<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkyODUzMjEzOA.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Mon, 23 Mar 2026 23:29:50 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>Windows x64汇编和Shellcode</title><link>https://mp.weixin.qq.com/s/oAH6d96AGVnw75Ht-w0Onw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-03-23T22:02:11</pubDate></item><item><title>Windows x64汇编</title><link>https://mp.weixin.qq.com/s/EGIXQ7L0Np_yOR6jEsG8Lw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-03-13T22:18:56</pubDate></item><item><title>COM对象劫持</title><link>https://mp.weixin.qq.com/s/d11gyXiH0WItzVXfmPjSPA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-15T19:21:39</pubDate></item><item><title>Notepad++供应链攻击--疑似国家级黑客实施的供应链攻击</title><link>https://mp.weixin.qq.com/s/p4_LK6ssINlxMCVAKgnGwg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-12T20:34:37</pubDate></item><item><title>DLL劫持</title><link>https://mp.weixin.qq.com/s/wpHGHKKzOYFtfr6b33fu-w</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-11T16:14:10</pubDate></item><item><title>深入学习PE文件结构系列五自己实现一个PE解析器</title><link>https://mp.weixin.qq.com/s/UNkxoXmTboLKMPlpRT2w2g</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-09T21:33:26</pubDate></item><item><title>深入学习PE文件结构系列四Import-Relocation</title><link>https://mp.weixin.qq.com/s/-VU9XcaWt9hNOJNEPB7Xng</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-07T09:43:57</pubDate></item><item><title>深入学习PE文件结构系列三Data-Directory-Section-Headers-Section</title><link>https://mp.weixin.qq.com/s/_HwbSrRj1yKTNLPdyEVOOw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-05T12:27:39</pubDate></item><item><title>深入学习PE文件结构系列二PE-Signature-PE-File-Header-PE-Optional-Header</title><link>https://mp.weixin.qq.com/s/KqDfQp2tZBQB0Le7EYpUnA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-04T12:28:57</pubDate></item><item><title>深入学习PE文件结构系列一DOS-Header-DOS-Stub-Rich-Header</title><link>https://mp.weixin.qq.com/s/pHZH74bQNW4VEaoxQ-3sbQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-02-03T12:39:32</pubDate></item><item><title>Windows任务计划COM Handler在权限维持中的应用</title><link>https://mp.weixin.qq.com/s/jU-8WAJPqt_1XQ2MWg77tQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-01-24T10:31:32</pubDate></item><item><title>利用控制面板COM对象实现内网横向移动的新型DCOM攻击技术</title><link>https://mp.weixin.qq.com/s/gwz57AoGkHVOChH9OI4_BA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-01-13T11:06:37</pubDate></item><item><title>DCOM内网横向探究</title><link>https://mp.weixin.qq.com/s/wGyXiBOLPKMukbgrTLLpoA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2026-01-12T12:01:32</pubDate></item><item><title>\"Windows任务计划及其COM组件\"后续</title><link>https://mp.weixin.qq.com/s/IehvXhBBaf-nh8AhS2yL5w</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-11-30T23:41:26</pubDate></item><item><title>Windows任务计划及其COM组件</title><link>https://mp.weixin.qq.com/s/6XFwEYDhqvewq-zIoJ0inA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-11-28T22:15:58</pubDate></item><item><title>Windows RPC初探</title><link>https://mp.weixin.qq.com/s/XQEayyiq03by0lXzdCOzTA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-11-27T20:52:41</pubDate></item><item><title>Windows任务计划权限提升漏洞分析（CVE-2025-60710）</title><link>https://mp.weixin.qq.com/s/zxMwegtggSuusu0fg4htGw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-11-23T19:46:35</pubDate></item><item><title>直接系统调用 VS 间接系统调用</title><link>https://mp.weixin.qq.com/s/wuXQ0d7ixMg8kCyDgHA-iQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-10-19T09:15:24</pubDate></item><item><title>直接系统调用之从上层API到下层API的旅程</title><link>https://mp.weixin.qq.com/s/wOf0foUmPUT5uroCZzzAwA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-10-15T20:10:31</pubDate></item><item><title>高级进程注入之利用线程名和APC（下）</title><link>https://mp.weixin.qq.com/s/jfTTcUfyTladoRb1ZmvK2A</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-10-13T22:06:18</pubDate></item><item><title>高级进程注入之利用线程名和APC</title><link>https://mp.weixin.qq.com/s/4sFoOvEEEtx4kvuGZT-Vkw</link><description>前言进程注入是攻击方武器库中最重要的技术之一，本文将会介绍如何使用线程描述相关的API实现绕过AV/EDR的</description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-10-10T21:20:26</pubDate></item><item><title>APC系列之用户模式APC</title><link>https://mp.weixin.qq.com/s/uDygo3YOY9XOyVLLH-yifQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-10-07T23:23:33</pubDate></item><item><title>Windows下32位汇编学习（二）PE文件解析</title><link>https://mp.weixin.qq.com/s/k47oEegsjvd0h7HQg93zDA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-09-29T23:05:11</pubDate></item><item><title>通过APC执行Shellcode</title><link>https://mp.weixin.qq.com/s/tYuRUkDBtQk7j8kG1hOuig</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-09-26T10:56:21</pubDate></item><item><title>回调函数</title><link>https://mp.weixin.qq.com/s/E4DHwDnT5vi-vichy8KODw</link><description>恶意的Loader和PIS（Position-Independent