Aggregator
HackTheBox Authority [ansible hash crack + ESC1 attack + pass-the-cert attack]
10 months 3 weeks ago
简述
本文是medium难度的HTB authority机器的域渗透部分,其中ansible hash crack + ESC1 attack + pass-the-cert attack等域渗透只是细节是此box的特色,主要参考0xdf’s blog authority walkthrough和HTB的authority官方writeup paper记录这篇博客加深记忆和理解,及供后续做深入研究查阅,备忘。
253
【独家】猎影实验室起底Kuiper勒索组织并支持解密
10 months 3 weeks ago
国内首个Kuiper勒索组织揭秘报告
锦衣夜行 | 首届BUGPWN TSCM黑盒挑战赛 • 顺利闭幕
10 months 3 weeks ago
首届国际TSCM反窃密挑战赛闭幕,感谢大家,2024再见
【处置手册】Apache Struts路径穿越文件上传漏洞S2-066(CVE-2023-50164)
10 months 3 weeks ago
近日,绿盟科技CERT监测到Apache官方发布安全公告,修复了一个Struts的路径穿越文件上传漏洞S2-066(CVE-2023-50164)。目前PoC已公开,请受影响的用户尽快采取措施进行防护。
RABET-V: A New Approach to Testing Election Technology
10 months 3 weeks ago
The traditional testing approach for non-voting technology constrains election security. Learn how RABET-V does things differently.
Akamai EdgeWorkers for SaaS: Balancing Customization and Security
10 months 3 weeks ago
Aaron Alquist
来了!你要的安卓系统定制全方位指南
10 months 3 weeks ago
Researching the hard problems in hardware security
10 months 3 weeks ago
Introducing the next chapter of the NCSC research problem book, which aims to inspire research on the biggest impact topics in hardware cyber security.
Go 模块库劫持 (repojacking) 介绍 from VulnCheck
10 months 3 weeks ago
Go 模块库劫持 (repojacking) 介绍 from VulnCheck
活动 | 反爬活动解锁新业务,全线3倍奖励等你来~
10 months 3 weeks ago
测试范围更新,到店反爬等你来测!
【风险通告】Apache Struts2 目录遍历漏洞(CVE-2023-50164)
10 months 3 weeks ago
2023年12月4日,Apache 官方披露 CVE-2023-50164 Apache Struts2 目录遍历漏洞。
如何持续保持精力旺盛
10 months 3 weeks ago
想要长期同时保持这几点其实是一件挺难的事情,我们需要持续正确的完成这里面的每一个动作,才能持续保持热情。
不通过互连网向iPhone传文件
10 months 3 weeks ago
不通过互连网也不借助额外软件从Windows传输文件到iPhone
每周云安全资讯-2023年第50周
10 months 3 weeks ago
一站跟进国内外最新云安全热点资讯~
双料冠军!总积分第一!HAC战队的“强网”拟态防御国际精英挑战赛之旅
10 months 3 weeks ago
安恒研究院HAC战队勇夺“强网”拟态防御国际精英挑战赛“互联网赛道”、“车辆网赛道”双冠军
冥河之水
10 months 3 weeks ago
Going Cloud Native, and What ?Portability? Really Means
10 months 3 weeks ago
Jay Jenkins
Fake Account Creation Bots – Part 4
10 months 3 weeks ago
The fourth and final part of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.
2023补天白帽年度盛典不见不散!
10 months 3 weeks ago
2023补天白帽大会即将在深圳召开,欢迎各位师傅的踊跃报名~12月22日,深圳科兴科学园国际会议中心见!