<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>安全防御</title>
    <link>https://wechat2rss.xlab.app/feed/aa17887af0644ece8360baf00c4c3d0642a745df.xml</link>
    <description>个人一些心得&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (安全防御)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM64Qs6M1Ve6pOcjHQTYDPG6fk2Hx4F6WZib6rP2sFj83jg/0</url>
      <title>安全防御</title>
      <link>https://wechat2rss.xlab.app/feed/aa17887af0644ece8360baf00c4c3d0642a745df.xml</link>
    </image>
    <item>
      <title>浅谈K8s安全</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483876&amp;idx=1&amp;sn=7e3e3b0398776e89f5517c9e6bdf128d</link>
      <description>个人对K8s的安全做个随笔总结</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2023-08-22 10:58</span> <span style="display: inline-block;">北京</span>
</p>

<p>个人对K8s的安全做个随笔总结</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=709e6152&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FibCalCUYKkZqkqFSqic8iaTYOj3lkswIkOeq7mLyqb8qLoqnxHGeXdaMncGjdiaANb26YmRDHuHdmLYMPm8313NrVA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  Kubernetes，简称K8s，相信看这篇文章的朋友，应该都不会太陌生，最近正好研究了一下这个东西，根据网上和自己的一些研究，简单对这个东西的安全性以及可能存在的安全问题，进行个总结。</p><p>一 K8s 架构</p><p>整体的架构如下图所示，</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="270" data-backw="578" data-ratio="0.46705202312138727" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=5c6a17a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZqkqFSqic8iaTYOj3lkswIkOeAAibeYZ9o3PlrSLia6MnPaSHib5In3gDaoYvnDdu7qdfc9yaicjpEic0EzA%2F640%3Fwx_fmt%3Dpng"/></p><p>K8s 整体可以分为控制节点（Master）与工作节点（Node)两部分。Master 节点又包括如下组件：<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">api</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">server，etcd，scheduler，contorller-manager。</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">各个组件的功能</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">里就不作太多介绍详情可以参考</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">K8s各组件介绍：</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><a href="https://kubernetes.io/zh-" target="_blank">https://kubernetes.io/zh-</a></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">cn/docs/concepts/overview/components/</span></p><p>二 K8s常见的安全问题</p><p>2.1 未授权访问<br/></p><p>  这是笔者认为最不应该或者最愚蠢的错误类型，包括且不限于因为各种五花八门的弱口令，配置错误导致的apiserver，kubectl，etcd等可以直接访问，或者得通过各种方式拿到到kubeconfig的配置文件，这样的后果便是使得整个K8集群彻底沦陷。</p><p>例如kubectl，默认情况下访问是未授权状态：</p><p><img class="rich_pages wxw-img js_insertlocalimg" data-backh="160" data-backw="578" data-ratio="0.2765957446808511" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1034" src="https://wechat2rss.xlab.app/img-proxy/?k=2e045742&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUKW0qHqeKD4xOc8yuwuyoyMuaARTHa7sSrxd5twpo1yOtdyRvNUfGIw%2F640%3Fwx_fmt%3Dpng"/></p><p>但如果修改了某个节点的config.yaml配置文件，将匿名认证打开：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="173" data-backw="552" data-ratio="0.3134057971014493" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="552" src="https://wechat2rss.xlab.app/img-proxy/?k=75c5bd30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUyIx8l4CRsce2XsrIsKEfMR7j8Hke2S1ONQLmZINCicq7X8tvVIS9eUw%2F640%3Fwx_fmt%3Dpng"/></p><p>再次访问则会出现信息泄露：</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8629629629629629" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f9132234&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUS8bxIF73Hj1mOx0D8qnJG2EfGE34QXLtVcNEXAno3OkOlslkibQ4PYQ%2F640%3Fwx_fmt%3Dpng"/></p><p>甚至可以在对应的宿主机的容器中进行命令执行：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="95" data-backw="578" data-ratio="0.1638888888888889" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7173fdf9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUxb2ibF0M60CYgyjNBMicIDiaiclrzGXYXhUaVRkEnc1plXPEXQoC1tnDoA%2F640%3Fwx_fmt%3Dpng"/></p><p>因此需要尽量在日常的应用运维中犯下类似这样的错误。常见的组件对应的端口如下：<br/></p><ol style="margin-bottom: 16px;padding-left: 2em;border-width: 0px;border-style: initial;border-color: initial;vertical-align: baseline;background-repeat: no-repeat;list-style: none;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;" class="list-paddingleft-1"><li><table><tbody><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;">K8S组件<br/></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;">默认端口<br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">kube-apiserver</span><br/></td><td width="254" valign="top" style="word-break: break-all;">6443<br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">kubelet</span><br/></td><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">10250</span><br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">etcd</span><br/></td><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(38, 38, 38);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, Helvetica, Roboto, Arial, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft Yahei&#34;, &#34;Microsoft Jhenghei&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">2379 , 2380</span><br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">kube-proxy</span></td><td width="254" valign="top" style="word-break: break-all;">10256<br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">kube-controller-manager</span><br/></td><td width="254" valign="top" style="word-break: break-all;">10252<br/></td></tr><tr><td width="254" valign="top" style="word-break: break-all;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, Helvetica, &#34;Meiryo UI&#34;, &#34;Malgun Gothic&#34;, &#34;Segoe UI&#34;, &#34;Trebuchet MS&#34;, Monaco, monospace, Tahoma, STXihei, 华文细黑, STHeiti, &#34;Helvetica Neue&#34;, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, FreeSans, Arimo, Arial, SimSun, 宋体, Heiti, 黑体, sans-serif;font-size: 14px;letter-spacing: normal;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">kube-scheduler</span><br/></td><td width="254" valign="top" style="word-break: break-all;">10251<br/></td></tr></tbody></table></li><li style="border-width: 0px;border-style: initial;border-color: initial;vertical-align: baseline;background-repeat: no-repeat;"><p><br/></p></li></ol><p>2.2 特权容器</p><p>  这也是运维中可能出现的情况，如下图配置，在运维过程中为了某种原因，把容器配置为特权模式:<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.466046511627907" data-s="300,640" style="" data-type="png" data-w="1075" src="https://wechat2rss.xlab.app/img-proxy/?k=26d8bbbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUv3lDYPqMUA1wDKxbsmqYvkDXIV9ALqNKjmkLPp7HjT1Pa6Go6VyJ0g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="letter-spacing: 0.578px;text-wrap: wrap;">  这</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">样，万一这个容器失陷</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">，便可以<span style="letter-spacing: 0.578px;text-wrap: wrap;">通过挂载</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">宿</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">主机目录，</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">操作</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">宿</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">主机的文件，</span></span>例如/root/.ssh/authorized_keys, crontab 等等，达到控制宿主机，进行逃逸。<span style="letter-spacing: 0.578px;text-wrap: wrap;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0842592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9ec8aff8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUJicTViaIpflkwhleibeLz6nEfbxicegZMVARM2gxkcazMrIMHPrVcEMS5Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.26282051282051283" data-s="300,640" style="" data-type="png" data-w="624" src="https://wechat2rss.xlab.app/img-proxy/?k=628ad04e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUDkBnfQ3zr2A7HX5YC5VLm6xdwOXVPuXhvopyPPb7Oz8sJc9koTGicGw%2F640%3Fwx_fmt%3Dpng"/></p><p>  除此之外，容器的一些特殊能力的赋予也需要慎重，例如CAP_SYS_PTRACE，便是拥有着追踪进程的能力，这样有可能通过strace等命令捕获SSH密码：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.24259259259259258" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5168fae6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnU6BUopTicia0DQVT38QicaJobvcpWMmxThlVBckywE9QHKEs7wsMYInCGQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/>  CAP_SYS_ADMIN，允许执行系统管理任务例如加载或卸载文件系统，基本等同于特权容器，也需要谨慎赋予。</p><p>其他容器能力介绍可以使用命令 man capabilities 进行参考。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3509259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1d6d7899&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUhTgLzWYHYJxV4Gic3h1W5XNkEoxiauDmvq2P5Qvu28GuOX6uHNHHJicoQ%2F640%3Fwx_fmt%3Dpng"/></p><p>2.3 挂载宿主机的重要目录<br/></p><p>  与2.2类似，尽量不要挂载宿主机的重要目录，例如/root ,/etc ,/porc等目录，毕竟这些目录都存有系统的重要信息，如果攻击者进入到容器内，便可能通过操作某些文件，达到容器逃逸的目的。</p><p>2.4 容器自身安全<br/></p><p>  因为容器本身与宿主机共享内核，那么便可以通过内核漏洞进入宿主机的namespace，从而达到逃逸的目的，最典型的应该算脏牛漏洞（CVE-2016-5195）。<br/></p><p>2.5 容器内应用安全</p><p>  容器内的应用本身也存在各种安全问题，例如命令执行，SQL注入，文件上传，rce等等，与传统安全一致，所以这里就不用再进行展开了。当然，如果通过某种漏洞进入到应用pod中，在没有网络隔离的情况下，便可以面向整个K8S集群进行进一步攻击了。</p><p><img class="rich_pages wxw-img" data-backh="429" data-backw="563" data-ratio="0.7619893428063943" style="width: 100%;height: auto;" data-type="png" data-w="563" src="https://wechat2rss.xlab.app/img-proxy/?k=d7ddbeca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZpI8kD6HibUD0XnQiahCvVfnUseayk3j0icLOyTOR7T09qgxLD6s5RD0PFvVeWYGiaRIff9GQDBvoo46g%2F640%3Fwx_fmt%3Dpng"/></p><p>2.6 容器镜像安全</p><p>   这也比较容易理解，例如使用了有漏洞的镜像，或者使用了被投毒的镜像，或者带有后门的镜像等等类似供应链攻击。<br/></p><p>2.7 K8s本身组件的漏洞及第三方组件的漏洞</p><p>  K8s本身拥有着非常众多的组件，因此非常有可能因为某些组件出现漏洞从而导致整个集群沦陷的可能。</p><p>2.8 一些管理平台<br/></p><p>  除了官方的Dashborad外，还有很多的K8s管理平台，例如Rancher ,KubeCube，KubeSphere 等等，这些平台除了未授权访问，弱口令外，本身也可能存在其他漏洞，一旦出现安全问题，也可能导致整个集群失陷。</p><p>2.9  其他问题</p><p>  例如某些功能，本意是想为运维提供方便，但被发现，可以利用控制集群的情况，类似system函数。</p><p>三  关于K8s的一些安全实践</p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">  个人觉得，K8s使用了这么长时间，只要做到了安全里边的最小授权原则，做好网络控制与准入，做好资源的用量规划，除pod应用与自身组件产生的安全问题外，基本不会出现太多的安全问题。当然，审计与安全工具也十分重要，例如我之前推荐的两款工具<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483859&amp;idx=1&amp;sn=e09e396dadc2f955172baf06aa0d292a&amp;chksm=c0761566f7019c705ecd6742be71baca8592a7031f5d6650de2d25137785f0abd4c9ddeb0aac&amp;scene=21#wechat_redirect" textvalue="Falco—云原生安全守护者" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Falco—云原生安全守护者</a>，</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483778&amp;idx=1&amp;sn=80102acbcb4ec21db0e46f168340814c&amp;chksm=c0761537f7019c21260ab92f06b2646d880601f9b1d7d1d04bffe8384750785086a0da517861&amp;scene=21#wechat_redirect" textvalue="NeuVector----功能丰富且强大的容器安全开源软件" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">NeuVector----功能丰富且强大的容器安全开源软件</a>，大到整体集群，小到单个容器，都可以进行监控。<br/></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><br/></span></p><p>四 一点感悟</p><p>  本文参考了腾讯安全的《<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">红蓝对抗中的云原生漏洞挖掘及利用实录》（</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><a href="https://security.tencent.c" target="_blank">https://security.tencent.c</a></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">om/index.php/blog/msg/183）这篇文章，这篇文章发表于2021年三月，感概<span style="letter-spacing: 0.578px;text-wrap: wrap;">腾</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">对K8s的研究领先了我</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">3年</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">半。这篇文章一直<span style="letter-spacing: 0.578px;text-wrap: wrap;">存在我的</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">收藏里。</span></span>从最初的完全懵逼到现在可以看懂，也欣慰自己在K8s方面也有了一点点进步，也终于可以可以把这个收藏的文章画个圈了。</span></p><p>  <br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483876">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7e5e88d6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483876%26idx%3D1%26sn%3D7e3e3b0398776e89f5517c9e6bdf128d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 22 Aug 2023 10:58:00 +0800</pubDate>
    </item>
    <item>
      <title>​Falco—云原生安全守护者</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483859&amp;idx=1&amp;sn=e09e396dadc2f955172baf06aa0d292a</link>
      <description>如果说之前的NeuVector是从宏观上看容器的安全，那么Falco便是从容器，主机的角度出发</description>
      <content:encoded><![CDATA[<p>
原创 <span>Lion</span> <span>2023-07-28 19:42</span> <span style="display: inline-block;">北京</span>
</p>

