<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkyMzI3MTI5Mg.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Wed, 04 Feb 2026 17:58:47 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>DJI SRC 新春活动上线（漏洞x情报）奖励值 UP！</title><link>https://mp.weixin.qq.com/s/QHLy5xEAOsmWLHKbRy-MJA</link><description>🎊 骏马迎春 安驭未来 DSRC 活动已上线！！</description><author>安全白白</author><category>安全白白</category><pubDate>2026-02-04T14:27:24</pubDate></item><item><title>Monsta FTP CVE-2025-34299 RCE 浅析</title><link>https://mp.weixin.qq.com/s/28gaTuhQkVq09eFfEswPyQ</link><description>Monsta FTP CVE-2025-34299 RCE 浅析</description><author>安全白白</author><category>安全白白</category><pubDate>2026-01-06T08:01:35</pubDate></item><item><title>致远oa-xrdController.do后台-文件复制漏洞分析</title><link>https://mp.weixin.qq.com/s/1nQWYHqIoqXGR-wjEc8awg</link><description>致远 OA 漏洞分析</description><author>安全白白</author><category>安全白白</category><pubDate>2026-01-05T07:00:18</pubDate></item><item><title>致远 OA 漏洞分析</title><link>https://mp.weixin.qq.com/s/JMHj33znP2dKlSpMjzgATQ</link><description>某远 OA 漏洞分析</description><author>安全白白</author><category>安全白白</category><pubDate>2025-12-31T15:22:13</pubDate></item><item><title>基于伪装Chrome浏览器升级的水坑攻击设计与实现</title><link>https://mp.weixin.qq.com/s/bBrGqNLQeylgb18gQPIjEw</link><description>在设计整个水坑的过程中思考了其中几个问题。后续也陆陆续续解决了。以下将通过鱼钩、诱饵、收杆逐步进行讲解。知己知彼，百战百胜。</description><author>安全白白</author><category>安全白白</category><pubDate>2025-12-29T14:33:23</pubDate></item><item><title>Java RCE场景下的RevShell技术全解析</title><link>https://mp.weixin.qq.com/s/PqQRaPlm5R9Hc58bbrccZw</link><description>一直研究 java RCE，证明的方法总是执行xa0calcxa0在本地机器上弹出计算器，就缺乏了对于各种 RCE 漏洞利用的研究，写篇文章记录一下 java 各种反弹 shell 的操作。</description><author>安全白白</author><category>安全白白</category><pubDate>2025-12-23T11:07:12</pubDate></item><item><title>JeecgBoot漏洞利用的Tips</title><link>https://mp.weixin.qq.com/s/er7kZvvZnXuIhqXCMqG21w</link><description>关于JeecgBoot漏洞利用的Tips</description><author>安全白白</author><category>安全白白</category><pubDate>2025-10-24T10:59:53</pubDate></item><item><title>金和OA JC6 JDBC远程代码执行</title><link>https://mp.weixin.qq.com/s/u_26Cq2O1FO_cArLXLdIqA</link><description>金和OA JC6 JDBC远程代码执行</description><author>安全白白</author><category>安全白白</category><pubDate>2025-10-23T16:32:12</pubDate></item><item><title>分享图片</title><link>https://mp.weixin.qq.com/s/433bD238qPkCT8YBv2-a7g</link><description>[衰]</description><author>安全白白</author><category>安全白白</category><pubDate>2025-09-22T18:30:08</pubDate></item><item><title>RemoteWebScreen红队实战屏幕监控利器</title><link>https://mp.weixin.qq.com/s/tj4aVCedNdf5Bg20JPuKow</link><description>本项目是一个远程控制应用，使用 Golang 开发，允许用户通过 Web 界面远程控制和屏幕监控其他计算机。主要功能包括屏幕共享、鼠标和键盘控制以及键盘记录。</description><author>安全白白</author><category>安全白白</category><pubDate>2025-08-07T16:19:36</pubDate></item><item><title>Easysite反序列化漏洞分析</title><link>https://mp.weixin.qq.com/s/qSpvW38XDBWjIkUsEN1j5g</link><description>Easysite反序列化漏洞分析</description><author>安全白白</author><category>安全白白</category><pubDate>2025-08-02T08:00:34</pubDate></item><item><title>中科汇联Easysite反序列化漏洞</title><link>https://mp.weixin.qq.com/s/u6H5hio-5U7JTENsF4DT8A</link><description>中科汇联Easysite反序列化漏洞简单分析</description><author>安全白白</author><category>安全白白</category><pubDate>2025-07-20T17:25:26</pubDate></item><item><title>契约锁电子签章系统RCE简单分析</title><link>https://mp.weixin.qq.com/s/mRu0RCM4hDx0EwEWwwyLcQ</link><description>契约锁电子签章系统RCE简单分析</description><author>安全白白</author><category>安全白白</category><pubDate>2025-06-11T18:53:48</pubDate></item><item><title>某企业终端防病毒系统简单分析</title><link>https://mp.weixin.qq.com/s/BJr3UG_-stsWuqGcTAUVIw</link><description>某企业终端防病毒系统简单分析</description><author>安全白白</author><category>安全白白</category><pubDate>