<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzOTI2NjUyNA.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Mon, 26 May 2025 17:14:51 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>搭建你自己的rustdesk编译环境！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485265&amp;idx=1&amp;sn=035215d9df23820518a2cc1731e897fd</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2025-05-26T13:28:23</pubDate></item><item><title>TeamViewer 用户到内核的权限提升  CVE-2024-7479 和 CVE-2024-7481</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485251&amp;idx=1&amp;sn=70f618d86ca9074029cc394e6529c2e6</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-11T12:47:24</pubDate></item><item><title>Docker 提权</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485242&amp;idx=1&amp;sn=ecd9e8c1e582b8be6959c23c660959c1</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-08T12:51:04</pubDate></item><item><title>[自动监测]  乌克兰财政部网站发生信息泄露，泄露总计21GB</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485219&amp;idx=1&amp;sn=1772ee9dac6ea9974b5ee989cc7811a0</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-07T12:30:00</pubDate></item><item><title>CVE-2024-9593 WordPress插件的远程代码执行  CVSS 8.3 高危漏洞  EXP</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485211&amp;idx=1&amp;sn=40b15e339a71543089df649613fee107</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-06T12:54:15</pubDate></item><item><title>小米设备 打印后台处理程序存在任意文件写入漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485205&amp;idx=1&amp;sn=3d0b1c9de804d67113f8cd10c834aece</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-04T12:50:32</pubDate></item><item><title>Ivanti  Connect Secure 通过 OpenSSL CRLF 注入的RCE CVE-2024-37404</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485200&amp;idx=1&amp;sn=49d99aba18014ff72a43ea15ba0308de</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-11-01T13:00:27</pubDate></item><item><title>CVE-2024-42640 CVSS评分10.0 - Angular 未经身份验证的远程代码执行 附EXP</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485179&amp;idx=1&amp;sn=fb1f65a038adf001b78dc6ed2d87f706</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-30T12:24:47</pubDate></item><item><title>小米设备存在的几个命令执行漏洞 -- 已提交修复</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485171&amp;idx=1&amp;sn=baf5a1de627effd78991b7a8d3579e50</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-28T12:27:44</pubDate></item><item><title>CVE-2024-9465：Palo Alto Expedition 未经身份验证的 SQL 注入 POC</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485162&amp;idx=1&amp;sn=0d63c7f890eb4563656383fdbb5c295c</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-26T09:59:41</pubDate></item><item><title>[TeamViewer提权漏洞] 从用户到内核的权限提升 CVE-2024-7479、CVE-2024-7481 附poc</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485111&amp;idx=1&amp;sn=39ec68a215bed622e730a2d46e5d4663</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-25T00:00:30</pubDate></item><item><title>SafeLine  一个开源的自托管 WAF，可保护您的 Web 应用程序免受攻击和利用</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485103&amp;idx=1&amp;sn=8df12eb3e9fb8013704595a9204e428a</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-24T11:00:09</pubDate></item><item><title>最新提权漏洞 Windows内核模式驱动特权提升漏洞 CVE-2024-35250</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485102&amp;idx=1&amp;sn=c996aae53a4c3fb1cf10bab755965d60</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-23T12:37:18</pubDate></item><item><title>Gitlab SAML身份认证绕过漏洞 CVE-2024-45409 CVSS评分10.0</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485069&amp;idx=1&amp;sn=7630b78bc6696c009cc3a13894abb0b2</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-22T12:49:51</pubDate></item><item><title>MediaTek MT7622/MT7915 芯片组驱动程序RCE   利用 CVE-2024-20017 4 