<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzODUzMjA1MQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Sun, 28 Sep 2025 15:19:53 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>深度解析：APP渗透的核心漏洞与攻防技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485445&amp;idx=1&amp;sn=1d2b13ff1ce8f1056e5af411e025d837</link><description>良心推荐一个性价比拉满的APP课程</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-28T10:00:50</pubDate></item><item><title>最简单的手工sql注入案例</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485439&amp;idx=1&amp;sn=2dcf1721578cb828b46277fab1dabed3</link><description>手把手教学学员手工sql注入案例</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-25T17:03:12</pubDate></item><item><title>关于转载被原创大哥追着@</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485425&amp;idx=1&amp;sn=529a86bc2b1aeec5f16375d9629b72cf</link><description>1、关于我转载了补天上的推文，导致原创作者追着我骂。连续骂了快半个星期了。额。。。。其实也不是很光彩。我想说下。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-24T14:31:25</pubDate></item><item><title>C**D审核，这么抽象吗？</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485419&amp;idx=1&amp;sn=2a3f788db93837126735f90397bf4fc0</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-24T14:23:35</pubDate></item><item><title>免费领取无问网安模型积分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485405&amp;idx=1&amp;sn=fe4c023a4b9b5c954bec4c5adbdfc83e</link><description>无问社区是一个面向网络安全行业的技术平台，其中涵盖内容检索、无问AI网络安全模型、网络安全</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-05T14:57:25</pubDate></item><item><title>[破解]dxscango工具ai自动化破解过程</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485398&amp;idx=1&amp;sn=0fa47dfe875b94658972b0a8d9a13f6c</link><description>本文介绍的主要是通过ai纯自动化破解某工具验证，需要准备好ida-mcp，ida pro即可。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-09-02T15:21:28</pubDate></item><item><title>真的建议所有网安马上搞个软考证书！（红利期）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485394&amp;idx=1&amp;sn=c715ceeb06929f3a315b12b64e85b682</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-08-07T16:06:50</pubDate></item><item><title>【代发】SRC实战：如何入侵牢美国防部军方卫星运营商</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485347&amp;idx=1&amp;sn=f2f8b9d103c78a8c30ff82d913405377</link><description>看前声明：此文章为Rebel编写，本文仅帮朋友推广宣发~有问题请联系作者Rebel下面的内容是本人学生时期在</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-08-05T10:56:49</pubDate></item><item><title>攻防实战从代码审计到rce之另类绕过waf创宇d(内含抽奖)</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485345&amp;idx=1&amp;sn=69771695c938ae5c1950fb38d8da3879</link><description>前言某次红队打点,从代码审计到rce，抽奖最下方不是星标不推送文章了。师傅也不想吧~快把极梦C设置成星标吧。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-08-04T10:47:17</pubDate></item><item><title>xss bypass</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485343&amp;idx=1&amp;sn=94ab6ec98c8b056a1a55f8a74eac6ed9</link><description>\\x26amp;lt;x onmousemove=操=\\x26#39;\\x26#39;,你=!操+操,妈=!你+操,操操=操+{},操你=你[操++],操妈=你[你操=操],你你=++你操+操,你妈=操操[你操+你你],你[你妈+=操操[操]+(你.妈+操操)[操]+妈[你你]+操你+操妈+你[你操]+你妈+操你+操操[操]+操妈][你妈](妈[操]+妈[你操]+你[你你]+操妈+操你+\\x26quot;(操)\\x26quot;)()\\x26amp;gt;test</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-08-01T14:54:28</pubDate></item><item><title>OAuth2.0劫持账号漏洞挖掘案例</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485323&amp;idx=1&amp;sn=ac6922e3b021da2f2f2b8bf3ecbfea55</link><description>OAuth2.0劫持账号漏洞挖掘案例</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-07-23T11:41:19</pubDate></item><item><title>几个常见场景下的xss漏洞案例</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485308&amp;idx=1&amp;sn=8fd476749a377051421b01bf2e950ee9</link><description>几个常见场景下的xss漏洞案例</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-07-09T16:50:22</pubDate></item><item><title>付费网安圈到底值不值？