<p>如果说之前的NeuVector是从宏观上看容器的安全，那么Falco便是从容器，主机的角度出发</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9319bfdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FibCalCUYKkZq462fibct7edvYfT96HAXHuUmZrOQ4jearMyVCx4FKBLzcmv4RmuHoqibkoZGtpCIyzTtVlw6m3rLQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="mso-style-parent: &#39;&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-justify: inter-ideograph;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-align: center;"><br/><span style="font-family:等线;"></span></p><p><span lang="EN-US">一 Faclo </span>介绍<span lang="EN-US"><o:p></o:p></span></p><p>      在云原生应用和容器化环境中，安全性成为了一个至关重要的关注点。随着容器技术的普及和应用的快速发展，容器环境中的安全挑战也日益增加。为了保护应用程序和数据免受潜在威胁，开发者和运维团队需要有效的安全工具和机制。<span lang="EN-US">Falco</span>是一个开源的云原生安全工具，通过实时监控和检测容器、主机和<span lang="EN-US">Kubernetes</span>集群中的安全事件，为云原生环境提供智能的守护功能。<span lang="EN-US">Falco </span>可以监测调用<span lang="EN-US"> <span style="color: windowtext;">Linux </span><span lang="EN-US" style="color: windowtext;"><span lang="EN-US">系统调用</span></span></span>的行为，并根据其不同的调用、参数及调用进程的属性发出警告。例如，<span lang="EN-US">Falco </span>可轻松检测：<span lang="EN-US"><o:p></o:p></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">     容器内运行的<span lang="EN-US"> Shell<o:p></o:p></span></p></li><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">     服务器进程产生意外类型的子进程<span lang="EN-US"><o:p></o:p></span></p></li><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">     敏感文件读取（如<span lang="EN-US"> /etc/shadow</span>）<span lang="EN-US"><o:p></o:p></span></p></li><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">     非设备文件写入至<span lang="EN-US"> /dev<o:p></o:p></span></p></li><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">     系统的标准二进制文件（如<span lang="EN-US"> ls</span>）产生出站流量等</p><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;">其原理如下图所示：</p></li></ul><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;"><span lang="EN-US"><o:p><img class="rich_pages wxw-img" data-backh="249" data-backw="557" data-ratio="0.44739884393063584" style="width: 100%;height: auto;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e4eec648&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuKibKeCdcRh9iak2tYRBVSRZrsqQe6X4h9dVRvpv3tIcWicSFFPjCPNXTw%2F640%3Fwx_fmt%3Dpng"/></o:p></span></p></li></ul><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;"><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;"><span lang="EN-US"><o:p><br/></o:p></span></p><p><span lang="EN-US">二FALCO </span>安装<span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US">Falco</span>的安装方式相对比较简单，<span style="text-indent: -22pt;font-size: var(--articleFontsize);letter-spacing: 0.034em;">单机版安装方式可以参考：</span><a href="https://falco.org/docs/getting-started/falco-linux-quickstart/" target="_blank">https://falco.org/docs/getting-started/falco-linux-quickstart/</a></p><section>K8S中的安装方式可以参考：</section><section><a href="https://falco.org/docs/getting-started/try-falco/try-falco-on-kubernetes/" target="_blank">https://falco.org/docs/getting-started/try-falco/try-falco-on-kubernetes/</a></section><section><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">这里需要说明一下的是我在</span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">centos7 </span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">中进行的安装时，遇到了</span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">bpf</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">驱动无法</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">下载的问题，改成了</span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">centos9</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">就可以了，看了一下是因为没有对应的内核驱动导致的，这点需要注意一下。</span></section><section><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">三 </span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">Falco </span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">配置</span></section><section><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><p><span lang="EN-US">  Falco </span>单机规则配置文件为自带的<span lang="EN-US">falco_rules.yaml</span>，以及可以用于自定义规则的<span lang="EN-US">falco_rules.local.yaml</span>文件构成，如果在<span lang="EN-US">K8S</span>中使用自定义的规则文件，需要创建<span lang="EN-US">configmap </span>指定。<span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US">   Falco</span>的配置规则由三大部分组成分别为：<span lang="EN-US">Lists,Macros,</span>以及<span lang="EN-US">Rules<o:p></o:p></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-indent:-22.0pt;mso-char-indent-count:0;mso-list:l0 level1 lfo1;"><span lang="EN-US">     Lists: </span>项目的命名集合，可以用于<span lang="EN-US">macros</span>、<span lang="EN-US">rule</span>甚至其他<span lang="EN-US">lists</span>中，由<span lang="EN-US">list</span>及<span lang="EN-US">items</span>两部分构成，例如定义一个<span lang="EN-US">user_lists:</span></p></li></ul><ul style="list-style: none;" class="list-paddingleft-1"><li><p><br/></p></li><li><p>- list: user_lists </p></li><li><p>   items: [root,lion,admin,nginx,public]</p></li><li><p> </p></li></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>Macros:可以在里边定义一些规则片段<span style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">，方便在</span><span lang="EN-US" style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">Rules</span><span style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">中重复使用，例如判断用户在上面的（</span><span lang="EN-US" style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">user_lists</span><span style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">）中，可以使用上面的</span><span lang="EN-US" style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">list</span><span style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">，由</span><span lang="EN-US" style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;">macro</span></p></li></ul><ul style="list-style: none;" class="list-paddingleft-1"><li><p>和condition 组成，conditi顾名思义，是各种表达条件例如定义一个用户在user_lists中的条件:</p></li><li><p><span style="color:black;mso-color-alt:windowtext;">- macro：user_in_user_lists</span><o:p></o:p></p></li><li><p><span style="color:black;mso-color-alt:windowtext;">   condition: user.name in (user_lists)</span><o:p></o:p></p></li><li><p><span style="color:black;mso-color-alt:windowtext;">更多的表达式可以参考 <a href="https://falco.org/docs/rules/conditions/" target="_blank">https://falco.org/docs/rules/conditions/</a></span></p></li><li><p><span style="color: black;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>Rules: 最重要的部分，生成告警的规则，由下面几个部分组成：</p></li></ul><ul style="list-style: none;" class="list-paddingleft-1"><li><p>      rule: 规则名字</p></li><li><p>      desc: 规则描述</p></li><li><p>      condition：定义具体的规则内容，也可以使用上面的宏</p></li><li><p>      exceptions: 排除的条件</p></li><li><p>      output：输出的内容</p></li><li><p>      priority：报警的级别</p></li><li><p>      tags：规则的分类标签</p></li><li><p>例如：当user_lists 中的用户执行了frp 便进行报警，输出用户名，进程号，进程id完整的规则为：</p></li><li><p><br/></p></li><li><p>-list: user_lists</p></li><li><p>  items: [root,lion,admin,nginx,public]</p></li><li><p>-macro：user_in_user_lists</p></li><li><p> condition: user.name in (user_lists)</p></li><li><p>-rule: some_one_open_frp</p></li><li><p>condition：user_in_user_list and proc.name contains “frp”</p></li><li><p>output: &#34;Detected frp process (user=%user.name command=%proc.cmdline pid=%proc.pid)&#34; </p></li><li><p>这里说明一下，falco有着非常丰富的可以作为条件判断源（condition）和输出（output）的字段，例如user.name，proc.pid 等等，大致分为：evt（事件类）例如:<span style="letter-spacing: 0.578px;text-wrap: wrap;">e</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">vt</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">.</span><span style="letter-spacing: 0.578px;text-wrap: wrap;">source</span></p></li><li><p>，process（进程类）例如 proc.name</p></li><li><p>，user（用户类）例如 user.name</p></li><li><p>，group（组类）例如 group.name</p></li><li><p>，container（容器类）例如 container.name</p></li><li><p>，fd（文件类）例如 fd.filename ,fd.cip</p></li><li><p>，syslog例如syslog.severity</p></li><li><p>，k8s ,例如：k8s.pod.name 等等，完整列表可以参考<a href="https://falco.org/docs/reference/rules/supported-fields/。" target="_blank">https://falco.org/docs/reference/rules/supported-fields/。</a></p></li><li><p><span style="">下面就分别在单机及k8s中分别挑几个案例进行演示</span></p></li><li><p><br/></p></li><li><p><span style="">3.1 FALCO 单机</span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="">判断主机有外连行为：</span></p></li></ul><ul style="list-style: none;" class="list-paddingleft-1"><li><p><span style="">规则为：</span></p></li><li><p><span style=""><img class="rich_pages wxw-img" data-backh="50" data-backw="557" data-ratio="0.09017341040462427" style="width: 100%;height: auto;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=572725d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuP4VkAyLYeJMb4wyAqQqcfUJT7ibDZdJib0kWpV9icXcXpLa1LSIcUOtBA%2F640%3Fwx_fmt%3Dpng"/></span></p></li></ul><p>当发现主机外联时会有如下告警：<span lang="EN-US"><o:p></o:p></span></p><p><img class="rich_pages wxw-img" data-ratio="0.03005780346820809" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a5edc4b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHua15ic1K54OGqia1pGQoEByZrXXMIq7Ugm60qY563mzIQVaPKA0hiaBITg%2F640%3Fwx_fmt%3Dpng"/></p><p>这里生成了一个cs的后门，通过strace跟踪ip</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.08504672897196262" data-s="300,640" style="" data-type="png" data-w="1070" src="https://wechat2rss.xlab.app/img-proxy/?k=29db9a51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuZrwSIjs9LK2V4ibcNow7YJge7icMb9pO3NbGd7rorCYKicVhrEqnplvLw%2F640%3Fwx_fmt%3Dpng"/></p><p>在Falco中生成的告警：<br/></p><p><img class="rich_pages wxw-img" data-ratio="0.057803468208092484" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=59f408cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuFoOo6jfC1SDsGtA4zZVCc54KxUO6YcibctZ7hTG0rBHGSMwcLp4bgFQ%2F640%3Fwx_fmt%3Dpng"/><br/></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span lang="EN-US">Webshell </span>或 其他文件访问敏感文件 例如<span lang="EN-US">/etc/shadow,规则为：</span></p><p><span lang="EN-US"><img class="rich_pages wxw-img" data-ratio="0.10635838150289018" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=00b89aff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuS3kTvXib8bn5Je9iaP0Q41s5KWeh7MCO7Sj8TZTfM8sCrEMCeia7CMfvQ%2F640%3Fwx_fmt%3Dpng"/></span></p></li></ul><p>产生的告警为：</p><p><span lang="EN-US"><o:p><img class="rich_pages wxw-img" data-ratio="0.09017341040462427" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=81f5b7de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuNApwPnncFZGwF1pm5FicDiaicYVvpHu3whIwXoRry4H7SBldHCGHSBWtg%2F640%3Fwx_fmt%3Dpng"/></o:p></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>检测<span lang="EN-US">frp</span>规则：</p></li></ul><p><img class="rich_pages wxw-img" data-ratio="0.11098265895953757" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5e42a13f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHu6oTHjYHKeWcGJA6xnmN1juyPVraXcbwxuduMhiaicu601GW1XImxDwibg%2F640%3Fwx_fmt%3Dpng"/><span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US"><o:p>产生的告警为：<br/></o:p></span></p><p><span lang="EN-US"><o:p><img class="rich_pages wxw-img" data-ratio="0.04161849710982659" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fa6a1706&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuXXRFycTLrdLbazGkvm2UOXhqicVdaicHqvxWj4NXWPtkvC9erKSybZfg%2F640%3Fwx_fmt%3Dpng"/></o:p></span></p><p><span style="">3.2 FALCO k8s</span></p><p><span style="">    在k8s中，falco 作为daemonset启动，利用configmap将自定义规则加入:</span></p><p><span style=""><img class="rich_pages wxw-img" data-ratio="0.507514450867052" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d5a5c728&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHunta3khtibzibsguOXlWOXicmIerYKGicUIJjBCKIycUdWdFMiciaAG7Cgdaw%2F640%3Fwx_fmt%3Dpng"/></span></p><p>同样的，当一个容器访问了敏感文件:<span lang="EN-US"><o:p></o:p></span></p><p><img class="rich_pages wxw-img" data-ratio="0.5190751445086705" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b8bea00e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuBLnKfsuUpbmtr1oJyHvgwe97B3rWDONFibt9SFCTqYmQiaIqXeFk4uXQ%2F640%3Fwx_fmt%3Dpng"/></p><p>产生的告警为：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="127" data-backw="578" data-galleryid="" data-ratio="0.21944444444444444" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f6dcf13f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuGGrHibO3d6C8FT9B9pzOyEekZNoSXKXJlSpjbcWGAoQiaFPRvc8QicRcg%2F640%3Fwx_fmt%3Dpng"/></p><p>检测当一个特权容器启动<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">规则为：</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><img class="rich_pages wxw-img" data-ratio="0.14797687861271677" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=105c79c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuoDiaGDKmtX4mVECLOagtflto0vwP0iaeVswmEoJsNMEK8vO3ywgicicOFw%2F640%3Fwx_fmt%3Dpng"/></span></p><p>对应告警：</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.24814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ac7c586f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHu7rWI2HfCFkuER15iaZwJMP3nLZmODNzV2k5gzCibDn2ib0BiaoCgia3XSag%2F640%3Fwx_fmt%3Dpng"/></p><p><span lang="EN-US">Falco</span>支持将告警通过<span lang="EN-US">syslog</span>，<span lang="EN-US">web</span>，文件等发送，这里我将<span lang="EN-US">falco</span>的告警转发至<span lang="EN-US">es</span>中，并用<span lang="EN-US">kibana </span>进行了展示，由于测试关系我没有对内容字段进行进一步拆解。<span lang="EN-US"><o:p></o:p></span></p><p>四 Faloc检测ebpf 后门</p><p>现在有很多关于ebpf的研究，我曾试着想利用falco发现ebpf后门，不过，经过测试，falco仅仅发现了系统调用了bpf函数,如下图所示，但是并未找到如何配置，让其产生告警。希望有兴趣的读者可以进一步进行研究。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.041666666666666664" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=01eac757&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FibCalCUYKkZq462fibct7edvYfT96HAXHuu8NOglHHvOVemaDWssNFwmrnekBUYGqibdY4ibtXmvGWGcB7w6JHxJsA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="">五 与ossec 比较</span></p><p><span style="">  在我的《互联网安全建设从0到1》这本书中，介绍了一款主机ids-ossec，这里可以简单的将两个软件进行比较，ossec的告警更多是依赖log进行，对log进行decoder，从而匹配规则，进而产生告警。而falco本身依赖的是系统的系统调用捕获，因此可以更加深度的对系统行为进行分析，而ossec，对容器方面支持的不够完善，而这正是falco的优势，当然ossec 可以进行集中管理，这点上falco还是需要运维软件进行控制，在这点上，不如ossec。</span></p><p><span style=""><br/></span></p><p><span style="">六 结语</span></p><p><span style="">   以上便是对falco的一些简单介绍，而falco的规则，有了gpt后，便更加容易编写了，很多规则可以通过询问gpt进行编写了，这很好的降低了编写规则的难度，但依然需要进行测试，毕竟有的时候gpt还是会一本正经的胡说八道。另外毕竟falco在这里仅仅是一个工具，想要真正发挥它的作用，还需要在日常工作中不断的打磨，需要对falco的资源占用情况，告警准确情况，进行不断的了解，改进这又变成了运营问题。同样的，这个软件想要发挥最大的价值，还需要考虑到其在公司业务系统的覆盖率，毕竟工程化一个软件，比研究一个软件的功能要难很多。</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483859">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dc21ddd6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483859%26idx%3D1%26sn%3De09e396dadc2f955172baf06aa0d292a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Jul 2023 19:42:00 +0800</pubDate>
    </item>
    <item>
      <title>祝大家兔年新年快乐</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483805&amp;idx=1&amp;sn=3bd6e79b6fc4d9f14a2a13b126ae1b65</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span>Lion</span> <span>2023-01-21 18:59</span> <span style="display: inline-block;">北京</span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d9a25a41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqAORySaw138Jl1Wa4wbwTx1x3KXOeIPJZfSkt26bdpBa08TquUhqpDEoeibdTJ6Td7O7MWmS4WEoA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><section style="display: inline-block;">  祝大家新年快乐。新的一年，希望大家继续交流安全技术，一起进步🎉。</section></section><section><section style="display: inline-block;"><img data-ratio="2.120370388031006" data-w="1080" data-type="jpg" src="https://wechat2rss.xlab.app/img-proxy/?k=35f4c92e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqAORySaw138Jl1Wa4wbwTxEMkpAf9JKo4Z2giaBdYyMz3ZEUib6W0nUPNNFXkVKCJlIXRetBV2leWQ%2F640%3Fwx_fmt%3Dpng"/></section>​</section><section><br/></section><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247483805">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=52950d7a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483805%26idx%3D1%26sn%3D3bd6e79b6fc4d9f14a2a13b126ae1b65%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 21 Jan 2023 18:59:00 +0800</pubDate>
    </item>
    <item>
      <title>安全防御体系建设</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483801&amp;idx=1&amp;sn=65690fcb35047d4f0e525deaee293380</link>
      <description>这个号叫安全防御，也应该分享一点个人在安全防御方面的一些心得。</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2022-08-31 19:50</span> <span style="display: inline-block;">北京</span>
</p>

