<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkyNjY3OTI4Ng.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 26 Feb 2026 18:03:30 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>【Windows逆向】Electron程序重打包启用控制台+ob混淆分析+绕过调试检测</title><link>https://mp.weixin.qq.com/s/SoqYOufJmMqZKVc4z6GpRQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-02-26T14:11:09</pubDate></item><item><title>【转载】AI-IDE技能管理系统实战</title><link>https://mp.weixin.qq.com/s/bO1G6MX5vTCSQodE1OmY-Q</link><description>分享一篇文章。</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-02-14T15:43:02</pubDate></item><item><title>【银行逆向百例】16Android逆向之算法助手+frida绕过环境检测分析加密算法</title><link>https://mp.weixin.qq.com/s/GELviQcxku5hd13IwM5CDA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-02-10T09:16:25</pubDate></item><item><title>【AI安全】Yak Mcp query_http_flow工具+chrome-devtools-mcp+TRAE自动化渗透初体验</title><link>https://mp.weixin.qq.com/s/YGTMcmiAsCldhfrBRwwmIg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-01-19T00:53:53</pubDate></item><item><title>【游戏逆向】H5游戏引擎LayaAir页游逆向之websocket分析</title><link>https://mp.weixin.qq.com/s/jvWPDXSAyRdYkEUfEQN89A</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-01-18T23:50:42</pubDate></item><item><title>【Web逆向】Yakit热加载之file.ReadFile+js.Run调用本地js加解密Vulinbox靶场CryptoJS.AES(CBC)</title><link>https://mp.weixin.qq.com/s/VBw6mTwWgf1Ff2cvgkizxQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-01-11T23:57:38</pubDate></item><item><title>【银行逆向百例】小程序逆向之支付宝提取data文件为tar格式</title><link>https://mp.weixin.qq.com/s/p5iWeZGGzNFXeURMIKC4SA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2026-01-03T00:01:08</pubDate></item><item><title>【转载】Entropy：在一个阳光明媚的下午，我决定对 Burp 发起一次“熵减”</title><link>https://mp.weixin.qq.com/s/xOXJFCWCfKiRqp59TrvQsA</link><description>分享一篇文章。</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-12-28T14:35:58</pubDate></item><item><title>【Android逆向】社交APP语音房间频道消息处理分析</title><link>https://mp.weixin.qq.com/s/UhFKdXvAC6EOJfiImT4Tig</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-11-27T23:58:25</pubDate></item><item><title>【Android逆向】autojs卡密软件启动脚本分析</title><link>https://mp.weixin.qq.com/s/HR5mLnZhfCXJtGaoDiBHFw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-11-23T11:49:10</pubDate></item><item><title>【Web逆向】反调试之跳转新标签页+dom断点vue框架定位+AntiDebug_Breaker绕过</title><link>https://mp.weixin.qq.com/s/XBNw0wAmH8jtn1jtCRS7XA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-11-19T23:00:44</pubDate></item><item><title>【游戏逆向】H5页游之置空反调试+Websocket协议分析+添加任意buff</title><link>https://mp.weixin.qq.com/s/_EE01w2r2cA75y1oNP1AVA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-10-28T12:57:35</pubDate></item><item><title>【Windows客户端】CDP调试端口未授权导致获取Cookie</title><link>https://mp.weixin.qq.com/s/XcXBquzwziQ07KXyL9NPgA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-10-20T10:46:11</pubDate></item><item><title>【银行逆向百例】14小程序逆向之报错快速定位加解密+版本过低升级4.0微信开启控制台</title><link>https://mp.weixin.qq.com/s/JROZJb9bwYSb-R5xxueI5g</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-10-17T15:30:14</pubDate></item><item><title>【游戏逆向】Unity+Lua端游协议封包分析初探之AssetStudio反编译Lua</title><link>https://mp.weixin.qq.com/s/wt1Dsl3ONO2BhaT8vThSsw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-10-07T18:39:55</pubDate></item><item><title>【游戏逆向】Unity+Lua端游协议封包分析初探之AssetStudio反编译Lua</title><link>https://mp.weixin.qq.com/s/ih-eLjTMqolcPDmWNJarYg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-10-06T21:12:00</pubDate></item><item><title>【Android逆向】逆向加密签名之frida hook