Submit #522423: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522423 / VDB-302024 yaowenxiao
Submit #522421: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522421 / VDB-302023 yaowenxiao
Submit #522420: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522420 / VDB-302022 yaowenxiao
Submit #522419: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522419 / VDB-302021 yaowenxiao
Submit #522418: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522418 / VDB-302020 yaowenxiao
Submit #522417: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522417 / VDB-302019 yaowenxiao
Submit #522416: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522416 / VDB-302018 yaowenxiao
Submit #522415: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522415 / VDB-302017 yaowenxiao
Submit #522414: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522414 / VDB-302016 yaowenxiao
Submit #522413: Concretecms 9.3.9 XSS [Accepted](link is external) Vuldb Submit 6 hours 41 minutes ago Submit #522413 / VDB-302015 yaowenxiao
PicoCTF 2025 - PWN & RE 方向全解(link is external) 先知技术社区 6 hours 53 minutes ago PicoCTF 2025 - PNW & RE 方向全解
glibc中realloc函数源码分析与利用(link is external) 先知技术社区 7 hours 1 minute ago 本文深入解析glibc-2.29中realloc函数的源码,包括不同场景下的内存分配与释放逻辑,如oldmem为空、size为0等特殊情况处理。重点分析了_int_realloc函数在调整堆块大小时的实现细节,以及如何通过unlink操作造成堆块重叠,从而实现对任意地址的覆盖攻击。结合实际CTF赛题,展示了利用off-by-one漏洞修改size字段,进而控制堆布局完成ROP链执行的具体方法。
深入剖析路由器FOTA固件升级流程:从解包到逆向分析(link is external) 先知技术社区 7 hours 20 minutes ago 本文以D-Link DWR-932路由器为例,系统性地剖析了物联网设备中FOTA(固件无线升级)技术的实现流程与安全机制。通过逆向工程与动态分析,揭示了FOTA从固件下载、解包校验到刷写重启的全链路细节,重点拆解了fotad、appmgr、prefota等核心组件的协同逻辑。研究发现,DWR-932采用多进程通信(如Unix域套接字appmgr.us)与分阶段状态机管理升级流程,通过flash_e
小迪安全2024内网靶场-VPC1 & VPC2 & VPC3(link is external) 先知技术社区 7 hours 21 minutes ago 小迪安全2024内网靶场-VPC1 & VPC2 & VPC3