<p>这个号叫安全防御，也应该分享一点个人在安全防御方面的一些心得。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=20accf9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUbMu8AaSltwyAkBh8bCUicHRl5XzY2Ribqia6euriaTmtMqEgcEORicmuQdg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  这个号叫安全防御，也应该分享一点个人在安全防御方面的一些心得。作为在攻防对抗的防守方，个人觉得有点类似对一个城池进行防守一样。而防守的目的，便是识别异常的能力。当然，这种能力不是与生俱来的，需要经过大量的事前准备，知识储备，应急演练等等才可以形成。在我之前的书中，以知己，知彼的角度写了一些心得，这次笔者再从平台（知己），技术（知彼），以及运营这几个纬度进行。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="233" data-backw="415" data-ratio="0.5614457831325301" data-s="300,640" style="width: 100%;height: auto;" data-type="jpeg" data-w="415" src="https://wechat2rss.xlab.app/img-proxy/?k=f1dc0c98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUpb1EycZfXiaDdsz2zaTfkCfAHb5VcTriclgXT1W8QP8KwjYicmjD4IESg%2F640%3Fwx_fmt%3Djpeg"/></p><p>一 平台层面（知己）：</p><p><span lang="EN-US"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;"> </span></span>工欲善其事，必先利其器。这里的平台是指搭建防御体系的产品（或者工具）的能力，因为对于防御者来说，并没有任何银弹可以使用，指望着一招鲜吃遍天的想法基本上来说是不现实的，因此好的防御应该是层次型的，或者立体式的防守。每层可以互相弥补不足，协同完成发现异常的过程。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="324" data-backw="554" data-ratio="0.5848375451263538" data-s="300,640" style="width: 100%;height: auto;" data-type="jpeg" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=82ae811b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUS6ia4GKbZtRL9FT5YEuxWuFBuGNYDPicEOEcngSewdrQVCnPcBKU47uA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;margin-bottom: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p>如上图所示，把一个传统<span lang="EN-US">IDC </span>分为网络层，业务层<span lang="EN-US">(HTTP),</span>主机层，以及周边部分，在不同的层上，使用不同的技术进行监控。</p><p><span lang="EN-US">1 </span>网络层</p><p>笔者认为是眼睛的作用，这里在笔者之前的书中已经介绍过，这里不多做介绍。可以使用的开源检测工具例如<span lang="EN-US">suricata</span>等。当然如果有能力做一个监控平台，那么就要考验开发能力和工程化的能力了，毕竟不同于做工具能使用即可的思路，需要考虑稳定性，在大流量下的可扩展性，操作的简易性，甚至对于误报，漏报，策略的准确性等等都要仔细考虑进去。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6011080332409973" data-s="300,640" style="" data-type="png" data-w="722" src="https://wechat2rss.xlab.app/img-proxy/?k=d76ba27b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUs0LbP7vWtFmVCcX3o9F7Zscjab8ibXYicakuWjfrR4QQRAG7Wmdtdq4w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">例如笔者这套自行开发的监控系统，基本上就算满足了上面的需要。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">另外讨论比较多的问题是关于流量的加密问题，其实主要分为两个部分，可解密场景，即业务访问，这个场景，因为证书是自己这边的，可以通过在抓取</span><span lang="EN-US" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">ssl</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">卸载节点后的流量即可解决。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">另外一个是无法解密的情况，类似木马，</span><span lang="EN-US" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">webshell</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">之类。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">这种情况，可能就需要下一个层面主机层进行协同了。</span><br/></p><p><span lang="EN-US">2 </span>主机层</p><p>针对网络层无法了解具体主机行为的这一缺陷，就可以在主机层进行进一步的布防，例如<span lang="EN-US">hids</span>，<span lang="EN-US">xdr</span>产品等等。这些系统可以针对主机文件，进程，端口变化，系统日志等信息进行收集并加以分析。另外现在的<span lang="EN-US">hids,</span>或<span lang="EN-US">xdr</span>产品，也有资产收集的功能，可以协助防守方了解资产情况。现在各种类型的<span lang="EN-US">hids</span>已经层出不穷，例如笔者书里花了不少篇幅介绍的<span lang="EN-US">ossec,</span>或者一些商业软件等等。</p><p><span lang="EN-US">3 </span>周边部分</p><p>可布防的区域除了主机，网络层外，还可以在数据库层，端口，<span lang="EN-US">DNS,</span>堡垒机，<span lang="EN-US">vpn</span>等众多地方进行监控，覆盖的范围越广，发现异常的概率也就越高，考验的其实也就是资产识别的能力。</p><p><span lang="EN-US">4</span>关于资产识别</p><p>笔者认为这是在进行安全防御中非常重要的环节，这就好比在守城中，如果将领对自己一方的人员，粮草，环境都不了解，那结果，基本上就可想而知了。笔者在书中用自创的圆圈理论已经阐述过，而且，公司越是大，资产识别越是一个苦差事，但不能说因为苦，就放弃这项工作，而相反，这算是考验安全能力的最基本功，先不说很多攻击都是从未识别到的资产中得手的情况，单说攻防对抗最重要的环节之一就是时间，如果监控到有问题，第一时间可以联系到相关业务的负责人，那也可能会在劣势中及时止损，争得时间。因此对于资产识别的重要性已经不言而喻了。当然对资产识别的颗粒度越细，那在监控中或对抗中越可以取得时间上的优势。而对于容器的使用，笔者推荐了一款个人认为比较出色的工具：<span lang="EN-US">neuvector</span>，具体可以参考之前的文章《<span lang="EN-US">NeuVector ---</span>功能丰富且强大的容器安全开源软件》。</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.41247002398081534" data-s="300,640" style="" data-type="png" data-w="834" src="https://wechat2rss.xlab.app/img-proxy/?k=d61aadeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUtM1yEAt7AgnPnpiaf0KbCxPYrnibodkvaWm75jtMNvLR0Ps0up0gb6aQ%2F640%3Fwx_fmt%3Dpng"/></p><p>二 技术层面（知彼）</p><p><span lang="EN-US"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;"> </span></span>攻防对抗，本身来说就是一个非常有技术挑战的事情，因为我们的对手是同样有着各种思想，不同目的人，因此笔者认为，不真正经历过一线的攻防对抗，提出来的策略基本上也就只能是纸上谈兵。而在对抗过程中能够灵活与变通，往往会是制胜的关键。但对于防守方来说，这两点更应该是日常积累才可能做到的，例如对于防守方来说，除了要了解攻击者可能使用的技术，工具外，还可能需要了解各种漏洞产生的原理，利用方式，甚至是系统或者语言等特性，因为在现实中可能就是因为对某种特性不熟悉，而导致被利用的情况发生。例如笔者能想到的基于资源的约束委派攻击便是利用了<span lang="EN-US">msDS-AllowedToActOnBehalfOfOtherIdentity</span>这一特性，通过伪造管理员申请<span lang="EN-US">ticket</span>的方式进行的。再比如<span lang="EN-US">webshell</span>中，利用了<span lang="EN-US">evel</span>，<span lang="EN-US">system</span>函数可以执行系统命令等等。</p><p>再例如反弹<span lang="EN-US">shell</span>这个场景，如下图所示（<span lang="EN-US">ps</span>：此图非本人原创，来源于<span lang="EN-US">AnonySec@</span>安恒<span style="color: black;font-family: DengXian;font-size: 10.5pt;background-color: rgb(245, 246, 250);">《实战中内网穿透的打法》）</span></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3237410071942446" data-s="300,640" style="" data-type="png" data-w="834" src="https://wechat2rss.xlab.app/img-proxy/?k=0abe4614&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUmkNlORIRja9bH1q4Ef9KfekvKfKXxLjgDQrqsAPr3WpLavGb0T8aVA%2F640%3Fwx_fmt%3Dpng"/></p><p>那么针对这么多情景，就需要有针对性的梳理和检验出来可以检测出的规则</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="258" data-backw="578" data-ratio="0.4460431654676259" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="834" src="https://wechat2rss.xlab.app/img-proxy/?k=2e3403d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUBaMmwXa1fEIy8pe9e6SFHdibicAbAglg33PicDGHibwmSO40CZUe61cTkA%2F640%3Fwx_fmt%3Dpng"/></p><p>而这对于防守方来说，便算是日常积累的事情，<span lang="EN-US">webshell</span>的检测也是同理：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="236" data-backw="578" data-ratio="0.4076086956521739" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="736" src="https://wechat2rss.xlab.app/img-proxy/?k=1cc8f428&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaU5fSZcPLemPv1lDja2xd7Sh1HYntAicvZkF8sqzyw8icnqvH95GrNZK4g%2F640%3Fwx_fmt%3Dpng"/></p><p>除此之外，例如一些特殊日志的产生，如下图所示：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.07344632768361582" data-s="300,640" style="" data-type="png" data-w="708" src="https://wechat2rss.xlab.app/img-proxy/?k=376f139e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUDhLT3JcXQxoOwQBB8dhRHpgphLvE9SbDxHZzHaduvqbKefyWnpYTKw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0472727272727274" data-s="300,640" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;width: 386px;height: auto;" data-type="png" data-w="275" src="https://wechat2rss.xlab.app/img-proxy/?k=1c7bfb5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUM9KKvXhfoTyuA8VvZp9Eibcp7hAqm4Rgtv5xlIcMYjiasnNdhyS9J6tg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;">（异常情况下的命令执行，执行账户:机器名）<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3206106870229009" data-s="300,640" style="width: 262px;height: auto;" data-type="png" data-w="262" src="https://wechat2rss.xlab.app/img-proxy/?k=d9f9721b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqm45lllA5aWm9gbzRQNUiaUvibjaEHcMFpgNN8cib6z7arxFrP39SkZtiayHqaAcTUZl8kMnic6a7zUzg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-no-proof:yes;">                  （正常情况下的管理员命令执行，执行账户:普通用户或管理员）</span></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">也</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">是可能产生异常行为，或攻击方攻击成功的标志，而作为防御方，则需要把对应的日志提炼成相应的规则。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">另外笔者在自己的书里第八章安全监控中也介绍了需要了解的其他攻击手段的技术，这里就不再赘述。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p><span style="mso-no-proof:yes;">三 运营</span></p><p><span style="mso-no-proof:yes;">有了平台，也有了技术，但最终的结果还需要人为做最终决断，因此，对于策略的运营也是非常重要的一环。而目前来说，笔者认为的主要手段有以下几种：</span></p><p><span lang="EN-US" style="mso-no-proof:yes;">1 </span><span style="mso-no-proof:yes;">关键字监控：</span></p><p><span style="mso-no-proof:yes;">这种方式是应用最广泛的方式，只要了解攻击中的任何特征，便可以建立监控规则，对于已知攻击来说，是最有效的检测手段。</span></p><p><span lang="EN-US" style="mso-no-proof:yes;">2 </span><span style="mso-no-proof:yes;">频率监控：</span></p><p><span style="mso-no-proof:yes;">用于弥补未知攻击的一种手段，例如极少数访问，或者某<span lang="EN-US">ip</span>突发访问某<span lang="EN-US">url</span>等情况。通过建立正常基线的方式，发现可能的异常行为，并进行判断。</span></p><p><span lang="EN-US" style="mso-no-proof:yes;">3 </span><span style="mso-no-proof:yes;">行为分析：</span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;"> </span></span><span style="mso-no-proof:yes;">通过发现异常行为，或设定一些场景，进而发现攻击的手段。例如非业务时间访问、不该有的访问或者端口开方等等。</span></p><p><span lang="EN-US" style="mso-no-proof:yes;">4 </span><span style="mso-no-proof:yes;">机器学习：</span></p><p><span style="mso-no-proof:yes;">频率监控的升级版本，目前来说针对<span lang="EN-US">DGA</span>识别比较有效，（笔者用来识别公交车的图像识别也比较成功<span lang="EN-US">:P</span>） 也可以先对异常进行第一步筛查，减少告警后，再使用人工进行二次判断，进而不断反馈规则经验，形成闭环，使报警更加准确。</span></p><p><span lang="EN-US">5 </span>关联分析：</p><p>笔者认为告警的最高境界，并一直研究的方向，（怎奈水平有限，突破很少）通过收集各个系统之间的日志（报警，行为）从而产生非常准确的告警，并可以把攻击路径完整识别。</p><p>除此之外，针对告警的运营，笔者认为还有几点也非常重要：</p><p>策略的优化：</p><p><span lang="EN-US"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;">  </span></span>尽量将做到告警的准确化，力争每条告警都是准确的，毕竟动辄<span lang="EN-US">999+</span>的告警，再有责任心的人耐心也会终将被耗尽，因此个人认为，作为防御者，应该把最大的精力用在规则的准确化上。</p><p>监控覆盖面：</p><p><span lang="EN-US"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;">  </span></span>就如同开篇介绍的，防守是个全方面的工作，任何一个细小的疏漏，都可能导致千里之堤，毁于蚁穴。因此对防守区域的了解，对资产的了解，对监控覆盖面的了解，便是能否做好防御的一个因素，更不应出现马奇诺防线这种情况发生。但在部署<span lang="EN-US">agent</span>的情况下，又需要对自己的<span lang="EN-US">agent</span>，系统有一定的了解，不能因此而影响业务，这又一次回到了技术领域的范畴。</p><p>责任心<span lang="EN-US">/</span>好奇心：</p><p><span lang="EN-US"><span style="mso-spacerun:yes;"></span><span style="mso-spacerun:yes;">  </span></span>笔者认为，这个是做安全工作，尤其是前者是防御工作的重要素质，笔者见过很多攻击事件，告警明明已经产生，但是由于没人去看，导致攻击的手，这非常令人惋惜。另外，笔者觉得很多攻击都是非常“朴素”的，不需要什么<span lang="EN-US">0day</span>，只用一个可能<span lang="EN-US">n</span>年前已知的漏洞，一个简单的弱口令，普通的再不能普通的<span lang="EN-US">bash</span>反弹，便打穿了整个防御体系。因此需要有足够的责任心，要从告警（哪怕是海量）中抽丝拨茧，发现问题。这里笔者有个非常深刻的感触，就是<span lang="EN-US">lake2</span>之前说的一个案例，他们可以从一个告警中发现<span lang="EN-US">cve</span>，个人觉得这应该算防御的一个最高境界了，而笔者个人觉得，一般公司做到这样固然好，但是没有那么强的技术能力，从告警中能识别到攻击，也已然非常不错了
。</p><p>最后<span style="mso-ascii-font-family:Cambria;mso-hansi-font-family:Cambria;mso-bidi-font-family:
Cambria;">，笔者还认为，既然建立了监控体系，那么就应该多用，因为只有使用了，才可以从中发现问题与不足，从而进一步完善系统与策略，毕竟只有平时像战时，才能战时像平时。</span></p><p><span style="mso-ascii-font-family:Cambria;mso-hansi-font-family:Cambria;mso-bidi-font-family:
Cambria;">以上便是个人的一点点关于安全防御的粗浅理解，在这条路上，个人觉得还是初学者，还有很长的路要走，也有很多经验需要学习，希望可以抛砖引玉，共同学习。</span></p><p><br/></p>



<p><a href="2247483801">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7473bdc1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483801%26idx%3D1%26sn%3D65690fcb35047d4f0e525deaee293380%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 31 Aug 2022 19:50:00 +0800</pubDate>
    </item>
    <item>
      <title>应邀工联大讲堂聊聊安全防御建设</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483787&amp;idx=1&amp;sn=38b86ca9a5084f0b9620fb616a0a6b5f</link>
      <description>应邀工联大讲堂聊聊安全防御建设</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2022-08-24 21:23</span> <span style="display: inline-block;">北京</span>
</p>

<p>应邀工联大讲堂聊聊安全防御建设</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=35b16753&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZrlp99sAagfCEnUrSNKiaRrw5KLmKdPw6d6Fp1yxUWTTaF8YLa9SQ5lUibOicV0pmWM08E9zjo0Q1QdQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div id="js_image_content" class="image_content "><!---->    <!----> <!----> <!----> <div class="wx_album_area js_album_wrap " style=""></div> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary "><!----></div></div> </div>


<p><img src="https://mmbiz.qpic.cn/mmbiz_png/ibCalCUYKkZrlp99sAagfCEnUrSNKiaRrwMLXMcrbDcgIeicXTbQK49vL0WVxia3chmp451ficfytwM4j4UxDgshLBw/0?wx_fmt=png"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1c72556d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483787%26idx%3D1%26sn%3D38b86ca9a5084f0b9620fb616a0a6b5f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Aug 2022 21:23:00 +0800</pubDate>
    </item>
    <item>
      <title>和好友聊一聊企业安全建设</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483784&amp;idx=1&amp;sn=84a5c00104fc9629822e3f779416dcc1</link>
      <description>跟好友301聊聊企业安全建设，从甲乙两方的视角，也看看乙方是怎么看这个事情的</description>
      <content:encoded><![CDATA[<p>
<span>lion_00</span> <span>2022-08-10 19:22</span> <span style="display: inline-block;">北京</span>
</p>

<p>跟好友301聊聊企业安全建设，从甲乙两方的视角，也看看乙方是怎么看这个事情的</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=25d326d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZptZOcUVzshO5314PEm06cyOjfjWhVib8XIEaVkibC2HFYoRPdibJ0rP9evOicbBWmuPdJ3gnkruonbVA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.7786666666666666" data-s="300,640" style="" data-type="jpeg" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=d58a485e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZptZOcUVzshO5314PEm06cy55icCcupdGVBkeDmIfyHu5jze0mUVyiaMubxZK2FqX16oVl504Evm9Vg%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p>



<p><a href="2247483784">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7a8d69e5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483784%26idx%3D1%26sn%3D84a5c00104fc9629822e3f779416dcc1%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Aug 2022 19:22:00 +0800</pubDate>
    </item>
    <item>
      <title>NeuVector----功能丰富且强大的容器安全开源软件</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483778&amp;idx=1&amp;sn=80102acbcb4ec21db0e46f168340814c</link>
      <description>好久没有遇到值得推荐的系统了，NeuVector可以称得上是一款开源容器安全解决方案了。</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2022-07-25 10:54</span> <span style="display: inline-block;">北京</span>
</p>

