漏洞报告
3500$的XSS
http://hackerone.com/reports/1410459
导入文档处SSRF5000$
http://hackerone.com/reports/1409727
自动化挖洞捡到1500$
http://hackerone.com/reports/1380121
挖洞技巧
Hack区块链
http://medium.com/immunefi/hacking-the-blockchain-an-ultimate-guide-4f34b33c6e8b
RTF 模板注入
http://letsdefend.io/blog/how-to-analyze-rtf-template-injection-attacks/
CVE-2022-24348
http://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments
挖洞工具
burpsuite插件,注入、fastjson、shiro
http://github.com/SkewwG/BurpExtender
基于ZoomEye的图形化搜索器
http://github.com/xzajyjs/ThunderSearch
GitHub代码泄漏监控系统
http://github.com/4×99/code6
文字来源于- 火线 Zone-云安全社区,安全小天地只做文章分享,如有侵权,请联系站长删除















请登录后查看评论内容