<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>狼目安全</title><link>http://localhost:8080</link><atom:link href="http://localhost:8080/rss.xml" rel="self" type="application/rss+xml"/><description>专注于网络安全,渗透测试,web安全,运维,网络攻防,CTF,算法,漏洞</description><generator>Halo v2.22.14</generator><language>zh-cn</language><image><url>http://localhost:8080/upload/1kl.png</url><title>狼目安全</title><link>http://localhost:8080</link></image><lastBuildDate>Sun, 16 Aug 2026 18:03:46 GMT</lastBuildDate><item><title><![CDATA[Windows、Linux 和 macOS 的本地权限提升和安全机制绕过参考模块]]></title><link>http://localhost:8080/archives/windows-linux-he-macos-de-ben-di-quan-xian-ti-sheng-he-an-quan-ji-zhi-rao-guo-can-kao-mo-kuai</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=Windows%E3%80%81Linux%20%E5%92%8C%20macOS%20%E7%9A%84%E6%9C%AC%E5%9C%B0%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E5%92%8C%E5%AE%89%E5%85%A8%E6%9C%BA%E5%88%B6%E7%BB%95%E8%BF%87%E5%8F%82%E8%80%83%E6%A8%A1%E5%9D%97&amp;url=/archives/windows-linux-he-macos-de-ben-di-quan-xian-ti-sheng-he-an-quan-ji-zhi-rao-guo-can-kao-mo-kuai" width="1" height="1" alt="" style="opacity:0;">权限升级技能 这是一个专注于本地权限升级和安全机制绕过参考模块的集合，适用于Windows、Linux和macOS——专为授权安全测试、官方红队行动、夺旗挑战和防御验证而构建。 一套聚焦本地权限提升与安全机制绕过的参考模块，覆盖 Windows / Linux / macOS，面向授权安全测试、合规]]></description><guid isPermaLink="false">/archives/windows-linux-he-macos-de-ben-di-quan-xian-ti-sheng-he-an-quan-ji-zhi-rao-guo-can-kao-mo-kuai</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F135816865.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 14:18:20 GMT</pubDate></item><item><title><![CDATA[CVE-2026-68138：Linux qdisc]]></title><link>http://localhost:8080/archives/cve-2026-68138-linux-qdisc</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=CVE-2026-68138%EF%BC%9ALinux%20qdisc&amp;url=/archives/cve-2026-68138-linux-qdisc" width="1" height="1" alt="" style="opacity:0;">一个概念验证的本地权限升级漏洞利用 针对 CVE-2026-68138，这是 Linux 流量控制速率表代码中的一场竞赛。在 在测试的QEMU环境中，PoC从普通进程升级为 外部 UID 1000 映射到初始用户命名空间中 UID 为 0 的 shell。 警告 该代码故意破坏内核堆状态。只在 你拥]]></description><guid isPermaLink="false">/archives/cve-2026-68138-linux-qdisc</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FCVE-2026-68138.gif&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 14:13:49 GMT</pubDate></item><item><title><![CDATA[IDA Pro 9.3 正式版泄露版+注册机]]></title><link>http://localhost:8080/archives/ida-pro-9.3-zheng-shi-ban-xie-lu-ban-zhu-ce-ji</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=IDA%20Pro%209.3%20%E6%AD%A3%E5%BC%8F%E7%89%88%E6%B3%84%E9%9C%B2%E7%89%88%2B%E6%B3%A8%E5%86%8C%E6%9C%BA&amp;url=/archives/ida-pro-9.3-zheng-shi-ban-xie-lu-ban-zhu-ce-ji" width="1" height="1" alt="" style="opacity:0;">V9.3.260213.91fc47de IDA Pro 9.3.260213 activation for compare windows original + patched files.7z 11.73 MB idapro.hexlic 3.86 KB keygens a]]></description><guid isPermaLink="false">/archives/ida-pro-9.3-zheng-shi-ban-xie-lu-ban-zhu-ce-ji</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F775692_HRXNVGK5VNCG82J.webp&amp;size=m" type="image/jpeg" length="0"/><category>团队笔记</category><pubDate>Sun, 