程序人生

Fuzzing / Vulnerability / Exploit


  • Home

  • Categories

  • Archives

  • Tags

  • About

  • Sitemap

Living Off the Land Techniques

Posted on 2024-03-03 | In Red Teaming

Living off the Land (LOTL) involves the abuse of native tools and processes on systems, especially living off the land binaries, often referred to as LOLBins, to blend in with normal system activities and operate discreetly with a lower likelihood of being detected or blocked because these tools are already deployed and trusted in the environment.

Read more »

漏洞案例研究 ConnectWise ScreenConnect Authentication Bypass

Posted on 2024-02-25 | In Vulnerability , Analysis

最近 ConnectWise ScreenConnect 爆了 2 个漏洞(CVE-2024-1709 和 CVE-2024-1708),其中 CVE-2024-1709 是一个 Authentication Bypass 漏洞,CVSS 评分 10 分。Sophos 安全团队表示,勤劳的攻击者已经在第一时间利用这些漏洞来投递勒索软件。本文简单整理相关信息,作为漏洞案例研究系列的第一篇文章。

Read more »

BlackHat Europe 2023 议题学习(二)

Posted on 2024-01-28 | In Conferences , BlackHat

BlackHat Europe 2023 - LogoFAIL: Security Implications of Image Parsing During System Boot

BlackHat USA 2009 - Attacking Intel® BIOS - PDF

Read more »

BlackHat Europe 2023 议题学习(一)

Posted on 2024-01-06 | In Conferences , BlackHat

Old code dies hard: Finding new vulnerabilities in old third-party software components and the importance of having SBoM for IoT/OT devices

Read more »

iOS 设备 GPS 位置模拟

Posted on 2021-05-30 | In Apple , iOS

未越狱 iOS 设备通过 Xcode 修改 GPS 定位信息。

Read more »

Ubuntu Snap Docker 国内加速镜像设置

Posted on 2020-09-12 | In Virtualization , Docker

为 Ubuntu 下通过 Snap 安装的 Docker 设置国内加速镜像(Registry Mirrors)。

Read more »

QEMU 信息泄露漏洞 CVE-2015-5165 分析及利用

Posted on 2020-06-30 | In Virtualization , QEMU

参考 Phrack 文章 VM escape - QEMU Case Study [1] 对 QEMU 信息泄露漏洞 CVE-2015-5165 和堆溢出漏洞 CVE-2015-7504 进行调试分析并编写 Exploit 代码,本文主要分析其中的 RTL8139 网卡信息泄露漏洞 CVE-2015-5165。

Read more »

Introduction to Hypercall

Posted on 2020-05-20 | In Virtualization , Hyper-V

Hyper-V Hypercall 相关基础知识介绍。

Read more »

Hyper-V 调试环境搭建

Posted on 2020-05-16 | In Virtualization , Hyper-V

本文将详细介绍使用 AMD CPU 的电脑如何利用 VMware Workstation 搭建 Hyper-V 的调试环境。

Read more »

Hyper-V on Windows 10 Notes

Posted on 2020-05-13 | In Virtualization , Hyper-V

周末花了点时间看了微软对 Hyper-V 的介绍文档《Hyper-V on Windows 10》,顺便记点笔记。

Read more »
123
Ke Liu

Ke Liu

Independent Security Researcher

30 posts
17 categories
75 tags
RSS
Twitter
© 2010 - 2024 Ke Liu
Powered by Hexo
Theme - NexT.Pisces