<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>X1r0z Blog</title><description>Web Security at X1cT34m and Nu1L Team</description><link>https://exp10it.io/</link><item><title>OpenShell: Ripgrep Command Injection in OpenCode Web UI</title><link>https://exp10it.io/posts/openshell-ripgrep-command-injection-in-opencode-web-ui/</link><guid isPermaLink="true">https://exp10it.io/posts/openshell-ripgrep-command-injection-in-opencode-web-ui/</guid><description>OpenShell: Ripgrep Command Injection in OpenCode Web UI</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Attack Surface Analysis of Cursor</title><link>https://exp10it.io/posts/attack-surface-analysis-of-cursor/</link><guid isPermaLink="true">https://exp10it.io/posts/attack-surface-analysis-of-cursor/</guid><description>Cursor 攻击面分析</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Attack Surface Analysis of Claude Code</title><link>https://exp10it.io/posts/attack-surface-analysis-of-claude-code/</link><guid isPermaLink="true">https://exp10it.io/posts/attack-surface-analysis-of-claude-code/</guid><description>Claude Code 攻击面分析</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Exploring MCP Security Risks</title><link>https://exp10it.io/posts/exploring-mcp-security-risks/</link><guid isPermaLink="true">https://exp10it.io/posts/exploring-mcp-security-risks/</guid><description>MCP 安全风险初探</description><pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Breaking Raft Consensus in Go: N1SAML Writeup for N1CTF 2025</title><link>https://exp10it.io/posts/breaking-raft-consensus-in-go-n1saml-writeup-for-n1ctf-2025/</link><guid isPermaLink="true">https://exp10it.io/posts/breaking-raft-consensus-in-go-n1saml-writeup-for-n1ctf-2025/</guid><description>Breaking Raft Consensus in Go: N1SAML Writeup for N1CTF 2025</description><pubDate>Sun, 02 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Hacking GraalVM Espresso: Abusing Continuation API to Make ROP-Like Attack</title><link>https://exp10it.io/posts/hacking-graalvm-espresso-abusing-continuation-api-to-make-rop-like-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/hacking-graalvm-espresso-abusing-continuation-api-to-make-rop-like-attack/</guid><description>Hacking GraalVM Espresso: Abusing Continuation API to Make ROP-Like Attack</description><pubDate>Sat, 23 Aug 2025 00:00:00 GMT</pubDate></item><item><title>NCTF 2024 Web 出题小记</title><link>https://exp10it.io/posts/nctf-2024-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/nctf-2024-web-writeup/</guid><description>NCTF 2024 Web 出题小记</description><pubDate>Mon, 24 Mar 2025 00:00:00 GMT</pubDate></item><item><title>H2 RCE 在 JRE 17 环境下的利用</title><link>https://exp10it.io/posts/h2-rce-in-jre-17/</link><guid isPermaLink="true">https://exp10it.io/posts/h2-rce-in-jre-17/</guid><description>H2 RCE 在 JRE 17 环境下的利用</description><pubDate>Mon, 24 Mar 2025 00:00:00 GMT</pubDate></item><item><title>击碎共识: 从 Raft Leader 劫持到分布式系统接管</title><link>https://exp10it.io/posts/breaking-consensus-from-raft-leader-hijacking-to-distributed-system-takeover/</link><guid isPermaLink="true">https://exp10it.io/posts/breaking-consensus-from-raft-leader-hijacking-to-distributed-system-takeover/</guid><description>击碎共识: 从 Raft Leader 劫持到分布式系统接管</description><pubDate>Mon, 03 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HITCON Training Pwn Writeup</title><link>https://exp10it.io/posts/hitcon-training-pwn-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/hitcon-training-pwn-writeup/</guid><description>HITCON Training Pwn Writeup</description><pubDate>Tue, 12 Nov 2024 00:00:00 GMT</pubDate></item><item><title>0xGame 2024 Pwn Writeup</title><link>https://exp10it.io/posts/0xgame-2024-pwn-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/0xgame-2024-pwn-writeup/</guid><description>0xGame 2024 Pwn Writeup</description><pubDate>Wed, 06 Nov 2024 00:00:00 GMT</pubDate></item><item><title>NTUSTISC Pwn Basic Writeup</title><link>https://exp10it.io/posts/ntustisc-pwn-basic-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ntustisc-pwn-basic-writeup/</guid><description>NTUSTISC