<?xml version="1.0" encoding="utf-8" ?><rss version="2.0"><channel><title><![CDATA[sechelper的博客]]></title><description><![CDATA[]]></description><link>https://blog.csdn.net/sechelper</link><language>zh-cn</language><generator>https://blog.csdn.net/</generator><copyright><![CDATA[Copyright &copy; sechelper]]></copyright><item><title><![CDATA[这个月坤哥可以负责任的说：没有辜负大家的期待]]></title><link>https://blog.csdn.net/sechelper/article/details/131035846</link><guid>https://blog.csdn.net/sechelper/article/details/131035846</guid><author>sechelper</author><pubDate>Sun, 04 Jun 2023 19:17:49 +0800</pubDate><description><![CDATA[答：大一开始接触，大二开始找实习，找不到没关系很正常，重要的是你要知道自己差在哪，学习补足就可以啦。从社区做的事情上可以看出，社区从各方面辅助大家就业，单纯的技术提升你未必能找到一份好工作，也许你也不知道这是否是一份好工作，在社区里和大家一起交流你可以感受到行业内不同领域所做的事，哪些是符合自己预期的，少走弯路，人生能有几个三年。公布的网站你看到的时候都挖掘了好几轮，当然没什么低级漏洞了，不要忘记挖掘漏洞的初心，不断在挖掘过程里发现自己的不足才是目的，持之以恒的坚持下去总有一天你可以挖到一个漏洞。]]></description><category></category></item><item><title><![CDATA[WebShell 特征分析]]></title><link>https://blog.csdn.net/sechelper/article/details/130882281</link><guid>https://blog.csdn.net/sechelper/article/details/130882281</guid><author>sechelper</author><pubDate>Fri, 26 May 2023 10:56:46 +0800</pubDate><description><![CDATA[关注公众号领取学习路线和资料。​WebShell是黑客经常使用的一种恶意脚本，其目的是获得服务器的执行操作权限，常见的webshell编写语言为aspjspphp。主要用于网站管理，服务器管理，权限管理等操作。使用方法简单，只需要上传一个代码文件，通过网址访问，便可进行很多日常操作，极大地方便了使用者对网站的服务器的管理。正因如此，也有小部分人将代码修改后当作后门程序使用，以达到控制网站服务器的目的，]]></description><category></category></item><item><title><![CDATA[一个POC的诞生，再见 ，脚本小子]]></title><link>https://blog.csdn.net/sechelper/article/details/130568914</link><guid>https://blog.csdn.net/sechelper/article/details/130568914</guid><author>sechelper</author><pubDate>Mon, 08 May 2023 22:32:03 +0800</pubDate><description><![CDATA[hello，大家好我是你们的坤哥，聊聊安全绕不开的话题POC（漏洞概念验证），只知道拿着工具扫的你，尝试过自己写POC吗？看坤哥极限拉扯你和大手子之间的差距。]]></description><category></category></item><item><title><![CDATA[向日葵RCE复现CNVD-2022-10270/CNVD-2022-03672]]></title><link>https://blog.csdn.net/sechelper/article/details/129113824</link><guid>https://blog.csdn.net/sechelper/article/details/129113824</guid><author>sechelper</author><pubDate>Sun, 19 Feb 2023 19:48:48 +0800</pubDate><description><![CDATA[手工复现过程，相关工具的使用与分享，批量检测利用]]></description><category></category></item><item><title><![CDATA[Burpsuite入门之target模块攻防中利用]]></title><link>https://blog.csdn.net/sechelper/article/details/128989559</link><guid>https://blog.csdn.net/sechelper/article/details/128989559</guid><author>sechelper</author><pubDate>Sat, 11 Feb 2023 21:53:26 +0800</pubDate><description><![CDATA[用来收集目标站点的更多资产；探测一些自动加载的接口，内容等]]></description><category></category></item><item><title><![CDATA[CouchDB 漏洞复现 CVE-2017-12635/12636]]></title><link>https://blog.csdn.net/sechelper/article/details/128989477</link><guid>https://blog.csdn.net/sechelper/article/details/128989477</guid><author>sechelper</author><pubDate>Sat, 11 Feb 2023 21:43:52 +0800</pubDate><description><![CDATA[CouchDB的CVE-2017-12635和12636联合利用，详细漏洞复现，exp下载获取]]></description><category></category></item><item><title><![CDATA[常见SQL注入手法总结与技巧(一)]]></title><link>https://blog.csdn.net/sechelper/article/details/128989343</link><guid>https://blog.csdn.net/sechelper/article/details/128989343</guid><author>sechelper</author><pubDate>Sat, 11 Feb 2023 21:32:56 +0800</pubDate><description><![CDATA[SQL注入产生本质，盲注基本原理的详解与技巧，union联合注入演示]]></description><category></category></item><item><title><![CDATA[【作业】ColddBox 靶场 作者：苏同学]]></title><link>https://blog.csdn.net/sechelper/article/details/128989212</link><guid>https://blog.csdn.net/sechelper/article/details/128989212</guid><author>sechelper</author><pubDate>Sat, 11 Feb 2023 21:20:13 +0800</pubDate><description><![CDATA[Wordpress 漏洞利用与后渗透。]]></description><category></category></item><item><title><![CDATA[关于External service interaction (DNS)漏洞的思考]]></title><link>https://blog.csdn.net/sechelper/article/details/128650293</link><guid>https://blog.csdn.net/sechelper/article/details/128650293</guid><author>sechelper</author><pubDate>Sat, 11 Feb 2023 19:23:58 +0800</pubDate><description><![CDATA[关于External service interaction (DNS)漏洞的思考]]></description><category></category></item><item><title><![CDATA[【安全术语】网络钓鱼攻击]]></title><link>https://blog.csdn.net/sechelper/article/details/128650203</link><guid>https://blog.csdn.net/sechelper/article/details/128650203</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 20:10:38 +0800</pubDate><description><![CDATA[网络钓鱼攻击是假冒的通信，看似来源可靠，但可能危及所有类型的数据源。