<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzNTYwMTk4Mw.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Fri, 26 Dec 2025 10:11:09 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>信息搜集之边缘资产和隐形资产的发掘</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247490094&amp;idx=1&amp;sn=95d90902ce6ce74affa4db777f87905d</link><description>在SRC挖掘和攻防中，往往就是挖不到漏洞呢？第一个就是实战的经验比较少，对于漏洞在哪出现，有什么手法还掌握的不多；第二个是信息搜集没有得到要领，只会僵硬的进行信息搜集，对于边缘资产和隐形资产的发掘没有经验。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-12-25T20:00:44</pubDate></item><item><title>密码重置漏洞挖掘指南：从原理到实战的完整路径</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247490055&amp;idx=1&amp;sn=a91b235f679c8c88d77574a91738b45c</link><description>密码重置功能是Web应用中最常见也最核心的环节之一，它直接关系到用户账户的安全。正因为其普遍性和高敏感性，一个细微的逻辑缺陷都可能导致整个账户体系的沦陷。密码重置漏洞核心思路为：站在攻击者的角度，尝试劫持任意用户的密码重置流程</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-11-07T20:00:27</pubDate></item><item><title>Fastjson2下的反序列化调用链完整过程</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247490021&amp;idx=1&amp;sn=a45b04a24b2a6ba9b5c4e157dd65d8dc</link><description>fastjson2下的反序列化调用链完整过程</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-10-27T20:00:14</pubDate></item><item><title>Kali Linux 2025.3</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489878&amp;idx=1&amp;sn=dba36f98769f258679ccdb5a914200c6</link><description>Kali团队已发布Kali Linux 2025.3版本，这是该广受欢迎的渗透测试与道德黑客发行版今年第三次重大更新。本次发布新增10款工具，对其移动平台Kali NetHunter进行了重大更新，并增强了树莓派设备的无线功能。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-09-25T20:01:35</pubDate></item><item><title>Zabbix漏洞复现汇总</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489869&amp;idx=1&amp;sn=97bd1618e3ae4262fb69f3ac6c844603</link><description>Zabbix各版本漏洞汇总</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-09-16T20:00:21</pubDate></item><item><title>国内外的网络安全对比</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489694&amp;idx=1&amp;sn=94ae19b3020b4cf69908c1127904f1aa</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-08-26T20:00:22</pubDate></item><item><title>Webshell免杀技术强特征+加密</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489689&amp;idx=1&amp;sn=8ee235e7f833d2fc520095ce89b89e23</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-08-04T20:00:18</pubDate></item><item><title>Shiro反序列化全版本漏洞原理详解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489665&amp;idx=1&amp;sn=a19a72b885344786ec7047f7cc298f20</link><description>Shiro反序列化漏洞原理详解，主要涉及Shiro认证的一些基础概念以及为什么能够这样进行攻击。文章削弱了具体代码以及反序列化部分，主要强调很多新手宝宝看不懂(面试常考)的漏洞版本划分即利用区别等内容。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-07-16T20:00:23</pubDate></item><item><title>Kerberos 票据攻击：黄金、白银、钻石、蓝宝石票据的攻防全解析</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489650&amp;idx=1&amp;sn=5e32c91ffe0dc112792e1627be4e8bca</link><description>在渗透测试和红队对抗中，针对 Kerberos 认证机制的攻击手段一直是 Windows 域渗透的重要突破口。本文将从 Kerberos 认证流程、原理、利用方法、常用工具、危害与防御几个维度，系统梳理这四种票据攻击的关键点。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-07-04T20:00:43</pubDate></item><item><title>Kali Linux 2025.2</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489644&amp;idx=1&amp;sn=e8af872ef723dab48ec64d46d44d298a</link><description>Kali Linux 2025.2 发布 (Kali 菜单焕新、BloodHound CE 和 CARsenal) - 领先的渗透测试发行版</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-06-22T20:01:11</pubDate></item><item><title>隧道代理攻防技术战争手册</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489637&amp;idx=1&amp;sn=c6fbf83e452c0af5f56b8e68bcd997f3</link><description>本文将深入解析各类隧道代理技术（如ICMP、HTTP、DNS、TCP/UDP等）的实现原理与实战应用，通过具体工具手法（如Ping、cURL、nslookup、Telnet等）演示如何伪装和转发流量，并详细介绍多级隧道代理的搭建方法与技巧。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-06-16T20:00:18</pubDate></item><item><title>Redis未授权漏洞复现汇总</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489508&amp;idx=1&amp;sn=0bfab3f39b28fb33bba8abd281d49b07</link><description>Redis是现在最受欢迎的NoSQL数据库之一，Redis是一个使用ANSI C编写的开源、包含多种数据结构、支持网络、基于内存、可选持久性的键值对存储数据库</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-06-10T20:00:32</pubDate></item><item><title>Linux提权总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489443&amp;idx=1&amp;sn=4995c7b14b2259e0262aacb03febbde1</link><description>本文总结了linux提权的常用方法，其中具体的被用于提权的工具如perl，python，git，man等，它们其实你在理解了suid和sudo提权后</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-06-05T20:01:00</pubDate></item><item><title>JSON Web Token (JWT) 渗透技巧【详解总结】</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489357&amp;idx=1&amp;sn=4a61c1bb9b7859e87ab60a4b3ef8e6db</link><description>JWT，全称是 JSON Web Token，是一种用于身份验证和信息传递的令牌。