Pwn Basic Writeup</description><pubDate>Mon, 28 Oct 2024 00:00:00 GMT</pubDate></item><item><title>BlackHat MEA CTF 2024 Quals Web Writeup</title><link>https://exp10it.io/posts/blackhat-mea-ctf-2024-quals-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/blackhat-mea-ctf-2024-quals-web-writeup/</guid><description>BlackHat MEA CTF 2024 Quals Web Writeup</description><pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate></item><item><title>巅峰极客 2024 初赛 Web Writeup</title><link>https://exp10it.io/posts/dfjk-2024-preliminary-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/dfjk-2024-preliminary-web-writeup/</guid><description>巅峰极客 2024 初赛 Web Writeup</description><pubDate>Thu, 22 Aug 2024 00:00:00 GMT</pubDate></item><item><title>通过 Java Fuzzing 挖掘 Nexus Repository 3 目录穿越漏洞 (CVE-2024-4956)</title><link>https://exp10it.io/posts/java-fuzzing-discover-nexus-repository-3-path-traversal-cve-2024-4956/</link><guid isPermaLink="true">https://exp10it.io/posts/java-fuzzing-discover-nexus-repository-3-path-traversal-cve-2024-4956/</guid><description>通过 Java Fuzzing 挖掘 Nexus Repository 3 目录穿越漏洞 (CVE-2024-4956)</description><pubDate>Mon, 27 May 2024 00:00:00 GMT</pubDate></item><item><title>Ethernaut Writeup</title><link>https://exp10it.io/posts/ethernaut-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ethernaut-writeup/</guid><description>Ethernaut Writeup</description><pubDate>Mon, 22 Apr 2024 00:00:00 GMT</pubDate></item><item><title>SolarWinds Security Event Manager AMF 反序列化 RCE (CVE-2024-0692)</title><link>https://exp10it.io/posts/solarwinds-security-event-manager-amf-deserialization-rce-cve-2024-0692/</link><guid isPermaLink="true">https://exp10it.io/posts/solarwinds-security-event-manager-amf-deserialization-rce-cve-2024-0692/</guid><description>SolarWinds Security Event Manager AMF 反序列化 RCE (CVE-2024-0692)</description><pubDate>Tue, 05 Mar 2024 00:00:00 GMT</pubDate></item><item><title>Hessian UTF-8 Overlong Encoding</title><link>https://exp10it.io/posts/hessian-utf-8-overlong-encoding/</link><guid isPermaLink="true">https://exp10it.io/posts/hessian-utf-8-overlong-encoding/</guid><description>Hessian UTF-8 Overlong Encoding</description><pubDate>Wed, 28 Feb 2024 00:00:00 GMT</pubDate></item><item><title>dotnet ObjRef Gadget 分析</title><link>https://exp10it.io/posts/dotnet-objref-rogue-remoting-server-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/dotnet-objref-rogue-remoting-server-analysis/</guid><description>dotnet ObjRef Gadget 分析</description><pubDate>Wed, 14 Feb 2024 00:00:00 GMT</pubDate></item><item><title>dotnet New Deserialization Gadgets</title><link>https://exp10it.io/posts/dotnet-new-deserialization-gadgets/</link><guid isPermaLink="true">https://exp10it.io/posts/dotnet-new-deserialization-gadgets/</guid><description>dotnet New Deserialization Gadgets</description><pubDate>Mon, 12 Feb 2024 00:00:00 GMT</pubDate></item><item><title>dotnet Insecure Serialization</title><link>https://exp10it.io/posts/dotnet-insecure-serialization/</link><guid isPermaLink="true">https://exp10it.io/posts/dotnet-insecure-serialization/</guid><description>dotnet Insecure Serialization</description><pubDate>Sun, 11 Feb 2024 00:00:00 GMT</pubDate></item><item><title>dotnet SerializationBinder 绕过</title><link>https://exp10it.io/posts/dotnet-serialization-binder-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/dotnet-serialization-binder-bypass/</guid><description>dotnet SerializationBinder 绕过</description><pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate></item><item><title>ASP.NET ViewState 反序列化</title><link>https://exp10it.io/posts/asp-net-viewstate-deserialization/</link><guid isPermaLink="true">https://exp10it.io/posts/asp-net-viewstate-deserialization/</guid><description>ASP.NET ViewState 反序列化</description><pubDate>Wed, 07 Feb 2024 00:00:00 GMT</pubDate></item><item><title>ASP.NET 内存马</title><link>https://exp10it.io/posts/asp-net-memory-shell/</link><guid isPermaLink="true">https://exp10it.io/posts/asp-net-memory-shell/</guid><description>ASP.NET 