java底层类Cipher和MessageDigest</title><link>https://mp.weixin.qq.com/s/gpm6qSSHHME-0EsVVEf6yw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-09-26T09:59:43</pubDate></item><item><title>【银行逆向百例】13小程序逆向之自动化反编译+云数据库获取密钥</title><link>https://mp.weixin.qq.com/s/wH7ktamSEMkNjiYmme-apQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-09-21T17:15:20</pubDate></item><item><title>【银行逆向百例】12小程序逆向之web-view加载h5页面</title><link>https://mp.weixin.qq.com/s/_GyI0nHbmXquOaw4YbhhsA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-08-11T11:58:26</pubDate></item><item><title>【工具】油猴脚本之Googlexa0搜索结果自动收集+Hunterxa0批量打开前10个链接</title><link>https://mp.weixin.qq.com/s/JkkA6MiB5i6k3GV6DhqO2Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-07-22T22:18:28</pubDate></item><item><title>【银行逆向百例】11小程序逆向之修复页面未注册+位置权限+Yakit 魔术方法afterRequest修改明文数据</title><link>https://mp.weixin.qq.com/s/kAHZthfvDQRfwUgA810aDw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-07-04T17:14:05</pubDate></item><item><title>【银行逆向百例】10小程序逆向之Yakit 魔术方法beforeRequest实时修改签名</title><link>https://mp.weixin.qq.com/s/TxiQH4wQ9eW_vU_DJrYk0Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-24T13:24:41</pubDate></item><item><title>【银行逆向百例】09小程序逆向之禁用调试模式+动态密钥+JsRpc+Yakit hijackSaveHTTPFlow热加载</title><link>https://mp.weixin.qq.com/s/WtnbobWZkG0ryPi3ZSFUbw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-16T10:26:23</pubDate></item><item><title>【银行逆向百例】08小程序逆向之JsRpc+Yakit hijackSaveHTTPFlow热加载实现明文流量显示</title><link>https://mp.weixin.qq.com/s/-oTirKKgNCJSRQa9U5QlHw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-09T12:00:14</pubDate></item><item><title>【转载】一个基于规则的加解密破签工具</title><link>https://mp.weixin.qq.com/s/03wu9KEp1VWU5Bb68CUw3Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-08T18:06:13</pubDate></item><item><title>【银行逆向百例】07小程序逆向之微信开发者工具反编译修复分包内容缺失+登录失败openid替换</title><link>https://mp.weixin.qq.com/s/D3CS5L_DkiOFe1THjGs0eQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-03T12:45:26</pubDate></item><item><title>【银行逆向百例】07小程序逆向之微信开发者工具反编译修复分包内容缺失+登录失败openid替换</title><link>https://mp.weixin.qq.com/s/N98WnOFCXoKnleKamoGsaA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-03T12:35:47</pubDate></item><item><title>【银行逆向百例】07小程序逆向之微信开发者工具反编译修复分包内容缺失+登录失败openid替换</title><link>https://mp.weixin.qq.com/s/nKOjNaRAUFJwlTZer8he5A</link><description>“ 并没有所谓的活着一定就有意义这种事，但是活下去，说不定能找到有趣的事情，就像你找到了那朵花，我找到了你一样</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-03T12:30:11</pubDate></item><item><title>【银行逆向百例】07小程序逆向之微信开发者工具反编译修复分包内容缺失+登录失败openid替换</title><link>https://mp.weixin.qq.com/s/510sJaiIo-PLRIHHV7muiA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-06-03T12:08:13</pubDate></item><item><title>【银行逆向百例】06小程序逆向之WeChatOpenDevTools-Python开启Devtools+跟踪调用堆栈</title><link>https://mp.weixin.qq.com/s/j54Cdl3kcTof9LeLSPR6cw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-29T18:24:36</pubDate></item><item><title>【银行逆向百例】05小程序逆向之微信开发者工具反编译修复插件未授权+WXSS+WXML格式错误</title><link>https://mp.weixin.qq.com/s/bByynW1OmgGjDkLXDPAe4Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-23T09:24:41</pubDate></item><item><title>【银行逆向百例】04小程序逆向之腾讯VMP加固静态分析+Yakit Codec模块编写</title><link>https://mp.weixin.qq.com/s/tTedqABdAtR-k1V6G0tE0A</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-22T09:30:31</pubDate></item><item><title>【银行逆向百例】03小程序逆向之微信开发者工具反编译修复app.json</title><link>https://mp.weixin.qq.com/s/JcrpCoLfxEUNG13AcBNlkg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-21T22:37:56</pubDate></item><item><title>【银行逆向百例】02小程序逆向之RSA加密随机密钥</title><link>https://mp.weixin.qq.com/s/9B2LTp28vYZKXpFVFVg06Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-21T20:27:00</pubDate></item><item><title>【银行逆向百例】01小程序逆向之webview动态调试</title><link>https://mp.weixin.qq.com/s/9vKWDZ6GFEXDnjCPEj2DlA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-21T20:19:55</pubDate></item><item><title>【逆向百例】02小程序逆向之webview调试动态KEY加密加签</title><link>https://mp.weixin.qq.com/s/gACP12if555E6WEO0GSucg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-13T23:38:47</pubDate></item><item><title>【逆向百例】02小程序逆向之sign签名校验静态分析</title><link>https://mp.weixin.qq.com/s/rMc6en6c2vrBwi1CkK49yQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-11T09:14:08</pubDate></item><item><title>【逆向百例】小程序逆向之webview调试</title><link>https://mp.weixin.qq.com/s/8iVxUVoUix2eXwwM3OhQqQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-05-10T15:19:51</pubDate></item><item><title>【SRC实战】游戏平台绕过安全实名认证</title><link>https://mp.weixin.qq.com/s/GMeF788sX5DJ5VqonvOvpA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-03-25T22:24:02</pubDate></item><item><title>【SRC实战】客户端自定义协议+data协议xss+file协议文件读取</title><link>https://mp.weixin.qq.com/s/6tQv0JtAe8yXcWsShSVa0Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-03-24T18:08:55</pubDate></item><item><title>【SRC实战】下载未上架内测客户端游戏</title><link>https://mp.weixin.qq.com/s/5_PZ62booYwfKE4fLzsaKw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-03-03T09:26:53</pubDate></item><item><title>【SRC实战】供应链漏洞之统计数据JS黑链</title><link>https://mp.weixin.qq.com/s/nNpfcXPdLG3RRro7ffxPwQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-28T09:24:16</pubDate></item><item><title>【转载】XX多业务融合网关小小DAY II</title><link>https://mp.weixin.qq.com/s/jtQjJe8qqsNYhIAKdAGiUg</link><description>分享一篇文章。</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-27T12:20:29</pubDate></item><item><title>【SRC实战】生成营业执照企业认证发布职位</title><link>https://mp.weixin.qq.com/s/9bs_qalNjk_XdkPIApaVUg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-26T07:43:13</pubDate></item><item><title>【SRC实战】支付漏洞之整数溢出</title><link>https://mp.weixin.qq.com/s/IsLcmsU9kOPk4q3SRmIlyA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-21T09:23:47</pubDate></item><item><title>【SRC实战】aksk泄露导致云主机接管</title><link>https://mp.weixin.qq.com/s/Wm2zMUd1sZh8MIGJwwmcvg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-20T09:42:30</pubDate></item><item><title>【SRC实战】AI内容安全之生成色情内容英文版提示词</title><link>https://mp.weixin.qq.com/s/363xpEAV7J_PgVzF8YdHcQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-19T09:18:55</pubDate></item><item><title>【SRC实战】AI内容安全之生成色情内容中文版提示词</title><link>https://mp.weixin.qq.com/s/MdFWb-0vUQBu0zcmuCDt9A</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-18T09:29:06</pubDate></item><item><title>【SRC实战】无中生有图形验证码拒绝服务</title><link>https://mp.weixin.qq.com/s/bkdR7m9sA0kyQxEOohhW7g</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-17T12:01:09</pubDate></item><item><title>【SRC实战】日期参数查询SQL报错注入</title><link>https://mp.weixin.qq.com/s/3dNs40aYqDJtuQpEqLJWog</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2025-02-16T14:59:33</pubDate></item><item><title>【SRC实战】逆向加密生成secret绕过修复方案</title><link>https://mp.weixin.qq.com/s/5YWKg3vZWovk-tf7PgYABA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-12-18T17:20:49</pubDate></item><item><title>【SRC实战】Window客户端本地文件实现远控</title><link>https://mp.weixin.qq.com/s/ZCL7jeSabHR5luhqQiVf3Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-08-31T18:32:35</pubDate></item><item><title>【SRC实战】修改价格导致零元购支付漏洞</title><link>https://mp.weixin.qq.com/s/nSb5IWjzZ_2oZj-RQX7ctA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-07-15T10:28:00</pubDate></item><item><title>【SRC实战】碰撞机制失效导致无敌外挂</title><link>https://mp.weixin.qq.com/s/AyPIjy0Ym54sYInABToieA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-07-01T10:43:07</pubDate></item><item><title>【SRC实战】分析windows客户端日志弱口令+越权</title><link>https://mp.weixin.qq.com/s/xQmBtjyxS6zuOvXK7B2XyA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-06-30T11:04:12</pubDate></item><item><title>【SRC实战】隐藏商品零元购支付漏洞</title><link>https://