简单来说，它就像是一个“通行证”，用户登录后，服务器会生成一个JWT返回给用户，用户之后访问其他资源时只需带上这个令牌，服务器验证通过后即可放行。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-06-03T20:00:21</pubDate></item><item><title>攻防项目中的代码审计</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489291&amp;idx=1&amp;sn=415ac9789e0c6f5b6c54d2da877e29bf</link><description>在一些攻防项目中，除了一些常见的大型系统外，还会遇到其他一些相对小众的系统，而在打不动大型系统时，这些相对小众的系统往往是比较好的入口点，这些系统更容易通过代码审计找到一些漏洞，从而getshell，在人力和时间成本上都比较契合一些攻防项目</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-05-28T20:01:28</pubDate></item><item><title>web安全 | 敏感信息泄露检测与防护技术详解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489222&amp;idx=1&amp;sn=f4de64fb84413e7a217aa9b84845831f</link><description>一、集中式硬编码密码描述硬编码密码是指将密码、密钥等敏感信息以明文形式直接写入代码中（如Java、Python</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-05-26T20:00:35</pubDate></item><item><title>记一次攻防和产品对抗</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489217&amp;idx=1&amp;sn=e0072f3af827e2067c1f6aeedb1111f0</link><description>本文主要介绍了医疗行业在无资产的场景下的一些测试思路以及在打点、内网过程中一些安全产品对抗相关的内容，涉及waf绕过、上线技巧、提权绕过杀软、特定条件下隧道链等，针对整体的攻击过程进行相关总结，以及针对防守方基于攻防场景下一些较为细节的建议</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-05-23T20:00:21</pubDate></item><item><title>PHP 静态分析漏洞挖掘：挑战、对策与研究进展综述</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489143&amp;idx=1&amp;sn=a25daaef4ea1b09e23bb13790cd43410</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-05-12T20:00:55</pubDate></item><item><title>若依(RuoYi)框架漏洞战争手册</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489135&amp;idx=1&amp;sn=1b47ec95f6a9cfeb72702cc7e0e36c85</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-05-07T20:00:35</pubDate></item><item><title>XSS 跨站脚本攻击详解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489050&amp;idx=1&amp;sn=75557dcdc0e935951c7862c6a4065389</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-04-30T20:04:11</pubDate></item><item><title>未授权服务加固与泛解析字符绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247489021&amp;idx=1&amp;sn=a01a0dd54d761e19b036f3d0a1679d3c</link><description>面向公网资产多轮加固的业务、异常的业务，通过泛解析字符让服务抛出异常信息回显，定位到无需认证的位置，缩短未授权业务测试的日常时间成本。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-04-23T20:03:26</pubDate></item><item><title>钓鱼网站与恶意链接检测指南</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488715&amp;idx=1&amp;sn=5639421b4d30d0708613c4ff31f0e941</link><description>钓鱼网站通常伪装成银行、电商或社交平台等真实网站，通过诱导用户输入账号、密码、信用卡号等敏感信息来进行诈骗。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-04-21T20:00:16</pubDate></item><item><title>Active Directory攻击杀伤链清单和工具列表- 2025</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488710&amp;idx=1&amp;sn=c81b2f82188490eac205ae93d0bc36d8</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-04-13T20:01:47</pubDate></item><item><title>内网隧道的搭建以及攻击流量特征概述</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488704&amp;idx=1&amp;sn=86c66cc0d1625e9dbce9ee953f5f5069</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-04-02T20:01:04</pubDate></item><item><title>网络安全—Web常见的漏洞描述与修复方案</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488589&amp;idx=1&amp;sn=d77bace9cbcfdba23c79244d92ff5aee</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-31T20:00:43</pubDate></item><item><title>从域认证协议以及密码凭据机制的角度来看内网渗透</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488583&amp;idx=1&amp;sn=6f9e9a33dad14911145fd8dcde7eddfe</link><description>原文链接：https://forum.butian.net/share/4191本文记录了内网渗透中主机之间的</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-19T20:00:13</pubDate></item><item><title>二维码钓鱼攻击（Quishing）详解及防范指南</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488568&amp;idx=1&amp;sn=cad7299e2d4bd60f5ebf9f95569df4dc</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-17T20:00:33</pubDate></item><item><title>Docker逃逸方式总结分享</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488561&amp;idx=1&amp;sn=32c248a4b7c280c9587ae5aa75471cd7</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-13T20:00:48</pubDate></item><item><title>使用分支对抗进行webshell