全部安全开发新闻数码摄影汽车北京AIIT其他
  • 文章封面

    Chrome 浏览器漏洞利用 (一):V8 引擎与 JavaScript 内部机制入门

    作者:securitainment发布日期:2026-03-04 13:37:00

    原文链接作者https://jhalon.github.io/chrome-browser-exploitation-1/Jack HalonWeb 浏览器——我们连接互联网的主要门户。如今浏览器在现

    阅读全文
  • 文章封面

    Chrome 浏览器漏洞利用 (二): Ignition 解释器、Sparkplug 编译器与 TurboFan JIT 优化详解

    作者:securitainment发布日期:2026-03-04 13:37:00

    原文链接作者https://jhalon.github.io/chrome-browser-exploitation-2/Jack Halon在我的上一篇文章 "Chrome Browser Expl

    阅读全文
  • 文章封面

    Chrome 浏览器漏洞利用 (三):CVE-2018-17463 分析与利用

    作者:securitainment发布日期:2026-03-04 13:37:00

    原文链接作者https://jhalon.github.io/chrome-browser-exploitation-3/Jack Halon欢迎阅读 "Chrome Browser Exploita

    阅读全文
  • 文章封面

    什么是自带漏洞驱动 (BYOVD) 攻击?

    作者:securitainment发布日期:2026-03-03 13:37:00

    原文链接作者https://www.picussecurity.com/resource/blog/what-are-bring-your-own-vulnerable-driver-byovd-at

    阅读全文
  • 文章封面

    我如何利用 LLM 多 Agent 工作流挖掘开源项目 0-day 漏洞

    作者:securitainment发布日期:2026-03-03 13:37:00

    原文链接作者https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LLM-Multi-Agent-WorkflowH

    阅读全文
  • 文章封面

    Fuzzing 的艺术:如何为库编写高效的 Harness

    作者:securitainment发布日期:2026-03-02 10:24:00

    原文链接作者https://bushido-sec.com/index.php/2025/01/03/fuzzing-harness-guide/Bushido SecurityIntro每位安全研究

    阅读全文
  • 文章封面

    Spring Boot Actuator 配置错误利用实战:路径探测、绕过技巧与敏感端点攻击

    作者:securitainment发布日期:2026-03-01 22:20:00

    原文链接作者https://www.dsecured.com/en/articles/spring-boot-actuator-using-misconfig-to-your-advantage-pa

    阅读全文
  • 文章封面

    持久化:驻留的艺术

    作者:securitainment发布日期:2026-02-25 13:37:00

    面向所有平台的权威红队持久化指南:涵盖 50 余种技术,横跨 Windows (注册表、IFEO、SSP、Time Provider、Office T1137、辅助功能、Application Shi

    阅读全文
  • 文章封面

    初始访问:突破的艺术

    作者:securitainment发布日期:2026-02-24 13:37:00

    红队 Initial Access 完整指南:Payload 开发 (DLL Sideloading、Shellcode Loader、Syscall)、HTML Smuggling、钓鱼 (QR C

    阅读全文
  • 文章封面

    EDR 绕过技术演进史:从 API Unhooking 到 AI 规避的十年攻防

    作者:securitainment发布日期:2026-02-23 13:37:00

    原文链接作者https://www.covertswarm.com/post/timeline-of-edr-bypass-techniquesIbai Castells终端检测与响应(EDR)解决方

    阅读全文
  • 文章封面

    将 Windows 痕迹视为证据而非指标

    作者:securitainment发布日期:2026-02-22 13:37:00

    原文链接作者https://sethenoka.com/posts/understanding-windows-artefacts-as-evidence-not-indicators/Seth En

    阅读全文
  • 文章封面

    Volatility 3 内存取证实战指南与速查表

    作者:securitainment发布日期:2026-02-21 13:37:00

    原文链接作者https://socfortress.medium.com/title-volatility-3-will-change-how-you-hunt-malware-and-heres-t

    阅读全文
  • 文章封面

    Predator iOS 恶意软件逆向分析:构建监控框架(第一部分)

    作者:securitainment发布日期:2026-02-20 13:37:00

    原文链接作者https://blog.reversesociety.co/blog/2025/predator-ios-malware-surveillance-framework-part-1Rev

    阅读全文
  • 文章封面

    Impacket 开发指南:第三部分 - 构建自定义横向移动工具

    作者:securitainment发布日期:2026-02-19 13:37:00

    原文链接作者https://cicada-8.medium.com/impacket-developer-guide-part-3-make-your-own-lateral-movement-a2f

    阅读全文
  • 文章封面

    Impacket 开发指南:第二部分 - 系统中的 RPC 发现与安全机制解析

    作者:securitainment发布日期:2026-02-18 13:37:00

    原文链接作者https://cicada-8.medium.com/impacket-developer-guide-part-2-finding-rpc-on-the-system-and-some

