Aggregator
技术分享|某办公系统代码执行漏洞分析及检测优化
10 months 2 weeks ago
7 reasons why cybercriminals want your personal data
10 months 2 weeks ago
Here's what drives cybercriminals to relentlessly target the personal information of other people – and why you need to guard your data like your life depends on it
解决html2canvas+jspdf 生成pdf 模糊的问题
10 months 2 weeks ago
问题 VUE项目使用html2canvas+jspdf生成PDF,发现不同的电脑,下载下来的文件大小不一样,清晰度也不一样;或者下载的PDF看着清晰,但使用打印 […]
root
2024第四届红明谷 WriteUp By Mini-Venom
10 months 2 weeks ago
欢迎喜欢CTFer加入……
云安全难点解题:云流量采集分析的各种姿势
10 months 2 weeks ago
系统定制技术难点在哪里?
10 months 2 weeks ago
安卓系统定制难点在哪里?
谛听 工控安全月报 | 3月
10 months 2 weeks ago
3月│月报 谛听工控安全月报上线了,工信部的最新政策,3月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
5月重磅 | 企业内控监察专项课程 • 真实测谎
10 months 2 weeks ago
内部调查时,如何判断对方有没有说谎?
先知安全沙龙 - 西安站 4月20日开启!
10 months 2 weeks ago
4月20日,我们西安见~
CVE-2024-3273: D-Link NAS RCE Exploited in the Wild
10 months 2 weeks ago
Stay informed about a critical remote code execution vulnerability affecting D-Link NAS devices. It is being tracked under CVE-2024-3273 and believed to affect as many as 92,000 devices.
Google AI Studio Data Exfiltration via Prompt Injection - Possible Regression and Fix
10 months 2 weeks ago
What I like about the rapid advancements and excitement about AI over the last few years is that we see a resurgence of the testing discipline!
Software testing is hard, and adding AI to the mix does not make it easier at all!
Google AI Studio - Initially not vulnerable to data leakage via image rendering When Google released AI Studio last year I checked for the common image markdown data exfiltration vulnerability and it was not vulnerable.
Как англичане переходили на недопустимые события или как Эйнштейн связан с ИБ?
10 months 2 weeks ago
美国网络安全从业人员规模与收入成色几何
10 months 2 weeks ago
他山之石,可以攻玉。大洋彼岸有多少从业人员,这些从业人员收入如何?
了解 GitHub
10 months 3 weeks ago
这些天对 GitHub 的信息做了些收集整理,看网上没有很完整的信息,发出来共享。
待到山花烂漫时,季度抽奖来预告!
10 months 3 weeks ago
第90篇:美国APT的全球流量监听系统(Turmoil监听与Turbine涡轮)讲解与分析
10 months 3 weeks ago
前言大家好,我是ABC_123。
Palantir告警和检测策略框架简介
10 months 3 weeks ago
标准的安全检测告警框架
OPNSense/PFSense 防火墙安装哪吒监控 Agent
10 months 3 weeks ago
哪吒监控:https.. 阅读更多
glzjin
HackTheBox Rebound [RID cycling + AS-REP-Roasting with Kerberoasting + Weak ACLs + ShadowCredentials attack + cross-session relay + Runascs and KrbRelay read gMSA password + Resource-Based Constrained Delegation (RBCD) + S4U2Self & S4U2Proxy]
10 months 3 weeks ago
简述
本文是Insane难度的HTB Rebound机器的域渗透部分,其中RID cycling + AS-REP-Roasting with Kerberoasting + Weak ACLs + ShadowCredentials attack + cross-session relay + Runascs and KrbRelay read gMSA password + Resource-Based Constrained Delegation (RBCD) + S4U2Self & S4U2Proxy等域渗透提权细节是此box的特色,主要参考0xdf’s blog rebound walkthrough和HTB的rebound官方writeup paper记录这篇博客加深记忆和理解,及供后续做深入研究查阅,备忘。
253