bypass</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488470&amp;idx=1&amp;sn=9c64b22e8b19775479d093ddd0d01598</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-11T20:00:30</pubDate></item><item><title>一句话木马大全</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488431&amp;idx=1&amp;sn=2e865b3d9fa228216bc628bc040c1ebc</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-08T20:02:18</pubDate></item><item><title>走进莆田潮鞋店铺，让你轻松购买到心仪潮品！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488431&amp;idx=2&amp;sn=81b231b025895d517a8bd07db03041a7</link><description>01莆田鞋微商推荐店铺，莆田鞋子专卖小程序，莆田鞋微商相册小程序，莆田鞋子厂家一手货源，莆田鞋批发，莆田鞋子</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-08T20:02:18</pubDate></item><item><title>HW 中利用 WAF 缺陷进行绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488404&amp;idx=1&amp;sn=866dabd98e99cf9b6b673970c1751342</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-07T20:00:24</pubDate></item><item><title>红队中的社工钓鱼姿势</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488389&amp;idx=1&amp;sn=1e7f109486dd9cb2cb324411bdb44c3e</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-03-05T20:00:55</pubDate></item><item><title>Fastjson漏洞小结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488347&amp;idx=1&amp;sn=2d5b248dada3528c7bde4f6fe91f02cb</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-27T20:01:07</pubDate></item><item><title>RCE（远程代码执行漏洞）函数&amp;命令&amp;绕过总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488342&amp;idx=1&amp;sn=d8cab760a31c4160cb61dd357fef0394</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-25T20:03:17</pubDate></item><item><title>免杀-常见shellcode执行方式</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488337&amp;idx=1&amp;sn=f398a0a116accecaefa07d85dd3da21d</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-22T20:01:14</pubDate></item><item><title>HW 中如何利用 WAF 缺陷进行绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488314&amp;idx=1&amp;sn=4e8e6d95501c927728d0dc7438fe2b6f</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-21T09:00:16</pubDate></item><item><title>常见WEB漏洞—XSS漏洞：藏在网页背后的“隐形黑客”</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488294&amp;idx=1&amp;sn=a79de8898255a4c9f2b48eee9a0b9307</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-19T20:01:07</pubDate></item><item><title>常见WEB漏洞—SQL 注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488289&amp;idx=1&amp;sn=4adfd4de8707c7989afa203de3cd49f2</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-18T20:02:00</pubDate></item><item><title>文件上传绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488283&amp;idx=1&amp;sn=3bc7c0b3856fea5597d386e413473e90</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-02-07T20:02:48</pubDate></item><item><title>后渗透：文件传输指南</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488230&amp;idx=1&amp;sn=1c55c9eec57e987f73284321529d275c</link><description>在红蓝对抗过程中，文件传输是后渗透场景中的关键步骤。文件传输有多种方法，在本文中我们将逐一介绍。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-28T20:00:17</pubDate></item><item><title>Web安全初级入门基础</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488216&amp;idx=1&amp;sn=70d13855adc495afcbb6902ddc41928f</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-21T20:00:35</pubDate></item><item><title>木马反制技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488211&amp;idx=1&amp;sn=a4a634096a3ea78aa825239e2869897b</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-18T20:02:28</pubDate></item><item><title>计算机知识——Windows进程</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488202&amp;idx=1&amp;sn=17e96bc2132996b2d1c05f123a60e0ad</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-11T20:00:35</pubDate></item><item><title>挖矿病毒的处置</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488185&amp;idx=1&amp;sn=a4547687f93e0bd63e6f96723be53e19</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-06T09:00:48</pubDate></item><item><title>WebShell代码免杀方式</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488152&amp;idx=1&amp;sn=32b64fa1cbb756b6137458408a32ef17</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2025-01-01T08:30:44</pubDate></item><item><title>Kali