Shellcode）会使用各种技术来绕</description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-09-18T10:22:49</pubDate></item><item><title>一次简单的钓鱼分析之FTP执行LNK</title><link>https://mp.weixin.qq.com/s/9unZILV45beT7QsSHa2KQQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-09-03T21:58:13</pubDate></item><item><title>Windows下32位汇编学习</title><link>https://mp.weixin.qq.com/s/SBsWvZOp_BH3I-jdjK2dDQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-08-14T21:48:24</pubDate></item><item><title>DOS下16位汇编学习</title><link>https://mp.weixin.qq.com/s/TmMpamuLc35l1_9Nu7XoFA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-08-05T16:25:28</pubDate></item><item><title>利用NtReadVirtualMemory实现IAT中规避高危API</title><link>https://mp.weixin.qq.com/s/afU82M9UM51eOdkk906lFQ</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-07-30T08:49:23</pubDate></item><item><title>“WorstFit”学习</title><link>https://mp.weixin.qq.com/s/v-NqWv91Hc1GRAM50dZksA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-01-12T21:03:19</pubDate></item><item><title>CVE-2024-25600 WordPress Bricks Builder远程代码执行漏洞分析</title><link>https://mp.weixin.qq.com/s/kmYY-5RvFmZWiaR6GMRPag</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2025-01-06T20:41:17</pubDate></item><item><title>Parallels Desktop虚拟机（PD虚拟机）迁移到VMware Workstation</title><link>https://mp.weixin.qq.com/s/hJlcFHHII2k0L73aLssTGw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-12-29T22:20:56</pubDate></item><item><title>ThinkPHP GetShell WAF绕过</title><link>https://mp.weixin.qq.com/s/FyFzSItYynVAXzK1S1V29g</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-11-18T20:58:25</pubDate></item><item><title>从shiro命令执行到远程桌面登录</title><link>https://mp.weixin.qq.com/s/2cTbygz3Aoc7Y4OytFUGVw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-10-06T10:01:59</pubDate></item><item><title>Windows命令学习之ICACLS</title><link>https://mp.weixin.qq.com/s/l0RLccNWkB19dvX7qbderA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-08-15T17:10:11</pubDate></item><item><title>移动端渗透测试环境搭建</title><link>https://mp.weixin.qq.com/s/xnOpHWXqyuTaC15oeqwcJg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-07-16T10:17:20</pubDate></item><item><title>自动化连接ssh并反弹shell</title><link>https://mp.weixin.qq.com/s/g7GzeiIQYeg3uB7ixnKNbg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-05-07T21:54:06</pubDate></item><item><title>分享一个自己开发的工具</title><link>https://mp.weixin.qq.com/s/nDnfdnn01spM8MFUlfmUpA</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-29T09:05:53</pubDate></item><item><title>向日葵旧版本下载</title><link>https://mp.weixin.qq.com/s/fDJ0c10N65HCojo866iZSw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-28T20:38:22</pubDate></item><item><title>微擎审计</title><link>https://mp.weixin.qq.com/s/jDgBGMFhJEkewubxXEHhcg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-26T09:43:04</pubDate></item><item><title>ThinkPHP最新版6-0-13-0day利用链分析</title><link>https://mp.weixin.qq.com/s/jO05JzS-XQ3OFVRVDwR-Wg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-25T09:13:51</pubDate></item><item><title>JPress审计</title><link>https://mp.weixin.qq.com/s/TPYLoVLkBd-O-fG2nl_XoQ</link><description>0x01 目标熟悉JPress 是一个使用 Java 开发的、开源免费的建站神器，灵感来源于 WordPres</description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-23T11:44:58</pubDate></item><item><title>悟空CRM审计（审计5分钟，环境2小时？）</title><link>https://mp.weixin.qq.com/s/gF_1nDfBXLEY0OW25ftuCw</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-19T10:02:02</pubDate></item><item><title>解决Windows Defender关闭后又自动打开的困扰（隐蔽的关闭杀软方式？）</title><link>https://mp.weixin.qq.com/s/ufG5-Iy53e2H5wj-8D5_Hg</link><description></description><author>卡卡罗特取西经</author><category>卡卡罗特取西经</category><pubDate>2024-04-18T21:09:43</pubDate></item></channel></rss>