种不同的方式</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485060&amp;idx=1&amp;sn=88aeba728cbc508c7e8d8a6877287b14</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-10-09T20:45:01</pubDate></item><item><title>记一次Plaid CTF 2014 的一个反序列化挑战</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485052&amp;idx=1&amp;sn=c99c1d7c730915038faeac38d2eb0b82</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-28T20:49:48</pubDate></item><item><title>解密和重放 VPN Cookie 以实现对VPN的渗透</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485037&amp;idx=1&amp;sn=fd77f84e609b84bf76189f23f528b728</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-26T05:00:17</pubDate></item><item><title>关于征集《公共数据授权运营合规要求》参编单位的通知</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485024&amp;idx=1&amp;sn=413174bf9edef881cc11b624bfb44cb2</link><description>公共数据授权运营合规标准，欢迎相关机构及从业者参与</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-25T12:35:57</pubDate></item><item><title>ChatGpt 越狱调教指南 -- github上的那些chatgpt逃逸相关项目大全</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485013&amp;idx=1&amp;sn=a83788bfb79d75309e673639905e6cd5</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-22T22:38:18</pubDate></item><item><title>macOS 日历 0-Click RCE 漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247485008&amp;idx=1&amp;sn=00337e072eff92e67f03b3d57e06fc03</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-20T17:38:11</pubDate></item><item><title>脑洞大开的新型钓鱼方法 -- reCAPTCHA 网络钓鱼</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484997&amp;idx=1&amp;sn=6408afd8d8478e6cacaf36606c0b7ae5</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-19T20:51:20</pubDate></item><item><title>CVE-2024-29847 Ivanti Endpoint Manager AgentPortal 反序列化远程代码执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484986&amp;idx=1&amp;sn=4f277c6cde91fae4518fa651b2cb6b0a</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-18T09:54:23</pubDate></item><item><title>浏览器隐私数据窃取工具 -- HACK BROWSER DATA 海外替代版</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484974&amp;idx=1&amp;sn=d5dcc4d9e794aa230d104590ae976cf1</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-16T21:20:38</pubDate></item><item><title>新一轮 Mirai 僵尸网络又来了 目标Avtech摄像头 CVE-2024-7029 附EXP</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484969&amp;idx=1&amp;sn=0b36540c53fee2e7a64c6f6e5c8ccb6e</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-13T23:23:01</pubDate></item><item><title>[红队技巧] SeamlessPass：利用 Kerberos 票证访问Azure云</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484961&amp;idx=1&amp;sn=c7c5a256f11368c90d316bdda81df3d4</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-09T09:19:35</pubDate></item><item><title>超高危 Wordpress RCE漏洞 CVE-2024-5932 全网资产 5W+ 附POC</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484918&amp;idx=1&amp;sn=0414f876c0d77a66e7f16a319822a208</link><description>poc见最下方阅读原文，欢迎关注。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-05T20:05:47</pubDate></item><item><title>CVE-2024-21413 Microsoft Outlook远程代码执行漏洞 附POC</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484902&amp;idx=1&amp;sn=eae50a81028e28f70c0b9c992a84f2b1</link><description>CVE-2024-21413 是影响 Microsoft Outlook 的关键远程代码执行 （RCE） 漏洞</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-09-01T20:11:03</pubDate></item><item><title>一个针对微信和钉钉用户的MacOS后台木马，安装源居然指向mihoyo.com？是蜜罐还是被黑？</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484896&amp;idx=1&amp;sn=2bd7e5fc7b597fa55c0f942002f6ab12</link><description>2024 年 6 月，我们发现了一个 macOS 版本的 HZ Rat 后门，目标是企业信使钉钉和社交网络和消</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-31T17:39:15</pubDate></item><item><title>2024KCON 黑客大会部分PPT资源</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484884&amp;idx=1&amp;sn=a99b0cec045c35881ebb788946762317</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-29T22:31:20</pubDate></item><item><title>CVE-2023-49965  SPACE-X 星链 路由器漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484870&amp;idx=1&amp;sn=6d5fe993d32922a8f2b07cdf182b5377</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-28T07:00:40</pubDate></item><item><title>云上渗透 之 AWS云上的攻击手法</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484860&amp;idx=1&amp;sn=9f76425cd17aee5b8ddd7daf6dc81946</link><description>本文以AWS为例讲解对于企业上云的渗透思路，各厂商云服务本质差别不大，可直接类推。