16 Aug 2026 14:08:23 GMT</pubDate></item><item><title><![CDATA[go shellcode加载 bypass AV]]></title><link>http://localhost:8080/archives/go-shellcodejia-zai-bypass-av</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=go%20shellcode%E5%8A%A0%E8%BD%BD%20bypass%20AV&amp;url=/archives/go-shellcodejia-zai-bypass-av" width="1" height="1" alt="" style="opacity:0;">在攻防实战中免杀技术尤为重要，站在巨人的肩膀上学习go shellcode免杀加载的方法 编写一个加载器需要围绕3个基本的功能实现： 申请内存空间：VirtualAlloc、VirtualAlloc2、VirtualAllocEx 导入内存：RtlCopyMemory、RtlCopyBytes、Rt]]></description><guid isPermaLink="false">/archives/go-shellcodejia-zai-bypass-av</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fimage-20230417210206730.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 14:03:32 GMT</pubDate></item><item><title><![CDATA[AI 免杀技术套件 v4.0 绕过主流杀软和 EDR 检测 ( AV Evasion Skill)]]></title><link>http://localhost:8080/archives/ai-mian-sha-ji-shu-tao-jian-v4.0-rao-guo-zhu-liu-sha-ruan-he-edr-jian-ce-av-evasion-skill</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=AI%20%E5%85%8D%E6%9D%80%E6%8A%80%E6%9C%AF%E5%A5%97%E4%BB%B6%20v4.0%20%E7%BB%95%E8%BF%87%E4%B8%BB%E6%B5%81%E6%9D%80%E8%BD%AF%E5%92%8C%20EDR%20%E6%A3%80%E6%B5%8B%20%28%20AV%20Evasion%20Skill%29&amp;url=/archives/ai-mian-sha-ji-shu-tao-jian-v4.0-rao-guo-zhu-liu-sha-ruan-he-edr-jian-ce-av-evasion-skill" width="1" height="1" alt="" style="opacity:0;">AI免杀技术套件v4.0是一套完整的Shellcode免杀解决方案，采用ModuleStomping、IPv4混淆、XOR加密、Fiber执行和间接Syscall等技]]></description><guid isPermaLink="false">/archives/ai-mian-sha-ji-shu-tao-jian-v4.0-rao-guo-zhu-liu-sha-ruan-he-edr-jian-ce-av-evasion-skill</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F8-1783010554.jpeg&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 13:47:54 GMT</pubDate></item><item><title><![CDATA[EDR规避深度剖析：系统调用间接执行、ETW绕过与内核回调脱钩]]></title><link>http://localhost:8080/archives/edrgui-bi-shen-du-pou-xi-xi-tong-diao-yong-jian-jie-zhi-xing-etwrao-guo-yu-nei-he-hui-diao-tuo-gou</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=EDR%E8%A7%84%E9%81%BF%E6%B7%B1%E5%BA%A6%E5%89%96%E6%9E%90%EF%BC%9A%E7%B3%BB%E7%BB%9F%E8%B0%83%E7%94%A8%E9%97%B4%E6%8E%A5%E6%89%A7%E8%A1%8C%E3%80%81ETW%E7%BB%95%E8%BF%87%E4%B8%8E%E5%86%85%E6%A0%B8%E5%9B%9E%E8%B0%83%E8%84%B1%E9%92%A9&amp;url=/archives/edrgui-bi-shen-du-pou-xi-xi-tong-diao-yong-jian-jie-zhi-xing-etwrao-guo-yu-nei-he-hui-diao-tuo-gou" width="1" height="1" alt="" style="opacity:0;">从Userland到Kernel：2025年终端安全对抗的最前线|前沿攻防技术系列 一、终端对抗的新格局 EDR（Endpoint Detection and Re]]></description><guid isPermaLink="false">/archives/edrgui-bi-shen-du-pou-xi-xi-tong-diao-yong-jian-jie-zhi-xing-etwrao-guo-yu-nei-he-hui-diao-tuo-gou</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fimage-20230413105756769.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 13:33:50 GMT</pubDate></item><item><title><![CDATA[BypassLoad:AES + XOR异或加密shellcode的免杀加载器]]></title><link>http://localhost:8080/archives/bypassload-aes-xoryi-huo-jia-mi-shellcodede-mian-sha-jia-zai-qi</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=BypassLoad%3AAES%20%2B%20XOR%E5%BC%82%E6%88%96%E5%8A%A0%E5%AF%86shellcode%E7%9A%84%E5%85%8D%E6%9D%80%E5%8A%A0%E8%BD%BD%E5%99%A8&amp;url=/archives/bypassload-aes-xoryi-huo-jia-mi-shellcodede-mian-sha-jia-zai-qi" width="1" height="1" alt="" style="opacity:0;">通过远程加载AES + XOR异或加密shellcode的免杀加载器，无过多技术细节。]]