攻击可以方便访问您的在线帐户和个人数据，获得修改和破坏连接系统的权限，例如销售点终端和订单处理系统，在某些情况下，在支付赎金之前，还可以劫持整个计算机网络。有时黑客会满足于获取您的个人数据和信用卡信息以获取经济利益。在其他情况下，发送钓鱼电子邮件是为了收集员工登录信息或其他详细信息，以便在针对少数个人或特定公司的恶意攻击中使用。网络钓鱼是一种网络攻击，每个人都应该了解它，以保护自己并确保整个组织的电子邮件安全。]]></description><category></category></item><item><title><![CDATA[应急响应-Linux篇]]></title><link>https://blog.csdn.net/sechelper/article/details/128650074</link><guid>https://blog.csdn.net/sechelper/article/details/128650074</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 20:04:41 +0800</pubDate><description><![CDATA[应急响应指遇到重大或突发事件后所采取的措施和行动。应急响应所处置的突发事件不仅仅包括硬件、产品、网络、配置等方面的故障，也包括各类安全事件，如：黑客攻击、木马病毒、勒索病毒、Web攻击等。]]></description><category></category></item><item><title><![CDATA[SQL注入的本质]]></title><link>https://blog.csdn.net/sechelper/article/details/128648534</link><guid>https://blog.csdn.net/sechelper/article/details/128648534</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 19:37:37 +0800</pubDate><description><![CDATA[常见的sql注入类型及方法，sqlmap的使用，BP和sqlmap的联动，防范sql注入的方法]]></description><category></category></item><item><title><![CDATA[Arch Linux LAMP环境搭建]]></title><link>https://blog.csdn.net/sechelper/article/details/128647671</link><guid>https://blog.csdn.net/sechelper/article/details/128647671</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 17:23:24 +0800</pubDate><description><![CDATA[LAMP环境搭建详细步骤教程]]></description><category></category></item><item><title><![CDATA[BurpSuite2021 -- 仪表盘(Dashboard)]]></title><link>https://blog.csdn.net/sechelper/article/details/128646939</link><guid>https://blog.csdn.net/sechelper/article/details/128646939</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 16:37:01 +0800</pubDate><description><![CDATA[BurpSuite仪表盘的详细使用教程]]></description><category></category></item><item><title><![CDATA[网络安全渗透神器——Burp Suite使用教程]]></title><link>https://blog.csdn.net/sechelper/article/details/128646624</link><guid>https://blog.csdn.net/sechelper/article/details/128646624</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 16:25:36 +0800</pubDate><description><![CDATA[网络安全渗透神器——Burp Suite使用教程，注册，CA证书安装]]></description><category></category></item><item><title><![CDATA[CTF Show web入门 1——20（信息收集）wp和一些感想]]></title><link>https://blog.csdn.net/sechelper/article/details/128645601</link><guid>https://blog.csdn.net/sechelper/article/details/128645601</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 15:39:59 +0800</pubDate><description><![CDATA[CTFshow中web入门信息收集20题wp与总结感悟]]></description><category></category></item><item><title><![CDATA[Struts2 S2-061 远程命令执行漏洞（CVE-2020-17530）漏洞复现]]></title><link>https://blog.csdn.net/sechelper/article/details/128645348</link><guid>https://blog.csdn.net/sechelper/article/details/128645348</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 15:26:07 +0800</pubDate><description><![CDATA[cve漏洞详细复现，漏洞利用，反弹shell，工具分享]]></description><category></category></item><item><title><![CDATA[Weblogic IIOP反序列化漏洞（CVE-2020-2551） 漏洞复现]]></title><link>https://blog.csdn.net/sechelper/article/details/128644979</link><guid>https://blog.csdn.net/sechelper/article/details/128644979</guid><author>sechelper</author><pubDate>Wed, 11 Jan 2023 15:14:47 +0800</pubDate><description><![CDATA[cve漏洞详细复现，漏洞利用，反弹shell，工具分享]]></description><category></category></item><item><title><![CDATA[CVE-2020-1938]]></title><link>https://blog.csdn.net/sechelper/article/details/128224789</link><guid>https://blog.csdn.net/sechelper/article/details/128224789</guid><author>sechelper</author><pubDate>Wed, 07 Dec 2022 18:16:59 +0800</pubDate><description><![CDATA[CVE-2020-1938漏洞复现]]></description><category></category></item><item><title><![CDATA[java安全 反序列化(二)]]></title><link>https://blog.csdn.net/sechelper/article/details/128224297</link><guid>https://blog.csdn.net/sechelper/article/details/128224297</guid><author>sechelper</author><pubDate>Wed, 07 Dec 2022 17:49:28 +0800</pubDate><description><![CDATA[java反射，CC6链源码分析，LazyMap利用连，ysoserial工具]]></description><category></category></item></channel></rss>