<p>好久没有遇到值得推荐的系统了，NeuVector可以称得上是一款开源容器安全解决方案了。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7bd5dc51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmMohnMNGib0aMv3NWrtX0XX1Odiba7oE23wTxIvwJkqjicwkMVNEsSooNw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  随着容器的广泛应用，容器的安全问题，也需要关注。例如容器中引用的组件，容器之间的隔离，甚至容器中的进程等等。因此对容器的管理，也会在安全防御中起着至关重要的影响，正好笔者无意中发现了NeuVector这款开源软件，在测试中发现，确实是一个功能丰富且强大的容器开源软件。<br/></p><p>一 安装</p><p>  关于NeuVector的安装，可以参考官方文档：<a href="https://open-docs.neuvector.com/deploying/kubernetes，或者这篇文章：《" target="_blank">https://open-docs.neuvector.com/deploying/kubernetes，或者这篇文章：《</a><span style="font-size: 16px;">云</span><span style="font-size: 16px;">原生安全平台 NeuVector 部署》，笔者在部署中遇到了一点点权限问题,不过按照相关提示设置权限也完成了安装，总体来说，安装还是比较容易的。安装完成后登录即可。</span></p><p style="text-align: justify;"><span style="font-size: 16px;"></span></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="269" data-backw="578" data-ratio="0.46484375" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=3f5ef690&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmibHFFj1bqbic0fCH1sRPNboPjaCngUOJhrMZEEbaKUzVRdwNPoPGibRMA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>二 主要功能介绍</p><p>  NeuVector的功能，也可以参考官方文档，笔者仅仅测试了几个功能，效果还是比较不错的<br/></p><p>2.1 检测出入口暴露风险</p><p>  该功能主要可以检测出对外暴露的pod，以特权或root运行的POD等。例如我新建一个influxdbPOD，内容如下图，网络为hostNetwork，外部可以之间访问到fnfluxdb的8086端口：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4397163120567376" data-s="300,640" style="" data-type="png" data-w="846" src="https://wechat2rss.xlab.app/img-proxy/?k=a2b82c29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmjbeRelicEu4N4Dkt8gbiatHpQwMxksibhBDPwib3VicT3iclqDJu99a1mpLQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75546875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d7cc9ee9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmdC11m8I0BazAlQtCNVOn8XazdbZc29losbibrY3k67e7KgiaPMlaNk4g%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">此时NeuVector便识别出该POD端口可以对外访问，如下图所示：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2765625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=aaa3e92a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmMgvQMZ5oHyVyBKIWhB2toQ3GF9mktMWEGTtxQx2wiceINeLWM2ZhjoQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;"><br/></p><p style="text-align: left;margin-bottom: 0em;">再建立个使用特权容器运行的POD，如下图所示：<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.528395061728395" data-s="300,640" style="" data-type="png" data-w="810" src="https://wechat2rss.xlab.app/img-proxy/?k=b346334f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmnwShFiciawiaWFjj87Kbo0YE0yyk7ESoDSliaKA6pCeSK5yVpPkWjUGZ2w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">在下图中，也可以看到已经识别到使用了特权模式</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="186" data-backw="578" data-ratio="0.32109375" data-s="300,640" style="width: 578px;height: 186px;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=1f551e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsme0xlPAkBp9O3fBNPmK62B7Kmzs86hQHibZwnHSUgOZvz5VDz1vBybmQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">2.2 WAF功能及网络可视化功能</p><p style="text-align: left;margin-bottom: 0em;">  网络可视化功能可以方便之间观察各组件之间的网络连接情况，可以查看会话，甚至进行数据包抓捕，极大的方便了管理。而WAF功能更是可以给组件提供保护，不过目前只支持正则表达式的模式。在下图中，使用test-con1及test-web1进行测试，在未连接前如下图所示：</p><p style="text-align: left;margin-bottom: 0em;">  </p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.56796875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8ddb4a5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmV2L9GWnMlMXZwI4HmXZDM1GagYvAxfqicPaj86bEEN6wVsmz8iakBrBg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">在test-con1中访问test-web1<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5609375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=020f5351&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmNNr0WgBGGpQiaM2BzzibuQZDDibhBHB4t3jGQoPtDibGBkPRErnIbib3bUQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">可以看到，连接的情况：<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/ibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmhRYPGbuYofoacQZXDqVk2O9OvCJX7qlMYBjia9skBxxRLEnLwmMMtww/0?wx_fmt=png" data-cropx1="166.00346020761245" data-cropx2="861.470588235294" data-cropy1="323.2698961937717" data-cropy2="491.02076124567486" data-ratio="0.24172661870503598" data-s="300,640" style="width: 398px;height: 96px;" data-type="jpeg" data-w="695" src="https://wechat2rss.xlab.app/img-proxy/?k=9cdbd38e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmdnLOsN3kx6SDvecErZ7zdt9Hwfxb3koRiaU1SFjmXmaiaJturicH28Q3w%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: left;margin-bottom: 0em;"><br/></p><p style="text-align: justify;">这时，配置WAF，并将WAF规则引用于test-web1中，内容为：若URL包含lion则进行后续处理</p><p style="text-align: justify;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4125" data-s="300,640" style="text-align: center;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8b1cef14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmXhx6knicQLK7RzLLKmG9k3sTt3gukicNWz4RDhlNib8SnrWzmo92XB6mA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: justify;">此时再次访问test-web，并在url中包含关键字lion</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.246875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=36c932e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmOMsEy6LoFWWCP0BUkzv9nOUjZoGA5BJuT7vlmD43qtgSvzkG3LtibJg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">可以看到，连线变成了黄色,并产生了安全事件的告警：<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3650602409638554" data-s="300,640" style="" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=c6e39d89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmiaPOG8FXTFvaEwlbEaYbhwKM3fRNgI72WjttteGmrjCsjQicdDn2icVog%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5dce8a71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmvmnx8TDBiaYuhg54g0ud7W64uNQdQXCTbnwEbys4xxWUkgZQXia37yPw%2F640%3Fwx_fmt%3Dpng"/></p><p>同时，可以在安全事件中的显示数据包中看到对应的内容：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4548611111111111" data-s="300,640" style="" data-type="png" data-w="1152" src="https://wechat2rss.xlab.app/img-proxy/?k=f7fda715&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmf7XpEia3ic0CckolEg41uw76hibvzWLYCYiavF6GgI4du739IO6guVayqA%2F640%3Fwx_fmt%3Dpng"/></p><p>但此时仍可以正常访问test-web1的原因是因为test-web1处于学习（或者监控）模式，若将该模式改为保护模式,则无法再进行访问，WAF功能已经拦截，并产生拦截告警，同时，网络活动中可以看到连线已经变成红色。<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.15703125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=19a50985&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmQKeHQvOuhzZvKnKWL8FkqejCKGHg5icibpE6VbJblUxcptuRMWFVXEuQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.07578125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=62284eff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmDlp2DzIWvibKJyUb2fS7S1ph8dsUHgVfIn8yxwRrsrkEtDm7ic3f9zmQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.09296875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=2d9053cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmoseIe5HicOEvyUb6iaCA2VhQdgrSiclVKDyCJBicTxCQJE1foUzL5ppPYg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4015625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=cb857686&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmHSzDpTVX0icODrMs1VYEf2iant4PMhXG5IKmlo2NVaVCeyjXZ8EebFQg%2F640%3Fwx_fmt%3Dpng"/></p><p>2.3 准入控制<br/></p><p>  在生产环境中，往往需要满足一定的安全条件才可以进行相关的发布操作，因此可以使用准入控制这一功能完成上述需求。这里以不可以以特权模式运行pod为例：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2234375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=075a6961&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmmRbosc03H3C1nwXxVyxgn4KpnxV1WyCqTUBIGCg3c63tkphdMnRmew%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=1b814ae9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmDqdN1ojODjmWCWmM1uqsVRMaicXw8msVBaPnzyYWOvWkuNDU3Y2AT6Q%2F640%3Fwx_fmt%3Dpng"/></p><p>  并将状态设为启用，并将模式改为保护：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.19765625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=a1655f98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmXJIok1pjKOTwe65S7wPyFOG588ZsmRe4WuEc1GSbHBIR3ShSJU0Jfg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;">此时再次建立另一个特权模式的POD ，便会提示无法创建，同时也会产生对应告警，如下图：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5320754716981132" data-s="300,640" style="" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=4dcd570b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmfrRY5wHicriaUtD2uOmAuGaeibajPX2nLvkqJxD0r7pjC0loV5Q8wtZGQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.0328125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=38fdfbc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmKZtUtibhicUwSdFmCCicX2BSUZ9JicU1GdnU25e0zvg2BicEW4BRWW8heLA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.07890625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=7b953606&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmeqjPNiacsRicFMdz0ia5jQI8I48EPaspbcibse6sfnmgBO9ZOhydtVCOyQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;margin-bottom: 0em;"><br/></p><p style="text-align: left;margin-bottom: 0em;">2.4 其他功能</p><p style="text-align: left;margin-bottom: 0em;">  除以上功能外，NeuVector还可以学习到容器中的网络连接，进程等相关信息，可以针对这些信息，设置相关的规则，进行后续的处理。<br/></p><p style="text-align: left;margin-bottom: 0em;">例如识别进程信息：</p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.15390625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5e71a805&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmF7nLhBcNg6kRI0LpHhxSNWT7F0u8okTIKeHiaic3iat64xwDIH89ia3PJA%2F640%3Fwx_fmt%3Dpng"/></p><p>识别网络规则：<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.13359375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=bf71c7ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmniasD79s9RoEiaHMwLE6nvianeKne8KGhxkxXDOrnic1IWPCgv2e6jJjpg%2F640%3Fwx_fmt%3Dpng"/></p><p>除此之外，还可以对容器/系统/集群/代码仓库进行扫描，<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4890625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=ce683768&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmahvyRFXmNA563OHK7e6WquSlVDsuVCwApkcPAFR2eeyebvpQDxF2Tg%2F640%3Fwx_fmt%3Dpng"/></p><p>还可以进行合规性的扫描：<br/></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.27265625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8203d77b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZric3eu9Q47D8yEGP8Y2XRsmE1ERu9RTcibgZDuIbXbyKsXEbHQBPPSV7T9nLIhP04xzLcY24eIcic5g%2F640%3Fwx_fmt%3Dpng"/></p><p>当然，以上的展示的只是笔者个人关注一部分，如果读者感兴趣，可以继续深入研究。</p><p>三 总结<br/></p><p>  通过上述的演示，笔者认为NeuVector确实可以解决实际生产中的容器安全问题，不过笔者也仅仅也是在实验环境中使用，在生产环境中，笔者了解到两个可能存在隐患的地方：</p><p>1 针对系统的漏洞扫描，是需要将整个系统转入内存中进行，因此如果POD过大，可能会对系统产生一定的资源消耗问题。</p><p>2 WAF,DLP 等功能，会对应用产生性能影响，如果配置错误，很可能也会演变为安全事故，因此这些功能也应该谨慎使用。<br/></p><p>  综上所述，个人觉得，这款软件确实可以称得上是一个容器安全解决方案了，值得推荐。不过这仅仅是一个工具，好比一把剑，普通人，只能瞎甩，而令狐冲可以使出独孤九剑，因此重要的更是使用的人。<br/></p>



<p><a href="2247483778">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c8d75e69&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483778%26idx%3D1%26sn%3D80102acbcb4ec21db0e46f168340814c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 25 Jul 2022 10:54:00 +0800</pubDate>
    </item>
    <item>
      <title>Kerberos协议之MS14-068分析和防御</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483740&amp;idx=1&amp;sn=ab0e022ce1863f16037d7b86df67ba6a</link>
      <description>本文主要简单说明 Kerberos 协议的认证过程，然后介绍了 MS14-068 的漏洞原理和利用过程，同时</description>
      <content:encoded><![CDATA[<p>
<span>猎豹安全中心</span> <span>2022-03-30 17:19</span> <span style="display: inline-block;"></span>
</p>