></description><guid isPermaLink="false">/archives/bypassload-aes-xoryi-huo-jia-mi-shellcodede-mian-sha-jia-zai-qi</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fimage-20230417154342538.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 13:29:57 GMT</pubDate></item><item><title><![CDATA[shellcode分离加载实现CS免杀上线]]></title><link>http://localhost:8080/archives/shellcodefen-chi-jia-zai-shi-xian-csmian-sha-shang-xian</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=shellcode%E5%88%86%E7%A6%BB%E5%8A%A0%E8%BD%BD%E5%AE%9E%E7%8E%B0CS%E5%85%8D%E6%9D%80%E4%B8%8A%E7%BA%BF&amp;url=/archives/shellcodefen-chi-jia-zai-shi-xian-csmian-sha-shang-xian" width="1" height="1" alt="" style="opacity:0;">基于XOR加密的Shellcode加载器项目，通过内存解密执行实现基础免杀，包含C++加载器和Python加密脚本，可绕过常规静态检测。]]></description><guid isPermaLink="false">/archives/shellcodefen-chi-jia-zai-shi-xian-csmian-sha-shang-xian</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F399abc95-509a-4399-8425-7859f2b0243c.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 13:26:06 GMT</pubDate></item><item><title><![CDATA[免杀技术（Bypass AV/EDR）]]></title><link>http://localhost:8080/archives/mian-sha-ji-shu-bypass-av-edr</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=%E5%85%8D%E6%9D%80%E6%8A%80%E6%9C%AF%EF%BC%88Bypass%20AV%2FEDR%EF%BC%89&amp;url=/archives/mian-sha-ji-shu-bypass-av-edr" width="1" height="1" alt="" style="opacity:0;">一、免杀基本概念 1.1 什么是”免杀”？ 免杀（Bypass AV/EDR）是网络安全领域中，攻击者为规避杀毒软件（AV）、终端检测与响应系统（EDR）的识别和拦截，使恶意代码成功在目标终端执行的一系列技术手段的统称。其本质不是” 关掉杀毒软件”，而是让它”看不见”。 免杀不是搞破坏，而是一场攻防]]></description><guid isPermaLink="false">/archives/mian-sha-ji-shu-bypass-av-edr</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fimage-20230505160305108.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 13:14:34 GMT</pubDate></item><item><title><![CDATA[Linux高危本地提权漏洞CVE-2026-31431实验复现]]></title><link>http://localhost:8080/archives/linuxgao-wei-ben-di-ti-quan-lou-dong-cve-2026-31431shi-yan-fu-xian</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=Linux%E9%AB%98%E5%8D%B1%E6%9C%AC%E5%9C%B0%E6%8F%90%E6%9D%83%E6%BC%8F%E6%B4%9ECVE-2026-31431%E5%AE%9E%E9%AA%8C%E5%A4%8D%E7%8E%B0&amp;url=/archives/linuxgao-wei-ben-di-ti-quan-lou-dong-cve-2026-31431shi-yan-fu-xian" width="1" height="1" alt="" style="opacity:0;">一、漏洞介绍 CVE-2026-31431是一个本地账号，提权root的高危漏洞 二、漏洞复现 通知执行一个POC python脚本， 就可以快速完成提权]]></description><guid isPermaLink="false">/archives/linuxgao-wei-ben-di-ti-quan-lou-dong-cve-2026-31431shi-yan-fu-xian</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FOIP-KAKf.webp&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 13:02:59 GMT</pubDate></item><item><title><![CDATA[CVE-2026-9700 Eventer插件SQL注入漏洞复现]]></title><link>http://localhost:8080/archives/cve-2026-9700-eventercha-jian-sqlzhu-ru-lou-dong-fu-xian</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=CVE-2026-9700%20Eventer%E6%8F%92%E4%BB%B6SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0&amp;url=/archives/cve-2026-9700-eventercha-jian-sqlzhu-ru-lou-dong-fu-xian" width="1" height="1" alt="" style="opacity:0;">CVE-2026-9700，一个在WordPress Eventer插件中埋了不知道多久的时间盲注漏洞，CVSS 7.5，直接打数据库，无需登录。