Skip to main content

Posts

2025

上班的生活-记录开始
·19 words·1 min
JAVA-内存马+servlet+Filter
·346 words·2 mins
JavaEE代码审计-鉴权逻辑
·393 words·2 mins
JavaEECC1链条持续更新+fastjson1.2.24+log4j
·1894 words·9 mins
JavaEE代码审计-文件操作
·773 words·4 mins
NPS-内网攻防信息打点工具
·467 words·3 mins
JavaEE代码审计-sql注入
·684 words·4 mins
PHP11-Laravel-代码审计
·305 words·2 mins
PHP10-thinkphp-RCE
·112 words·1 min
PHP代码审计9-框架-YII
·263 words·2 mins
PHP代码审计8-XXE-XSS
·272 words·2 mins
PHP代码审计7-变量覆盖
·190 words·1 min
MVC-PHP代码审计6-框架-文件包含
·151 words·1 min
Maze-GuoQing靶机!
·129 words·1 min
MVC-PHP代码审计5-框架-反序列化构建链
·249 words·2 mins
MVC-PHP代码审计4-框架-SQL注入
·309 words·2 mins
Logi靶机-maze-JWT-Ti15中国队加油!
·265 words·2 mins
readfile靶机-maze-snmp-rbash-能力机制
·723 words·4 mins
MVC-PHP代码审计3-反序列化-原生-框架-phar
·452 words·3 mins
MVC-PHP代码审计2
·204 words·1 min
MVC-PHP代码审计
·336 words·2 mins
Dockerfile-使用-docker语法
·434 words·3 mins
Apache-nginx安装-配置文件修改+linux,windows常用命令
·253 words·2 mins
Weblogic-拿到密钥解密
·45 words·1 min
原生PHP代码审计-文件方面
·245 words·2 mins
原生PHP代码审计-sql注入
·263 words·2 mins
Halfhour靶机-Maze-通配符漏洞
·371 words·2 mins
Confidence靶机-Maze-windows
·1616 words·8 mins
Mount靶机-maze
·525 words·3 mins
vmware-esxi-vscenter-靶场vulntarget-o
·219 words·2 mins
poppips-mazasec
·1025 words·5 mins
fluffy-htb
·930 words·5 mins
Editor-htb
·260 words·2 mins
K8s-3-靶场渗透
·218 words·2 mins
K8s-2-未授权访问-proxy
·931 words·5 mins
K8s-1-未授权访问
·977 words·5 mins
Pane12靶机-VITE
·27 words·1 min
Docker-逃逸-LINux内核漏洞
·216 words·2 mins
CodeTwo靶机-HTB
·157 words·1 min
Docker-逃逸-本身漏洞-CDK工具使用
·241 words·2 mins
Docker-逃逸-安全
·274 words·2 mins
云上服务-OSS存储桶渗透-AKSK两种利用特征
·272 words·2 mins
JWT渗透相关
·125 words·1 min
红日靶场4
·242 words·2 mins
XuanJi靶机---难度low知识点-Git,TOTP
·45 words·1 min
Wechat渗透相关抓包反编译
·56 words·1 min
nuclei-POC编写
·248 words·2 mins
自动化漏洞扫描工具
·65 words·1 min
APP脱壳
·43 words·1 min
红日靶场1-CS内网渗透
·136 words·1 min
红日靶场7-WP-MS17-010-WMI-laravel-docker-exp
CS怎么上线LINUX
·18 words·1 min
APP动态调试
·26 words·1 min
APP-逆向修改
·38 words·1 min
APP-安卓9模拟器抓包设置-绕过双向验证
·63 words·1 min
APP-安卓9模拟器抓包设置-安装系统BP证书
·136 words·1 min
ActiveMQ-RocketMQ-Kafka-CVE
·90 words·1 min
THINKPHP-laravel-SpringBoot-Gateway-Struct2 CVE
·97 words·1 min
Fastjson
·96 words·1 min
CVE-java-jackson-xstream-fastjson
·109 words·1 min
CVE-vulfocus-apache-tomcat-jetty-weblogic
CVE-java-solr-log4j-shiro
·77 words·1 min
sudo靶机---难度low知识点-爆破-sudoers
·30 words·1 min
CVE-vulfocus-vulhub-redis-couchdb-H2DB
·200 words·1 min
websocket-messages-to-exploit-vulnerabilities
·192 words·1 min
language靶机---难度easy知识点-docker逃逸-爆破
·144 words·1 min
hoshi靶机---难度medium知识点-文件包含+表达式注入+盲水印
·134 words·1 min
yibasuo靶机---难度easy知识点-nail
·39 words·1 min
gigachad靶机---难度easy知识点-nail
·18 words·1 min
talk靶机---难度easy知识点-SQL注入
·170 words·1 min
matrix靶机---难度easy知识点-表达式注入
·202 words·1 min
pwn-tool
·106 words·1 min
insomnia靶机---难度easy知识点-分号截断
·90 words·1 min
vulny靶机---难度easy知识点-file-manager
·78 words·1 min
Locker靶机---难度easy知识点-分号截断,Sulogin
·150 words·1 min
observe靶机---难度low知识点-fuzz-ln
·49 words·1 min
flower靶机---难度low知识点-base64-py
·63 words·1 min
mixue靶机---难度群友知识点-logic-monitor.我冰城呢
·51 words·1 min
ximai靶机---难度LOW-easy-知识点-wp-sqlmap-wpplugin
·154 words·1 min
受益匪浅translate靶机---难度LOW-easy-知识点-tmp-定时任务-socat
·77 words·1 min
大窑dayao靶机---难度LOW-知识点-tftp-udp-定时任务
·64 words·1 min
connection靶机---难度LOW-知识点-smb-enm4linux
·50 words·1 min
baseme靶机---难度LOW-知识点-爆破ssh密钥-base64语法-
·95 words·1 min
VUlNyx-infected靶机---难度LOW-知识点-backdoor-module
·43 words·1 min
Vulnyx-agent靶机-LOW-知识点-Agent-dirb工具
·66 words·1 min
群友Qingmei靶机-LOW-知识点-SSH
·75 words·1 min
Commit靶机---难度LOW-知识点-bash_history
·58 words·1 min
Loower靶机---难度LOW-知识点-SSH观察
·26 words·1 min