</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485274&amp;idx=1&amp;sn=cd39dd82e806b36f63668b461db050a9</link><description>12小时实时答疑 + 原创漏洞圈，才算值。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-06-20T17:16:54</pubDate></item><item><title>sql注入绕过雷池WAF测试</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485261&amp;idx=1&amp;sn=906d250e8ebf30965435b4e2d2ae06d4</link><description>sql注入绕过雷池WAF测试</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-06-18T10:00:19</pubDate></item><item><title>绑定微信功能挖掘的 0-Click 任意账号接管漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485199&amp;idx=1&amp;sn=0be243d7fee8f9b532ee3d2741d818fe</link><description>绑定微信功能挖掘的 0-Click 任意账号接管漏洞</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-06-11T14:30:27</pubDate></item><item><title>PostgreSQL数据库绕过单引号和括号进行sql注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485161&amp;idx=1&amp;sn=7904bc9405113c6ed4899970286a849c</link><description>PostgreSQL数据库绕过单引号和括号进行sql注入</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-06-04T17:30:40</pubDate></item><item><title>某众测项目下的光速捡洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485126&amp;idx=1&amp;sn=95b7c7c69fbd0d7fcca69e9d0a4d59f2</link><description>某众测项目下的光速捡洞</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-05-29T17:30:18</pubDate></item><item><title>一次异常艰难的sql注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485107&amp;idx=1&amp;sn=d76d60665a15aa6043b7945831f3c6c8</link><description>一次异常艰难的sql注入</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-05-27T18:04:35</pubDate></item><item><title>一次edu站点从前台sql注入到后台rce</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485083&amp;idx=1&amp;sn=cb851893d4ab208b12e467f1dfd3fd6c</link><description>一次edu站点从前台sql注入到后台rce</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-05-12T17:19:52</pubDate></item><item><title>第二届“Parloo杯”CTF 应急响应挑战赛正式启动啦！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485051&amp;idx=1&amp;sn=fee06fd9b420430fdf13361d88e51f03</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-05-07T10:23:30</pubDate></item><item><title>无问社区 - 免费畅享网安技术资源，轻松度过护网</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485045&amp;idx=1&amp;sn=ca09d8c27593359092f319679872965a</link><description>免费使用网安大模型及百万网安技术资料库</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-05-04T11:00:59</pubDate></item><item><title>超简单的众测挖洞经验分享</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485042&amp;idx=1&amp;sn=cc988eaf080703f74145e79dbfee0997</link><description>超简单的众测挖洞经验分享</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-04-29T16:00:59</pubDate></item><item><title>攻防第一天，内网又穿了？</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485018&amp;idx=1&amp;sn=301acbe3172ca8a390030101a45b2624</link><description>序言u2003u2003记一次三天1.3w分拿下靶标过程复盘总结突破u2003u2003通过互联网公开的web服务，针对子域名信息收集到目标</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-04-24T09:36:01</pubDate></item><item><title>汉堡白吃？某连锁餐饮 App 竟藏\"0元购\"漏洞！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247485014&amp;idx=1&amp;sn=1dd0782f1c6e77e88e56b004c111e1b6</link><description>作为一名日常喜欢点外卖、又喜欢吃汉堡的苦逼大学生，我最近在某汉堡连锁店的点餐小程序里，发现了一个支付逻辑漏洞，可以实现0元购。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-04-19T23:16:17</pubDate></item><item><title>一次VUE环境下的渗透测试</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484990&amp;idx=1&amp;sn=9808e7e94de371caa6b146c4875403d9</link><description>一次VUE环境下的渗透测试</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-04-18T17:45:51</pubDate></item><item><title>想学代码审计的师傅进来了！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484940&amp;idx=1&amp;sn=71c4817aa40e2a016ba795e4506b1f14</link><description>想学代码审计的师傅进来了！(现在报名有额外福利赠送)</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-28T10:00:26</pubDate></item><item><title>安卓模拟器系统安卓高版本配置Burp抓包教程，全网最详细！