来吧，上手试一下。 漏洞背景 Eventer 是一个流行的WordPress活动管理插件，用于创建和管理活动日程、票务等。该漏洞存在于所有版本中（截至漏洞]]></description><guid isPermaLink="false">/archives/cve-2026-9700-eventercha-jian-sqlzhu-ru-lou-dong-fu-xian</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FOIP%2520%281%29.webp&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 13:00:59 GMT</pubDate></item><item><title><![CDATA[Ecommerce-CodeIgniter-Bootstrap 远程代码执行漏洞复现]]></title><link>http://localhost:8080/archives/ecommerce-codeigniter-bootstrap-yuan-cheng-dai-ma-zhi-xing-lou-dong-fu-xian</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=Ecommerce-CodeIgniter-Bootstrap%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0&amp;url=/archives/ecommerce-codeigniter-bootstrap-yuan-cheng-dai-ma-zhi-xing-lou-dong-fu-xian" width="1" height="1" alt="" style="opacity:0;">漏洞简介 CVE-2026-14637 是一个影响 kirilkirkov Ecommerce-CodeIgniter-Bootstrap 项目的 SQL 注入漏洞，CVSS 评分 8.2，攻击者无需认证即可通过精心构造的请求实现远程代码执行。这玩意儿在野已经有人开始扫了，今天带兄弟们手把手复现一波]]></description><guid isPermaLink="false">/archives/ecommerce-codeigniter-bootstrap-yuan-cheng-dai-ma-zhi-xing-lou-dong-fu-xian</guid><dc:creator>lmteam</dc:creator><category>漏洞</category><pubDate>Sun, 16 Aug 2026 12:59:44 GMT</pubDate></item><item><title><![CDATA[CVE-2026-16723复现（fastjson rce）]]></title><link>http://localhost:8080/archives/cve-2026-16723fu-xian-fastjson-rce</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=CVE-2026-16723%E5%A4%8D%E7%8E%B0%EF%BC%88fastjson%20rce%EF%BC%89&amp;url=/archives/cve-2026-16723fu-xian-fastjson-rce" width="1" height="1" alt="" style="opacity:0;">1. 漏洞介绍 Fastjson 是阿里巴巴开源的一款高性能 Java JSON 解析库，支持将 Java 对象序列化为 JSON 字符串以及将 JSON 字符串反序列化为 Java 对象。该库凭借其出色的解析性能和简洁的 API 设计，在国内 Java 生态系统中占据主导地位，被广泛应用于企业级后]]></description><guid isPermaLink="false">/archives/cve-2026-16723fu-xian-fastjson-rce</guid><dc:creator>lmteam</dc:creator><category>漏洞</category><pubDate>Sun, 16 Aug 2026 12:50:19 GMT</pubDate></item><item><title><![CDATA[CVE-2026-34037 Coolify 未授权RCE漏洞复现]]></title><link>http://localhost:8080/archives/cve-2026-34037-coolify-wei-shou-quan-rcelou-dong-fu-xian</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=CVE-2026-34037%20Coolify%20%E6%9C%AA%E6%8E%88%E6%9D%83RCE%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0&amp;url=/archives/cve-2026-34037-coolify-wei-shou-quan-rcelou-dong-fu-xian" width="1" height="1" alt="" style="opacity:0;">漏洞背景 Coolify 是一个开源的自托管平台，用于管理服务器、应用和数据库，类似 Vercel 或 Netlify 的私有化部署版本。CVE-2026-34037 是一个未经身份验证的远程代码执行漏洞，影响 Coolify 4.0.0-beta.258 及之前版本。 