Aggregator
攻击面是指什么?为什么对网络安全至关重要?
加速人才流动 #7
加速人才流动 #7
PeiQi文库 - Github更新 (3)
PeiQi文库 - Github更新 (3)
PeiQi文库 - Github更新 (3)
Expanding the scope of Cyber Incident Response (CIR)
8.11HVV情报速递
HVV中GodzillaPlugin-Suo5-MemProxy钓鱼项目分析预警!
Verisign Will Help Strengthen Security with DNSSEC Algorithm Update
As part of Verisign’s ongoing effort to make global internet infrastructure more secure, stable, and resilient, we will soon make an important technology update to how we protect the top-level domains (TLDs) we operate. The vast majority of internet users won’t notice any difference, but the update will support enhanced security for several Verisign-operated TLDs […]
The post Verisign Will Help Strengthen Security with DNSSEC Algorithm Update appeared first on Verisign Blog.
RealWorld|针对某特殊群体的供应链打击2
Simplifying BOF Development: Debug, Test, and Save Your B(e)acon
Beacon Object Files (BOFs) were introduced in Cobalt Strike 4.1 in 2020. Since their release, BOFs have played a key role in post-exploitation activities, surpassing Reflective DLLs, .NET assemblies, and PowerShell scripts. However, in our experience, many developers struggle with four primary pain points: In this blog post, we will tackle these difficulties by introducing [...]
Read More... from Simplifying BOF Development: Debug, Test, and Save Your B(e)acon
The post Simplifying BOF Development: Debug, Test, and Save Your B(e)acon appeared first on Cobalt Strike.
利用yakit功能特性溯源攻击者
Episode 007 - Ryan Irving
Embarking on a career in the cybersecurity field can be a daunting task for those entering the classroom to learn about its ever-evolving challenges of the field. In our newest podcast, we’ll explore the indispensable role of mentors in helping to guide and shape the careers of cyber newcomers.
Ryan Irving, a seasoned cyber professional, who serves as the Security Operations Center Manager, leads a student-operated Security Operations Center (SOC) as part of a degree program at the University of South Florida. The program integrates academia with real-world application and gives students an opportunity to develop the attributes that can contribute to their success as defenders.
Join us for this month’s podcast, “Paving the Path for Cybersecurity Students,” as we discuss the essence of mentorship and explore the ever-evolving field of cybersecurity.
Find him here:
Linkedin: http://linkedin.com/in/ryan-i-63581229
Twitter: https://twitter.com/rirving77
Cyber Florida, University of South Florida: https://cyberflorida.org/
Trend Micro Empowers Organizations to Tackle Malicious AI
一次edu存储型XSS挖掘过程
对目标站进行子域收集。
浏览了一下爆破出来的站点,发现有个数字图书馆,访问之,界面默认直接是一个test用户,点击直接登陆
登陆后,文章用户评论界面评论处插入xsspayload,存在过滤
进入用户界面修改评论
在修改框处插入xss fuzz payload,可以成功弹框。
2 个帖子 - 1 位参与者