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-27T01:32:13</pubDate></item><item><title>[提权漏洞] CVE-2024-38054 特权提升漏洞 win11可用 含利用脚本</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484854&amp;idx=1&amp;sn=5ac416b2eaf4283d12d612c8d2b4459f</link><description>漏洞：CVE-2024-38054  发布日期： 2024-07-09漏洞描述：内核流式处理 WOW Thun</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-25T13:51:14</pubDate></item><item><title>记一次简单的Vulnhub渗透 希望以后的每次渗透都能这么简单顺利</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484846&amp;idx=1&amp;sn=86e2805546b4dcfbbd658fcecdb4ac67</link><description>第 1 步：网络扫描首先发现网络上的实时主机：这将扫描网络并列出所有活动的 IP 地址，查找目标 IP 地址。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-22T22:44:40</pubDate></item><item><title>CVE-2024-7928 FastAdmin 任意文件读取 全网20w+潜在风险资产 含批量验证脚本</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484772&amp;idx=1&amp;sn=9a08022aff8607607dc4cc3acb382217</link><description>fofa icon_hash=\\x26quot;-1036943727\\x26quot;漏洞复现：pocGET /index/ajax/lan</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-21T21:38:58</pubDate></item><item><title>今天不日站，打打EDR - 第 3 部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484730&amp;idx=1&amp;sn=313b918688773d1c21028f977c79f731</link><description>本期分享的是三篇高质量的EDR漏洞挖掘相关的文章，提供了很不错的漏洞挖掘思路介绍在本系列的第三部分也是最后一部</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-18T08:46:18</pubDate></item><item><title>今天不日站，打打EDR - 第 2 部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484714&amp;idx=1&amp;sn=04c52f398ecb2092beb2c5eb63b375e0</link><description>本期分享的是三篇高质量的EDR漏洞挖掘相关的文章，提供了很不错的漏洞挖掘思路简介继续我们上次的研究，我们在 S</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-17T06:02:28</pubDate></item><item><title>Windows本地提权漏洞 CVE-2024-21338</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484713&amp;idx=1&amp;sn=234c3686e5e6cd33c5f3f8cb81de28eb</link><description>AppLocker安全功能存在本地提权的(CVE-2024-21338)，允许本机完成身份验证的用户提升至SY</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-16T08:09:29</pubDate></item><item><title>今天不日站，打打EDR 第 1 部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484713&amp;idx=2&amp;sn=4bb7a88161b568029a3cdfaa901a0c9a</link><description>本期分享的是三篇高质量的EDR漏洞挖掘相关的文章，提供了很不错的漏洞挖掘思路介绍我们希望，这篇文章将是一长串文</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-16T08:09:29</pubDate></item><item><title>HW2024验真漏洞情报 8.14</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484690&amp;idx=1&amp;sn=b2ea67eaec909243fe17b441216003fe</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-15T08:03:23</pubDate></item><item><title>开源项目投毒警告提醒-藏在POC代码中的挖矿投毒</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484673&amp;idx=1&amp;sn=268dfdae6d31f178afad62f715d7becd</link><description>近期又发现一起开源投毒事件，CVE-2024-27198在Github的Poc存在投毒，且该项目被很多漏洞库和</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-14T00:37:28</pubDate></item><item><title>HW2024验真漏洞情报 8.12</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484665&amp;idx=1&amp;sn=4bc879bd3234288fea6a699fe362c800</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-13T08:00:33</pubDate></item><item><title>[企业安全运维]大华-DDS数字监控系统-现新漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484658&amp;idx=1&amp;sn=47dc535885c64c8fd94cd36db5d55994</link><description>fofa语法：app=\\x26quot;dahua-DSS\\x26quot;漏洞详情：GET/emap/group_saveGroup?</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-12T21:07:58</pubDate></item><item><title>7k7k.com 小游戏网站数据库被泄露...</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484652&amp;idx=1&amp;sn=3d06e6f2dc1187e64de0dc96c2c15104</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-11T02:51:17</pubDate></item><item><title>Cursor！  