Aggregator
CTF | 2022 未知之境 腾讯网络安全T-Star高校挑战赛 WriteUp
2 years 11 months ago
前几天AK了个腾讯的T-Star高校挑战赛,题目比较偏向Misc和Web,这里记录一下解题过程。
MiaoTony
Reaching the Convergence of Security and Productivity
2 years 11 months ago
It?s all too common that IT security tools and practices come at the cost of productivity. Even physical security has this trade-off. There would be no rush to arrive at the airport an hour early if it weren?t for the extensive security measures that flying entails. As a result of this trade-off, our concern often isn?t if we can increase security in our networks ? rather, it?s if the increased security is worth the impact on the business.
Dan Petrillo
Jira Security Advisory 2022-04-20
2 years 11 months ago
Summary
A critical flaw in Atlassian's Jira software that could be used to bypass authentication has been identified. Atlassian has issued an advisory detailing the versions vulnerable to the exploit.
Threat Type
Vulnerability
Overview
Be advised that X-Force Incident Command is tracking the disclosure of an authentication bypass vulnerability in Jira's web authentication framework, Seraph. Tracked as CVE-2022-0540 , the vulnerability scores a 9.9 CVSS score. A specially crafted HTTP request sent to vulnera
Protecting the Digital Experience
2 years 11 months ago
Christine Ferrusi Ross
WSO2 proxy SSRF漏洞 WSO2-2019-0598
2 years 11 months ago
WSO2 proxy SSRF漏洞 WSO2-2019-0598
我的理想型企业
2 years 11 months ago
CVE-2022-22947 注入哥斯拉内存马
2 years 11 months ago
前言 CVE-2022-22947是Spring Cloud Gateway的一个SpEL命令注入漏洞,前一阵 …
whwlsfb
HD Moore讲的一个故事
2 years 11 months ago
生擒0Day,活捉Botbet
第二十一周/20220426 红队推送
2 years 11 months ago
第二十一周/20220426 红队推送
2 years 11 months ago
第二十一周/20220426 红队推送
2 years 11 months ago
第二十一周/20220426 红队推送
2 years 11 months ago
第二十一周/20220426 红队推送
2 years 11 months ago
第二十一周/20220426 红队推送
2 years 11 months ago
一个双非安全菜鸡的秋招总结
2 years 11 months ago
hurricane618
What?s New for Developers: April 2022
2 years 11 months ago
We have big news this month. You may have already heard that we acquired Linode, creating the world?s most distributed compute platform. In addition, we have release announcements and new developer content to share with you!
Jessica Capuano Mora
ATT&CK Goes to v11
2 years 11 months ago
Adam Pennington
Malware analysis report on SparrowDoor malware
2 years 11 months ago
A technical analysis of a new variant of the SparrowDoor malware.
WSO2 fileupload 任意文件上传漏洞 CVE-2022-29464
2 years 11 months ago
WSO2 fileupload 任意文件上传漏洞 CVE-2022-29464