680&amp;idx=1&amp;sn=e806c9f7a6e4136462a6b0e8af83a090</link><description>复现时遇到的最大的一个坑，翻了很多公众号也没找到原因，最后就因为这么一个点。。。。。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-02-27T16:10:39</pubDate></item><item><title>confluence远程代码执行（CVE-2023-22527）内存马注入工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjY1NjI2MQ==&amp;mid=2247483680&amp;idx=2&amp;sn=183e9a87081be8379ddb14c065d9f0f2</link><description>confluence（CVE-2023-22527）漏洞利用工具，支持冰蝎/哥斯拉内存马注入，支持设置 http 代理。</description><author>CH1N安全</author><category>CH1N安全</category><pubDate>2024-02-27T16:10:39</pubDate></item></channel></rss>