真正的AI开发大杀器</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484643&amp;idx=1&amp;sn=22c92f6a78284fb79c058e912f57e021</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-10T07:00:30</pubDate></item><item><title>HW2024验真漏洞情报 8.9</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484643&amp;idx=2&amp;sn=86d2694abc327710469202d9902bd06c</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-10T07:00:30</pubDate></item><item><title>恶意软件开发、分析和 DFIR 系列 - 第 四 部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484643&amp;idx=3&amp;sn=fcb52265471416333a070c6ca2ca35f3</link><description>恶意软件开发、分析和DFIR系列第四部分介绍在这篇文章中，我们将从 Windows 取证的基础知识开始，了解对</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-10T07:00:30</pubDate></item><item><title>HW2024验真漏洞情报 8.8</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484606&amp;idx=1&amp;sn=2fe606fb30d5d3945bf00acf2e1e4781</link><description>A11-2AspCMS--SQL漏洞复现：payload：/plug/comment/commentList.</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-09T08:01:03</pubDate></item><item><title>恶意软件开发、分析和 DFIR 系列 - 第三部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484606&amp;idx=2&amp;sn=1964e01c2656c64dcb3aa27c8fa77d30</link><description>恶意软件开发、分析和DFIR系列第三部分介绍在这篇文章中，我们将深入研究 Windows 内存内部结构，了解如</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-09T08:01:03</pubDate></item><item><title>恶意软件开发、分析和 DFIR 系列 - 第二部分</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484596&amp;idx=1&amp;sn=d24a39b7d9b5193dcbb0ddecf84450c3</link><description>恶意软件开发、分析和DFIR系列第二部分介绍在这篇博客中，我们将介绍 x86 汇编中的重要主题。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-08T08:00:12</pubDate></item><item><title>HW2024验真漏洞情报 8.7</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484596&amp;idx=2&amp;sn=308918e27511d5c37611987a1767a21c</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-08T08:00:12</pubDate></item><item><title>ApacheOFBiz - 最新0Day 含EXP 漏洞编号：CVE-2024-38856 速查速修复！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484558&amp;idx=1&amp;sn=4e0839f8703368fddb2db4063c4f07f8</link><description>漏洞描述：Apache OFBiz是⼀个著名的电⼦商务平台，提供了创建基于最新 J2EE/ XML规范和技术标</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-07T00:00:19</pubDate></item><item><title>HW2024验真漏洞情报 8.5</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484457&amp;idx=1&amp;sn=d22231ae11be465e4fed725d5843bd4a</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-06T08:00:47</pubDate></item><item><title>GPU投毒  在 GPU 内存中隐藏有效负载</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484431&amp;idx=1&amp;sn=27cceca6729054a02ca6652e73e4dfa2</link><description>近期一直在思考新的过AV方案，偶然看到了这个项目，仔细看了一下感觉很有意思，遂分享1- 首先，我们需要设置和初</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-05T08:00:26</pubDate></item><item><title>HW2024验真漏洞情报 8.3</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484425&amp;idx=1&amp;sn=227c9634c5ade124fd28dcd47ab48d96</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-04T07:49:34</pubDate></item><item><title>[企业安全运维] 海康威视现新0day 可未授权致RCE 速查！</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484409&amp;idx=1&amp;sn=f72dcefb7d5608fb375bb480e60b4c05</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-03T14:37:18</pubDate></item><item><title>HW2024验真漏洞情报  8.1</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484392&amp;idx=1&amp;sn=39e65d38f926733f5f97d7dfe48e90f6</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-02T08:00:32</pubDate></item><item><title>HW2024验真漏洞情报. 