2025-06-06T14:51:27</pubDate></item><item><title>攻防随手记之阿里云防护微对抗</title><link>https://mp.weixin.qq.com/s/ksYl33ibmPtTd1T7sa9w2Q</link><description>攻防随手记之阿里云防护微对抗</description><author>安全白白</author><category>安全白白</category><pubDate>2025-05-26T11:23:59</pubDate></item><item><title>某电子签章安全补丁绕过</title><link>https://mp.weixin.qq.com/s/Y0voLm2WyhT9WX9fGK1YoA</link><description></description><author>安全白白</author><category>安全白白</category><pubDate>2025-02-27T15:14:37</pubDate></item><item><title>某Github开源物联网系统RCE</title><link>https://mp.weixin.qq.com/s/-vpdsRoAbNbQ1NUN1epWoA</link><description>Github开源系统远程代码执行漏洞</description><author>安全白白</author><category>安全白白</category><pubDate>2024-12-26T13:50:01</pubDate></item><item><title>浅析异常线程检测逻辑（unbacked）</title><link>https://mp.weixin.qq.com/s/ZvfV3M4jH-B_nYgKKLjZ7w</link><description>浅析异常线程检测</description><author>安全白白</author><category>安全白白</category><pubDate>2024-12-10T14:38:59</pubDate></item><item><title>某友反序列化漏洞黑名单绕过浅析</title><link>https://mp.weixin.qq.com/s/X13act3My24CQ5rzv-VPAg</link><description>某友NC、NCCloud反序列化漏洞黑名单绕过浅析</description><author>安全白白</author><category>安全白白</category><pubDate>2024-10-11T18:13:09</pubDate></item><item><title>实战攻防中高版本JDK反射类加载浅析</title><link>https://mp.weixin.qq.com/s/es3vXQLCs2--7KzOM4z6FQ</link><description>实战攻防中高版本JDK反射类加载浅析</description><author>安全白白</author><category>安全白白</category><pubDate>2024-07-16T09:35:31</pubDate></item><item><title>红队实战屏幕监控利器RemoteWebScreen</title><link>https://mp.weixin.qq.com/s/WszffAdsWPLADCgBi8RFJw</link><description>本项目是一个远程控制应用，使用 Golang 开发，允许用户通过 Web 界面远程控制和屏幕监控其他计算机。主要功能包括屏幕共享、鼠标和键盘控制以及键盘记录。</description><author>安全白白</author><category>安全白白</category><pubDate>2024-06-24T18:56:41</pubDate></item><item><title>分享的图片、视频、链接</title><link>https://mp.weixin.qq.com/s/eis-zR5JdiUmnocAdPlFOg</link><description></description><author>安全白白</author><category>安全白白</category><pubDate>2024-06-11T12:27:55</pubDate></item><item><title>与众不同的Netty回显链挖掘</title><link>https://mp.weixin.qq.com/s/Uhxz0LyHvphcTn1DKfcOYQ</link><description>与众不同的Netty回显链挖掘</description><author>安全白白</author><category>安全白白</category><pubDate>2024-05-30T19:27:59</pubDate></item><item><title>IP网络对讲广播系统审计</title><link>https://mp.weixin.qq.com/s/eIMLQdm7SPu8Dz_9exLHvQ</link><description>IP网络对讲广播系统审计</description><author>安全白白</author><category>安全白白</category><pubDate>2024-04-02T18:30:57</pubDate></item><item><title>某HR系统组合漏洞挖掘过程</title><link>https://mp.weixin.qq.com/s/Y0k_4yRFNXuSsmXyn10gGQ</link><description>某HR系统组合漏洞挖掘过程</description><author>安全白白</author><category>安全白白</category><pubDate>2024-03-12T18:24:07</pubDate></item><item><title>红队信息收集&amp;移动安全从0-1</title><link>https://mp.weixin.qq.com/s/BGQ_IXBZSDNriWxzG7ihGQ</link><description>红队信息收集\\x26amp;移动安全从0-1</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-21T22:15:47</pubDate></item><item><title>移动安全之少壮不努力老大搞APP</title><link>https://mp.weixin.qq.com/s/4Ms8zyWt6UBBfnaGQluGtg</link><description>一次大起大落落落落落的红队评估移动端打工流程</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-17T12:31:32</pubDate></item><item><title>Commons Collections7利用链调试</title><link>https://mp.weixin.qq.com/s/ggE-Hx7h4Nehnb9itUO7TA</link><description>Commons Collections7利用链调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-09T08:35:42</pubDate></item><item><title>hellsgate浅析</title><link>https://mp.weixin.qq.com/s/233kWU2fHAw9wYG-34sM0A</link><description>0x00 前言几个月前，知道了hellsgate，然后看了那篇论文https://vxug.fakedoma</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-08T08:30:13</pubDate></item><item><title>Common Collection6利用链调试分析</title><link>https://mp.weixin.qq.com/s/NX2B2vBaov41AhTctG6ikQ</link><description>Common