Aggregator
2023 强网杯三道 pyjail 的题解
上周的强网杯 2023 没准备参加,一个是去年帮忙打 ctf 打得实在是有点累了;第二个是上周末有其他比赛冲突了,所以也没时间看题。偶然在公众号推送上看到了强网杯的 wp 提到了有几道 python 题,还是忍不住来玩一玩。
XZ-Utils后门事件过程及启示
Akamai?s Perspective on April?s Patch Tuesday 2024
中国网络安全行业全景图(第十一版)发布
渗透入门靶场大盘点
渗透入门靶场大盘点
渗透入门靶场大盘点
当Nashorn失去括号:非典型Java命令执行绕过
昨天『代码审计』知识星球里有同学向我提了一个有趣的问题:
简单来说就是,在Java的Nashorn脚本中,如果不允许使用小括号(、)和中括号[、],如何执行任意命令?
0x01 浏览器JavaScript无括号XSS我们知道,Nashorn脚本本质上是JavaScript,而无括号的XSS Payload其实是一个老问题了。因为JavaScript在执行函数的时候需要使用括号,所以解决问...
Importance of Scanning Files on Uploader Applications
Cybersecurity Decluttered: A Journey to Consolidation
SDL 18/100问:编码阶段,开展哪些安全活动?
How to Dramatically Simplify PCI DSS Compliance
Ransomware Groups Experiment with a New Tactic: Re-Extortion
As we regularly observe in this blog, ransomware is devious and endlessly inventive. It’s this ability to find new variations on the same basic extortion template that has made it the most successful commercial form of cybercrime yet invented. Excepting the occasional technical hack (including a talent for spotting weaknesses everyone else has overlooked), most […]
The post Ransomware Groups Experiment with a New Tactic: Re-Extortion appeared first on Ransomware.org.