Domain Fronted仍然是最佳的C2隐藏手段 - don0t Donot 6 years 4 months ago 各种隐藏C2 Server的方式众多,其中Domain Fronted域前置的方式在2016年低被提出,近些年一直被大家研究利用,本文将结合实践对该技术再次进行介绍,弥补目前网上资料的一些不完整的地方。 don0t
自研Web漏洞扫描器后的几点思考 - don0t Donot 6 years 4 months ago 本文主要记录我在Web漏洞扫描器实践过程中的一些思考,篇幅较长,没有图片,都是文字性叙述,大多结论、论述来自自己的思考、近些年的所见所闻、朋友的交流等,肯定有很多不全面、错误的地方,欢迎指教与交流。 don0t
ThinkPHP5.x命令执行漏洞分析 - don0t Donot 6 years 4 months ago 2018.12.10晚上,看到有人发tp5命令执行,第一眼看到poc大致猜到什么原因,后来看到斗鱼src公众号的分析文章。这里分析记录一下。 don0t
在 macOS 上禁止 App 连网的一个方法 Proteas的专栏 6 years 4 months ago 在 macOS 上禁止 App 连网的一个方法 在 macOS 上可以使用沙盒策略来禁止 App 连网。 App 假设目标 App 的目录结构如下: /Applications/AbcdEfg.app └── Contents ├── Info.plist ├── MacOS │ ├── AbcdEfg ├── PkgInfo ├... Proteas
Director General of the GCSB speech to New Zealand Internet Task Force Annual Conference Government Communications Security Bureau 6 years 5 months ago
Regional Threat Perspectives, Fall 2019: Australia F5 Labs 6 years 5 months ago Attackers probed Australian applications for vulnerabilities on the most commonly used ports, and credential stuffing attacks were prevalent.
Regional Threat Perspectives, Fall 2019: Australia F5 Labs 6 years 5 months ago Attackers probed Australian applications for vulnerabilities on the most commonly used ports, and credential stuffing attacks were prevalent.
Regional Threat Perspectives, Fall 2019: Australia F5 Labs 6 years 5 months ago Attackers probed Australian applications for vulnerabilities on the most commonly used ports, and credential stuffing attacks were prevalent.
Is the Cloud Safe? Part 1: Models and Misadventures F5 Labs 6 years 5 months ago Cloud security breaches happen, but how prevalent and dangerous are they? More than you might think.