mp.weixin.qq.com/s/RcgM1tE98os9AXhZc7iXSg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-06-15T22:31:25</pubDate></item><item><title>【端午安康】2024年SRC端午礼盒评测</title><link>https://mp.weixin.qq.com/s/X5oP3cKu19p0igmEkEHznw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-06-10T14:11:24</pubDate></item><item><title>【SRC实战】小游戏漏洞强制挑战</title><link>https://mp.weixin.qq.com/s/7C4wYJ-3JIBPaKlZ9H02NQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-06-01T18:01:15</pubDate></item><item><title>【SRC实战】越权会员付费课程</title><link>https://mp.weixin.qq.com/s/5jsw8PJ7NODHUPZgnKxSKA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-31T00:06:09</pubDate></item><item><title>【SRC实战】获取连续签到额外奖励</title><link>https://mp.weixin.qq.com/s/2dPq5gqxDl36aDmsDDcwbA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-30T08:21:54</pubDate></item><item><title>【SRC实战】无限试用免费套餐</title><link>https://mp.weixin.qq.com/s/ZJ7-BcFZKOYqPrCKoO--zA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-29T09:10:50</pubDate></item><item><title>【SRC实战】跳过任务获取奖励</title><link>https://mp.weixin.qq.com/s/IEzdk4nR9UtatzBdDlJS2Q</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-28T08:30:40</pubDate></item><item><title>【SRC实战】隐藏商品零元购支付漏洞</title><link>https://mp.weixin.qq.com/s/K7f172BAxCK5VEch_my7GA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-27T09:16:18</pubDate></item><item><title>【SRC实战】隐藏商品零元购支付漏洞</title><link>https://mp.weixin.qq.com/s/yXQIY2fowrHW5WQL7ZGuVQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-26T09:09:46</pubDate></item><item><title>【SRC实战】信息泄露导致越权会员功能</title><link>https://mp.weixin.qq.com/s/Olm77cNCJM24CxS_JD24Tw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-25T09:09:28</pubDate></item><item><title>【SRC实战】搜索功能泄露订单号+用户定位</title><link>https://mp.weixin.qq.com/s/2g2EMYubKAoSAniXydol-g</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-24T10:17:02</pubDate></item><item><title>【SRC实战】搜索功能查看会员内容</title><link>https://mp.weixin.qq.com/s/mZ4fUTfhyUFvwczMCohXQA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-23T12:15:54</pubDate></item><item><title>【SRC实战】修改金币数量实现财富自由</title><link>https://mp.weixin.qq.com/s/enqrmKGM1jC-gIv0e-9r3Q</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合”01—漏洞证明1、进入阅读奖励2、此时金币数量03、来到新手福利</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-22T08:11:47</pubDate></item><item><title>【SRC实战】信息泄露导致越权会员功能</title><link>https://mp.weixin.qq.com/s/WpOCAgNigR2eLocKPRxyyQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-21T00:05:23</pubDate></item><item><title>【SRC实战】信息泄露导致越权会员功能</title><link>https://mp.weixin.qq.com/s/-ZaeU5VrouMZEDy-ZdB3iQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-20T07:44:09</pubDate></item><item><title>【SRC实战】二手购物平台低价捡漏外挂</title><link>https://mp.weixin.qq.com/s/UuNOr-nVzKBAyZ8NAcTD3A</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-19T09:10:47</pubDate></item><item><title>【SRC实战】无限购买新人礼包半价支付漏洞</title><link>https://mp.weixin.qq.com/s/EUSTnO-vq1n7deK8kSpGxA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-18T09:02:54</pubDate></item><item><title>【SRC实战】越权会员付费内容</title><link>https://mp.weixin.qq.com/s/goCCeJcBhD4AzfDpdW4pVQ</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-17T00:02:50</pubDate></item><item><title>【SRC实战】F12查看加密文档密码</title><link>https://mp.weixin.qq.com/s/8o9V_2mAZX-YgYG3bjwPQw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-16T09:38:11</pubDate></item><item><title>【SRC实战】问卷调查奖励重放漏洞</title><link>https://mp.weixin.qq.com/s/HIUnUNTWdfxkfU-wN9ImFA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-15T09:14:45</pubDate></item><item><title>【SRC实战】退款导致零元购支付漏洞</title><link>https://mp.weixin.qq.com/s/3k3OCC5mwI5t9ILNt6Q8bw</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