Linux 2024.4</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488101&amp;idx=1&amp;sn=3e3084be470e2f5858d88042ad35bba3</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-12-24T09:00:57</pubDate></item><item><title>动态逃逸杀软</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488075&amp;idx=1&amp;sn=30866fcd85c0b1a1f1d5fef6f8f2cde1</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-12-03T20:03:50</pubDate></item><item><title>资产收集常用工具以及思路总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247488016&amp;idx=1&amp;sn=ae433530b54807250c730cd7e343d0b2</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-11-16T20:00:15</pubDate></item><item><title>常见网络安全设备</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487972&amp;idx=1&amp;sn=1c3996c42d0b13b693b24bb376305d87</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-11-01T20:00:08</pubDate></item><item><title>网安资源知识库</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487972&amp;idx=2&amp;sn=a0a1932b0887b7ee7a078b4eee48d01e</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-11-01T20:00:08</pubDate></item><item><title>11 种绕过 CDN 查找真实 IP 方法</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487956&amp;idx=1&amp;sn=b80c2e09c08f3a46785a2be0df335d8c</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-10-27T20:00:59</pubDate></item><item><title>攻防演练中红队的主要工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487933&amp;idx=1&amp;sn=30db175e7528465aaa4ce7bf08148f57</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-10-19T20:02:54</pubDate></item><item><title>Java Web审计中常见的任意文件操作绕过缺陷</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487928&amp;idx=1&amp;sn=bee9efb079c266f3460a8688ec3a364a</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-10-12T20:00:47</pubDate></item><item><title>应急响应——全类型JAVA内存马排查</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487860&amp;idx=1&amp;sn=2ed2f06b4df3d698111de170ba601896</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-10-01T09:01:44</pubDate></item><item><title>Web应急基础指南</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487804&amp;idx=1&amp;sn=ab255aa57b214a1e2e1431cd5176176f</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-28T20:00:54</pubDate></item><item><title>渗透测试之验证码渗透最全总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487754&amp;idx=1&amp;sn=bbfe56323f4005105bcca3481fc54534</link><description>不少人在碰见验证码的时候，大多数只是看了一眼就过去了，没想到验证码还有啥可测试的。但其实验证码也能在项目中导致高危,并且验证码漏洞能在一定情况下造成危害。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-20T20:00:13</pubDate></item><item><title>信息收集—外网信息收集（祝大家中秋快乐！）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487729&amp;idx=1&amp;sn=5d876002209a080aa20bd0e6122f61f2</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-17T09:00:27</pubDate></item><item><title>小白必看的Bypass WAF食用方法</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487268&amp;idx=1&amp;sn=cdba3ae6d7c6cd7ecd90ff06245cc74e</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-14T20:00:56</pubDate></item><item><title>关于让钓鱼攻击无所遁形的浅谈</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487216&amp;idx=1&amp;sn=791ff0fc7926739b0ebcabdc2f367408</link><description>一年一度的大型活动还在进行中，想必在这个过程中不管是BT还是甲方安全人员都会遇到各种各样的钓鱼攻击。本文的初衷就是助力各位BT相关人员分析研判各种钓鱼攻击，让钓鱼攻击无所遁形。