内存马 (Filter/Route/HttpListener/VirtualPath)</description><pubDate>Tue, 06 Feb 2024 00:00:00 GMT</pubDate></item><item><title>N1CTF Junior 2024 Web Official Writeup</title><link>https://exp10it.io/posts/n1ctf-junior-2024-web-official-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/n1ctf-junior-2024-web-official-writeup/</guid><description>N1CTF Junior 2024 Web Official Writeup</description><pubDate>Mon, 05 Feb 2024 00:00:00 GMT</pubDate></item><item><title>RWCTF 2024 体验赛 Writeup</title><link>https://exp10it.io/posts/rwctf-2024-junior-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/rwctf-2024-junior-writeup/</guid><description>RWCTF 2024 体验赛 Writeup</description><pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate></item><item><title>NCTF 2023 Web Official Writeup</title><link>https://exp10it.io/posts/nctf-2023-web-official-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/nctf-2023-web-official-writeup/</guid><description>NCTF 2023 Web Official Writeup</description><pubDate>Mon, 25 Dec 2023 00:00:00 GMT</pubDate></item><item><title>TCTF 2022 Final Web Writeup</title><link>https://exp10it.io/posts/tctf-2022-final-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/tctf-2022-final-web-writeup/</guid><description>TCTF 2022 Final (RisingStar) Web Writeup</description><pubDate>Mon, 11 Dec 2023 00:00:00 GMT</pubDate></item><item><title>2023 京麒 CTF ez_oracle Writeup</title><link>https://exp10it.io/posts/2023-jqctf-ez-oracle-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-jqctf-ez-oracle-writeup/</guid><description>2023 京麒 CTF ez_oracle Writeup</description><pubDate>Sun, 03 Dec 2023 00:00:00 GMT</pubDate></item><item><title>Black Hat MEA CTF 2023 Web Writeup</title><link>https://exp10it.io/posts/blackhat-mea-ctf-2023-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/blackhat-mea-ctf-2023-web-writeup/</guid><description>Black Hat MEA CTF 2023 Web Writeup</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate></item><item><title>2023 鹏城杯 Web Writeup</title><link>https://exp10it.io/posts/2023-pengcheng-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-pengcheng-cup-web-writeup/</guid><description>2023 鹏城杯 Web Writeup</description><pubDate>Sat, 04 Nov 2023 00:00:00 GMT</pubDate></item><item><title>0xGame 2023 Web Official Writeup</title><link>https://exp10it.io/posts/0xgame-2023-web-official-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/0xgame-2023-web-official-writeup/</guid><description>0xGame 2023 Web Official Writeup</description><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate></item><item><title>WordPress Core RCE Gadget 分析</title><link>https://exp10it.io/posts/wordpress-core-rce-gadget-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/wordpress-core-rce-gadget-analysis/</guid><description>WordPress Core RCE Gadget 分析</description><pubDate>Thu, 26 Oct 2023 00:00:00 GMT</pubDate></item><item><title>Apache ActiveMQ (版本 &lt; 5.18.3) RCE 分析</title><link>https://exp10it.io/posts/apache-activemq-version-5-18-3-rce-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/apache-activemq-version-5-18-3-rce-analysis/</guid><description>Apache ActiveMQ (版本 &lt; 5.18.3) RCE 分析</description><pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate></item><item><title>Spring AMQP 反序列化漏洞 (CVE-2023-34050) 分析</title><link>https://exp10it.io/posts/spring-amqp-deserialization-cve-2023-34050-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/spring-amqp-deserialization-cve-2023-34050-analysis/</guid><description>Spring AMQP 反序列化漏洞 (CVE-2023-34050) 分析</description><pubDate>Fri, 20 Oct 2023 00:00:00 GMT</pubDate></item><item><title>2023 中华武术杯 Web Writeup</title><link>https://exp10it.io/posts/2023-zhonghuawushu-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-zhonghuawushu-cup-web-writeup/</guid><description>2023 中华武术杯 Web Writeup (AWDP + 靶场)</description><pubDate>Tue, 17 Oct 2023 00:00:00 GMT</pubDate></item><item><title>Atlassian Confluence CVE-2023-22515 分析</title><link>https://exp10it.io/posts/atlassian-confluence-cve-2023-22515-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/atlassian-confluence-cve-2023-22515-analysis/</guid><description>Atlassian Confluence CVE-2023-22515 分析以及一种 RCE? 