DDCTF 2019 部分WP - 淚笑 淚笑 6 years 4 months ago WEB 滴~ http://117.51.150.246/index.php?jpg=TmpZMlF6WXhOamN5UlRaQk56QTJOdz09 观察链接可发现jpg的值是文件名转hex再base64编码两次得到,由此得到任意文件读取漏洞 读取index.php http://117.51.1 淚笑
CVE-2019-11243 Kubernetes Official CVE Feed 6 years 4 months ago rest.AnonymousClientConfig() does not remove the serviceaccount credentials from config created by rest.InClusterConfig()
If I Had To Do It Over Again, Part 3 F5 Labs 6 years 4 months ago More stories from CISOs who describe how they would “do it over” again in some of their early security program deployments.
Regional Threat Perspectives: Europe F5 Labs 6 years 4 months ago Attackers are using IP addresses in the Netherlands, United States, and China to target systems in Europe over SIP, Microsoft SMB, and SSH.
CVE-2019-11244 Kubernetes Official CVE Feed 6 years 4 months ago `kubectl:-http-cache=<world-accessible dir>` creates world-writeable cached schema files
挖掘src漏洞 Posts on 青鸟的博客 6 years 4 months ago 前言 挖src也将近两个月了,写篇博客总结一下. 首先挖洞成果 3中危 2低危, 收入~2k. 真实菜到扣脚,收入连泡面都吃不起.只挖了bilibili
真真假假的创新 - RSAC2019之三 DJ的札记 6 years 4 months ago RSAC2019已近余波消散,再回头看看会上的热点,并以此展开写创新,是个不错的选择。无论议题或大厂展台或初创博览,创新处处可见。如果参与者自己未曾留意或根本看不到,从而评论说缺乏创新,那未免大大委屈了此次业界盛会。
真真假假的创新 - RSAC2019之三 DJ的札记 6 years 4 months ago RSAC2019已近余波消散,再回头看看会上的热点,并以此展开写创新,是个不错的选择。无论议题或大厂展台或初创博览,创新处处可见。如果参与者自己未曾留意或根本看不到,从而评论说缺乏创新,那未免大大委屈了此次业界盛会。
真真假假的创新 - RSAC2019之三 DJ的札记 6 years 4 months ago RSAC2019已近余波消散,再回头看看会上的热点,并以此展开写创新,是个不错的选择。无论议题或大厂展台或初创博览,创新处处可见。如果参与者自己未曾留意或根本看不到,从而评论说缺乏创新,那未免大大委屈了此次业界盛会。
真真假假的创新 - RSAC2019之三 DJ的札记 6 years 4 months ago RSAC2019已近余波消散,再回头看看会上的热点,并以此展开写创新,是个不错的选择。无论议题或大厂展台或初创博览,创新处处可见。如果参与者自己未曾留意或根本看不到,从而评论说缺乏创新,那未免大大委屈了此次业界盛会。
真真假假的创新 - RSAC2019之三 DJ的札记 6 years 4 months ago RSAC2019已近余波消散,再回头看看会上的热点,并以此展开写创新,是个不错的选择。无论议题或大厂展台或初创博览,创新处处可见。如果参与者自己未曾留意或根本看不到,从而评论说缺乏创新,那未免大大委屈了此次业界盛会。
Director-General remarks: Select Committee Inquiry into the 2017 General Election and 2016 Local Elections Government Communications Security Bureau 6 years 4 months ago
Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in March 2019 F5 Labs 6 years 5 months ago In March, threat actors focused on targeting vulnerabilities released in the last few months. WordPress Easy SMTP Plugin Authentication Bypass vulnerability attacks had the most impact during that time frame.