<p>本文主要简单说明 Kerberos 协议的认证过程，然后介绍了 MS14-068 的漏洞原理和利用过程，同时</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c7027374&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FmUB2xUVsqMUFEIFB8vY2j703WcKKhVSIRf4PwE8G2DibXJARx3ES5RTdia8WuydIHdjfF5eJcCX2D65cXAMME2uQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);visibility: visible;overflow-wrap: break-word !important;">本文主要简单说明 Kerberos 协议的认证过程，然后介绍了 MS14-068 的漏洞原理和利用过程，同时结合了漏洞利用产生的事件日志和攻击流量进行分析。</p><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);visibility: visible;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;visibility: visible;overflow-wrap: break-word !important;">Kerberos</span></h2><blockquote style="padding: 15px 15px 15px 1rem;outline: 0px;border-left-width: 0px;border-left-color: rgb(220, 230, 240);color: rgb(129, 145, 152);font-size: 14.4px;max-width: 100%;box-sizing: border-box;overflow-wrap: normal;letter-spacing: 0.544px;white-space: normal;line-height: inherit;background: rgb(242, 247, 251);overflow: auto;word-break: normal;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;visibility: visible;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;visibility: visible;overflow-wrap: break-word !important;">Kerberos 是 MIT 提出的一种网络身份验证协议，它通过密钥加密技术验证用户或主机的身份。Kerberos 默认使用 UDP 端口88。</p></blockquote><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);visibility: visible;overflow-wrap: break-word !important;">Windows 使用 Kerberos 作为其默认身份验证方法。如果将客户端加入 Windows 域，则说明将启用 Kerberos 作为从该客户端到 Windows 域中的服务以及与该域具有信任关系的所有域的身份验证的默认协议。但需要注意的是，如果客户端或服务端或两者都未加入域，Windows 将改为NTLM提供身份验证。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);visibility: visible;overflow-wrap: break-word !important;">先看看Kerberos的角色功能。</p><ul class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Domain Controller (DC)：域控制器。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Key Distribution Center (KDC)：秘钥分发中心，默认安装在域控里，包括 AS 和 TGS。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Authentication Service (AS)：身份验证服务，用于 KDC 对 Client 认证。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Ticket Grantng Service (TGS)：票据授予服务，用于 KDC 对通过 AS 发送给 Client 的 TGT 换取 ST(Service Ticket)。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Active Directory (AD)：活动目录，用于存储用户、用户组、域相关的信息。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">Privilege Attribute Certificate (PAC)：特权属性证书，用于验证是否有服务访问权限。</span></p></li></ul><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">再来看看看认证流程。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.49874686716791977" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;width: 677px !important;" data-type="png" data-w="1197" src="https://wechat2rss.xlab.app/img-proxy/?k=5761cd11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISwSFjia6Uw72fSUqs3lfGt2Rs87tJibPrLjOSNibKj5qjiaJViaT2rXmJBQw%2F640%3Fwx_fmt%3Dpng"/></p><ol class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">AS REQ<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>客户端用户 Client 向 KDC 发送一条消息 AS REQ 进行预验证，其中消息包含了 Client 密码 HASH 加密的时间戳、Client-info、网络地址等。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">AS REP<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>KDC 请求AD查询Client，若存在该用户则用其密码 HASH 解密 AS REQ 中的时间戳，若解密成功且时间戳在5分钟之内，则验证成功。AS 会返回 Sessionkey-AS (经过 Client 密码 HASH 加密)和 TGT (包含经 KRBTGT HASH 加密的 Sessionkey-AS 和时间戳等信息，因此 TGT 无法被 Client 解密解析)。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">TGS REQ<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>Client 用自身密码解密 Sessionkey-AS，再用 Sessionkey-AS 加密时间戳和 Client-info 作为其中一部分内容，和 TGT 一起发送给 KDC 中的 TGS 以认购换取 ST 票据。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">TGS REP<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>TGS 首先自检是否存在 Client 所请求的服务，若存在，则使用 KRBTGT 密码 HASH 解密 TGT，解密得到 Sessionkey-AS 、时间戳、Client-info。然后再用这个 Sessionkey-AS 解密步骤 3 中的一部分内容，得到第二份时间戳和 Client-info，两者进行比较，有效时间范围，网络地址是否相同。认证成功后，TGS 会生成用 Sessionkey-AS 加密的 Sessionkey-TGS 和 Server 密码 HASH 加密的 Sessionkey-TGS (即 ST 票据)返回给 Client。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">AP REQ<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>Client 先用之前本地缓存的 Sessionkey-AS 解密得到 Sessionkey-TGS。当 Client 需要访问 Server 上的服务时，Client 使用 Sessionkey-TGS 加密时间戳等信息，和 ST 一起发送给 Server。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">AP REP<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>Server 使用自己密码 HASH 解密 ST 得到 Session-Key TGS，然后再解密得到时间戳等信息，与 ST 的时间戳和 Client-info 等分别进行验证对比。</p></li></ol><blockquote style="padding: 15px 15px 15px 1rem;outline: 0px;border-left-width: 0px;border-left-color: rgb(220, 230, 240);color: rgb(129, 145, 152);font-size: 14.4px;max-width: 100%;box-sizing: border-box;overflow-wrap: normal;letter-spacing: 0.544px;white-space: normal;line-height: inherit;background: rgb(242, 247, 251);overflow: auto;word-break: normal;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">这里需要提醒的是，一般地，有些服务并不需要 PAC 验证，该服务会接受 TGS 票证中的所有数据，而不与 DC 通信。</p></blockquote><h3 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.3em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">PAC</span></h3><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">PAC 即 Privilege Attribute Certificate(特权属性证书)，它是 Kerberos 票证的扩展。需要注意的是，Kerberos 以上认证过程说明了客户端是否为真实有效用户，但未声明该用户是否具有访问目标服务的权限，因为在域中不同权限的用户所能访问的资源是不同，而 PAC 解决了访问权限问题。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">PAC 包含了用户或组安全标识符 (SID)。当用户在 AD 域中进行身份验证时，域控制器会将此信息添加到 Kerberos 票证中。当用户使用 Kerberos 票证访问其他服务进行身份验证时，可以读取 PAC 来确认其权限级别，而无需联系域控制器来查询该信息。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">继续完善上面的认证流程。</p><ul class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">PAC Validation Request<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>PAC 是在 AS REQ 后由 KDC 生成的，返回给 Client 的 TGT 包含了 PAC。CLient 与 KDC 完成认证以后，此时需要访问 Server 所提供的某项服务，Sever 会拿着 PAC 去请求 DC 查询 Client 是否有访问权限。</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">PAC Validation Response<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>DC 对 PAC 进行解密，通过 PAC 中的 SID 判断 Client 的用户组信息、用户权限等信息，然后将结果返回给 Server，Server 再将此信息与域用户请求的服务资源的 ACL 进行对比，最后决定是否给 Client 提供相关的服务。通过认证后 Server 将返回最终的 AP-REP 并与 Client 建立通信。</p></li></ul><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">但需要说明的是，有些服务并不需要 PAC 验证，该服务会接受 TGS 票证中的所有数据，而不与 DC 通信，而银票攻击则也正利用了这个条件。</p><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">MS14-068</span></h2><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">MS14-068 是位于 kdcsvc.dll 域控制器的 KDC 服务中的漏洞，它允许经过身份验证的用户在其获得的票证 TGT 中伪造插入任意的 PAC 。普通域用户可以通过呈现改变了的 PAC 的 TGT 来伪造票据获得管理员权限。</p><h3 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.3em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">利用过程</span></h3><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">域测试环境：</p><ul class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">DC<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>系统：Windows Server 2008 R2 x64<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>主机名：win08<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>地址：192.168.1.8<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>域名：bbk.lab<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>系统信息：无 KB3011780 补丁</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">域成员机器<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>系统：Windows 7 x64<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>主机名：pc<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>地址：192.168.1.7<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/>域普通账户：user1</p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">exp：Pykek工具包的 ms14-068.py 编译后的可执行文件exe</span></p></li></ul><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">漏洞利用前，收集账户信息，查看当前权限。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.34798534798534797" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 546px !important;visibility: visible !important;" data-type="png" data-w="546" src="https://wechat2rss.xlab.app/img-proxy/?k=df070a67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISZOphyo3LELzXLuTn8XeV7iarjMtlnKLKPGNa7HB7ZnCuFy7ptQvzwkA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">使用 exp 在当前目录路径下生成一个高权限的 TGT 票据</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.3277439024390244" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 656px !important;visibility: visible !important;" data-type="png" data-w="656" src="https://wechat2rss.xlab.app/img-proxy/?k=2c814b05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISsRmjhqE9naL7AZkIJGnBiaSZNvZIgChXqicqA1Hj9Ecu4bP4sNzbxicXw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">mimikatz 清楚内存中票据信息，将 TGT 票据注入到内存。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.5780487804878048" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="820" src="https://wechat2rss.xlab.app/img-proxy/?k=6fc71fdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIShDrAA19yvR6Sh49cthWswr3ibOmy8xicN3vMCH5OLj5JdXa6SrU6zodw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">注入成功，<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">dir</code>查看当前权限，可以看到已经提权成功。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.5081081081081081" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 555px !important;visibility: visible !important;" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=438c8b28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISYqyrCYJUFmdukSF9sH5OuicQecD1mVLVsSOOrZcffIicKibR2mh9htgkQ%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">漏洞成因与流量分析</span></h2><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">以下通过 exp 结合流量分析和学习 MS14-068 漏洞原理。对 exp 设置断点 debug，并使用大鲨鱼抓包。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.2359375" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=c86e3899&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISA1EsoCOHJeYhsS7mNia25OogC5Fme0HTNaVqNgSjbMeoTB5e21SCEqw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">这里的参数<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">pac_request</code>为 False，说明在构建 AS REQ 消息时，Client 将向 KDC 申请一张不包含 PAC 票据，这个是微软默认的设计。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.6593495934959349" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1230" src="https://wechat2rss.xlab.app/img-proxy/?k=158e52a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISPc2Cfyynhz80BR7GibS1D641y3dBMzZKNDKq2tjLZZRsUOxIH5Wb6Qw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">查看对应流量，确认<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">include-pac: False</code>。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.4568744662681469" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1171" src="https://wechat2rss.xlab.app/img-proxy/?k=3612ff9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISPxKfddkdxPALqcRSVhy4GI11xWhQfPHY2PAsACmU8usg0UX6fhdricQ%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">查看正常 AS REQ 请求流量，两者进行对比。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.4386339381003202" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="937" src="https://wechat2rss.xlab.app/img-proxy/?k=f6aed656&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISRZg8SOIKpL2LY6GD3HbHL3PkMhjv35WXZryCRHLyT1gsevndXeKZTQ%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">AS REP 响应，将 KDC 加密的TGT 返回给客户端。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.4546218487394958" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1190" src="https://wechat2rss.xlab.app/img-proxy/?k=609b8be2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISo9UBovV0EvxPw9H2lsJUiaZCtft4Q6jJOATeRqrjPBibxUOUIELWXbxw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">参数<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">tgt_a</code>获取 TGT 票据。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.17758484609313338" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1267" src="https://wechat2rss.xlab.app/img-proxy/?k=d9dbbb0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISCic1j1gSNvMwBVWoKHugiaGnXHCUSibv68kYazfgXWKCldg2WAS5zhK5Q%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">构造 TGS REQ。跟进<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">build_pac</code>函数查看 PAC 构造。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.27818853974122" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1082" src="https://wechat2rss.xlab.app/img-proxy/?k=251ff8fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISVDwAz4EXibn1G6kDzOcdDmCcOXB13Kc6HqwAKNhApEarzrM6wAw2oEQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.24582869855394884" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="899" src="https://wechat2rss.xlab.app/img-proxy/?k=7455e48c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISfsbiacgQhjNaZsP0icbkehicbrr1fz8rvicKULCU3W4syT09VTVMampCGQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">分别提取了 domain_sid、user_id，<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">_build_pac_logon_info</code>构造高权限 SID 以达到提权目的。<br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.9562937062937062" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 572px !important;visibility: visible !important;" data-type="png" data-w="572" src="https://wechat2rss.xlab.app/img-proxy/?k=fb345718&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS0HEWV49MJCics5t8uwm0r3Fb1bdesmZpIff25VGJ0UiaDaViaAh80xbGA%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">该函数将组成员身份声明更改为包含更高特权的组，由于 PAC 包含用户或组 SID，这就使得 AD 域中具有有效 AD 凭据的计算机上的 Client 能够绕过所有已配置资源的 ACL。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.33669609079445145" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="793" src="https://wechat2rss.xlab.app/img-proxy/?k=9da467fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISA8JcA5omLuDu6hOZ55Gj3EGuWPz8yyuBMgjzibicNHL78zc0UNdicT5qg%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">往下，关注默认参数<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">server_key=(RSA_MD5,None)</code>、<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">server_key=(RSA_MD5,None)</code>，关注<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">checksum</code>函数，以及参数<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">server_key</code>和<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">kdc_key</code>。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.43671875" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d21b0203&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS73bu3Vv3hHt6E6uuicPMfBSsV6triaFFlIgOn1OAvVf3dBYAxeCEqwOg%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">关于 PAC 签名，微软也做了相应的说明。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="1.0234604105571847" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1023" src="https://wechat2rss.xlab.app/img-proxy/?k=8f7e1dcb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISzwvicibb2ttpyj22BQvPSdGf1kNTicq5Ycko2JSic18uUZXRmNx71IYjwQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">意思就是 </span><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">PAC 通过包含两个数字签名(分别为 Server 密码 HASH 与 KDC 密码 HASH)防止 PAC 被伪造。</span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">那么这两个数字签名 PAC_SERVER_CHECKSUM 和 PAC_PRIVSVR_CHECKSUM 则对应为<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">chksum1</code>和<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">chksum2</code>。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">跟进查看<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">checksum</code>函数，<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">server_key[0]</code>和<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">kdc_key[0]</code>指的就是加密方式，指定为 MD5，这里<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">server_key[1]</code>和<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">kdc_key[1]</code>应为 Server 和 KDC 密码 HASH 并都设置了为<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">None</code>。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-backh="157" data-backw="472" data-ratio="0.3326271186440678" data-s="300,640" style="outline: 0px;width: 677px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-type="png" data-w="472" src="https://wechat2rss.xlab.app/img-proxy/?k=a0f5a23e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISm6mxibibJibuKr2F2iatJCLICsgEsdZrlg9wrHkAvTO3X6RCfsTp2icuoxw%2F640%3Fwx_fmt%3Dpng"/><span style="outline: 0px;max-width: 100%;text-align: justify;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">构造好 PAC 后，将其传入<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">build_tgs_req</code>函数构造 TGS REQ，然后发送给 KDC。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.5050691244239631" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1085" src="https://wechat2rss.xlab.app/img-proxy/?k=bb791cb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS0ByTB9jsib5FGtL1GvtMqCfjLszexlnticVYPjyByMicHIoB12dYmKA5A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">在上图中可以看到前面得到的 TGT 和通过<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">eTYPE-ARCFOUR-HMAC-MD5</code>加密方式的 PAC。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">KDC 验证完成以后，返回 TGS REP，其中包含一张新的 TGT，它会将 exp 生成具有高权限的 PAC 包含在其中。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.5262689225289403" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1123" src="https://wechat2rss.xlab.app/img-proxy/?k=122173fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS4jNpjV9OvlENtG6VuJO8zjrygVSIBhdJTDc0xy0Vs0Ubh1Nc3kG5Pw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">exp 收到上图新的 TGT 后会将其保存为<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">TGT_user1@bbk.lab.ccache</code>文件以方便 Client 导入到内存中使用。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">在 Client 上使用 mimikatz 清除内存中现有的 Kerberos 票据，然后将 exp 生成的 TGT 导入到内存中进行提权。尝试连接访问 DC 的共享文件夹，继续抓包。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.6393034825870647" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1206" src="https://wechat2rss.xlab.app/img-proxy/?k=4b1005db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISbGlYUAjicB899ycv6dLvBTlEvW1VSmuJSAEmRzU1C0uuSYw4bJkJTjA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">进行了两次的 TGS REQ 请求，第一次 TGS REQ 请求是使用上面exp生成的高权限 TGT 票据，然后返回了一张 win08.bbk.lab (win08是DC主机名)的 CIFS 服务的 ST 票据。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.6832358674463938" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1026" src="https://wechat2rss.xlab.app/img-proxy/?k=a74ef9aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIShn4DxjzgLaibSDPCPD1AVY4PAKLZbG17hwYB4Ufhjy4EPKjsdYtbicXA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">然后通过 SMB 协议拿着这个 ST 票据请求 CIFS 服务，发起 Session Setup Request(AP REQ)。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.7416462917685411" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1227" src="https://wechat2rss.xlab.app/img-proxy/?k=b4376866&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS6w9tezJGUASFh9eUwkNnc78nF8f4Ko43ctkExbUibPwkgKEwsRRLlJA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">最后，返回 Session Setup Response(AP REP)响应。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.5668016194331984" data-s="300,640" style="outline: 0px;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;" data-type="png" data-w="1235" src="https://wechat2rss.xlab.app/img-proxy/?k=012c8486&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPIS7HfZ6dJ5yovriaaC0KTfiaJws11o6k6cdBKzRXKXYdqmibdAK1ia31CIXw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">此时，Client 拥有了 DC 上 CIFS 服务的有效 TGS，并且能够使用它通过 SMB 访问共享文件夹，甚至通过 psexec 远程连接。</p><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">日志分析与防御措施</span></h2><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">以下是使用伪造 TGT 获取 TGS 以访问 DC 的 c<span style="padding: 8px 3px;outline: 0px;max-width: 100%;box-sizing: border-box;font-variant-numeric: normal;font-variant-east-asian: normal;font-stretch: normal;font-size: inherit;line-height: inherit;font-family: KaTeX_Main, &#34;Times New Roman&#34;, serif;text-rendering: auto;color: inherit;overflow-wrap: break-word !important;"></span></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">事件4769显示 user1@bbk.lab 使用伪造的 TGT 请求 TGS Kerberos服务票证。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-backh="549" data-backw="410" data-ratio="1.3395638629283488" data-s="300,640" style="outline: 0px;width: 677px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-type="png" data-w="642" src="https://wechat2rss.xlab.app/img-proxy/?k=9ea9d7ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISlhe8JXNBdnkRTbpwXAJs2PD6AKcibPwd3AA0oRmV9SxDzuO8UGG0o5g%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">事件4624显示 user1@bbk.lab 使用 TGS 服务票证登录到 DC。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-backh="582" data-backw="411" data-ratio="1.4156928213689481" data-s="300,640" style="outline: 0px;width: 677px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-type="png" data-w="599" src="https://wechat2rss.xlab.app/img-proxy/?k=edbed6ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISdAhlOkflF4SF50yicKCZibaCO0SDzV4Ziarvkwk6icicyKicsOx1ZM3E2ibGg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">事件5140显示 user1@bbk.lab 使用 ST 连接到只有管理员有权访问的目标域控制器的 c<span aria-hidden="true" style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;height: 0.73354em;vertical-align: -0.0391em;overflow-wrap: break-word !important;"></span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">共</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">享</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">的</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">事</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">件</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">日</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">志</span><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">。</span></span><span style="outline: 0px;max-width: 100%;color: inherit;font-size: inherit;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-backh="542" data-backw="416" data-ratio="1.3026113671274961" data-s="300,640" style="outline: 0px;width: 677px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-type="png" data-w="651" src="https://wechat2rss.xlab.app/img-proxy/?k=d5fd341e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISXUd8Rb7bZweUq6EaUFL9LSLHicD8LDp4cJn0TFVjF9hyyrH2FUoKQHA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">事件4672显示 user1@bbk.lab 已成功验证（并登录到）只有域管理员才能访问的目标域控制器。</p><p style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-backh="589" data-backw="425" data-ratio="1.384735202492212" data-s="300,640" style="outline: 0px;width: 677px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-type="png" data-w="642" src="https://wechat2rss.xlab.app/img-proxy/?k=a86a0c6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqmsEG5cicCicFrjXULicy684U832s5TrPISsJtPRzKWM5AmNPBIV4DABJXoQCH6WAiaauWK5yl7R7X1esq2zjK0mHw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">而且，此该用户具有 SeBackupPrivilege、SeRestorePrivilege、SeDebugPrivilege、SeTakeOwnership 等权限，表明该用户具有对此计算机的完全管理员访问权限。说明域控已经沦陷。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box;color: inherit;font-size: inherit;line-height: inherit;overflow-wrap: break-word !important;">防御措施：</strong></p><ul class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">使用更高版本操作系统，安装补丁(KB3011780)，定期进行安全更新。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">对域内账户进行控制，禁止使用弱口令，及时、定期修改密码。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">当确认已被提权成功域控沦陷时，重装域服务。</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击检测：内部流量分析标记<code style="margin-right: 2px;margin-left: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word;font-size: inherit;color: rgb(233, 105, 0);line-height: inherit;border-radius: 4px;background: rgb(248, 248, 248);">include-pac: False</code>作为特征，结合事件日志研判攻击是否成功。</p></li></ul><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">总结</span></h2><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">MS14-068漏洞主要是经过身份验证的域用户向 Kerberos KDC 发送伪造的 Kerberos 票据，票据其中包含了声称该用户是域管理组成员的 PAC。KDC 在处理来自攻击者的请求时不正确地验证伪造的票据签名，从而允许攻击者以域管理员身份访问任何资源。</p><p style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;">从接触内网渗透以来，第一次分析 Windows 提权类型的漏洞，收获良多，受益匪浅。MS14-068 虽然是14年的老漏洞，但是放在今天仍然还具有一定的影响，且对该漏洞的处理与防护，也能举一反三应用到其他漏洞上。关于 Kerberos 协议的认证流程和 exp 利用，还有很多细节没深入去挖掘出来，文章篇幅较长，如有错漏还请海涵。</p><h2 style="margin-top: 1.5em;margin-bottom: 1.5em;outline: 0px;font-weight: bold;font-size: 1.4em;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;">参考</span></h2><ul class="list-paddingleft-1" style="padding-left: 32px;outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;list-style-position: initial;list-style-image: initial;font-size: 16px;color: rgb(62, 62, 62);line-height: inherit;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Microsoft Security Bulletin MS14-068 - Critical<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/><span style="outline: 0px;max-width: 100%;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;letter-spacing: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;">(</span><span style="outline: 0px;max-width: 100%;letter-spacing: normal;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-068" target="_blank">https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-068</a></span><span style="outline: 0px;max-width: 100%;letter-spacing: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;">)</span></span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Python Kerberos Exploitation Kit  </p><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;">(<span style="outline: 0px;max-width: 100%;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a href="https://github.com/mubix/pykek" target="_blank">https://github.com/mubix/pykek</a></span>)</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Utilizing the Windows 2000 Authorization Data in Kerberos Tickets for Access Control to Resources<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/><span style="outline: 0px;max-width: 100%;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;">(<span style="outline: 0px;max-width: 100%;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a href="https://docs.microsoft.com/en-us/previous-versions/aa302203(v=msdn.10)" target="_blank">https://docs.microsoft.com/en-us/previous-versions/aa302203(v=msdn.10)</a></span>)</span></p></li><li style="margin-bottom: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Digging into MS14-068, Exploitation and Defence<br style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: inherit;color: inherit;line-height: inherit;overflow-wrap: break-word !important;"/><span style="outline: 0px;max-width: 100%;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;">(<span style="outline: 0px;max-width: 100%;color: rgb(0, 128, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><a href="https://labs.f-secure.com/archive/digging-into-ms14-068-exploitation-and-defence" target="_blank">https://labs.f-secure.com/archive/digging-into-ms14-068-exploitation-and-defence</a></span>)</span></p></li></ul><p style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;color: rgb(231, 135, 48);font-size: 14px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;">猎豹安全中心技术分享频道</span></p><section style="margin-top: 15px;margin-bottom: 15px;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;line-height: 1.5em;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 663.458px;vertical-align: top;border-style: solid;border-width: 1px;border-radius: 0px;border-color: rgb(189, 189, 189);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;text-align: right;overflow-wrap: break-word !important;"><section style="padding-right: 10px;padding-left: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: top;width: 529.167px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: 5px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;background-color: rgb(231, 135, 48);height: 2px;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></section></section></section><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: top;width: 132.292px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: -11px;outline: 0px;max-width: 100%;box-sizing: border-box;transform: translate3d(1px, 0px, 0px);overflow-wrap: break-word !important;"><section style="padding-top: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 40px;height: 50px;vertical-align: top;overflow: hidden;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;text-align: center;overflow-wrap: break-word !important;"><img data-ratio="1" data-type="png" data-w="140" style="outline: 0px;box-sizing: border-box;vertical-align: middle;overflow-wrap: break-word !important;visibility: visible !important;width: 140px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2f17cf30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmUB2xUVsqMUCc18wgBO2KbZ6gLhDYxsNLG3icMRHTLc7fWkvSZ2YMlCMARU11iajGwjsFBhwibClKDd77v0LonGNw%2F640%3Fwx_fmt%3Dpng"/>  </section></section></section></section></section><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding: 20px 10px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 661.458px;vertical-align: top;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;transform: rotate(0deg);overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;font-size: 15px;line-height: 1.8;overflow-wrap: break-word !important;"><ol class="list-paddingleft-1" style="outline: 0px;max-width: 100%;width: 555.438px;overflow-wrap: break-word !important;"><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483677&amp;idx=1&amp;sn=992c59eee0b1c6324e26b6971734292e&amp;chksm=feac44d5c9dbcdc358593aa7f6477c69991fdb17dc81bddd5121ffe1327a9cd41ce692cd35aa&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">海量日志分析的预处理</span></a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483707&amp;idx=1&amp;sn=ffe1443b56aa2c8cdc82d705bf947c8e&amp;chksm=feac44f3c9dbcde55c3a2f07ca61ec7cc7db1b4bee711771dcbf1d0774c293659ab11641bcbc&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">OSSEC-Execd功能模块分析</span></a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483732&amp;idx=1&amp;sn=8bfc3f526d3a3975047a40c781557c8e&amp;chksm=feac449cc9dbcd8aef3da223ba1b5b59f5359cd7fc8d9a4fee115e6b57a6fbab2c74a59d34a8&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">通过流量快速识别域名信息</span></a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483808&amp;idx=1&amp;sn=c00e1471e097419957ab59632d1b1cba&amp;chksm=feac4468c9dbcd7eeb70c99d69d2d629c5edf7da8824bd56f3b32ee04f0c99af45ea0c9cf299&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">从android源码看脱壳</span></a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483809&amp;idx=1&amp;sn=46f713281a53368353f25da47c2ddde1&amp;chksm=feac4469c9dbcd7f3f435e072f76088dca06f6317192d18b2b8370c206e64360bf36b3397012&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">Ossec-Agentd模块分析</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483887&amp;idx=1&amp;sn=c7df5f6782836613249c8bffe5b40699&amp;chksm=feac4427c9dbcd310a7f4dae54e8e31d3a1f29c746647e3e03e9b587e74778be0dc95bf9af32&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">猎豹移动DPIA系统开源</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483895&amp;idx=1&amp;sn=ef3d63fde5284afc30963fd290a63b71&amp;chksm=feac443fc9dbcd29f0e3b0ca67b7ef78fbed656c4cb9d27d34f51b2c08b8e62c1bb81831e084&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">一种新的分词方法在机器学习中的应用</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247483943&amp;idx=1&amp;sn=1e1633d9f335a2f753ee0e4a15368c90&amp;chksm=feac47efc9dbcef90b3a271c71317b8760bab8f6955291f6dfcf62bd703b742561cfb0d12d1a&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">Ossec-Logcollector模块分析</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484009&amp;idx=1&amp;sn=b2f543643afdad9b4c2401a76eae3cde&amp;chksm=feac47a1c9dbceb7488e95c93ceab1d2fe107e22ffd1ac199a4f214ec63673657ff19ad1cc15&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">Ossec-Agent-Syscheckd模块分析</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484053&amp;idx=1&amp;sn=56031d998b604e760584f8445df77063&amp;chksm=feac475dc9dbce4bde81344b030cba770815a1094d298d0126c53c46081c1372266994796ae0&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">Ossec Agent总结</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484076&amp;idx=1&amp;sn=ac760b9bbdb5c2f25667867d4c891196&amp;chksm=feac4764c9dbce7213db802172811e150386e99b7f2bbec2e9f8b914faa2a8479a84e7381e47&amp;scene=21#wechat_redirect" target="_blank" data-itemshowtype="0" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;">HTTP走私漏洞分析</a></p></li><li style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484108&amp;idx=1&amp;sn=5ca181639fc2493cb99ffa613ab755a9&amp;chksm=feac4704c9dbce12081d6a1b8fba4e4225d53a199935040db97befbf9fae1ae4f48e4ac24097&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">BurpSuite扩展插件使用分享</span></a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484139&amp;idx=1&amp;sn=fa91e8086270cf3a79f38671692d612d&amp;chksm=feac4723c9dbce35f189b41f2263d73f9e1a21d753b48030c7918083d98b0b73912fa88646ef&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">webshell连接工具流量分析</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484193&amp;idx=1&amp;sn=a21130acc8d36da61d52620c1dc68912&amp;chksm=feac46e9c9dbcffff6f77faa2efdc10cf0b6df4b36db893f8ac78884c08159ed9a0b4b3eb6fd&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">JDK7u21调用链分析</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484224&amp;idx=1&amp;sn=5213dabbf8ab166f435870db9cc75b94&amp;chksm=feac4688c9dbcf9e598fc1e9905d0ea3bc4363d32f5badc449a783f5670067db96cba46dec0e&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">php函数中的那些坑</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484272&amp;idx=1&amp;sn=51077f4222fac627ce2987edb7e23140&amp;chksm=feac46b8c9dbcfaeb368db29834e52898b302c3ed82d817ac64406412de6b5ff748f9afe5344&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">通过sqlmap源代码分析SQL注入漏洞检测流程</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484323&amp;idx=1&amp;sn=fdd463b01d9d23a6e442021f556af6e9&amp;chksm=feac466bc9dbcf7d3aa75fd24a5ae8e16919216eeaea8e8d4bc4965b70b42984f4fd5ef610a8&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">猎豹移动通过“全球首个隐私信息管理体系标准”ISO/IEC 27701认证</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484488&amp;idx=1&amp;sn=2aae23b30558b8191efcd1d1808f0619&amp;chksm=feac4180c9dbc896fae6be11abbe05b82957499fce45b188883d7d071433a4d7c95e4800a18a&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">DGA域名检测</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484501&amp;idx=1&amp;sn=ba631b9bba465141c04d5734e82ce856&amp;chksm=feac419dc9dbc88b4345d770fa3764dfa93f43de074f8cd810f769a40856d63dbb7659c9aead&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">基于NSL-KDD数据集的网络入侵检测分析</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484515&amp;idx=1&amp;sn=bd3ddebd7372d6eec2e506fe0ad3beb2&amp;chksm=feac41abc9dbc8bd3716b328dc8e29e110c9118c2fcc6f4b67d93f8610fd3cf62e57f5f1032e&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">采用HAN网络模型的WebShell检测</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484529&amp;idx=1&amp;sn=15c6b7b652a438b4df73be4f4062f4b5&amp;chksm=feac41b9c9dbc8afe52474f0d8c93149b6e0932ccc56a4afcbc2265465b708b12c8c547ab61a&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Suricata可视化规则（简单）编辑器及规则统计告警系统开源</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484561&amp;idx=1&amp;sn=5204f59168cb27d705bfef068a2f41a9&amp;chksm=feac4159c9dbc84f6faa6070c8ff7b1b3a58f5a6feda7e7341aa6b349156279d5cea85168c6f&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">SQL注入检测</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484629&amp;idx=1&amp;sn=277930053938ec886f66789f8d268dd6&amp;chksm=feac411dc9dbc80b0df0f87a2098d5fef4c21281e3fba407fee88cf8f33b2cfa07037652b2a1&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" wah-hotarea="click" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Typecho利用链分析</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484639&amp;idx=1&amp;sn=df90a1a38d576f6f053f45eed7d7798f&amp;chksm=feac4117c9dbc8017785c29297a150e3fbf91200ef3d61e7a18565a085b440585f64d864fa0a&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">ISO27701</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484673&amp;idx=1&amp;sn=0062fc57364e10783d6c81ef7f6abf44&amp;chksm=feac40c9c9dbc9dfc841000952646aa585b4df19409d8a1555732ad4013ea010b3c23dd5de69&amp;scene=21#wechat_redirect" textvalue="phpinfo里面有什么？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">phpinfo里面有什么？</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484688&amp;idx=1&amp;sn=71d511ca6b6a6db28e5b7e1c6c52f7a8&amp;chksm=feac40d8c9dbc9ce2a3ae09a3427bb68644af908b31c981566750e452a2b3cc682ea27573137&amp;scene=21#wechat_redirect" textvalue="Django QuerySet.order_by() SQL注入分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Django QuerySet.order_by() SQL注入分析</a></p></li><li style="outline: 0px;max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484688&amp;idx=1&amp;sn=71d511ca6b6a6db28e5b7e1c6c52f7a8&amp;chksm=feac40d8c9dbc9ce2a3ae09a3427bb68644af908b31c981566750e452a2b3cc682ea27573137&amp;scene=21#wechat_redirect" textvalue="Django QuerySet.order_by() SQL注入分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></a><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU5OTk1NDU5OQ==&amp;mid=2247484741&amp;idx=1&amp;sn=1f51213ca73cb8c1024434b022afb46a&amp;chksm=feac408dc9dbc99b759326a71e0b870cefcfe348883462f39cc67fac71056b14c78e176a8144&amp;scene=21#wechat_redirect" textvalue="内网渗透之SOCKS代理的5类基本场景" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">内网渗透之SOCKS代理的5类基本场景</a><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p></li></ol><p cid="n0" mdtype="heading" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><br style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p></section></section></section></section></section></section><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);color: rgb(0, 0, 0);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;line-height: 1.5em;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 677px;vertical-align: top;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;text-align: center;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 643.146px;vertical-align: top;box-shadow: rgba(81, 81, 81, 0.54) 0px 0px 0px;border-color: rgb(0, 0, 0);border-width: 1px;border-radius: 0px;border-style: solid;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: 5px;outline: 0px;max-width: 100%;box-sizing: border-box;transform: translate3d(5px, 0px, 0px);overflow-wrap: break-word !important;"><section style="padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;width: 641.146px;vertical-align: top;box-shadow: rgba(81, 81, 81, 0.54) 0px 0px 0px;background-color: rgba(255, 255, 255, 0.2);border-color: rgb(0, 0, 0);border-width: 1px;border-radius: 0px;border-style: solid;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: bottom;width: 49.5313px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;vertical-align: middle;display: inline-block;line-height: 0;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="1.47" style="outline: 0px;box-sizing: border-box;vertical-align: middle;overflow-wrap: break-word !important;visibility: visible !important;width: 100px !important;" data-type="png" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=9f43c80a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmUB2xUVsqMUCc18wgBO2KbZ6gLhDYxsNvDnA4p2VOHl9Wc0HjPDQ2NfrmOxfFplGgkWicibRqSNouVJWKZaE3aZA%2F640%3Fwx_fmt%3Dpng"/></section></section></section><section style="padding-left: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: bottom;width: 569.604px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;text-align: justify;font-size: 14px;line-height: 1.6;overflow-wrap: break-word !important;"><p style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;">长按下方二维码关注我们</strong></p></section></section></section><section powered-by="xiumi.us" style="outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: middle;width: 309.573px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: 10px;margin-bottom: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;vertical-align: middle;display: inline-block;line-height: 0;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="1" style="outline: 0px;box-sizing: border-box;vertical-align: middle;overflow-wrap: break-word !important;visibility: visible !important;width: 677px !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4ced5913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FmUB2xUVsqMUCc18wgBO2KbZ6gLhDYxsNPQtOkiaWuWLWibw5GaxbibiciaaIFEOQvswWG5UrAzhsBdgxHsYE148qWYg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section><section style="padding-right: 5px;padding-left: 5px;outline: 0px;max-width: 100%;box-sizing: border-box;display: inline-block;vertical-align: middle;width: 309.573px;overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin-top: 10px;margin-bottom: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;letter-spacing: 0.544px;color: rgb(95, 111, 120);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;overflow-wrap: break-word !important;"><section style="outline: 0px;max-width: 100%;box-sizing: border-box;vertical-align: middle;display: inline-block;line-height: 0;overflow-wrap: break-word !important;"><img class="rich_pages wxw-img" data-ratio="0.9972826" style="outline: 0px;box-sizing: border-box;vertical-align: middle;overflow-wrap: break-word !important;visibility: visible !important;width: 368px !important;" data-type="png" data-w="368" src="https://wechat2rss.xlab.app/img-proxy/?k=f5f4b125&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmUB2xUVsqMUCc18wgBO2KbZ6gLhDYxsNYdhXka5N8QaAXtVxQvaVIXkE3JuBhYGicXVJVYZqeialPaNNyyossCGA%2F640%3Fwx_fmt%3Dpng"/></section></section><p><br/></p><p><br/></p></section></section></section></section></section></section></section></section><p style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span><br/></p><p><br/></p>



