Aggregator
解决OSSEC Agent 3.6.0 无法注册问题
4 years 7 months ago
解决OSSEC Agent 3.6.0 无法注册问题
Cybersecurity Myths That Are Harming Your Business
4 years 7 months ago
Cybersecurity experts are falling prey to seven myths in the effort to protect their business. Shape's Daniel Woods writes for Forbes, explaining where these myths have led us astray, and how to keep the useful bits while discarding the chaff.
Technical Controls for a Secure Open Banking Initiative
4 years 7 months ago
Learn about the technical controls that leading regulators around the world endorse for an effective and secure Open Banking initiative.
2020 Firefox 安全、隐私、实用扩展指南
4 years 7 months ago
本篇文章将会介绍一些我目前使用的安全、隐私和实用相关的 Firefox 扩展。
Taking a Human Approach to a Global Crisis
4 years 7 months ago
Since March, the COVID crisis has caused massive disruption to every area of life and work. It has tested us, as individuals and as a business. Akamai has taken a very human-centric approach during the pandemic. Our guiding principle has been to do what is right for the health and safety of employees, customers and partners. I feel proud of this, because when I think about what I'm grateful for, it really does come down to people. I'm grateful to be working for a company that is keeping people connected to the world through technology. I'm grateful to be among smart, immensely resilient colleagues. And I'm grateful to have friends and family who are sticking together. Ultimately, it's the humanity that matters.
Prasad Mandava
Blast from the past: Cross Site Scripting on the AWS Console
4 years 7 months ago
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program
Bad news: AWS is out of scope!
When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console.
This post is a write up on how I found the XSS back then, techniques I used and how they evolved over the years and Amazon’s response.
AWS Console and Cross Site Scripting The story is that I had just created an AWS account and started using the service.
Feedspot ranked 'Embrace the Red' one of the top 15 pentest blogs
4 years 7 months ago
I’m excited that Feedspot ranked this blog (Embrace the Red) the number #10 pentest blog out there.
Subscribe and check-in regularly for new content related to offensive security engineering, penetration testing and red teaming.
You can also follow me on Twitter @wunderwuzzi23.
Cheers.
TCTF 2020 Web Writeup partial
4 years 7 months ago
To begin with
今年 TCTF Web 题目比原来要多,但还是那么强(做不出来
easyphp这道题被非预期了,正确解法也是在看到一叶飘零的
xmsec
欢迎各位关注我的视频号,会有一些好玩的AI产品和不一样的分享。
4 years 7 months ago
欢迎各位关注我的视频号,会有一些好玩的AI产品和不一样的分享。
TCTF/0CTF 2020 Writeup
4 years 7 months ago
又是一年 0CTF, 这次一个人一队单刷一次, 做出了两题 WEB, 可惜只输出了一天, 第二天还要赶 ddl, 还是太蔡了 orz
【新书推荐】互联网安全建设从0到1
4 years 7 months ago
这是一本适合从安全小白到企业安全负责人阅读的安全书籍,作者将自己多年丰富的安全经验融入此书,通俗易懂,雅俗共赏,既可作为安全工程师的工具手册,解决各类常见的安全问题,也可以指导安全负责人如何从0到1系统地建设企业安全体系,非常值得推荐!
Hack The Box - Postman Writeup - Linux
4 years 7 months ago
TonghuaRoot
Android tcpdump TCP 抓包
4 years 7 months ago
0x01 概述本文将介绍安卓模拟器环境下面使用tcpdump抓包的方法,适合小白用户查看。
独自等待
Apache Dubbo Provider默认反序列漏洞复现(CVE-2020-1948) - Zhengjim
4 years 7 months ago
Apache Dubbo Provider默认反序列漏洞(CVE-2020-1948) 0x01 搭建漏洞环境 漏洞介绍 2020年06月23日, 360CERT监测发现Apache Dubbo 官方发布了Apache Dubbo 远程代码执行的风险通告,该漏洞编号为CVE-2020-1948,漏洞
Zhengjim
全面了解风控策略体系
4 years 7 months ago
在那么多为了better life奋斗的人里面,总有几个是为了better world的。
一步步教你制作移动式银行卡信息读取器
4 years 7 months ago
银行卡信息读取器?太强了
武学大家治学传承赏析
4 years 7 months ago
武学大家治学传承心态赏析:扫地僧、风清扬、独孤...
再谈离职留人的难处和经验
4 years 7 months ago
员工离职,怎么留人?
第五空间 2020 Web Writeup
4 years 7 months ago
do you kown
非预期解法:
$_SERVER['QUERY_STRING']; 未进行解码操作,可以直接绕过读 /var/www/html/flag.php
xmsec