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-11T20:03:52</pubDate></item><item><title>一朝沐杏雨，一生念师恩</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487190&amp;idx=1&amp;sn=450210943eb9271d09aec81c7459d11c</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-10T08:00:16</pubDate></item><item><title>Windows UAC机制逻辑及提权原理</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487181&amp;idx=1&amp;sn=7465811ec4b345797d362ac3bda18f31</link><description>\\x26quot;一文讲清楚windows UAC核心机制逻辑，总结历史上常见UAC提权方式是如何利用这些逻辑的漏洞来实现提权的，并提出检测思路\\x26quot;</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-07T20:00:55</pubDate></item><item><title>安利一个分享副业的知识星球</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487181&amp;idx=2&amp;sn=f3a5baa01f59335a219c3ebe2833349d</link><description>本星球致力于分享各种副业教程，资料基本为夸克网盘链接，需要下载的可联系。\\x0d\\x0a不定时分享各种网赚副业资源，欢迎大家加入交流。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-07T20:00:55</pubDate></item><item><title>内网活动目录利用方法</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247487024&amp;idx=1&amp;sn=3f1b5fc1a1683ae3635ab29c3710699b</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-09-02T20:00:41</pubDate></item><item><title>内网渗透横向移动技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486898&amp;idx=1&amp;sn=90b41689b348814c4bf774d16f3a5478</link><description>在正常情况中，横向移动是在已经获取了足够的权限的情况下进行横向移动，下面中的方法大部分也需要高权限的操作。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-26T20:00:45</pubDate></item><item><title>命令执行保姆级总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486680&amp;idx=1&amp;sn=dc1d710525983bc6103b14b441256cea</link><description>原文链接：奇安信攻防社区-保姆级命令执行总结 (butian.net)写在前面：ASCII码表完整版ASCII</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-22T20:01:16</pubDate></item><item><title>Zimbra邮件服务器渗透技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486654&amp;idx=1&amp;sn=aff4d4fd49d25ad3c1b03d4c09a03be8</link><description>Zimbra 是一家提供专业的电子邮件软件开发供应商，主要提供ZimbraDesktop邮件管理软件。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-15T20:00:25</pubDate></item><item><title>给大家推荐一个分享副业的公众号</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486654&amp;idx=2&amp;sn=42f8406c47b354102ef0bad1a9ee31f1</link><description>公众号分享互联网上的各种网赚副业，对于想在家做副业的朋友们提供一些教程思路，内容取材于网络，大家仅供参考。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-15T20:00:25</pubDate></item><item><title>内网渗透导出HASH</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486593&amp;idx=1&amp;sn=46ebd788eac19efdf9f86486c1746f26</link><description>在内网渗透中当我们得到一台高权限用户的身份时，就可以抓取到当前机器上的各类密码。 虽然任务要求是导出域hash的方式，但在内网渗透中，获取当前机器的hash也有可能获取到域用户的hash。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-12T20:00:21</pubDate></item><item><title>Spring Boot Actuator信息泄露漏洞三种利用方式总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486481&amp;idx=1&amp;sn=bf1d2ead48ef7adb0c4cad509a0ecb61</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-10T20:00:51</pubDate></item><item><title>漏洞挖掘 | edusrc挖掘的骚技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486469&amp;idx=1&amp;sn=6f7f53793e09ad849b789bbb987fd628</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-01T20:00:19</pubDate></item><item><title>网赚教程分享（二）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486469&amp;idx=2&amp;sn=da678e5c8696e254ed77fe168e3267d1</link><description>2024短视频掘金项目，AI制作治愈系风景，奇幻天空特效操作简单。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-08-01T20:00:19</pubDate></item><item><title>攻防演练中利用 WAF 缺陷进行绕过</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486446&amp;idx=1&amp;sn=d95d5fc8f6a100a8e919664c355a5c8e</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-07-28T20:00:58</pubDate></item><item><title>网赚教程分享（一）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486446&amp;idx=2&amp;sn=b337298476e0451dfe64edb1a3750cea</link><description>AI美女情感语录，收益收徒两不误，每天半小时，附带变现渠道。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-07-28T20:00:58</pubDate></item><item><title>Nginx后门集合</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486407&amp;idx=1&amp;sn=ea90b62791fa5351ab422b08f286bbbb</link><description>简介目前的nginx后门根据加载方式来分有两类: 动态库模块(so module)和二进制nginx程序。