<p><a href="2247483740">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3732f283&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483740%26idx%3D1%26sn%3Dab0e022ce1863f16037d7b86df67ba6a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 30 Mar 2022 17:19:00 +0800</pubDate>
    </item>
    <item>
      <title>贫民版的SOAR----Node-red</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483738&amp;idx=1&amp;sn=d84f629cb30decbc72d7f0d925ea0d8f</link>
      <description>贫民版的SOAR----Node-red</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2022-03-21 11:23</span> <span style="display: inline-block;"></span>
</p>

<p>贫民版的SOAR----Node-red</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=551c6551&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZoDKpLicYibjGvCOAcScZWfic5ukpdNia85EKcjdfAyQrUibtEPyicZC9ib3kLIphBiahw7Q59EVZUAywCKZQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"><br/></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;">  非常感谢二胡老板的推荐，一下增加了300多人，CEO下一步可以考虑直播带货了。</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;">既然CEO都推荐了，怎么也要写点什么才对得起推荐，也对得起关注我的人。不过自从写完了书，感觉肚子里边的墨水真有点掏干净了，所以也憋不出太多的东西。我们对团研究的一些技术方向的文章都会发在《小豹讲安全》里边，如果有兴趣的读者，也可以关注一下这个公众号。</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;">       回到正文，这次主要想说一下Node-red(简称NR) 这个东西，这个是我研究智能家居的时候接触到的一个东西，这里放两张流程图,用来处理网络出现故障进行线路切换的：</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> </p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.44921875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=4ae0242c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZoDKpLicYibjGvCOAcScZWfic5J10fXY3FMGswIa1YSibtJwcBic0D7a0NmPZEqIsRjrgKPibyzYcicByZhQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3921875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5a5935b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZoDKpLicYibjGvCOAcScZWfic5AXmmEybiaMgDawwCT5npuM7tHgNp42lpIgW0MSVHUZAGsdJ1c5x9Xmg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> <br/></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;">可以发现，这个东西，有点类似现在比较流行的SOAR，可以把一些防御策略做成可视化的形式。这样，每次想看一下当前的策略（或者给老板显摆一下），就可以非常直观的看到。</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;">这东西的安装非常简单，有兴趣的朋友，可以参考官方文档进行安装即可，自带的插件也比较多，我主要用的SSH,HTTP,ELASTICSEARCH等等都有，所以，基本上也算可以满足一些场景的定义了。</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;">不过这个东西的安全性，也需要注意，这里放一下TSRC的一篇针对NR的安全性研究的文档，写的已经很全了有兴趣的读者也可以看看  《物联网开源组件安全Node-RED白盒审计》  <a href="https://security.tencent.com/index.php/blog/msg/181" target="_blank">https://security.tencent.com/index.php/blog/msg/181</a></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;"> </p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;">最后说一下个人对SOAR的一点看法吧，个人对这个来看，还是觉得有点花里胡哨的，主要我觉得安全对抗的本质还是人与人之间的对抗，用定义好的场景，脚本，往往可能都会处于自己跟自己玩的情况。而且，需要对规则的定义，使用，甚至结果都需要把握的非常准确，否则可能容易晚上没法好好睡觉了。而且看这类产品的核心功能应该是可以对接多少设备，能对接的设备越多，才能处理更加丰富的场景。不过如果作为常规性操作的防御的可视化来说，还是可以研究一下的。总之，个人觉得，注意力还是应该集中在对规则的掌控上，能做到精准判断，不误报，不漏报才是最好的。当然，针对这个话题，以后再慢慢写吧。</p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;"><br/></p><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 14px;">下期有感中途岛海战，谈谈安全工作中的战略和战术吧。</p>



<p><a href="2247483738">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=72094fdf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483738%26idx%3D1%26sn%3Dd84f629cb30decbc72d7f0d925ea0d8f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 21 Mar 2022 11:23:00 +0800</pubDate>
    </item>
    <item>
      <title>新年快乐</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483731&amp;idx=1&amp;sn=2f3baf7228bc58c0eca5b8c01d8383c2</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2022-01-31 14:53</span> <span style="display: inline-block;"></span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=bf711bf3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZq3mKOwgpxRHOEV7UV8qcxwIIdILZymic0br1mHQ7ZRHa99EMDg5gmFnCZ3hoP6eWjRK5gOPnGEHew%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>祝大家新年快乐</p><div><section style="display: inline-block;"><img data-ratio="1" data-w="240" data-type="jpg" src="https://wechat2rss.xlab.app/img-proxy/?k=aa18b44d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FibCalCUYKkZq3mKOwgpxRHOEV7UV8qcxwhKJ3OjdibNNXylfY1LNgL1soDTGNuibI1nvpsNzPYAu84mIycsmAPAIA%2F640%3Fwx_fmt%3Dgif"/></section>​</div><p><br/></p>



<p><a href="2247483731">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=14224874&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483731%26idx%3D1%26sn%3D2f3baf7228bc58c0eca5b8c01d8383c2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 31 Jan 2022 14:53:00 +0800</pubDate>
    </item>
    <item>
      <title>大咖话安全第十四期 | 林鹏：企业网络安全防御建设</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483726&amp;idx=1&amp;sn=5ce7fc0c55aef00ff0b5a77c8a1dde8b</link>
      <description>随着科技的进步，网络的发展越来越完善，企业网络的规模也在日益扩大，一旦企业网络安全失去保障，轻则影响正常办公</description>
      <content:encoded><![CDATA[<p>
<span>JK</span> <span>2021-12-14 19:18</span> <span style="display: inline-block;"></span>
</p>

