Aggregator
2018DDCTF writeup
9 months 1 week ago
第二次参加滴滴的比赛,第一次是刚接触CTF不久。身为一个web狗,做出两道逆向题。
这是第二次,总的来说,题目对新人还是蛮友好的,而且还能学到很多东西。
时间方面,也还不错。体验到了肛题的快感。这次…蛮可惜的。差一点就ak了web题。
还好时间不够了。否则后面那道java一定会折磨我许久。
最后,赞一下各位出题师傅,题目很喜欢!
还有安姐姐也辛苦了。这一周,看到安姐姐基本上天天通宵。
丶诺熙
记一次简单的渗透测试
9 months 1 week ago
丶诺熙
2018 0CTF final h4x0rs.date
9 months 1 week ago
当时比赛时,差一点就解出来了。结束前半小时,才发觉获取nonce的漏洞点。
还是太菜了,否则能一跃第四。
这题其实挺有意思的, 赛后仔细想想,好像也不是太难。但是题目真心不错。
最后证实,这题有多种解法,但每一种解法,都感觉学到了很多。
题目链接:https://h4x0rs.date/
丶诺熙
GourdScan V2 配置安全及使用
9 months 1 week ago
最近i春秋举办挖洞活动,于是自己也去凑个热闹。之前听大佬们讲过被动扫描,于是自己搜到了ysrc的这个扫描器。
丶诺熙
MysqlOnline writeup 巅峰极客
9 months 1 week ago
丶诺熙
2018HCTF-share
9 months 1 week ago
本文首发先知社区,文章链接:https://xz.aliyun.com/t/3258
这次比赛感觉比较有意思的一道题。2019 HCTF-share
丶诺熙
2019DDCTF writeup
9 months 1 week ago
本文首发先知社区,文章链接:https://xz.aliyun.com/t/4862
最近打了打DDCTF,本来是无聊打算水一波。最后竟然做high了,硬肛了几天..
以下为本次比赛web题目的WriteUp:
丶诺熙
近两次比赛遇到的node题目简析
9 months 1 week ago
最近水了水国际赛(摸鱼选手),两次比赛都出现了node的题目。感觉挺有意思的,拿来分析一下。
- HackTM CTF 2020 - Draw with us
- nullcon HackIM 2020 - split second
- 自己出的 - node game
丶诺熙
Hexadecimal analysis on Mac - FNDRERIK@
9 months 1 week ago
Hexadecimal analysis on Mac - FNDRERIK@
British telecoms giant BT confirms attempted cyberattack after ransomware gang claims hack
9 months 1 week ago
British telecoms giant BT confirms attempted cyberattack after ransomware gang claims hack
New DroidBot Android banking malware spreads across Europe
9 months 1 week ago
New DroidBot Android banking malware spreads across Europe
SQL Injection Prevention: 6 Strategies
9 months 1 week ago
SQL Injection Prevention: 6 Strategies
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
9 months 1 week ago
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
Senators say U.S. military is failing to secure its phones from foreign spies
9 months 1 week ago
Senators say U.S. military is failing to secure its phones from foreign spies
IAM tech debt: Balancing modernization and legacy identity infrastructure
9 months 1 week ago
IAM tech debt: Balancing modernization and legacy identity infrastructure
CVE-2024-11643 | AllAccessible Accessibility Plugin up to 1.3.4 on WordPress Option Update authorization
9 months 1 week ago
A vulnerability classified as problematic has been found in AllAccessible Accessibility Plugin up to 1.3.4 on WordPress. This affects an unknown part of the component Option Update Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-11643. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-12138 | horilla up to 1.2.1 deserialization
9 months 1 week ago
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-12138. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-53614 | Thinkware Cloud APK 4.3.46 hard-coded key
9 months 1 week ago
A vulnerability was found in Thinkware Cloud APK 4.3.46. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to use of hard-coded cryptographic key
.
The identification of this vulnerability is CVE-2024-53614. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-12182 | DedeCMS 5.7.116 /member/soft_add.php body cross site scripting
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. The manipulation of the argument body leads to cross site scripting.
This vulnerability is handled as CVE-2024-12182. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com