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484931&amp;idx=1&amp;sn=bdf6986043916aeb3ee8441c62857e96</link><description>安卓模拟器系统安卓高版本配置Burp抓包教程，全网最详细！</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-24T10:30:41</pubDate></item><item><title>2025年HW专项启动！免费培训-面试指导助你通关！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484929&amp;idx=1&amp;sn=f053027785b80455d01b9b6bbf2c8e95</link><description>2025年HW专项启动！免费培训-面试指导助你通关！</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-23T00:06:31</pubDate></item><item><title>巧妙利用参数污染进行sql注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484916&amp;idx=1&amp;sn=2c3f75edf4397167849e20fa53724cfb</link><description>巧妙利用参数污染进行sql注入</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-22T14:00:15</pubDate></item><item><title>【2025HW招聘】- 河南宁云志</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484913&amp;idx=1&amp;sn=54db5d73bf3b154b4732585a2a91d4e8</link><description>河南宁云志25年国HW招聘前言：2025国家级护网将要开始，我们开启人才筹备计划。此计划旨在为甲方提供高质量</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-21T15:41:44</pubDate></item><item><title>无问网安模型实战 | sql注入 bypass</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484895&amp;idx=1&amp;sn=ff3512d6e83395dcfef8ce8fee56d4f1</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-13T16:03:33</pubDate></item><item><title>mysql盲注小技巧（众测捡洞之路）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484872&amp;idx=1&amp;sn=a4508150f9669446ade763ce343333da</link><description>mysql盲注小技巧（众测捡洞之路）</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-09T12:31:05</pubDate></item><item><title>hc哥vs挖洞之神</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484845&amp;idx=1&amp;sn=7fd884bc69895c8f044120b01db98a73</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-03-04T11:40:37</pubDate></item><item><title>护网踩坑? 合同陷阱?</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484832&amp;idx=1&amp;sn=b123e53ab06bb28c40c86b1104b7d5d1</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-02-21T21:00:40</pubDate></item><item><title>实战 | 供应链渗透之资产多方面信息收集（一）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484826&amp;idx=1&amp;sn=d9ba75ae855355f03e9431442fe97d23</link><description>供应链渗透之资产多方面信息收集，挖到通用漏洞多维度寻找资产</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-02-09T20:08:51</pubDate></item><item><title>无问社区|春节大放送</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484823&amp;idx=1&amp;sn=79c8d9e62761290554ec8eda780fba9c</link><description>推荐一个白帽子交流学习的公益社区</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-01-18T16:00:52</pubDate></item><item><title>sql注入之无列名注数据详解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484812&amp;idx=1&amp;sn=9c59b82c3fc8797de6dba73d331c9f12</link><description>在CTF中会经常遇到的无列名注数据原理详解</description><author>起凡安全</author><category>起凡安全</category><pubDate>2025-01-14T20:10:23</pubDate></item><item><title>年末最后EDUSRC邀请码送一波！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484747&amp;idx=1&amp;sn=2d325d931ffd59aec09244132d4e646d</link><description>年末最后EDUSRC邀请码送一波！</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-12-30T10:00:20</pubDate></item><item><title>开启渗透测试工程师职业进阶的超燃引擎！！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484729&amp;idx=1&amp;sn=64170a070410377ac23b1be337dfc457</link><description>开启渗透测试工程师职业进阶的超燃引擎！！