方式</description><pubDate>Thu, 12 Oct 2023 00:00:00 GMT</pubDate></item><item><title>JumpServer 伪随机数密码重置漏洞 (CVE-2023-42820) 分析</title><link>https://exp10it.io/posts/jumpserver-pesudo-random-number-password-reset-cve-2023-42820-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/jumpserver-pesudo-random-number-password-reset-cve-2023-42820-analysis/</guid><description>JumpServer 伪随机数密码重置漏洞 (CVE-2023-42820) 分析以及自动化利用</description><pubDate>Wed, 04 Oct 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 2022 网鼎杯半决赛复盘 Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-2022-wangding-cup-semi-final-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-2022-wangding-cup-semi-final-writeup/</guid><description>春秋云镜 2022 网鼎杯半决赛复盘 Writeup</description><pubDate>Sun, 20 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Flarum Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-flarum-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-flarum-writeup/</guid><description>春秋云镜 Flarum Writeup</description><pubDate>Sat, 19 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Privilege Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-privilege-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-privilege-writeup/</guid><description>春秋云镜 Privilege Writeup</description><pubDate>Fri, 18 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Delivery Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-delivery-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-delivery-writeup/</guid><description>春秋云镜 Delivery Writeup</description><pubDate>Thu, 17 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Spoofing Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-spoofing-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-spoofing-writeup/</guid><description>春秋云镜 Spoofing Writeup</description><pubDate>Wed, 16 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Delegation Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-delegation-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-delegation-writeup/</guid><description>春秋云镜 Delegation Writeup</description><pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Exchange Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-exchange-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-exchange-writeup/</guid><description>春秋云镜 Exchange Writeup</description><pubDate>Wed, 09 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Certify Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-certify-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-certify-writeup/</guid><description>春秋云镜 Certify Writeup</description><pubDate>Sat, 05 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Brute4Road Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-brute4road-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-brute4road-writeup/</guid><description>春秋云镜 Brute4Road Writeup</description><pubDate>Fri, 04 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Time Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-time-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-time-writeup/</guid><description>春秋云镜 Time Writeup</description><pubDate>Wed, 02 Aug 2023 00:00:00 GMT</pubDate></item><item><title>基于资源的约束委派 (RBCD) 利用总结</title><link>https://exp10it.io/posts/resource-based-constrained-delegation-attack-summary/</link><guid isPermaLink="true">https://exp10it.io/posts/resource-based-constrained-delegation-attack-summary/</guid><description>RBCD 常见利用方法以及在 Relay 攻击中的应用</description><pubDate>Tue, 01 Aug 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Tsclient Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-tsclient-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-tsclient-writeup/</guid><description>春秋云镜 Tsclient Writeup</description><pubDate>Sun, 30 Jul 2023 00:00:00 GMT</pubDate></item><item><title>春秋云镜 