<p>随着科技的进步，网络的发展越来越完善，企业网络的规模也在日益扩大，一旦企业网络安全失去保障，轻则影响正常办公</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=15802237&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FUZ1NGUYLEFjSHib0NjuzwqicDdcdKIfL7MjibUf31ticWicyZuzt2Nk434AKC2SCiajTnwFI4dBllC6tlB6TuJRKJOpw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 16px;" data-mpa-powered-by="yiban.io"><section style="margin: 10px 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgba(237, 230, 221, 0.32);padding: 39px;"><section style="margin-right: 0%;margin-bottom: 10px;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 25px;height: auto;"><section style="text-align: left;justify-content: flex-start;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 14px;height: 14px;vertical-align: top;overflow: hidden;background-color: rgb(237, 230, 221);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 25px;height: auto;"><section style="text-align: left;justify-content: flex-start;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 14px;height: 14px;vertical-align: top;overflow: hidden;background-color: rgb(237, 230, 221);"><br/><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 25px;height: auto;"><section style="text-align: left;justify-content: flex-start;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 14px;height: 14px;vertical-align: top;overflow: hidden;background-color: rgb(237, 230, 221);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 25px;height: auto;"><section style="text-align: left;justify-content: flex-start;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 14px;height: 14px;vertical-align: top;overflow: hidden;background-color: rgb(237, 230, 221);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="font-size: 13px;line-height: 1.8;" powered-by="xiumi.us"><p style="text-indent: 2em;white-space: normal;">随着科技的进步，网络的发展越来越完善，企业网络的规模也在日益扩大，一旦企业网络安全失去保障，轻则影响正常办公，重则影响企业整个发展战略，如何提高企业网络的安全，对企业的运营及发展起到至关重要的作用。</p><p style="text-indent: 2em;white-space: normal;">本期安世加诚邀猎豹移动的安全总监林鹏先生，一起聊一聊《企业网络安全防御建设》这个话题。</p></section></section></section><section style="margin: 10px 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;padding: 34px;"><section style="text-align: center;margin: 10px 0% 20px;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-ratio="0.562963" style="vertical-align: middle;box-sizing: border-box;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=66a407dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FUZ1NGUYLEFjSHib0NjuzwqicDdcdKIfL7MNUBDlSOwxq1V0qq7DGicotmhicZiac4lo7Fc3FiaMWiaaibI0ynwiad7tibj5w%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: center;justify-content: center;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: 33.33%;align-self: center;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(230, 81, 62);height: 1px;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;height: auto;align-self: center;"><section style="color: rgb(230, 81, 62);" powered-by="xiumi.us"><p>★</p></section></section><section style="display: inline-block;vertical-align: middle;width: 33.33%;align-self: center;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(230, 81, 62);height: 1px;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section powered-by="xiumi.us"><p style="white-space: normal;"><br/></p></section><section style="font-size: 13px;line-height: 1.8;" powered-by="xiumi.us"><p><span style="font-size: 16px;"><strong>本期嘉宾：林鹏</strong></span></p><p style="text-indent: 2em;">曾任当当网的安全经理、网信金融安全专家、万达电商信息安全部总经理等职务，有着长达10年的一线安全攻防实战经验，研究领域为日志分析，安全防御，金融安全等，EISS-2021北京站安全运营专场出品人。</p></section></section></section><section style="text-align: center;margin: -20px 0% 10px;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 12px;height: 12px;padding: 2px;border-width: 1px;border-style: solid;border-color: rgb(106, 162, 213);transform: rotate(45deg);"><section style="width: 100%;height: 100%;background-color: rgb(106, 162, 213);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: left;justify-content: flex-start;margin: 10px 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(194, 209, 255);min-width: 10%;height: auto;border-left: 4px solid rgb(255, 223, 156);border-bottom-left-radius: 0px;"><section style="text-align: justify;color: rgb(62, 62, 62);padding-right: 10px;padding-left: 10px;" powered-by="xiumi.us"><p style="white-space: normal;"><strong>本期看点</strong></p></section></section></section><section style="text-align: center;justify-content: center;" powered-by="xiumi.us"><section style="display: inline-block;width: 36%;vertical-align: top;height: auto;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(116, 159, 238);height: 1px;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="margin: 10px 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgba(116, 159, 238, 0.1);padding: 34px;"><section style="font-size: 14px;line-height: 1.8;" powered-by="xiumi.us"><ul class="list-paddingleft-2"><li><p><strong>企业网络安全与企业信息安全的关联</strong></p></li><li><p><strong>企业网络安全建设的优先次序</strong></p></li><li><p><strong>企业网络安全建设的关键点</strong></p></li><li><p><strong>如何获得高层的支持</strong></p></li><li><p><strong>安全建设实践经验分享</strong></p></li><li><p><strong>安全管理者及员工的要求</strong></p></li></ul></section></section></section><section style="text-align: center;justify-content: center;" powered-by="xiumi.us"><section style="display: inline-block;width: 36%;vertical-align: top;height: auto;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(116, 159, 238);height: 1px;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="" powered-by="xiumi.us"><section style="margin: 20px 0% 10px;display: flex;flex-flow: row nowrap;text-align: center;justify-content: center;transform: translate3d(10px, 0px, 0px);"><section style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(214, 225, 225);min-width: 10%;flex: 0 0 auto;height: auto;padding-top: 2px;padding-bottom: 2px;padding-left: 2px;align-self: flex-start;z-index: 2;"><section style="text-align: right;letter-spacing: 1px;color: rgb(62, 62, 62);line-height: 1;" powered-by="xiumi.us"><p style="text-align: center;"><strong>视频资料</strong></p></section></section><section style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="text-align: left;margin-top: -15px;margin-right: 0%;margin-left: 0%;justify-content: flex-start;transform: translate3d(-20px, 0px, 0px);" powered-by="xiumi.us"><section style="display: inline-block;width: 33px;height: 33px;vertical-align: top;overflow: hidden;background-color: rgb(162, 200, 231);border-width: 0px;border-radius: 60px;border-style: none;border-color: rgb(62, 62, 62);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section><iframe class="video_iframe rich_pages" data-vidtype="1" data-cover="http%3A%2F%2Fshp.qpic.cn%2Fqqvideo_ori%2F0%2Fv3311s1pjvz_496_280%2F0" allowfullscreen="" frameborder="0" data-ratio="2" data-w="864" data-src="https://v.qq.com/iframe/preview.html?width=500&amp;height=375&amp;auto=0&amp;vid=v3311s1pjvz" src="https://v.qq.com/iframe/preview.html?width=500&amp;height=375&amp;auto=0&amp;vid=v3311s1pjvz"></iframe></section><section style="" powered-by="xiumi.us"><section style="margin: 20px 0% 10px;display: flex;flex-flow: row nowrap;text-align: center;justify-content: center;transform: translate3d(10px, 0px, 0px);"><section style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(214, 225, 225);min-width: 10%;flex: 0 0 auto;height: auto;padding-top: 2px;padding-bottom: 2px;padding-left: 2px;align-self: flex-start;z-index: 2;"><section style="text-align: right;letter-spacing: 1px;color: rgb(62, 62, 62);line-height: 1;" powered-by="xiumi.us"><p style="text-align: center;"><strong>音频资料</strong></p></section></section><section style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="text-align: left;margin-top: -15px;margin-right: 0%;margin-left: 0%;justify-content: flex-start;transform: translate3d(-20px, 0px, 0px);" powered-by="xiumi.us"><section style="display: inline-block;width: 33px;height: 33px;vertical-align: top;overflow: hidden;background-color: rgb(162, 200, 231);border-width: 0px;border-radius: 60px;border-style: none;border-color: rgb(62, 62, 62);"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section><mpvoice class="js_editor_audio audio_iframe js_uneditable custom_select_card" src="/cgi-bin/readtemplate?t=tmpl/audio_tmpl&amp;name=%E6%9E%97%E9%B9%8F%EF%BC%9A%E4%BC%81%E4%B8%9A%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E9%98%B2%E5%BE%A1%E5%BB%BA%E8%AE%BE&amp;play_length=43:55" isaac2="1" low_size="4902.16" source_size="4915.2" high_size="20636.81" name="林鹏：企业网络安全防御建设" play_length="2635000" voice_encode_fileid="Mzg5NzA3NDY1MF8yMjQ3NDgzNzI1" data-topic_id="" data-topic_name="" data-pluginname="insertaudio" data-trans_state="0" data-verify_state="1"></mpvoice></section><section style="font-size: 12px;text-align: center;" powered-by="xiumi.us"><p>（本期节目时长44分钟，请根据情况自行选择播放形式）</p></section><section style="margin-top: 10px;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;"><section style="" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;"><section style="margin-top: 10px;margin-bottom: 10px;text-align: center;" powered-by="xiumi.us"><section style="background-color: rgb(68, 68, 68);display: inline-block;width: 2.5em;height: 2.5em;line-height: 2.5em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 18px;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;"><p><br/></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><section style="transform: translate3d(10px, 0px, 0px);" powered-by="xiumi.us"><section style="font-family: Optima-Regular, PingFangTC-light;"><p style="white-space: normal;"><strong>往期介绍</strong></p></section></section></section></section></section><section style="margin-right: 0%;margin-bottom: 8px;margin-left: 0%;" powered-by="xiumi.us"><section style="background-color: rgb(68, 68, 68);height: 1px;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247512169&amp;idx=1&amp;sn=d72f1855c36a73541695c6a600610af6&amp;chksm=fc7bb4b4cb0c3da22e0cf5c6a87f262640399e69400b453f10233b7847e0774000242d1d19ca&amp;scene=21#wechat_redirect" textvalue="大咖话安全第十三期 | 王建强：货运场景下的SDL实践" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="font-size: 10px;" data-linktype="2"><span style="font-size: 10px;">大咖话安全第十三期 | 王建强：货运场景下的SDL实践</span></a><br/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247510852&amp;idx=1&amp;sn=47212e507cd43148e7e99bdd4b7b52fb&amp;chksm=fc7baf99cb0c268fc684a736050b6dffe68c597c1d61c80697320707515b97288601fedf4174&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第十二期 | 李少鹏：网络安全产业的过去、现在与未来</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247509618&amp;idx=1&amp;sn=5926aade0a7ab6fb09cc6f67ed41aac1&amp;chksm=fc7ba2afcb0c2bb97426111563cab68110d1f028eb3dbb45b5e9743f71c3fbd1b45a35cc6578&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第十一期 | 肖寒：制造业信息安全建设之路</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247509297&amp;idx=1&amp;sn=6f353dbb62b79c62a1ee70590a4f50f7&amp;chksm=fc7ba1eccb0c28fa484c50e998117df9b71593e092824ac4882b57957fece672d7618617f058&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第十期 | 黄鹏华：针对APP开展个人信息影响的评估</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247507844&amp;idx=1&amp;sn=98c1444e2828e20e7a3c26f1ea56788c&amp;chksm=fc7bdb59cb0c524f2a0ef0a943ffc8e686029999de69577f1033562b9fba259ddfea66d47b5b&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第九期 | 马辰：基于DevSecOps理念的安全运营</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247506855&amp;idx=1&amp;sn=4d9b42ee3b0e348efa8172ed35aab920&amp;chksm=fc7bdf7acb0c566c1beaf4e0d3040db3f1a2eec7c0af7c8824cf9ab3412fd0b60b6de7926a18&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第八期 | 大雄：SDL实践之道</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247503138&amp;idx=1&amp;sn=8304146269af3d918a6f15c648efebc6&amp;chksm=fc7bc9ffcb0c40e9f28d6038c24bbcdd9388f81be6270d23fb7b84e8a1b9a770a798a4496272&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第七期 | 胡剑飞：漫谈企业信息安全建设</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247502121&amp;idx=1&amp;sn=37d7b7dc851b3284687119245b3914d6&amp;chksm=fc7bcdf4cb0c44e26045312c1936b38df120bde3020abf132b461fb6612a40033143971451ad&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第六期 | Joe Cai：浅析第三方风险管理</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247501817&amp;idx=1&amp;sn=e100e68ee73e012848d6d2ba3cf1d46d&amp;chksm=fc7bc324cb0c4a325f03e0280831e8196665f154a0c526e51113322835712ca881c5fc57c729&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第五期 | 钱君生：一期看懂DevSecOps</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247501454&amp;idx=1&amp;sn=65d718e8629a69347a73028ecf0b8068&amp;chksm=fc7bc253cb0c4b45156d7ceab23d5995631b7283203c372e36c9ae2b5fb00fe61b1818e453c5&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第四期 | 蒋琼：新技术创新安全实践的思考与展望</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247500915&amp;idx=1&amp;sn=90e58c5ff00df35ecf2f0fd5a2867cc0&amp;chksm=fc7bc0aecb0c49b89d12283490c73f7d5ff594be4a434353a889ce2cd82887786dc9004c61ff&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第三期 |  周明昊：漫谈安全风险治理中的数字化</span></a></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247500183&amp;idx=1&amp;sn=dad535833e97e08bca5e003e17953264&amp;chksm=fc7bc54acb0c4c5c8aca94901a4ae8b919a334ae003155db142761e91a08b787f2ced790281b&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第二期 | Luwikes：聊一聊业务安全那些事</span></a><br style="outline: 0px;"/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU2MTQwMzMxNA==&amp;mid=2247499786&amp;idx=1&amp;sn=9e2b70ddf7cf9fae87cec77f913f79e7&amp;chksm=fc7bc4d7cb0c4dc17c6440b63f9091e84072ebd21714480ee374e709c4e724bc265048b9e220&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" wah-hotarea="click" hasload="1" style="font-size: 10px;"><span style="font-size: 10px;">大咖话安全第一期 | 黄乐：浅谈安全运营之道</span></a></p>



<p><a href="2247483726">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=130e3f42&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483726%26idx%3D1%26sn%3D5ce7fc0c55aef00ff0b5a77c8a1dde8b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 14 Dec 2021 19:18:00 +0800</pubDate>
    </item>
    <item>
      <title>欢迎报名5.14 EISS 大会，提问题送书啦</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483723&amp;idx=1&amp;sn=cc51706eb8bd7d292fde69d60e728ae4</link>
      <description>欢迎大家扫码报名参加5.14日的eiss大会，提问题送书啦</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2021-05-08 16:10</span> <span style="display: inline-block;"></span>
</p>

<p>欢迎大家扫码报名参加5.14日的eiss大会，提问题送书啦</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f9a8ea19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L4vKicNWDliaaqOYsazHYpWKtTjPJ54wvBOxnIC0w9BVkD9jNbUrQ9soibg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;">  欢迎大家扫码报名参加5.14日的eiss大会，这次我终于不用写PPT,改成了小组讨论的主持人了 <img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=49030edf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L4bo9icTkATQrlNMh1MeibPBcMAIia8icEib3LX1u73ndERF1fgwKRV8qEicUQ%2F640%3Fwx_fmt%3Dpng"/>。 当然这次讨论的议题个人觉得也比较贴地气的，关于安全运营与安全实践方法论，小组嘉宾也是业内实战经验非常丰富的，希望可以给大家带来一些收获。另外大家如果关于这方面有什么好问题，可以回复我，我可以代为向嘉宾提问，同时我会挑出5个问题的读者，赠送《互联网安全建设从0到1》或《网络安全与攻防策略》</p><p style="text-align: left;">在这里也感谢华章图书的支持<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=bc3a27b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L4ONskccvywqibOa4WFENyoGxoRNYLVHRw3IhdKCdCkyiaPAJtG4HLyBiag%2F640%3Fwx_fmt%3Dpng"/>，欢迎大家提问。</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="1709" data-backw="578" data-ratio="2.956603773584906" data-s="300,640" style="width: 100%;height: auto;" data-type="jpeg" data-w="1060" src="https://wechat2rss.xlab.app/img-proxy/?k=3b039918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L4DPGWwW8xKexd48pQI8A4ibTEnvLhKiaVt7iaNCwg8ya8yfnlprJsAZMRw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: left;"><img class="rich_pages js_insertlocalimg" data-ratio="1" data-s="300,640" style="width: 261px;height: 261px;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=abdfa38f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L4sibjWTMAiaIsKCsbUYeh3r33Fju4J60UgEn5x8rbL8XIE90qiakxJ9ByA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages" data-backh="417" data-backw="236" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/ibCalCUYKkZondPzwps9fLszfQRQ0gngALvOWOyK7PJNGOxASxB5BtoNm2ppgPdkZdNEf9bNZIAWxKLBZIr0p0Q/0?wx_fmt=jpeg" data-cropx1="43.63636363636363" data-cropx2="933.8181818181818" data-cropy1="129.041225714737" data-cropy2="1117.776022745222" data-galleryid="" data-ratio="1.1101123595505618" data-s="300,640" style="text-align: center;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;width: 231px;height: 256px;" data-type="jpeg" data-w="890" src="https://wechat2rss.xlab.app/img-proxy/?k=7f260071&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZodygibs5fQNDzFm0FU8w2L419urib95iaowZWeQabibCibs5CPtD5Uk383ic8Oqiaw4zUAbW71j4NEPWxpA%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p>



<p><a href="2247483723">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0a0d96ab&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483723%26idx%3D1%26sn%3Dcc51706eb8bd7d292fde69d60e728ae4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 08 May 2021 16:10:00 +0800</pubDate>
    </item>
    <item>
      <title>Suricata可视化规则（简单）编辑器及规则统计告警系统开源</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483712&amp;idx=1&amp;sn=6572e76a41bc21c74482937c2fa87b93</link>
      <description>开发的两个关于suricata的小工具，便于编写规则和进行告警使用。</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2021-02-24 16:15</span> <span style="display: inline-block;"></span>
</p>

<p>开发的两个关于suricata的小工具，便于编写规则和进行告警使用。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=32dd815e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FmUB2xUVsqMVzxpjCC4mvIe5UFqhXYXGWlu2zHhVdTZlb5TYdU6Tmn0bs4ia1ic9pScj2TujwTxlyj9F7KAIuvUyQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>






<p><a href="2247483712">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=67e8dce2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483712%26idx%3D1%26sn%3D6572e76a41bc21c74482937c2fa87b93%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Feb 2021 16:15:00 +0800</pubDate>
    </item>
    <item>
      <title>那个曾经的勇者，也终将变成恶龙？</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483710&amp;idx=1&amp;sn=d1bb3f641850b82682397b26d218bc11</link>
      <description>那个曾经的勇者，在得到了市场的垄断后也终将变成恶龙？</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2020-10-30 14:59</span> <span style="display: inline-block;"></span>
</p>

<p>那个曾经的勇者，在得到了市场的垄断后也终将变成恶龙？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a44d67b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZraaoDbqono76vGK1ugGlGV66KKxFEDAre2X167h7r4j5ibaaRkf3bRg19tUtj9KRvmg10ctFa4STA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  今天想说说最近我们公司遇到的一个事情，牵涉的是互联网巨头公司，也是安全领域里一家技术顶级的公司-谷歌以及他的浏览器Chrome。<br/></p><p>  </p><p>  事情的经过很简单，周三（10月28日）下午的时候，想登陆一下内网的oa系统，结果突然弹出来一个“大红叶”：</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="346" data-backw="576" data-ratio="0.6015424164524421" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1167" src="https://wechat2rss.xlab.app/img-proxy/?k=df13b713&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZraaoDbqono76vGK1ugGlGVcpdbxoGVr0zcapFv7dM3AAz5Nk2Xok9hOibbT2HaqIxx73HMPuPngBw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;">  一看到这种大红叶，没看内容的情况下我还以为是我的浏览器出了什么问题，或者是系统时间问题，再一看内容以为OA系统可能出了什么问题，还打算问问OA的人看看是不是被黑了。但是，接下来发现事情没有那么简单，我们的所有域名(*.cmcm.com)都被标红，只能去google的管理后台查看原因。结果发现：</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.2621145374449339" data-s="300,640" style="" data-type="png" data-w="908" src="https://wechat2rss.xlab.app/img-proxy/?k=f03210c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZraaoDbqono76vGK1ugGlGVElyziaUW2lcyUgmPg0vtqWQqF7Sa9RWk7QeibJyrmy8PUUar8N7HlP8w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;">仅仅只是发现了两个页面（可能）有问题，就把一个公司的全部域名彻底拉红，而且，根本不给你申诉的机会：28号在收到这个通知的时候，google就把公司整个二级域名全部判断为恶意。这分明就是打着安全的旗号刷流氓的具体表现嘛。<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="511" data-backw="285" data-ratio="1.7941952506596306" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="379" src="https://wechat2rss.xlab.app/img-proxy/?k=092b6568&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZraaoDbqono76vGK1ugGlGVAgDgrNPAR6iaWhoB0rZiclAicMicD9hXjOLzWcheMoSPIib1hKZDAma9L2w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;">先不说检测的结果是否正确，（上一次是把ir的pdf财报认为是有问题的软件，后来也是申诉成功）<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6430976430976431" data-s="300,640" style="" data-type="png" data-w="594" src="https://wechat2rss.xlab.app/img-proxy/?k=ebdbe6ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZraaoDbqono76vGK1ugGlGVfyK9NyoMxT6gQAH2lLQKrLZdUdUF37QNR8HpA9uyxRicHT1KVtyHyCQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;">能不能只把有问题的域名标记，或者至少标记二级域名这么大的操作，是否可以提前通知一下管理员，这种行为对企业会造成多大的影响。这种行为算是一个有责任的科技公司干的事情吗？任何一家做安全的公司都不能因为一个ip 有问题，直接把c段甚至b段都给ban掉了吧。这种行为倒像是一个垄断企业掌握了生杀大权后行为。这不禁让我想到也许曾经的google 是一名勇者，但是也终于变成了一条恶龙。</p><p style="text-align: left;"><br/></p><p style="text-align: left;">当然，这件事也给了我们一些经验，做一点分享：</p><p style="text-align: left;">1 因为google的算法问题，可能会把一些下载的内容标记为有问题的软件，因此可能会导致全域名标红，因此如果有这样的功能页面，最好单独使用一个域名，以免主要域名受到影响。</p><p style="text-align: left;">2 经过两次的申述经验，大概判断google的审核时间为1天左右。</p><p style="text-align: left;">3 可以通过<a href="https://developers.google.com/safe-browsing对域名进行监控。" target="_blank">https://developers.google.com/safe-browsing对域名进行监控。</a></p>