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-07-14T20:01:05</pubDate></item><item><title>截止目前2024 年 10 个最热门的网络安全工具和产品</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486370&amp;idx=1&amp;sn=5813b4b3f8c4296262cb03fb3f9f2fa0</link><description>今年上半年，GenAI 一直是网络安全供应商关注的重点，但包括 SIEM、SASE 和 XDR 在内的许多其他</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-07-04T20:00:15</pubDate></item><item><title>常见网络攻击方式及防御方法</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486370&amp;idx=2&amp;sn=da50708b904ea72782827284a7f5e281</link><description>网络安全威胁的不断演变和增长，网络攻击的种类和数量也在不断增加，攻防对抗实战演练在即，让我们一起了解一下常见网络攻击方式及防御方法。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-07-04T20:00:15</pubDate></item><item><title>【两万字】零基础学Fastjson提高篇（一）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486217&amp;idx=1&amp;sn=7363d3c7f982f86e9472331ce26a3292</link><description>本文是半年前的写的完全零基础入门Fastjson系列漏洞（基础篇）的提高篇的第一篇，后续会发布第二篇。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-26T20:01:21</pubDate></item><item><title>【两万字原创长文】完全零基础入门Fastjson系列漏洞（基础篇）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247486153&amp;idx=1&amp;sn=1e6139e55a62e853a78e064411262c1a</link><description>零、前言与目录			        我在学习Java漏洞的时候，感觉很痛苦，不知道从何学起，因为我的Java</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-21T20:00:40</pubDate></item><item><title>基于未授权的渗透测试技巧总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485767&amp;idx=1&amp;sn=8519cdc7e51f5c5d76fc08e1f588ce37</link><description></description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-18T07:13:47</pubDate></item><item><title>一个汇集全网资源的星球</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485767&amp;idx=2&amp;sn=5d9cfbc260b122de0f123ef8481ed734</link><description>资源库酷酷本星球致力于整理收集互联网上各种资源，包括但不限于网络安全相关资料、各种网盘资源、行业报告，各种软件，收集整理各种海量资源。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-18T07:13:47</pubDate></item><item><title>一个汇集全网资源的星球</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485764&amp;idx=2&amp;sn=94f9ee3b0ae4f1cc0da73a93abddc615</link><description>资源库酷酷本星球致力于整理收集互联网上各种资源，包括但不限于网络安全相关资料、各种网盘资源、行业报告，各种软件，收集整理各种海量资源。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-16T20:00:11</pubDate></item><item><title>Kali Linux 2024.2</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485667&amp;idx=1&amp;sn=7d8b79fd52b3ef9b6f8ec41943cc7c8b</link><description>比平常晚了一点，但 Kali 2024.2 来了！延迟是由于实现这一目标的幕后变化所致，这也是人们关注的焦点。社区提供了大量帮助，这次他们不仅添加了新的软件包，还更新和修复了错误！</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-06-09T20:01:15</pubDate></item><item><title>【资源分享】最新BurpSuite2024.5专业中英文开箱即用版下载</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485650&amp;idx=1&amp;sn=aa68d9e5bd3ef1bd9bbb756c556c885b</link><description>免责声明本文所涉及的任何技术、信息或工具，仅供学习和参考之用。请勿利用本文提供的信息从事任何违法活动或不当行为。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-31T21:30:25</pubDate></item><item><title>域渗透-获取域控方法总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485638&amp;idx=1&amp;sn=ade6555539e33c1ed1996b7c8b6d59bb</link><description>前言：在域渗透中、作为渗透测试人员，获取域控的权限基本上可以获取整个内网的权限。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-24T20:04:32</pubDate></item><item><title>PHP序列化、反序列化漏洞超全总结</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485571&amp;idx=1&amp;sn=3987c1065c0cc19b366fecc254e53c12</link><description>一、基础1、简介序列化其实就是将数据转化成一种可逆的数据结构，自然，逆向的过程就叫做反序列化。</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-21T20:00:32</pubDate></item><item><title>2024年最佳Red Team工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485547&amp;idx=1&amp;sn=350649bfd5315bfdbffc0829d9783cea</link><description>1.Reconnaissance主动情报收集EyeWitness的设计目的是截取网站的屏幕截图，提供一些服务器</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-15T20:09:02</pubDate></item><item><title>宝藏资源库限时免费体验</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485547&amp;idx=2&amp;sn=0aafd7382f18bbedcfbd72c936917573</link><description>资源库酷酷本星球致力于整理收集互联网上各种资源，包括但不限于网络安全相关资料、各种网盘资源、行业报告，各种软件</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-15T20:09:02</pubDate></item><item><title>反弹shell汇总</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNTYwMTk4Mw==&amp;mid=2247485508&amp;idx=1&amp;sn=76e9e96976ce51884e2597a2f352d29d</link><description>文章旨意在于总结各类反弹shell,有不足或漏缺请各位是否指出.注意有些反弹shell的方法或脚本只适用于Li</description><author>网安探索员</author><category>网安探索员</category><pubDate>2024-05-11T20:03:48</pubDate></item></channel></rss>