Initial Writeup</title><link>https://exp10it.io/posts/chunqiuyunjing-initial-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chunqiuyunjing-initial-writeup/</guid><description>春秋云镜 Initial Writeup</description><pubDate>Fri, 28 Jul 2023 00:00:00 GMT</pubDate></item><item><title>2023 CISCN 总决赛 AWD &amp; 渗透 Writeup</title><link>https://exp10it.io/posts/2023-ciscn-final-awd-and-pentest-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-ciscn-final-awd-and-pentest-writeup/</guid><description>2023 CISCN 总决赛 AWD &amp; 渗透 Writeup</description><pubDate>Thu, 27 Jul 2023 00:00:00 GMT</pubDate></item><item><title>2023 CISCN 华东北分区赛 Web Writeup</title><link>https://exp10it.io/posts/2023-ciscn-semi-final-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-ciscn-semi-final-web-writeup/</guid><description>2023 CISCN 华东北分区赛 Web Writeup</description><pubDate>Mon, 26 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Nacos JRaft Hessian 反序列化 RCE 分析</title><link>https://exp10it.io/posts/nacos-jraft-hessian-deserialization-rce-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/nacos-jraft-hessian-deserialization-rce-analysis/</guid><description>Nacos JRaft Hessian 反序列化 RCE 分析</description><pubDate>Tue, 13 Jun 2023 00:00:00 GMT</pubDate></item><item><title>2023 CISCN 初赛 Web Writeup</title><link>https://exp10it.io/posts/2023-ciscn-preliminary-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-ciscn-preliminary-web-writeup/</guid><description>跟 defcon 时间冲了, 抽空随便打的 (</description><pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate></item><item><title>MinIO CVE-2023-28432 &amp; 自更新 RCE 分析</title><link>https://exp10it.io/posts/minio-cve-2023-28432-self-update-rce-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/minio-cve-2023-28432-self-update-rce-analysis/</guid><description>正好最近入坑了 Golang, 做个简单的审计练练手</description><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate></item><item><title>Apache Kafka Clients JNDI (CVE-2023-25194) &amp; Druid RCE 分析</title><link>https://exp10it.io/posts/apache-kafka-client-jndi-cve-2023-25194-druid-rce-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/apache-kafka-client-jndi-cve-2023-25194-druid-rce-analysis/</guid><description>Apache Kafka Clients JNDI (CVE-2023-25194) 分析以及在 Apache Druid 环境下的利用</description><pubDate>Wed, 10 May 2023 00:00:00 GMT</pubDate></item><item><title>Hessian CVE-2021-43297 &amp; D3CTF 2023 ezjava</title><link>https://exp10it.io/posts/hessian-cve-2021-43297-d3ctf-2023-ezjava/</link><guid isPermaLink="true">https://exp10it.io/posts/hessian-cve-2021-43297-d3ctf-2023-ezjava/</guid><description>Hessian CVE-2021-43297 分析以及 D3CTF 2023 ezjava 复现</description><pubDate>Sun, 07 May 2023 00:00:00 GMT</pubDate></item><item><title>2023 D3CTF Web 部分 Writeup</title><link>https://exp10it.io/posts/2023-d3ctf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-d3ctf-web-writeup/</guid><description>2023 D3CTF</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate></item><item><title>2023 红明谷杯 Web Writeup</title><link>https://exp10it.io/posts/2023-hongminggu-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-hongminggu-cup-web-writeup/</guid><description>2023 红明谷杯</description><pubDate>Sun, 30 Apr 2023 00:00:00 GMT</pubDate></item><item><title>TryHackMe K8s 靶机 Writeup</title><link>https://exp10it.io/posts/tryhackme-k8s-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/tryhackme-k8s-writeup/</guid><description>TryHackMe K8s 靶机 Writeup</description><pubDate>Thu, 13 Apr 2023 00:00:00 GMT</pubDate></item><item><title>Apache Dubbo CVE-2023-23638 分析</title><link>https://exp10it.io/posts/apache-dubbo-cve-2023-23638-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/apache-dubbo-cve-2023-23638-analysis/</guid><description>Apache Dubbo CVE-2023-23638 的另外一种利用方式</description><pubDate>Sun, 12 Mar 2023 00:00:00 GMT</pubDate></item><item><title>pbctf 2023 XSPS Writeup</title><link>https://exp10it.io/posts/pbctf-2023-xsps-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/pbctf-2023-xsps-writeup/</guid><description>人生第一道 xsleaks, 感觉挺有意思的. 