CVE编号: CVE-202]]></description><guid isPermaLink="false">/archives/cve-2026-34037-coolify-wei-shou-quan-rcelou-dong-fu-xian</guid><dc:creator>lmteam</dc:creator><category>漏洞</category><pubDate>Sun, 16 Aug 2026 12:47:10 GMT</pubDate></item><item><title><![CDATA[金和OA C6 PlanGiveOut.aspx SQL注入漏洞+越权访问IDOR漏洞+XSS漏洞]]></title><link>http://localhost:8080/archives/jin-he-oa-c6-plangiveout.aspx-sqlzhu-ru-lou-dong-yue-quan-fang-wen-idorlou-dong-xsslou-dong</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=%E9%87%91%E5%92%8COA%20C6%20PlanGiveOut.aspx%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%2B%E8%B6%8A%E6%9D%83%E8%AE%BF%E9%97%AEIDOR%E6%BC%8F%E6%B4%9E%2BXSS%E6%BC%8F%E6%B4%9E&amp;url=/archives/jin-he-oa-c6-plangiveout.aspx-sqlzhu-ru-lou-dong-yue-quan-fang-wen-idorlou-dong-xsslou-dong" width="1" height="1" alt="" style="opacity:0;">漏洞简介 金和网络是专业信息化服务商,为城市监管部门提供了互联网+监管解决方案,为企事业单位提供组织协同OA系统开发平台,电子政务一体化平台,智慧电商平台等服务。金和OA C6 PlanGiveOut.aspx 接口处存在SQL注入漏洞、XSS漏洞、越权访问IDOR漏洞，攻击者除了可以利用SQL注入]]></description><guid isPermaLink="false">/archives/jin-he-oa-c6-plangiveout.aspx-sqlzhu-ru-lou-dong-yue-quan-fang-wen-idorlou-dong-xsslou-dong</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fa579134e-74ba-4f21-b274-7950383ffd17.png&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 12:29:13 GMT</pubDate></item><item><title><![CDATA[普华PowerPMS /Plan/BatchHandleFeedBackRecord 鉴权绕过漏洞]]></title><link>http://localhost:8080/archives/pu-hua-powerpms-plan-batchhandlefeedbackrecord-jian-quan-rao-guo-lou-dong</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=%E6%99%AE%E5%8D%8EPowerPMS%20%2FPlan%2FBatchHandleFeedBackRecord%20%E9%89%B4%E6%9D%83%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E&amp;url=/archives/pu-hua-powerpms-plan-batchhandlefeedbackrecord-jian-quan-rao-guo-lou-dong" width="1" height="1" alt="" style="opacity:0;">漏洞简介 普华科技 PowerPMS 的 /Plan/BatchHandleFeedBackRecord 接口存在鉴权绕过（自动登录后门）漏洞。该接口完全不需要登录即可访问，匿名访问时服务端会自行从]]></description><guid isPermaLink="false">/archives/pu-hua-powerpms-plan-batchhandlefeedbackrecord-jian-quan-rao-guo-lou-dong</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FOIP-MBxj.webp&amp;size=m" type="image/jpeg" length="0"/><pubDate>Sun, 16 Aug 2026 12:16:21 GMT</pubDate></item><item><title><![CDATA[用友GRP-U8Cloud产品jmreport组件模块Freemarker模板SSTI致RCE漏洞讲解]]></title><link>http://localhost:8080/archives/yong-you-grp-u8cloudchan-pin-jmreportzu-jian-mo-kuai-freemarkermo-ban-sstizhi-rcelou-dong-jiang-jie</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=%E7%94%A8%E5%8F%8BGRP-U8Cloud%E4%BA%A7%E5%93%81jmreport%E7%BB%84%E4%BB%B6%E6%A8%A1%E5%9D%97Freemarker%E6%A8%A1%E6%9D%BFSSTI%E8%87%B4RCE%E6%BC%8F%E6%B4%9E%E8%AE%B2%E8%A7%A3&amp;url=/archives/yong-you-grp-u8cloudchan-pin-jmreportzu-jian-mo-kuai-freemarkermo-ban-sstizhi-rcelou-dong-jiang-jie" width="1" height="1" alt="" style="opacity:0;">目标：http://192.168.168.168:8088]]></description><guid isPermaLink="false">/archives/yong-you-grp-u8cloudchan-pin-jmreportzu-jian-mo-kuai-freemarkermo-ban-sstizhi-rcelou-dong-jiang-jie</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F05fa3886-8607-4b53-beb5-b32f2cc56be8.png&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 12:08:16 GMT</pubDate></item><item><title><![CDATA[C2-Rich：纯 Go 多协议 C2 框架]]></title><link>http://localhost:8080/archives/c2-rich-chun-go-duo-xie-yi-c2-kuang-jia</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=C2-Rich%EF%BC%9A%E7%BA%AF%20Go%20%E5%A4%9A%E5%8D%8F%E8%AE%AE%20C2%20%E6%A1%86%E6%9E%B6&amp;url=/archives/c2-rich-chun-go-duo-xie-yi-c2-kuang-jia" width="1" height="1" alt="" style="opacity:0;">简介 基于 Go 语言的命令与控制（C2）框架，纯 Go 实现，支持 Windows/Linux 交叉编译，集成多协议通信、流量加密、代码混淆、WebShell 管理、内网穿透等功能。]]