
WordPress權限提升漏洞分析
原文地址:https://xz.aliyun.com/t/3659 WordPress部落格文章建立過程中存在一個邏輯缺陷,攻擊者可以訪問只有管理員能夠訪問的功能,這將導致WordPress core中存在儲存型XSS(Stored XSS...

原文地址:https://xz.aliyun.com/t/3659 WordPress部落格文章建立過程中存在一個邏輯缺陷,攻擊者可以訪問只有管理員能夠訪問的功能,這將導致WordPress core中存在儲存型XSS(Stored XSS...

原文地址:https://www.freebuf.com/articles/web/192052.html 摘要:千辛萬苦拿到的 webshell 居然無法執行系統命令,懷疑服務端 disable_functions 禁用了命令執行函數,通...

原文地址:https://www.ripstech.com/php-security-calendar-2018/ RIPSTECH PRESENTS PHP SECURITY CALENDAR 是由 RIPS 團隊出品的PHP程式碼安全審...

原文地址:https://techvomit.net/web-application-penetration-testing-notes/ WEB APPLICATION PENETRATION TESTING NOTES 前言引用來源:h...

原文地址:https://mohemiv.com/all/exploiting-xxe-with-local-dtd-files/ This little technique can force your blind XXE to outp...

原文地址:https://github.com/swisskyrepo/PayloadsAllTheThings A list of useful payloads and bypass for Web Application Securi...

原文地址:https://xz.aliyun.com/t/3537 正則表示式(regular expression)描述了一種字元串匹配的模式(pattern),可以用來檢查一個串是否含有某種子串、 將匹配的子串替換或者從某個串中取出符合...

原文地址:https://www.freebuf.com/articles/rookie/190953.html 透過機器學習 MLP算法,檢測Webshell。 前言引用來源:https://www.freebuf.com/article...

原文地址:https://mp.weixin.qq.com/s/oWzDIIjJS2cwjb4rzOM4DQ 近日thinkphp團隊釋出了版本更新https://blog.thinkphp.cn/869075,其中修復了一處getshel...

原文地址:https://zhuanlan.zhihu.com/p/51907363 作者在偵錯分析 DiscuzX (以下簡稱 Dz)歷史漏洞的時候,發現 Dz 的 SSRF 漏洞其實都是由一個叫dfsockopen的函數導致的,並且官方...