<p><a href="2247483710">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7abd0523&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483710%26idx%3D1%26sn%3Dd1bb3f641850b82682397b26d218bc11%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 30 Oct 2020 14:59:00 +0800</pubDate>
    </item>
    <item>
      <title>推荐一本个人认为最好的风控书-风控要略</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483697&amp;idx=1&amp;sn=7b4833faeb381b205e3f809fef367fac</link>
      <description>推荐一本个人认为最好的风控书-风控要略</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2020-08-16 18:06</span> <span style="display: inline-block;"></span>
</p>

<p>推荐一本个人认为最好的风控书-风控要略</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e547d49d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZrxpXKMKUYIibiaCpLFDia6mibx0E0zxgcup3jPl088FgFbPVUvleVt0y3knZvZXjibuuqUTwLOtGQy4kA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>   预售地址：<a href="https://item.jd.com/12946188.html" target="_blank">https://item.jd.com/12946188.html</a></p><p>  今天给大家推荐一本我觉得非常好，好到应该是做风控甚至是业务运营人员都必备的一本书-《风控要略 互联网业务反欺诈之路》。<br/></p><p>  先说一下这本书的作者马传雷（也给我的书写过推荐），曾经是同盾反欺诈研究院院长，个人认为同盾的风控业务水平在国内来说也算数一数二的，而马院长一直保持着对技术的热情，一直坚持研究技术，属于绝对的实战派，因此，此书一定也是干货满满，这点也可以从目录以及院长之前给我的样稿中可以看出。</p><p>   其次，我的观点是安全最好要服务于业务，而安全与业务贴合最紧密，最容易计算价值的，便是风控系统，毕竟你跟老板说发现100个webshell，没有跟老板说直接为公司止损10w，更能让老板直观的认识到安全部门的价值（当然，基础安全也非常重要，属于地基的作用）。尽管我在我的书中用了一个大章节介绍了互联网电商的刷单案例，风控系统以及解决方案，但我觉得那仅仅只是一小部分，可能是冰山的一角。而这本书能更加全面，系统的介绍这些方面的内容，因此非常适合做风控或者是向往风控业务发展的人。<br/></p><p>   综上理由，推荐给大家这本书。了解我的人，或者读过我的书的朋友或许知道，我不爱搞什么虚的东西，文笔也不是太好，但是写的都是大实话。我也不说什么写书不易之类的话，而且这本书能出版确实也很不容易，也经历了许多波折，但之所以推荐的理由就是有内容，有干货，值得去看。尽管院长已经送我一本，但，还是要再买一本支持。<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="1.7777777777777777" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=42cea58b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZrxpXKMKUYIibiaCpLFDia6mibxaMicJ64e0vhNIaLOZMkBhUYc5cn06QVicaDNgloaJF8wiaUvOm7NpMNBQ%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p>



<p><a href="2247483697">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=01da427d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483697%26idx%3D1%26sn%3D7b4833faeb381b205e3f809fef367fac%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 16 Aug 2020 18:06:00 +0800</pubDate>
    </item>
    <item>
      <title>这几周再准备安全加和知道创宇的议题，所以没更新，明天再讲讲安全建设这事</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483691&amp;idx=1&amp;sn=3d5086e99a8f9caa11f69fa3eb35e412</link>
      <description>这几周再准备安全加和知道创宇的议题，所以没更新，明天再讲讲安全建设这事</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2020-08-12 20:41</span> <span style="display: inline-block;"></span>
</p>

<p>这几周再准备安全加和知道创宇的议题，所以没更新，明天再讲讲安全建设这事</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=8ae9cb8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqnk1d3Yic0abUkZs49AeSBCRJ6kAiab38egncloRKgBDESc3q4Tiaa07o9RYtoMfXbFD0295wZRxicuQ%2F0"/>
</p>


<div id="js_image_content" class="image_content "><!---->    <!----> <!----> <!----> <div class="wx_album_area js_album_wrap " style=""></div> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary "><!----></div></div> </div>


<p><img src="https://mmbiz.qpic.cn/mmbiz_jpg/ibCalCUYKkZqnk1d3Yic0abUkZs49AeSBCM8dXnSSCyB9VKKicicQhRqP9FRu33XbGMzia2IfMl5RU82hv5uEIibJBeA/0?wx_fmt=jpeg"/></p>
<p><img src="https://mmbiz.qpic.cn/mmbiz_jpg/ibCalCUYKkZqnk1d3Yic0abUkZs49AeSBCLfJGydJRicyT127DD9e0kNLqjdlelDjBunmYoxkBwVlFnkjtHoZHogw/0?wx_fmt=jpeg"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5d6de084&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483691%26idx%3D1%26sn%3D3d5086e99a8f9caa11f69fa3eb35e412%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Aug 2020 20:41:00 +0800</pubDate>
    </item>
    <item>
      <title>第一次勘误及为啥暂时不建立读者群</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483689&amp;idx=1&amp;sn=8918ff21d1baaf82ea0aae4787c99c45</link>
      <description>第一次勘误及为啥暂时不建立读者群</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2020-07-10 17:16</span> <span style="display: inline-block;"></span>
</p>

<p>第一次勘误及为啥暂时不建立读者群</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a7f64594&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqsGFiau46ZT5bnCFInGv2k1ibjTcMoz86Xt7HampDjBAJcQfALtM0laBfUmUskHE2I5Y8cF4neS4eg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  书已经上市了一段时间了，也得到了一些读者的好评，这里感谢所有读者对我的支持，目前接到一些读者反馈，有一些小的错别字及失误的地方，在此处进行更正:</p><p>感谢处：<br/><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">应该是感谢</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">靳晓飞</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">@</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">VIPKID 而非靳</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">小飞，这里向</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">他表示道歉。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">🙇‍♀️</span></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">漏掉了</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">向红阳@</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">国美</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">，他在</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">运维安全方面给了我很多启发，这里也表</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">示</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">感谢</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">🙏</span></p><p><br/></p><p>正文部分：</p><p> 149页，第三行，针对主机所产生的的异常行为，这里少了一个机字 。笔误</p><p> 195页，倒数第四行 /var/messa，应改为/var/messages 。笔误</p><p> 236页，第八行，此时如果发现有攻击是针对这种服务器漏洞的（负）载荷的，多了个负字。笔误<br/></p><p> 244页，倒数第四行 5W1H, WHERE 少了一个E。笔误</p><p><br/></p><p>关于读者群：<br/></p><p>  有些读者问是否有读者群，我暂时觉得还没有这个必要，相信大家都有很多群是死群，平时几乎没有什么交流，我就不再给大家多增加一个这样的群了。当然也很希望对本书，或者对安全工作有想法建议的朋友一起交流。如果真的有一起沟通的情况，到时候再建群也来得及。<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d6e25c8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqsGFiau46ZT5bnCFInGv2k1Xo0tXEqFiaDaGUsj3IvQax6ZlicVxFyw5XymiaqHPudGpKjpUEz8fic0sA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><br/></p>



<p><a href="2247483689">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b52b7cf9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483689%26idx%3D1%26sn%3D8918ff21d1baaf82ea0aae4787c99c45%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Jul 2020 17:16:00 +0800</pubDate>
    </item>
    <item>
      <title>解决OSSEC Agent 3.6.0 无法注册问题</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483684&amp;idx=1&amp;sn=5d9dd3e60a58c991c3a2015d6b86aa82</link>
      <description>解决OSSEC Agent 3.6.0 无法注册问题</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2020-07-04 11:53</span> <span style="display: inline-block;"></span>
</p>

<p>解决OSSEC Agent 3.6.0 无法注册问题</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6fff5471&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicSuZibRW7Oy4JP4WuxGPo4jZcxtiaTiceq8SyxpRcYO32TmLzKxpuSdX0g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>  在第三章主机安全中，介绍了OSSEC 的使用方法，但当时Agent 使用的是3.2.0版本，在测试Agent 为3.6.0版本时发现无法注册的问题：使用Server生成的key注册时会出现下图错误：<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="197" data-backw="578" data-ratio="0.34140625" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=dc51a1c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicJZ0CZOyXyzzlfRicDcYHMY0HYqibolIicJ6RdoiaSYPxd5EW584tnPen9A%2F640%3Fwx_fmt%3Dpng"/></p><p>提示：ERROR: Cannot,unlink /queue/rids/sender: No such file or directory 。</p><p>解决方法也很简单，使用如下命令：</p><p>touch /var/ossec/queue/rids/sender</p><p>即，在OSSEC 安装目录下的qurue/rids目录下新建sender 文件即可。</p><p>这样 ，便可以让Agent注册成功（需要重启Agent 服务），如下图：<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="393" data-backw="578" data-ratio="0.68046875" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d34bb933&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicAye5A2HHAgryCjyrcAC5eibJsXx5O5Yds9FxU1LMjaIYICLQRhpvLmQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p>在Server端，使用agent_control -l 命令也可以看到客户端是Active状态，（一定要是Active，如果没成功，可能会显示Never connected之类的）如图：</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="75" data-backw="578" data-ratio="0.1296875" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=af678005&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwic5zhSRibQv6KvMeTWHkwQVLaZxIcvOibeDUKZMuc0NtLz3wRrDjcL6gHg%2F640%3Fwx_fmt%3Dpng"/></p><p>。</p><p>也可以在Server端让客户端直接重启操作。（客户端需要开启ar-auto  response 功能。这里再次建议这个功能一定要慎重使用，一定要配合白名单及绝对有把握的情况下使用）如图</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="108" data-backw="578" data-ratio="0.18695652173913044" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="920" src="https://wechat2rss.xlab.app/img-proxy/?k=4c14d082&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicibXGoibaXzAJkP0nibib0K5NnlHxqO2MDlbJTZolT2QUCq42mibfLAficJ7g%2F640%3Fwx_fmt%3Dpng"/></p><p>Agent收到Server端的重启信号开始重启：<br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="29" data-backw="578" data-ratio="0.05" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=79889fb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicn2mKssEh85MVIjkXJtYiaQe6c84TwhABibVibksP0BuLZuwIIJypuibNFg%2F640%3Fwx_fmt%3Dpng"/></p><p>至此，便解决了 3.6.0版本Agent的问题。</p><p><br/></p><p>PS：OSSEC 其实是一个比较不错的HIDS，不过因为是开源的版本，因此BUG,和坑也是很多的，坑在本书中已经介绍过一些了，BUG 也是经常有的。但个人觉得更难的是日常维护及批量部署，因此个人建议一定要有一定的开发能力，使用批量部署工具，否则会是一个比较繁重的工作<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d604ef48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZqFdTRrPpHlGVwiar0XvVAwicucaflI0e8P4raiavstGYtqldwILs1OhtHypdD9icv3iapPUmFibGAyMU8g%2F640%3Fwx_fmt%3Dpng"/>。</p><p><br/></p>



<p><a href="2247483684">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4b75ba57&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483684%26idx%3D1%26sn%3D5d9dd3e60a58c991c3a2015d6b86aa82%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 04 Jul 2020 11:53:00 +0800</pubDate>
    </item>
    <item>
      <title>互联网安全建设从0到1 发售</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483673&amp;idx=1&amp;sn=a64d70fcb5d4650abc33c3505503b611</link>
      <description>互联网安全建设从0到1 发售，安全防御公众号正式运营</description>
      <content:encoded><![CDATA[<p>
原创 <span>lion_00</span> <span>2020-06-26 15:38</span> <span style="display: inline-block;"></span>
</p>

<p>互联网安全建设从0到1 发售，安全防御公众号正式运营</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a0402168&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZondPzwps9fLszfQRQ0gngARDiby7CsIHwzHqEMWSkwrcjYx6DdPNQFYCYjjf2HHbAalJlic7TM8aiag%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>    时间过得真快，大概是去年6月13日，开始下定决心写书，到今天终于算是修成正果了，也算是给自己这些年的一些经验做了一次总结<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d10be762&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngArUETeYyKJQDxFVctyAstvMJvgVBvZP1PfibutKTeMrAGDe6hibYibmkVw%2F640%3Fwx_fmt%3Dpng"/>。同时为了继续让自己保持一点学习的动力，今天也正式开始维护这个公众号，这个号会以勘误为主，另外写一些技术方面的内容和自己的一些安全心得。</p><p><br/></p><p>    书的内容和目录在各大平台应该都能看到了，通过之前的图片，也能看到我个人对自己内容的评价：<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d10be762&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngArUETeYyKJQDxFVctyAstvMJvgVBvZP1PfibutKTeMrAGDe6hibYibmkVw%2F640%3Fwx_fmt%3Dpng"/>是觉得写的满意的，<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=bcef956c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngAgHCGmmiaLUhXxchqrgrGbD8EmHgcC2xuuVSdhhHK4jINdX3KJnq7z2g%2F640%3Fwx_fmt%3Dpng"/>是觉得写的可以的，<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=86b24714&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngAJMQwXJkLJ88DTblsicP5CgPFF1tE3ton7OdBSArLfTJ44A1SMbnOSwg%2F640%3Fwx_fmt%3Dpng"/>是我确实不擅长，或者写的觉得不太好的地方。不过基本上也算是把我个人这些年的一些经验都扔进去了（想了一下还有一点点内容忘了写），然后现在感觉貌似基本上也没啥可讲的了<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=a286e6fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngAiaKv8ZOZr4MjMIwcQlPQXBP9oz8lj5Vr3ujibnX2d7POPK5sliciaib6q2Q%2F640%3Fwx_fmt%3Dpng"/>。</p><p><br/></p><p>  不管怎样，本书已经写完了，也算是我个人里程碑的一个小节点，人活一世，草木一秋，不求写书赚钱，只求给安全行业，给刚入行的安全人员留下点自己的经验，希望踩过的坑，就别再踩一次，造过的轮子也就别重新再造，仅此而已。但即使这样，我个人水平还是有限的，有错误的地方还请各位读者多多指正，有兴趣的读者，可以一起交流，毕竟安全防御这块，虽然不如攻击者那么耀眼，但幕后英雄这个称号也不错。<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d10be762&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngArUETeYyKJQDxFVctyAstvMJvgVBvZP1PfibutKTeMrAGDe6hibYibmkVw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>PS：头像是之前玩的塞尔达的海拉鲁之盾，也是整个游戏最好，最坚固的盾了，希望安全防御也可以做到这样，那就好了。<img data-ratio="1" style="display:inline-block;width:20px;vertical-align:text-bottom;" data-type="png" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d10be762&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FibCalCUYKkZondPzwps9fLszfQRQ0gngArUETeYyKJQDxFVctyAstvMJvgVBvZP1PfibutKTeMrAGDe6hibYibmkVw%2F640%3Fwx_fmt%3Dpng"/><br/></p><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/ibCalCUYKkZondPzwps9fLszfQRQ0gngALvOWOyK7PJNGOxASxB5BtoNm2ppgPdkZdNEf9bNZIAWxKLBZIr0p0Q/640?wx_fmt=jpeg" data-cropx1="0" data-cropx2="960.0000000000001" data-cropy1="116.26297577854673" data-cropy2="1697.4394463667825" data-ratio="1.6479166666666667" data-s="300,640" style="width: 578px;height: 952px;" data-type="jpeg" data-w="960" src="https://wechat2rss.xlab.app/img-proxy/?k=8e84d22d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZondPzwps9fLszfQRQ0gngAtibHpxuvC2ZaYhAKBAQTNAurvHNWdpnvt1yiazibs77ccs9coq3ZdqFJw%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p>



<p><a href="2247483673">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4855b268&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483673%26idx%3D1%26sn%3Da64d70fcb5d4650abc33c3505503b611%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 26 Jun 2020 15:38:00 +0800</pubDate>
    </item>
    <item>
      <title>互联网安全建设从0到1</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5NzA3NDY1MA==&amp;mid=2247483654&amp;idx=1&amp;sn=a556ff95908576b208dfa30539ba452a</link>
      <description>互联网安全建设从0到1</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2020-02-12 20:58</span> <span style="display: inline-block;"></span>
</p>

<p>互联网安全建设从0到1</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=46035a42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FibCalCUYKkZoRqpmQu9ib6lPOUCibAKgc3rDam6tjQ4HNgdmTmVVLrwERud05c9OPUhZIZDSajUV6smFokYuPugcw%2F0"/>
</p>


<div id="js_image_content" class="image_content "><!---->    <!----> <!----> <!----> <div class="wx_album_area js_album_wrap " style=""></div> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary "><!----></div></div> </div>


<p><img src="https://mmbiz.qlogo.cn/mmbiz_png/ibCalCUYKkZoRqpmQu9ib6lPOUCibAKgc3rrRqXuXyuGl2seGP2TNiaD7qh7G9Gj49L2jUT3ms7Ip3sqVpmkktibndw/0?wx_fmt=png"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=37b1fad2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5NzA3NDY1MA%3D%3D%26mid%3D2247483654%26idx%3D1%26sn%3Da556ff95908576b208dfa30539ba452a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Feb 2020 20:58:00 +0800</pubDate>
    </item>
  </channel>
</rss>