Aggregator
Springboot之Actuator信息泄露漏洞利用
Springboot之Actuator信息泄露漏洞利用
Springboot之Actuator信息泄露漏洞利用
2022网鼎杯白虎组部分wp(新增re-junk)
Springboot之Actuator信息泄露漏洞利用
New Prolexic Partner Megaport Now Live in Australia
PureCrypter is busy pumping out various malicious malware families
In our daily botnet analysis work, it is common to encounter various loaders.Compared to other types of malware, loaders are unique in that they are mainly used to "promote", i.e., download and run other malware on the infected machine. According to our observations, most loaders are
方法论 | 我与入侵检测的二三事儿
方法论 | 我与入侵检测的二三事儿
CVE-2022-26911 Skype for Business 任意文件读取漏洞分析与复现
CVE-2022-26911 Skype for Business 任意文件读取漏洞分析与复现
CVE-2022-26911 Skype for Business 任意文件读取漏洞分析与复现
1password6 在chromeV99复活 - sevck
Machine Learning Attack Series: Backdooring Pickle Files
Recently I read this excellent post by Evan Sultanik about exploiting pickle files on Trail of Bits. There was also a DefCon30 talk about backdooring pickle files by ColdwaterQ.
This got me curious to try out backdooring a pickle file myself.
Pickle files - the surprisesSurprisingly Python pickle files are compiled programs running in a VM called the Pickle Machine (PM). Opcodes control the flow, and when there are opcodes there is often fun to be had.
利用Azure Attest Service持久化
PureCrypter Loader持续活跃,已经传播了10多个其它家族
在我们的日常botnet分析工作中,碰到各种loader是常事。跟其它种类的malware相比,loader的特殊之处在于它主要用来“推广”,