</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-12-05T10:30:11</pubDate></item><item><title>某SRC中的Oracle数据库sql注入-从判断到注表</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484717&amp;idx=1&amp;sn=1827342dd584f960e8f5a0d021f7da4b</link><description>某SRC中的Oracle数据库sql注入-从判断到注表</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-12-03T13:00:11</pubDate></item><item><title>域内密码喷洒详解</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484690&amp;idx=1&amp;sn=d3b239d2166cc7f0a9345ed7c3da5537</link><description>关于域内密码喷洒详解</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-12-02T20:03:27</pubDate></item><item><title>【北京安全招聘】丈八网安直招（北京西铁营附近），多个安全岗位招聘</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484666&amp;idx=1&amp;sn=2dbb43818fe81de6a058c28270fed452</link><description>北京西铁营附近多个安全岗位招聘，文末附投递方式</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-11-29T10:30:55</pubDate></item><item><title>与牛子哥自研后门的一次对抗经历</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484662&amp;idx=1&amp;sn=9e6d1d17e544f0db5932073524ec404e</link><description>自研后门，自带微软签名。VT杀软全绿</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-11-28T13:00:12</pubDate></item><item><title>【北京招聘】北京西铁营附近多个安全岗位招聘</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484581&amp;idx=1&amp;sn=3ba4a202fb973a89c3c0c42b68408037</link><description>北京西铁营附近多个安全岗位招聘，文末附投递方式</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-11-22T13:40:37</pubDate></item><item><title>几个常见的越权漏洞挖掘案例</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484575&amp;idx=1&amp;sn=abd69fc656d121c2d04f7988fa8a2bee</link><description>几个常见的越权漏洞挖掘案例</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-11-20T17:31:05</pubDate></item><item><title>SRC中的几个sql注入挖掘过程</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484539&amp;idx=1&amp;sn=5eb566fbb603172826f8ce28904e5987</link><description>SRC中的几个sql注入挖掘过程</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-11-09T20:50:41</pubDate></item><item><title>几款常用域渗透工具分享</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484451&amp;idx=1&amp;sn=d5d2b47bd762dea29f958211ef19036d</link><description>几款常用域渗透工具分享，后台私信域工具获取详细文档</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-27T14:00:30</pubDate></item><item><title>一次绕过Burp检测的水洞记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484389&amp;idx=1&amp;sn=62983930f351817b1b453631bd0d490e</link><description>一次绕过Burp检测的水洞记录</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-21T15:03:44</pubDate></item><item><title>一次简单的sql注入挖掘绕过记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484356&amp;idx=1&amp;sn=57ce25a038a8e99d2844567d709d715d</link><description>一次简单的sql注入挖掘绕过记录</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-17T10:00:36</pubDate></item><item><title>ProxyCat：stras过千的优秀代理池中间件</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484328&amp;idx=1&amp;sn=5606781115ed52f14aea19a548edfcba</link><description>ProxyCat：stras过千的优秀代理池中间件</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-16T15:47:41</pubDate></item><item><title>游魂-新一代webshell管理工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484319&amp;idx=1&amp;sn=f3fe5680d6e6255ceb9c87a8d7b177b8</link><description>游魂-新一代webshell管理工具</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-11T16:17:15</pubDate></item><item><title>SQL注入个人手工测试思路</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484316&amp;idx=1&amp;sn=7f8631bc28050f83ed8b21ecec226aeb</link><description>sql注入手工挖掘测试思路</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-10-10T13:28:48</pubDate></item><item><title>EDU两个证书站的漏洞挖掘记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484272&amp;idx=1&amp;sn=791fc40b0ef20f23c61c37b194350956</link><description>两个EDU证书站的测试记录</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-09-27T13:04:45</pubDate></item><item><title>一次攻防演练记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484227&amp;idx=1&amp;sn=9a2942201acad0a36065c0cdd4ff452f</link><description>一次攻防演练记录</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-09-12T10:09:49</pubDate></item><item><title>edu学校src挖掘漏洞思路及案例</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484122&amp;idx=1&amp;sn=2c425961c71ead30b7cfa0bf96561264</link><description>edu学校src挖掘漏洞思路及案例</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-08-15T19:32:15</pubDate></item><item><title>xss测试利用总结（附个人常用payload）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484073&amp;idx=1&amp;sn=24f398e064d333f1bedf4cc1d4e36fdd</link><description>xss测试利用总结（附个人常用payload）</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-07-23T17:15:50</pubDate></item><item><title>一款基于FOFA