Aggregator
帮好友转-基础安全招聘
1 year 6 months ago
携程,基础安全招聘
Safeguard Medical Devices: New H-ISAC Guidance on Cusp of FDA Rule
1 year 6 months ago
Carley Thornell
Sensor Intel Series: Top CVEs in July 2023
1 year 6 months ago
One old favorite CVE declined by more than half in July, and a new one (to us) was so heavily targeted it ended up ranked fifth out of 72.
15天总结
1 year 6 months ago
点鼠标的猴子
流量背后的阴谋:黑公关的暗流运作与应对之道
1 year 6 months ago
信息技术的发展使得网络通信设备在极大程度上实现了普及,人人都有“麦克风”,自媒体时代随之而来。部分自媒体靠博眼球赚取流量,再以流量为筹码挟持企业,在利益的驱使下,“黑公关”应运而生。
Vulnerability scanning tools and services
1 year 6 months ago
Advice on the choice, implementation and use of automated vulnerability scanning tools for organisations of all sizes.
初学CTF
1 year 6 months ago
flag明文 账号审核
于是第一题就这么顺利的解决掉了
开始小白学习流量分析题, 当然是从最基础的开始啦,使用到的工具是wireshark哪有什么做流量题不用wireshark的啊
打开流量包,最先开始的思路就是搜一下flag这个字符串是否存在于流量包中
于是第一题就这么顺利的解决掉了
像这里的话可观察到flag是存于txt中的,因为是textdata数据
右击-->显示分组字节流
右击协议-->追踪流-->TCP流
即可查看text数据:
2 个帖子 - 2 位参与者
X
近期大型攻防演练观感及未来攻防趋势判断
1 year 6 months ago
在此之前的几年,我一直在百度、贝壳主要负责企业的甲方安全建设,多数时候是直接以防守方的角色参与其中。今年,从过去的一周来看,整体活跃程度是要比往年更热烈的。
我想吹个牛
1 year 6 months ago
中国成色最好的安全新人,在我们这!
APP合规实践3000问之五
1 year 6 months ago
Top 3 Benefits MSSPs & MDRs Receive With GreyNoise
1 year 6 months ago
Many traditional threat intelligence solutions used by MSSPs can have an unintended consequence of creating more noise for your security operations center (SOC) – GreyNoise changes that. In this post, we will take a deeper look at exactly HOW existing GreyNoise MSSP customers are realizing these benefits.
3 Steps to Elevate Your Cybersecurity in a Post-Pandemic World
1 year 6 months ago
As cybercrime grows more sophisticated in the remote work era, you can take three essential steps to fortify your organization against evolving threats.
Sandeep Rath
中孚信息秋季人才招聘|元亨实验室等你来
1 year 6 months ago
【漏洞预警】RARLAB WinRAR代码执行漏洞威胁通告
1 year 6 months ago
1. 通告信息近日,安识科技A-Team团队监测到RARLAB WinRAR中存在一个代码执行漏洞(CVE-
深入浅出Joern(二)CPG与图数据库
1 year 6 months ago
在上篇文章里,我们从Joern入手大致介绍了CPG(Code Property Graph)的设计理念和简单逻辑
但实际上来说,如果想要更深入的了解Joern,CPG和图数据库是绕不开的一个话题。CPG作为一种代码属性图,就必须寻找一种图数据库作为载体,就像我们常用的数据和SQL数据库的关系一样。
旧版本的Joern使用的Gremlin,但后来的开发中换成了OverflowDB,在joern中也完全支持使用OverflowDB的查询语法。
但属性图本身没有什么特异性,比较常见的比如Neo4J,OrientDB或者JanesGraph都支持CPG的表现形式。
但,在这之前,我们首先需要知道,为什么是图?
LoRexxar
小白!终于等到你~
1 year 6 months ago
在VSRC的花园里挖呀挖呀挖~
Akamai World Tour 2023: Let?s Connect on Security and Cloud Innovation
1 year 6 months ago
Adam Karon & Mani Sundaram
ChatGPT and large language models: what's the risk?
1 year 6 months ago
Do loose prompts* sink ships? Exploring the cyber security issues of ChatGPT and LLMs.
CVE-2022-26923 (Certifried) explained
1 year 6 months ago
CVE-2022-26923 is an Active Directory domain privilege escalation vulnerability that enables a privileged user to access the Domain Controller by abusing Active Directory Certificate Service