-14T00:54:42</pubDate></item><item><title>【SRC实战】findsomething未授权修改密码</title><link>https://mp.weixin.qq.com/s/i6R7OZ-5h9V5o3Kfho7QWA</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-13T09:42:56</pubDate></item><item><title>【SRC实战】信息泄露管理员token</title><link>https://mp.weixin.qq.com/s/Ziux0RFzK4Zh0rewU9iRdg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-12T17:04:56</pubDate></item><item><title>【SRC实战】文件名回显导致反射型XSS，URL重定向</title><link>https://mp.weixin.qq.com/s/hnrm-snkETuR-gqPOSnQXQ</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、反射型XSS“ 文件名回显，能否触发XSS？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-11T20:58:49</pubDate></item><item><title>【SRC实战】小游戏漏洞修改分数打榜</title><link>https://mp.weixin.qq.com/s/Um0HU2srvZ0UlZRAsbSVug</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明“ 如何刷分提高排名？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-10T15:55:36</pubDate></item><item><title>【SRC实战】无限获取优惠码</title><link>https://mp.weixin.qq.com/s/HgMK4S8275VvFVbnSp6Qsw</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明“ 获取优惠码有次数限制的情况下，如何绕过？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-09T07:13:17</pubDate></item><item><title>【SRC实战】修改赠送金额支付漏洞</title><link>https://mp.weixin.qq.com/s/NQKJQF81XpG8815EfgvgKw</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明“ 充值赠送金额能否修改？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-08T07:46:19</pubDate></item><item><title>【SRC实战】越权获取全站用户姓名，手机号，收货地址三要素明文</title><link>https://mp.weixin.qq.com/s/4ce4lxqSnqN_WlWvDbCJiA</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明“ 越权返回数据为加密值，如何处理？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-07T10:54:29</pubDate></item><item><title>【SRC实战】无限领取优惠券</title><link>https://mp.weixin.qq.com/s/b4YhYGwleFZLAY62Dv93_A</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、无限领取优惠券“ 只能领取1张优惠券场景，能</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-06T10:46:02</pubDate></item><item><title>【SRC实战】无法支付的修改金额支付漏洞</title><link>https://mp.weixin.qq.com/s/F4f8R4uKN0Q9BnTmjDMleg</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、企业用户，标准商品“ 支付订单需要公对公银行</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-05T12:21:29</pubDate></item><item><title>【SRC实战】前端脱敏信息泄露</title><link>https://mp.weixin.qq.com/s/xnCQQCAneT21vYH8Q3OCpw</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、前端脱敏，请求包泄露明文“ 前端脱敏处理，请</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-04T13:54:15</pubDate></item><item><title>【SRC实战】利用信息泄露漏洞100%获奖</title><link>https://mp.weixin.qq.com/s/8MaDDfGUE1ZmgIRmG2xhkg</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、翻牌场景“ 翻牌次数有限的情况下，如何提高获</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-03T08:25:13</pubDate></item><item><title>【SRC实战】遍历手机号给全站用户发放优惠券</title><link>https://mp.weixin.qq.com/s/m8ULZ52p1q_mKrCRnaI_7A</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、遍历手机号“ 没有验证码二次校验的漏洞如何扩</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-02T11:03:55</pubDate></item><item><title>【SRC实战】一键完成全部任务获取奖励</title><link>https://mp.weixin.qq.com/s/LkPfJuuP1K8vaFXRn-8wVg</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合 ”01—漏洞证明一、业务逻辑“ 如何欺骗APP完成任务获取奖励？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-05-01T09:23:33</pubDate></item><item><title>【SRC实战】利用APP前端加密构造数据包</title><link>https://mp.weixin.qq.com/s/cr15pejhRMzjF3cvevdgdw</link><description>“ 以下漏洞均为实验靶场，如有雷同，纯属巧合”01—漏洞证明“ 参数加密的情况，不会逆向怎么办？</description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-04-30T08:04:12</pubDate></item><item><title>【SRC实战】合成类小游戏外挂漏洞</title><link>https://mp.weixin.qq.com/s/ZnaRn222xJU0MQxWoRaiJg</link><description></description><author>挖个洞先</author><category>挖个洞先</category><pubDate>2024-04-29T10:46:26</pubDate></item></channel></rss>