不太会写 js 所以痛失一血 ()</description><pubDate>Mon, 20 Feb 2023 00:00:00 GMT</pubDate></item><item><title>VNCTF 2023 Web 部分 Writeup</title><link>https://exp10it.io/posts/vnctf-2023-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/vnctf-2023-web-writeup/</guid><description>VNCTF 2023</description><pubDate>Sun, 19 Feb 2023 00:00:00 GMT</pubDate></item><item><title>对 Thymeleaf SSTI 的一点思考</title><link>https://exp10it.io/posts/thinking-about-thymeleaf-ssti/</link><guid isPermaLink="true">https://exp10it.io/posts/thinking-about-thymeleaf-ssti/</guid><description>尝试写点网上没有的东西</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate></item><item><title>DiceCTF 2023 Web 赛后复现</title><link>https://exp10it.io/posts/dicectf-2023-web-reproduce/</link><guid isPermaLink="true">https://exp10it.io/posts/dicectf-2023-web-reproduce/</guid><description>第一次跟 Nu1L 打国际赛, 然后自己被题目虐爆了 (不得不说 Nu1L 的师傅们实在是太强了</description><pubDate>Wed, 08 Feb 2023 00:00:00 GMT</pubDate></item><item><title>HGAME 2023 Web Writeup</title><link>https://exp10it.io/posts/hgame-2023-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/hgame-2023-web-writeup/</guid><description>HGAME 2023</description><pubDate>Tue, 07 Feb 2023 00:00:00 GMT</pubDate></item><item><title>2023 西湖论剑 Web 部分 Writeup</title><link>https://exp10it.io/posts/2023-xihulunjian-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-xihulunjian-web-writeup/</guid><description>web 差一半, 等官方 wp 吧... 团队整体第二名, 学长们 tql</description><pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate></item><item><title>2023 N1CTF Junior Web 部分 Writeup</title><link>https://exp10it.io/posts/2023-n1ctf-junior-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2023-n1ctf-junior-web-writeup/</guid><description>2023 N1CTF Junior Web 部分 Writeup</description><pubDate>Wed, 01 Feb 2023 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 11</title><link>https://exp10it.io/posts/buuctf-web-writeup-11/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-11/</guid><description>BUUCTF 刷题记录...</description><pubDate>Sat, 28 Jan 2023 00:00:00 GMT</pubDate></item><item><title>Apache Commons Text RCE 漏洞分析</title><link>https://exp10it.io/posts/apache-commons-text-rce-analysis/</link><guid isPermaLink="true">https://exp10it.io/posts/apache-commons-text-rce-analysis/</guid><description>Apache Commons Text RCE 漏洞分析</description><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate></item><item><title>RWCTF 2023 体验赛 Web Writeup</title><link>https://exp10it.io/posts/rwctf-2023-junior-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/rwctf-2023-junior-web-writeup/</guid><description>Real World CTF 正赛打不动了过来打体验赛 (</description><pubDate>Sun, 08 Jan 2023 00:00:00 GMT</pubDate></item><item><title>Java Agent 内存马</title><link>https://exp10it.io/posts/java-agent-memory-shell/</link><guid isPermaLink="true">https://exp10it.io/posts/java-agent-memory-shell/</guid><description>Java Agent 内存马学习</description><pubDate>Wed, 04 Jan 2023 00:00:00 GMT</pubDate></item><item><title>JNDI 注入浅析</title><link>https://exp10it.io/posts/jndi-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/jndi-injection/</guid><description>JNDI 注入学习笔记</description><pubDate>Sun, 25 Dec 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 10</title><link>https://exp10it.io/posts/buuctf-web-writeup-10/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-10/</guid><description>BUUCTF 刷题记录...</description><pubDate>Sat, 24 Dec 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 9</title><link>https://exp10it.io/posts/buuctf-web-writeup-9/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-9/</guid><description>BUUCTF 刷题记录...</description><pubDate>Wed, 21 Dec 2022 00:00:00 GMT</pubDate></item><item><title>Shiro-550 反序列化分析</title><link>https://exp10it.io/posts/shiro-550-deserialization/</link><guid isPermaLink="true">https://exp10it.io/posts/shiro-550-deserialization/</guid><description>Shiro-550 反序列化原理分析, 以及无数组 CommonsCollections 链和 CommonsBeanutils 利用链的构造</description><pubDate>Sun, 18 Dec 2022 00:00:00 GMT</pubDate></item><item><title>JDK7u21 反序列化分析</title><link>https://exp10it.io/posts/jdk-7u21-deserialization/</link><guid isPermaLink="true">https://exp10it.io/posts/jdk-7u21-deserialization/</guid><description>以及一种可能是新的构造方式?