API的图形化工具-fofaEX</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247484016&amp;idx=1&amp;sn=4723235d536779c293766dbfb08af11b</link><description>一款基于fofa API的图形化信息收集工具</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-07-08T19:33:42</pubDate></item><item><title>EDU学校漏洞挖掘思路整理</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483984&amp;idx=1&amp;sn=c7aef605f6b2863967e14978d108e29a</link><description>个人EDU挖掘思路整理</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-06-17T18:03:15</pubDate></item><item><title>EDU某大学办公系统sql注入挖掘绕过记录</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483963&amp;idx=1&amp;sn=e888021185714cee5f2372494368e21f</link><description>EDU某大学办公系统sql注入挖掘绕过记录</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-06-15T19:11:00</pubDate></item><item><title>使用JSRPC实现前端加密破解，自动化加密</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483939&amp;idx=1&amp;sn=60d5970754e307187353e85387005005</link><description>通过JSRPC实现前端加密破解，不需要去扣代码细节，只需要找到加密函数即可编写代码调用来实现自动化加密</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-06-14T17:59:21</pubDate></item><item><title>Fastjson反序列化漏洞深度分析</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483902&amp;idx=1&amp;sn=2742f2bdd57db09b5e1f0e46ee4f5a36</link><description>本文主要分析当我们打了fastjson payload之后具体是怎么实现反序列化的，以及相关利用链的详细分析</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-06-12T10:34:05</pubDate></item><item><title>windows令牌窃取原理及手动实现</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483832&amp;idx=1&amp;sn=b566609ebfa1cd5e41c798467982ba1a</link><description>在内网渗透中，令牌窃取只能窃取当前用户或者比当前用户权限低的令牌，利用msf中的incognito模块可以列出利用令牌，本文主要分析一下关于windows令牌窃取的原理以及手动实现。</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-06-05T18:15:50</pubDate></item><item><title>2024护网蓝队面试题</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483786&amp;idx=1&amp;sn=d69b76a7d9d355193f8d555e789f6edb</link><description>以下均为近期面试遇到的问题，有些问题也比较偏红队，答案仅作参考，错误之处，多多包涵</description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-04-15T09:48:24</pubDate></item><item><title>不懂js遇到前端加密该如何进行JS逆向</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483780&amp;idx=1&amp;sn=1fdbdb8e34cf8259db77678292bfe95b</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-03-27T10:31:32</pubDate></item><item><title>Kerberos 协议认证流程和相关安全问题</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483740&amp;idx=1&amp;sn=d5477d871bbe3201a755aa5b9b2dd1e3</link><description></description><author>起凡安全</author><category>起凡安全</category><pubDate>2024-03-19T09:26:16</pubDate></item><item><title>sql注入报错注入案例分享</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483727&amp;idx=1&amp;sn=97161039709d3c44e0b482d93ffccfeb</link><description>前言这个系统是扫c段扫到的，通过弱口令进来，后端是java，功能点很多，好像做了全局的预编译也做了鉴权，找s</description><author>起凡安全</author><category>起凡安全</category><pubDate>2023-12-06T17:14:28</pubDate></item><item><title>实战挖洞之任意用户名密码修改</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODUzMjA1MQ==&amp;mid=2247483702&amp;idx=1&amp;sn=e32bd7ee9e66868c1f75427ce4693c22</link><description>一 前言    漏洞逻辑比较简单，技术含量不高，主要分享下思路，如何从修改任意用户密码到想修改谁的密码就修改</description><author>起凡安全</author><category>起凡安全</category><pubDate>2023-08-17T19:20:15</pubDate></item></channel></rss>