Aggregator
记一次简单计算验证码的识别过程
某CMS的验证码是简单的计算验证码,都是一位数的加减乘除运算,之前尝试用分割的方法识别,但成功率较低。后来采用了pytorch训练后进行识别,可以达到98%以上的识别率,于是整理一下过程,水一篇文章。
记一次APP爬虫比赛
5月中旬的时候,猿人学举行了一个APP爬虫大赛,共设10题,主要涉及Android反混淆,双向认证,tls指纹对抗等技术。而且只需要答对一题就有参与奖,即可获得一件猿人学定制T恤。另外第一题不涉及so,仅涉及java层加密。为了T恤,立马去报了名参赛。
BlueBleed Data Leak
PenTest Magazine Open Source Toolkit: ropci
Great news!
An article about ropci is in the latest free issue of the Pentest Magazine!
The article has a lot more info then my ropci blog post or the info on the ropci Github repo.
Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools.
Cheers.
Link: https://pentestmag.com/product/pentest-open-source-pentesting-toolkit
ROPC - So, you think you have MFA?
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC.
The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant for ROPC based MFA bypass opportunities.
Github: https://github.com/wunderwuzzi23/ropci
Update: The latest free issue of Pentest Magazine has a ropci article. Check it out.
Securing Applications in a Multicloud World
Student Insights on Cybersecurity Careers
以 Desperate Cat 为始学一些姿势
Trustlook's Integration with OKC (OKX Chain)
San Jose, California, Oct. 19, 2022, Trustlook, the global leader of AI-powered cybersecurity, today announced an integration with OKC (OKX Chain) an EVM-compatible L1 built on Cosmos with a focus on true interoperability (IBC) and maximized performance. Trustlook will provide their extensive portfolio of blockchain security products to OKC, which