Aggregator
国内开发者的网络超时日常
8 months 2 weeks ago
Life find its way.
三仙归洞
8 months 2 weeks ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
SigmaHQ Rules Release Highlights — r2024–02–12
8 months 2 weeks ago
Nasreddine Bencherchali
甲辰随笔:关于策略性思考
8 months 2 weeks ago
新的一年希望自己能多读书,也会把自己的一些感触记录在这里。想到哪写到哪,不成体系,仅为记录。
Data Matters ? Is Your API Security Data Rich or Data Poor?
8 months 2 weeks ago
Taking a data-rich approach to security is the most effective way to stay a step ahead of today?s quickly evolving API threats.
Abigail Ojeda
DiceCTF 2024 筆記
8 months 2 weeks ago
相比於去年跟前年,今年的 web 題難度有顯著降低了不少,變得更平易近人了,靠著隊友的努力拿下了第一名,而 web 題也只剩一題沒解出來。
這次我基本上只解了簡單的 funnylogin 跟難的 safestlist,其他都是隊友解開的,還有另一題 another-csp 有看了一下,因此這篇只會記我有看過的以及比較難的題目。
如果想看其他題,可以參考其他人的 writeup:
官方提供的所有題目原始碼:https://github.com/dicegang/dicectf-quals-2024-challenges
關鍵字列表:
- crash chromium
- slower css style
- xsleak
- URL length limit
- service worker
- background fetch
- connection pool + css injection
- iframe width + css inection
Huli
Governments Have Zero Reason To Be Flipping Mad About Open Source SDR Tech
8 months 2 weeks ago
Discover insights into the drawbacks of a proposed ban on open-source SDR, and explore the argument for enhanced security measures to strike a balance between innovation and safeguarding against vulnerabilities in wireless systems.
在 JavaScript 中实现和使用 Context
8 months 2 weeks ago
使用过 React 构建应用的开发者对 React Context 一定不会陌生。在 React 的世界中,相比于把 prop 不断透传给下一层子组件(prop-drilling),React Context 可以更优雅地自上而下将数据从父组件传递到深层级的子组件、并确保数据在不同子组件之间保持一致。不过,Context 绝不是仅属于 React,在 JavaScript 中 Context 一样可以大展拳脚。
Sukka
白帽100给大家拜年了~
8 months 3 weeks ago
寒冬下的安全研究
8 months 3 weeks ago
七月在野,八月在宇,九月在户,十月蟋蟀入我床下。
人生海海——2023年终总结
8 months 3 weeks ago
当窗外升起第一朵新年烟花时,当躺平了一整个月的欧洲
Important Active Directory Attribute for Red/Blue Teamer
8 months 3 weeks ago
Active Directory attributes play a crucial role in managing user accounts and group memberships within Windows environments. Attributes such as SAMACCOUNTNAME and USERPRINCIPALNAME are often targeted for username enumeration and phishing attacks. The...
Reza Rashidi
Ransomware payments hit a record high in 2023 – Week in security with Tony Anscombe
8 months 3 weeks ago
Called a "watershed year for ransomware", 2023 marked a reversal from the decline in ransomware payments observed in the previous year
100 Methods for Container Attacks
8 months 3 weeks ago
Insecure Container Images
Using Trivy:
trivy -q -f json : | jq '.[] | select(.Vulnerabilities != null)'
This command uses Trivy, a vulnerability scanner for containers, to scan a specific container image (:
Reza Rashidi
龙腾盛世,瑞气盈门,T00ls给您拜年了,祝福大家新春快乐,所想皆如愿,所盼皆实现
8 months 3 weeks ago
玉兔呈祥辞旧岁,金龙献瑞迎新春。癸卯兔年的脚步声逐渐远去,甲辰龙年的钟声即将敲响。
新春快乐 | 福龙高照,步步无畏!
8 months 3 weeks ago
祝愿DataCon的朋友们,福龙高照,蒸蒸日上,虎步龙行,步步无畏!
龙舞乾坤,星阑科技恭贺大家新春大吉
8 months 3 weeks ago
恭祝新春
8 months 3 weeks ago
[庆祝]Numen cyber 祝大家农历新春愉快,阖家欢乐,万事如意。[爆竹][烟花]
纽创信安祝您新春快乐,龙年大吉!
8 months 3 weeks ago