</description><pubDate>Sat, 17 Dec 2022 00:00:00 GMT</pubDate></item><item><title>2022 安洵杯决赛线上 AWD 小记</title><link>https://exp10it.io/posts/2022-anxun-cup-final-online-awd-note/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-anxun-cup-final-online-awd-note/</guid><description>第一次打 awd, 然后被按在地上摩擦... 最后跟着队友混了个二等奖</description><pubDate>Thu, 15 Dec 2022 00:00:00 GMT</pubDate></item><item><title>RCTF 2022 Web 赛后复现</title><link>https://exp10it.io/posts/rctf-2022-web-reproduce/</link><guid isPermaLink="true">https://exp10it.io/posts/rctf-2022-web-reproduce/</guid><description>最近疫情严重, rctf 看了两题就收拾行李回家去了... 赛后趁着环境没关赶紧复现一下</description><pubDate>Tue, 13 Dec 2022 00:00:00 GMT</pubDate></item><item><title>NCTF 2022 Web Writeup</title><link>https://exp10it.io/posts/nctf-2022-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/nctf-2022-web-writeup/</guid><description>被队友们带飞了, 最后总榜第十 校内第二</description><pubDate>Mon, 05 Dec 2022 00:00:00 GMT</pubDate></item><item><title>2022 安洵杯 Web Writeup</title><link>https://exp10it.io/posts/2022-anxun-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-anxun-cup-web-writeup/</guid><description>被学长们带飞了</description><pubDate>Mon, 28 Nov 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 8</title><link>https://exp10it.io/posts/buuctf-web-writeup-8/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-8/</guid><description>BUUCTF 刷题记录...</description><pubDate>Thu, 24 Nov 2022 00:00:00 GMT</pubDate></item><item><title>CommonsCollections 反序列化分析</title><link>https://exp10it.io/posts/commons-collections-deserialization/</link><guid isPermaLink="true">https://exp10it.io/posts/commons-collections-deserialization/</guid><description>CommonsCollections 反序列化分析, 鸽了好久了</description><pubDate>Wed, 23 Nov 2022 00:00:00 GMT</pubDate></item><item><title>Java RMI 安全</title><link>https://exp10it.io/posts/java-rmi-security/</link><guid isPermaLink="true">https://exp10it.io/posts/java-rmi-security/</guid><description>Java RMI 安全</description><pubDate>Sun, 20 Nov 2022 00:00:00 GMT</pubDate></item><item><title>NCTF 2021 Web 部分复现</title><link>https://exp10it.io/posts/nctf-2021-web-reproduce/</link><guid isPermaLink="true">https://exp10it.io/posts/nctf-2021-web-reproduce/</guid><description>今年 nctf 快要开始了, 做做去年的题. 看了 wp 之后发现自己对前端安全还是不太熟, 太菜了呜呜</description><pubDate>Sat, 19 Nov 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 7</title><link>https://exp10it.io/posts/buuctf-web-writeup-7/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-7/</guid><description>BUUCTF 刷题记录...</description><pubDate>Fri, 11 Nov 2022 00:00:00 GMT</pubDate></item><item><title>ROME 反序列化分析</title><link>https://exp10it.io/posts/rome-deserialization/</link><guid isPermaLink="true">https://exp10it.io/posts/rome-deserialization/</guid><description>之前打 ctf 遇到的, 顺带写一下吧</description><pubDate>Tue, 08 Nov 2022 00:00:00 GMT</pubDate></item><item><title>Java ClassLoader</title><link>https://exp10it.io/posts/java-classloader/</link><guid isPermaLink="true">https://exp10it.io/posts/java-classloader/</guid><description>利用 ClassLoader 动态加载 Java 字节码</description><pubDate>Mon, 07 Nov 2022 00:00:00 GMT</pubDate></item><item><title>Tomcat Listener 型内存马分析</title><link>https://exp10it.io/posts/tomcat-listener-memory-shell/</link><guid isPermaLink="true">https://exp10it.io/posts/tomcat-listener-memory-shell/</guid><description>Tomcat Listener 型内存马</description><pubDate>Sun, 06 Nov 2022 00:00:00 GMT</pubDate></item><item><title>Tomcat Filter 型内存马分析</title><link>https://exp10it.io/posts/tomcat-filter-memory-shell/</link><guid isPermaLink="true">https://exp10it.io/posts/tomcat-filter-memory-shell/</guid><description>Tomcat Filter 型内存马</description><pubDate>Sat, 05 Nov 2022 00:00:00 GMT</pubDate></item><item><title>Java Servlet 基础</title><link>https://exp10it.io/posts/java-servlet-basic/</link><guid isPermaLink="true">https://exp10it.io/posts/java-servlet-basic/</guid><description>Java Servlet 基础</description><pubDate>Thu, 03 Nov 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 6</title><link>https://exp10it.io/posts/buuctf-web-writeup-6/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-6/</guid><description>BUUCTF 刷题记录...