<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzNjEwNzU2OA.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 20 Mar 2025 20:22:05 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>OneBlog &lt;=v2.3.6 存在模板注入漏洞CVE原创(CVE-2024-54954	)</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483789&amp;idx=1&amp;sn=5859a64579307321cb5793ab98183f46</link><description>OneBlog \\x26lt;=v2.3.6 存在模板注入漏洞CVE原创(CVE-2024-54954	)</description><author>hack boy</author><category>hack boy</category><pubDate>2025-03-20T17:16:14</pubDate></item><item><title>JAVA代码审计-fastcms模版注入漏洞已申请CVE</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483773&amp;idx=1&amp;sn=79f9152f7b9f769985605ba216f9fbb2</link><description></description><author>hack boy</author><category>hack boy</category><pubDate>2024-12-23T17:37:02</pubDate></item><item><title>JAVA代码审计-jfinal CMS未授权远程代码执行漏洞已申请获得CVE编号（CVE-2024-53477）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483763&amp;idx=1&amp;sn=990038107b5e65c4284d56b5a802cbd4</link><description></description><author>hack boy</author><category>hack boy</category><pubDate>2024-12-10T11:17:03</pubDate></item><item><title>SpiderFlow平台命令执行漏洞(CVE-2024-0195)</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483754&amp;idx=1&amp;sn=f66f2384b2be00ac9426f9e78137951b</link><description>SpiderFlow平台命令执行漏洞(CVE-2024-0195)</description><author>hack boy</author><category>hack boy</category><pubDate>2024-10-31T11:08:20</pubDate></item><item><title>java代码审计-JDBC数据库连接方式的sql注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483738&amp;idx=1&amp;sn=7cc7a3f786972a4f8c10f9dccc41ba82</link><description>java代码审计-JDBC数据库连接方式的sql注入</description><author>hack boy</author><category>hack boy</category><pubDate>2023-07-05T23:18:35</pubDate></item><item><title>小程序反编译以及抓包渗透测试</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483728&amp;idx=1&amp;sn=f753316aaf54f62c3cca5529b3ba695d</link><description>前言随着微信pc端可以点击进入小程序以及公众号，给我们抓包带来了极大的便利，以下主要讲解微信小程序的抓包以及</description><author>hack boy</author><category>hack boy</category><pubDate>2022-05-05T14:04:45</pubDate></item><item><title>shiro漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483713&amp;idx=1&amp;sn=2a96b559ef0003e3d5bc0e1c4f49a72d</link><description>weblogic总结</description><author>hack boy</author><category>hack boy</category><pubDate>2022-04-29T17:11:40</pubDate></item><item><title>python运算符以及列表学习</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483690&amp;idx=1&amp;sn=033d541b5296cb256e14c9a7a1b44c23</link><description>python运算符</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-28T23:40:10</pubDate></item><item><title>python 学习</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483686&amp;idx=1&amp;sn=308078520634f4e848e37fc0382e76d0</link><description>目录f1.文件写入12.input()内置函数1三．注释符号：#单行注释23.3代码的缩进33.4 编码规范</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-26T23:12:05</pubDate></item><item><title>病毒分析|经典熊猫烧香(小部分)</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483682&amp;idx=1&amp;sn=2d33810b90d802cc6364236aff91dcee</link><description>病毒分析1.熊猫烧香病毒：查杀病毒。</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-23T21:06:22</pubDate></item><item><title>sqlmap参数|简单介绍burpsuite爬虫模块</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483678&amp;idx=1&amp;sn=d38d2d94097bd334091012e8ef43603a</link><description>目录一．Sqlmap的使用（补充）1二． 在线解asscll码网站：1三． burp suite 的Spid</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-22T21:39:06</pubDate></item><item><title>工具的总结和一些杂项</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483674&amp;idx=1&amp;sn=cc375cf53e7cc1cb5cbd668cea73c214</link><description>nmap参数详解：\\x0a\\x0a 弱口令工具：\\x0a\\x0a可能会造成任意命令注入的函数（php）\\x0a安装PentestDB模块与环境依赖（社工字典生成）\\x0a文件包含漏洞\\x0aburp suite\\x0a七文件上传:</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-21T22:21:52</pubDate></item><item><title>后渗透信息收集|小部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483666&amp;idx=1&amp;sn=7e809906860db05e0cf73dc82388752d</link><description>wmic命令：关于：wmic和cmd一样存在所有的Windows版本中。wmic与现有的shell和使用程序</description><author>hack boy</author><category>hack boy</category><pubDate>2020-09-01T18:02:30</pubDate></item><item><title>内网渗透之信息收集（小部分总结）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483661&amp;idx=1&amp;sn=d5e55be41db15a21d75e3dcc55b8a240</link><description>内网渗透之信息收集（小部分总结）</description><author>hack boy</author><category>hack boy</category><pubDate>2020-08-31T15:19:55</pubDate></item><item><title>php序列化与反序列化了解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzNjEwNzU2OA==&amp;mid=2247483654&amp;idx=1&amp;sn=0b6409165c48e04f4fbddac831e83fb7</link><description>php序列化与反序列化了解</description><author>hack boy</author><category>hack boy</category><pubDate>2020-08-28T11:19:29</pubDate></item></channel></rss>