dingtalk RCE 6.3.5钉钉远程代码执行漏洞, remote command/code execute dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true
Read more
暗网|黑客|极客|渗透测试|专注信息安全|数据泄露|隐私保护
dingtalk RCE 6.3.5钉钉远程代码执行漏洞, remote command/code execute dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true
Read more
绕过Razer基于DOM的XSS补丁可以教给我们什么,URI 片段部分永远不会发送到应用程序服务器,在执行代码审查时,我希望更好地了解开发人员的想法。换句话说,我们需要确定上面代码的用途并回答“为什么?”bypassing razers dom based xss filter
Read more
ctf Writeup | Hacky Holidays Writeup,Hacky Holidays Writeup: The notebook of the Grinch’s Punisher,Finding the Grinch’s Hidden Lair
Read more
Go中的SSTI方法混淆SSTI Method Confusion,该应用程序容易受到 SSTI 方法混淆的影响,通过滥用模板在 golang 中的工作方式,我们可以访问该ChangePassword方法并更改管理员的密码,从而允许我们接管管理员帐户并访问/admin
Read more
2022年中继攻击渗透测试综合指南,内部渗透测试团队通过一种称为 NTLM 中继的技术成功地获得了立足点,甚至损害了整个域,在 2022 年撰写这篇博文时,令人惊讶的是,中继仍然非常活跃。这篇博文旨在成为一个全面的资源,将介绍今天继续有效的攻击原语
Read more