7.31</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484380&amp;idx=1&amp;sn=668f09a5e7354d9ed9782d0d71778a81</link><description>C16-1喰星云-数字化餐饮服务系统-SQL漏洞复现：payload：GET /logistics/home_</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-08-01T08:03:05</pubDate></item><item><title>HW2024验真漏洞情报 7.30</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484356&amp;idx=1&amp;sn=0cbf4840a47456f59ce46a3652509975</link><description>用友NC FileUploadServlet 反序列化rce漏洞</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-31T08:01:01</pubDate></item><item><title>JAVA注入以实现内存驻留</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484339&amp;idx=1&amp;sn=02417f4dc80b439a282f00447d431e31</link><description>本文将尝试介绍一些用于注入内存中 Java 负载的其他技巧，并通过针对知名应用程序的具体示例进行说明。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-30T08:00:16</pubDate></item><item><title>HW2024验真漏洞情报 7.26</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484334&amp;idx=1&amp;sn=39df89bb74c1a60c84a9838c2c8ab753</link><description>HW2024验真漏洞情报 26日</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-27T00:36:39</pubDate></item><item><title>HW2024-07-23-微步验真漏洞情报合集</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484287&amp;idx=1&amp;sn=efc91d6383368e02390ee047840e4752</link><description>HW2024-07-23-微步验真漏洞情报合集</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-25T00:00:32</pubDate></item><item><title>常见的未授权漏洞检测工具</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484274&amp;idx=1&amp;sn=0aab7cb84c43b54f31ba605ef7d22f54</link><description>常见的未授权漏洞检测工具</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-24T09:09:39</pubDate></item><item><title>渗透测试漏洞挖掘src集成版</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484273&amp;idx=1&amp;sn=e373e308e8f8685cff7b35e828e3bbee</link><description>一款集成了H3C,致远，泛微，万户，帆软，海康威视，金蝶云星空，畅捷通，Struts等多个RCE的漏洞利用工具</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-23T08:00:50</pubDate></item><item><title>用IHxHelpPaneServer代替传统进程注入</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484259&amp;idx=1&amp;sn=aa9dc5ded8fa7680d8a1d4f5701bcf3e</link><description>Process injection alternative</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-22T08:00:10</pubDate></item><item><title>用友U8 CRM 文件上传致RCE漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484240&amp;idx=1&amp;sn=4467be07eab1806b8b59c62abfe5e6f0</link><description>用友U8 CRM 文件上传致RCE漏洞</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-21T15:34:56</pubDate></item><item><title>NAC OS 0day</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484226&amp;idx=1&amp;sn=060f6bd72e328b87355169e06f0dcba1</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-16T07:00:24</pubDate></item><item><title>记一次渗透提权某影视站</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484163&amp;idx=1&amp;sn=8f1d9bfdc949c141cb2b125dbf5e17a2</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-09T21:54:52</pubDate></item><item><title>CVE-2023-34312腾讯QQTIM本地提权.pdf</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484147&amp;idx=1&amp;sn=3a75bdc24abb6cc6e4b22d54ef256ffb</link><description>偶然看到这个漏洞的分析，恰恰好，又找到了可以用的版本，于是顺手复现了一遍这个漏洞影响版本- QQ 9.6.2.</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-07T23:14:10</pubDate></item><item><title>subfinder子域名收集神器 原理剖析</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484120&amp;idx=1&amp;sn=ffd15768333132c444aa92955b6d6a6d</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-05T08:02:19</pubDate></item><item><title>安全开发：进程重影技术 Process_Ghosting</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484095&amp;idx=1&amp;sn=f1cb470283fdc77739ac4df376f861f2</link><description>进程重影是一种进程注入技术，攻击者在该技术中创建一个临时文件，将其标记为删除（删除挂起状态），将恶意软件复制/映射到内存中（图像部分），关闭句柄（将其从磁盘中删除），然后从现在无文件的部分创建进程。