Aggregator
Log4shell 小记
3 years 2 months ago
好久没更新博客了~
Sariel.D
冬奥网络安全卫士招募正式启动!
3 years 2 months ago
12月16日,北京冬奥组委技术部组织招募白帽黑客作为“冬奥网络安全卫士”参与北京冬奥会网络安全工作。
Livery Delivers a Seamless Low Latency Streaming Experience with Help from Akamai
3 years 2 months ago
Our new normal has ushered in the advent of hybrid events ? a mix of in-person and virtual events. This has made seamless live streaming with active participation of the audience, both live and remote, more important than ever. Amsterdam-headquartered company Livery is an end-to-end SaaS solution running on the Akamai content distribution network (CDN), which is perfectly suited for interactive sports, interactive learning, and live commerce productions. We?re delighted that they have chosen to work with us to deliver the experience their clients have come to love.
Ina Christova
Codeql 挖洞?
3 years 2 months ago
挖洞神器 codeql?
Log4j_RCE_Tool V1.0 保姆级使用教程
3 years 2 months ago
工具经过了三个版本的迭代,现在已经发布了V1.0正式版,该版本由之前版本的默认内置常见参数方式改为更科学的爬虫爬取参数,自动进行参数识别(识别登陆表单、搜索表单、以及其他常见表单等),提高了测试的准确率与覆盖率;
[译] 不,Web3 不是去中心化
3 years 2 months ago
加密货币社区对元宇宙和 Web3 的狂热仍在继续,大量投资人和开发者前仆后继加入其中。但是,Web3 真的能实现支持者们的种种愿景吗?亦或是另一个镜中月、水中花?也许让历史照进现实,能给我们答案。
Sukka
Magecart Skimmers Are Alive and Well ? Constant Vigilance Is Required
3 years 2 months ago
Magecart skimmers are here to stay, and they?re becoming more sophisticated, more creative, and harder to detect. In this post, we reveal a new skimmer infrastructure that targets ecommerce sites all over the world with advanced methods of detection evasion and obfuscation.
Roman Lvovsky
大咖话安全第十四期 | 林鹏:企业网络安全防御建设
3 years 2 months ago
随着科技的进步,网络的发展越来越完善,企业网络的规模也在日益扩大,一旦企业网络安全失去保障,轻则影响正常办公
Log4shell中被忽视的威胁:BurpSuite插件
3 years 2 months ago
log4shell可以说是这几天最火爆的漏洞,对于红队人员,算是过了个早年。
第十一周/20211213红队推送
3 years 2 months ago
【特别推荐】Log4j2 (CVE-2021-44228) | 域内大杀器
How to Protect Yourself From Holiday Shopping Scammers
3 years 2 months ago
Like many consumers around the world, you’re probably scouring the internet to find the perfect gifts for your friends and...
The post How to Protect Yourself From Holiday Shopping Scammers appeared first on McAfee Blog.
Jasdev Dhaliwal
Kali Linux 工具使用 - 持续更新
3 years 2 months ago
kali工具包详解目录
[译] 捍卫自由的互联网,对 Web3 说不
3 years 2 months ago
作为一个充满泡沫和噱头的新概念,Web3 和元宇宙在区块链的社区中掀起了一波浪潮。鼓吹者坚信 Web3 就是互联网的未来、不惜砸下大把的金钱和精力、希望能在未来中捞一杯羹;而大部分人保持观望的态度。是时候来一点 Web3 的反对意见了。
Sukka
log4j 1.x 与 logback 的鸡肋RCE讨论
3 years 2 months ago
关于log4j1.x 和 logback 的鸡肋 RCE 讨论
log4j 1.x 与 logback 的鸡肋RCE讨论
3 years 2 months ago
0x01 写在前面对 log4j2 漏洞的后续研究中,发现一些有趣的东西,记录分享一下0x02 log4j 真的在任何情况不存在 JNDI注入吗?首先提出一个问题,log4j 真的在任何情况不存...
panda
Explaining the Widespread log4j Vulnerability
3 years 2 months ago
The log4j security vulnerability is one of the most widespread cybersecurity vulnerabilities in recent years. Here's a non-technical explanation of it.
信息安全BP的能力模型
3 years 2 months ago
利用飞机上的时间,自创一套信息安全BP的能力模型,欢迎探讨。
系统安全应急响应指导手册(干货)
3 years 2 months ago
应急响应必备手册
Log4j 严重漏洞修复方案参考
3 years 2 months ago
CVE-2021-44228