></description><guid isPermaLink="false">/archives/c2-rich-chun-go-duo-xie-yi-c2-kuang-jia</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FOIP.webp&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 11:44:24 GMT</pubDate></item><item><title><![CDATA[一张假「公安一网通办」钓出 170 台服务器——飞鹰与夜龙黑产武器库全景拆解]]></title><link>http://localhost:8080/archives/yi-zhang-jia-gong-an-yi-wang-tong-ban-diao-chu-170-tai-fu-wu-qi----fei-ying-yu-ye-long-hei-chan-wu-qi-ku-quan-jing-chai-jie</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=%E4%B8%80%E5%BC%A0%E5%81%87%E3%80%8C%E5%85%AC%E5%AE%89%E4%B8%80%E7%BD%91%E9%80%9A%E5%8A%9E%E3%80%8D%E9%92%93%E5%87%BA%20170%20%E5%8F%B0%E6%9C%8D%E5%8A%A1%E5%99%A8%E2%80%94%E2%80%94%E9%A3%9E%E9%B9%B0%E4%B8%8E%E5%A4%9C%E9%BE%99%E9%BB%91%E4%BA%A7%E6%AD%A6%E5%99%A8%E5%BA%93%E5%85%A8%E6%99%AF%E6%8B%86%E8%A7%A3&amp;url=/archives/yi-zhang-jia-gong-an-yi-wang-tong-ban-diao-chu-170-tai-fu-wu-qi----fei-ying-yu-ye-long-hei-chan-wu-qi-ku-quan-jing-chai-jie" width="1" height="1" alt="" style="opacity:0;">源码泄露后，黑产从“卖工具”进化到“开平台”，安卓安全正面临工业化挑战。 一、从一款假App挖出工业化产业链]]></description><guid isPermaLink="false">/archives/yi-zhang-jia-gong-an-yi-wang-tong-ban-diao-chu-170-tai-fu-wu-qi----fei-ying-yu-ye-long-hei-chan-wu-qi-ku-quan-jing-chai-jie</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fc4eb5de2-04f0-42d1-89e6-b312537772fb-QckC.png&amp;size=m" type="image/jpeg" length="0"/><category>网络安全</category><pubDate>Sun, 16 Aug 2026 11:27:30 GMT</pubDate></item><item><title><![CDATA[wp2shell（CVE-2026-63030）：WordPress 核心免认证 RCE 漏洞深度解析]]></title><link>http://localhost:8080/archives/wp2shell-cve-2026-63030-wordpress-he-xin-mian-ren-zheng-rce-lou-dong-shen-du-jie-xi</link><description><![CDATA[<img src="http://localhost:8080/plugins/feed/assets/telemetry.gif?title=wp2shell%EF%BC%88CVE-2026-63030%EF%BC%89%EF%BC%9AWordPress%20%E6%A0%B8%E5%BF%83%E5%85%8D%E8%AE%A4%E8%AF%81%20RCE%20%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E8%A7%A3%E6%9E%90&amp;url=/archives/wp2shell-cve-2026-63030-wordpress-he-xin-mian-ren-zheng-rce-lou-dong-shen-du-jie-xi" width="1" height="1" alt="" style="opacity:0;">漏洞简介 wp2shell（CVE-2026-63030）是WordPress核心中的免认证远程代码执行]]></description><guid isPermaLink="false">/archives/wp2shell-cve-2026-63030-wordpress-he-xin-mian-ren-zheng-rce-lou-dong-shen-du-jie-xi</guid><dc:creator>lmteam</dc:creator><enclosure url="http://localhost:8080/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fc8c29453-f793-481d-b7a6-99c2436f3527.png&amp;size=m" type="image/jpeg" length="0"/><category>漏洞</category><pubDate>Sun, 16 Aug 2026 11:08:11 GMT</pubDate></item></channel></rss>