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-04T08:01:11</pubDate></item><item><title>CVE-2024-27348 Apache HugeGraph RCE一键利用和分析</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484088&amp;idx=1&amp;sn=d5f345a542b591594684a5fd087831e9</link><description>CVE-2024-27348 是一个远程代码执行 （RCE） 漏洞，存在于 1.3.0 之前版本的 Apach</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-03T07:01:13</pubDate></item><item><title>Free Bug Bounty Course</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484088&amp;idx=2&amp;sn=d83d4f60b1e467f3cc4ce4ff66dc0ff2</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-03T07:01:13</pubDate></item><item><title>CVE-2024-6387</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484088&amp;idx=3&amp;sn=ef00bc534023423e2ef5c2a02fbd3f80</link><description>FOFA Query: app=\\x26quot;OpenSSH\\x26quot;昨晚看到tg上有人发poc的时候去github搜了一下，唯一</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-03T07:01:13</pubDate></item><item><title>深入分析 Windows 系统中的关键痕迹 --HVV备用3</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484010&amp;idx=1&amp;sn=a61b51b5e979a38215863b94ca6695fe</link><description>在进行数字取证和安全事件响应时，分析程序的执行轨迹对于揭示攻击者活动和系统异常行为至关重要。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-02T09:01:03</pubDate></item><item><title>横向渗透痕迹的排查  --HVV备用2</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247484004&amp;idx=1&amp;sn=dbcda9a42775935a8c97c058247a0bae</link><description>横向渗透痕迹的排查，包含 远程桌面、文件共享、psexec、计划任务、服务、wmic、powershell等的源主机与目的主机的排查。</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-07-01T08:00:42</pubDate></item><item><title>查找恶意进程 之 windows正常进程有哪些 --HVV备用1</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483992&amp;idx=1&amp;sn=28b476585d2812500e2f8c0695b8ab5e</link><description>作为一个合格的蓝队人员，上机排查是基本的技能，那么上机时怎么去发现机器上存在的异常进程？</description><author>合规渗透</author><category>合规渗透</category><pubDate>2024-06-30T17:40:47</pubDate></item><item><title>羊了个羊更新后如何修改第二关地图极速通关</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483979&amp;idx=1&amp;sn=b0a73755991c5752d41a76c2419de7e9</link><description>开发者勉强算是大改了，但是地图这些太底层的东西如果改那可真是估计到羊了个羊热度消散都不会说能过关了，修改思路</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-09-20T16:14:43</pubDate></item><item><title>咩了个咩怎么极速通关？</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483969&amp;idx=1&amp;sn=f08396bedd6b5047024fbea1f9462ad5</link><description>羊了个羊最近火了起来，素有第一关教你1+1，第二关直接让你考研的美誉今天抓包看了一下，通过本文对此进行一个概</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-09-16T21:49:54</pubDate></item><item><title>内网信息收集</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483949&amp;idx=1&amp;sn=82921da7d521b79a60e312943ef07cc7</link><description>网络配置信息ipconfig /all查询操作系统及软件信息systeminfo 查看安装的软件及版本路径等</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-09-13T16:51:15</pubDate></item><item><title>简易badusb制作与鱼儿上线</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483819&amp;idx=1&amp;sn=e4403490e6fc7ee15217835849517c3e</link><description>本文badusb基于digispark制作，成本大概14元，淘宝如图Arduino IDE+驱动我用的1.6</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-09-11T23:17:41</pubDate></item><item><title>Linux 入侵类问题排查思路</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483757&amp;idx=1&amp;sn=b2fb7495921388f08f432456a4d44cee</link><description>Linux 入侵类问题排查思路和操作方式</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-08-19T19:54:30</pubDate></item><item><title>Windoews下的应急响应（二）</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483752&amp;idx=1&amp;sn=5b6ceae546d7633f4a9403018f2b950d</link><description>接昨天的内容系统进程检查进程检查一般使用如下几个工具Evaleye.exeprocessExplorer.e</description><author>合规渗透</author><category>合规渗透</category><pubDate>2022-08-18T23:47:14</pubDate></item><item><title>cs 4.4源码</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483713&amp;idx=1&amp;sn=d46f374b280d6acbd869b17dd279d18b</link><description>Cs4.4链接：https://pan.baidu.com/s/1znchapid2mpAV9hMBNKsC</description><author>合规渗透</author><category>合规渗透</category><pubDate>2021-08-26T00:40:29</pubDate></item><item><title>含有token怎么用bp来爆破用户名密码</title><link>https://mp.weixin.qq.com/s?__biz=MzkzOTI2NjUyNA==&amp;mid=2247483668&amp;idx=1&amp;sn=537e7cfdbd1942a6e3c32e98d198fd78</link><description></description><author>合规渗透</author><category>合规渗透</category><pubDate>2021-07-17T20:29:31</pubDate></item></channel></rss>