    阅读全文
  • 文章封面

    Impacket 开发指南:第一部分 - RPC 远程过程调用深入解析

    作者:securitainment发布日期:2026-02-17 13:37:00

    原文链接作者https://cicada-8.medium.com/impacket-developer-guide-part-1-rpc-4df4fe6d79d7CICADA8大家好,我叫 Mich

    阅读全文
  • 文章封面

    深入剖析 RDP 活动取证

    作者:securitainment发布日期:2026-02-16 13:37:00

    原文链接作者https://thelocalh0st.com/posts/rdp/sujay adkesar"RDP 是一把双刃剑——它提供了无缝的远程访问能力,但一旦落入攻击者手中,就成了入侵的通道

    阅读全文
  • 文章封面

    Windows 事件日志被清除后因未初始化内存 bug 在无关日志文件中复活

    作者:securitainment发布日期:2026-02-16 13:37:00

    原文链接作者https://dfir.ru/2026/01/26/windows-event-logs-were-cleared-but-resurrected-in-another-file/MAX

    阅读全文
  • 文章封面

    在 Beacon 的技术花园中探索:发现 Eden

    作者:securitainment发布日期:2026-02-15 13:37:00

    原文链接作者https://www.cobaltstrike.com/blog/playing-in-the-tradecraft-garden-of-beaconWilliam Burgess我们此

    阅读全文
  • 文章封面

    证书透明度机制详解

    作者:securitainment发布日期:2026-02-14 10:24:00

    原文链接作者https://latedeployment.github.io/posts/certificate-transparency-101/latedeployment本文是 Certific

    阅读全文
  • 文章封面

    证书透明度机制下的企业基础设施信息泄露

    作者:securitainment发布日期:2026-02-14 10:24:00

    原文链接作者https://latedeployment.github.io/posts/certificate-transparency-info-leaks/latedeployment这是 Ce

    阅读全文
  • 文章封面

    滥用 SCCM 远程控制实现原生 VNC 连接

    作者:securitainment发布日期:2026-02-13 13:37:00

    原文链接作者https://www.netero1010-securitylab.com/red-team/abuse-sccm-remote-control-as-native-vncNetero1

    阅读全文
  • 文章封面

    越可预测越难被检测 - 利用 Shannon 编码隐藏恶意 Shellcode

    作者:securitainment发布日期:2026-02-12 10:24:00

    原文链接作者https://kleiton0x00.github.io/posts/The-more-predictable-you-are-the-less-you-are-able-to-get-

    阅读全文
  • 文章封面

    RPC Proxy Injection 技术详解

    作者:securitainment发布日期:2026-02-11 12:32:00

    原文链接作者https://medium.com/@s12deff/rpc-proxy-injection-1a4b08f59823S12 - 0x12Dark欢迎阅读本文。本文将介绍一种新型进程注入

    阅读全文
  • 文章封面

    Administrator Protection 安全边界绕过漏洞分析

    作者:securitainment发布日期:2026-02-09 21:31:00

    原文链接作者https://projectzero.google/2026/26/windows-administrator-protection.htmlJames ForshawWindows 1

    阅读全文
  • 文章封面

    通过补丁对比分析 N-day 漏洞

    作者:securitainment发布日期:2026-02-09 21:31:00

    原文链接作者https://c0w5lip.github.io/posts/2026-01-25-patch-diffing-introduction/c0w5lip介绍本文旨在快速入门"补丁对比"(

    阅读全文
  • 文章封面

    缺失的访问控制如何导致 Cal.com 泄露数百万条预订信息并导致完全账户接管

    作者:securitainment发布日期:2026-02-08 22:25:00

    原文链接作者https://www.gecko.security/blog/caldotcom-broken-access-controlsJeevan Jutla执行摘要Cal.com 是一个开源的

    阅读全文
  • 文章封面

    Lenovo 机器上的 AppLocker 绕过: MFGSTAT.zip 的离奇案例

    作者:securitainment发布日期:2026-02-07 20:24:00

    这篇博文记录了我在 Lenovo 机器上的一个小发现:C:\Windows目录下存在一个可写文件。最初我以为只有少数几款 Lenovo 机型受影响,但后来发现这个问题似乎波及所有型号。由于它可以被利用

    阅读全文
  • 文章封面

    Samstung 第 1 部分:MagicINFO 9 Server 远程代码执行

    作者:securitainment发布日期:2026-02-06 16:50:00

    原文链接作者https://srcincite.io/blog/2026/01/28/samstung-part-1-remote-code-execution-in-magicinfo-server

    阅读全文
  • 文章封面

    Samsung MagicINFO 9 预认证 RCE 漏洞链分析 - TOCTOU 竞争与目录遍历导致认证绕过

    作者:securitainment发布日期:2026-02-06 16:50:00

    原文链接作者https://srcincite.io/blog/2026/01/28/samstung-part-2-remote-code-execution-in-magicinfo-server

    阅读全文
上一页下一页