Collection6利用链调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-07T00:00:00</pubDate></item><item><title>Commons Collections5调试分析</title><link>https://mp.weixin.qq.com/s/khsO86A2_bII1XGGZ_q_lg</link><description>Commons Collections5调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-06T11:01:46</pubDate></item><item><title>Commons Collections4利用链调试分析</title><link>https://mp.weixin.qq.com/s/S5mpqVAh1VCsU4HuGw_1-g</link><description>Commons Collections4利用链调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-05T13:57:04</pubDate></item><item><title>从未授权反序列化RCE到代码审计</title><link>https://mp.weixin.qq.com/s/w9blG6WiMBRB3PfjpS5wHw</link><description>从未授权反序列化RCE到代码审计</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-04T00:01:14</pubDate></item><item><title>Commons Collections3 利用链调试分析</title><link>https://mp.weixin.qq.com/s/Mx_-C3cfBMupqkL-eOOGRw</link><description>Commons Collections3调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-03T18:05:19</pubDate></item><item><title>Commons Collections2利用链分析</title><link>https://mp.weixin.qq.com/s/iPM659FfCy-hXTzxXYs08g</link><description>Commons Collections2利用链调试分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-04-02T13:28:12</pubDate></item><item><title>Commons Collections1利用分析(二)</title><link>https://mp.weixin.qq.com/s/UZ2CgyelM7maDRPvSbkphA</link><description>Commons Collections1 利用分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-03-17T16:53:17</pubDate></item><item><title>Commons Collections1利用链分析(一)</title><link>https://mp.weixin.qq.com/s/t0sEnHji7-TLiEyn_d8GsQ</link><description>ApacheCommons Collections反序列化漏洞利用链的分析学习</description><author>安全白白</author><category>安全白白</category><pubDate>2022-03-04T00:00:15</pubDate></item><item><title>从0到1学会反射型DLL注入</title><link>https://mp.weixin.qq.com/s/YtETwM8t3_g9JS2HZT0RHg</link><description>前言：普通的DLL注入就是利用CreateRemoteProcess和LoadLibraryA进行注入，而反</description><author>安全白白</author><category>安全白白</category><pubDate>2022-03-03T00:00:00</pubDate></item><item><title>Windows Server 2016 部署AD RMS</title><link>https://mp.weixin.qq.com/s/P_Z2DR8IeDEoyou8dF8BSQ</link><description>AD RMS服务（ Active Directory 权限管理服务部署</description><author>安全白白</author><category>安全白白</category><pubDate>2022-03-02T16:12:58</pubDate></item><item><title>Exchange Server 2016 安装部署</title><link>https://mp.weixin.qq.com/s/3p-zfkWriJ8LN0Cxu9I2hw</link><description>Exchange 安装部署</description><author>安全白白</author><category>安全白白</category><pubDate>2022-02-28T17:53:38</pubDate></item><item><title>Apache Shiro-550反序列化分析</title><link>https://mp.weixin.qq.com/s/m-ieQM9tLAT_VHuJ6fav9Q</link><description>Apache Shiro-550反序列化分析</description><author>安全白白</author><category>安全白白</category><pubDate>2022-02-24T11:50:51</pubDate></item><item><title>MacOS多个JAVA版本切换使用</title><link>https://mp.weixin.qq.com/s/iG8WedC9HjgGwDaSgBIvGw</link><description>Mac安装多个Java版本</description><author>安全白白</author><category>安全白白</category><pubDate>2021-11-06T22:34:23</pubDate></item><item><title>【免杀】Go远程加载图片上线CS</title><link>https://mp.weixin.qq.com/s/Geni8ANsxfQ3smz2PH6dtQ</link><description>GO免杀利用远程加载图片上线CS</description><author>安全白白</author><category>安全白白</category><pubDate>2021-10-01T13:37:30</pubDate></item><item><title>内网渗透之OXID</title><link>https://mp.weixin.qq.com/s/Ey7yaybWssxS3BEkTBKSDQ</link><description>内网渗透横向Scan之OXID</description><author>安全白白</author><category>安全白白</category><pubDate>2021-08-19T00:00:00</pubDate></item><item><title>利用CDN技术隐藏真实C2</title><link>https://mp.weixin.qq.com/s/_fjZ8deIO7HJuNCue5NNjA</link><description>通过CDN技术隐藏真实攻击IP，防止溯源。</description><author>安全白白</author><category>安全白白</category><pubDate>2021-08-18T14:24:02</pubDate></item></channel></rss>