</description><pubDate>Wed, 02 Nov 2022 00:00:00 GMT</pubDate></item><item><title>2022 祥云杯 Web Writeup</title><link>https://exp10it.io/posts/2022-xiangyun-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-xiangyun-cup-web-writeup/</guid><description>看了两天的 Token is invalid ...</description><pubDate>Mon, 31 Oct 2022 00:00:00 GMT</pubDate></item><item><title>0xGame 2022 Writeup</title><link>https://exp10it.io/posts/0xgame-2022-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/0xgame-2022-writeup/</guid><description>0xGame 2022 Writeup</description><pubDate>Sun, 30 Oct 2022 00:00:00 GMT</pubDate></item><item><title>2022 HNCTF Web Writeup</title><link>https://exp10it.io/posts/2022-hnctf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-hnctf-web-writeup/</guid><description>题目还行</description><pubDate>Sat, 29 Oct 2022 01:20:40 GMT</pubDate></item><item><title>MoeCTF 2022 Writeup</title><link>https://exp10it.io/posts/moectf-2022-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/moectf-2022-writeup/</guid><description>web 的支付系统挺有意思的. 其它方向的题之前也做了点, 后面就懒得写了...</description><pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate></item><item><title>2022 SWPU NSS 新生赛 Web Writeup</title><link>https://exp10it.io/posts/2022-swpu-nss-junior-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-swpu-nss-junior-web-writeup/</guid><description>简单题</description><pubDate>Tue, 25 Oct 2022 01:20:52 GMT</pubDate></item><item><title>DASCTF 2022 十月赛 Web Writeup</title><link>https://exp10it.io/posts/dasctf-2022-october-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/dasctf-2022-october-web-writeup/</guid><description>被师傅们带飞了, 混了个第三名. 文章最后补充了一些预期解和官方 wp</description><pubDate>Mon, 24 Oct 2022 00:00:00 GMT</pubDate></item><item><title>2022 NewStarCTF Web Writeup</title><link>https://exp10it.io/posts/2022-newstar-ctf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-newstar-ctf-web-writeup/</guid><description>题目挺简单的, 但是也学到了一些比较细节的技巧</description><pubDate>Sun, 23 Oct 2022 01:20:17 GMT</pubDate></item><item><title>2022 ByteCTF Web 部分 Writeup</title><link>https://exp10it.io/posts/2022-bytectf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-bytectf-web-writeup/</guid><description>军训没啥时间, 只能赛后自己试着做了一下... 感觉挺难的, 就做出来两道题</description><pubDate>Thu, 29 Sep 2022 00:00:00 GMT</pubDate></item><item><title>2022 5space Web 部分 Writeup</title><link>https://exp10it.io/posts/2022-5space-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-5space-web-writeup/</guid><description>5_web_Eeeeasy_SQL 没做出来...</description><pubDate>Tue, 20 Sep 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 5</title><link>https://exp10it.io/posts/buuctf-web-writeup-5/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-5/</guid><description>BUUCTF 刷题记录...</description><pubDate>Sun, 18 Sep 2022 23:33:08 GMT</pubDate></item><item><title>2022 MT CTF Web 部分 Writeup</title><link>https://exp10it.io/posts/2022-mt-ctf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-mt-ctf-web-writeup/</guid><description>超常发挥了属于是, Web 只有 easyjava 没做出来</description><pubDate>Sun, 18 Sep 2022 00:22:22 GMT</pubDate></item><item><title>BUUCTF Web Writeup 4</title><link>https://exp10it.io/posts/buuctf-web-writeup-4/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-4/</guid><description>BUUCTF 刷题记录...</description><pubDate>Wed, 31 Aug 2022 00:00:00 GMT</pubDate></item><item><title>MySQL 无列名注入的几种方式</title><link>https://exp10it.io/posts/mysql-no-column-name-isql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/mysql-no-column-name-isql-injection/</guid><description>总结一下无列名注入的几种方式</description><pubDate>Mon, 29 Aug 2022 00:00:00 GMT</pubDate></item><item><title>XXE 总结笔记</title><link>https://exp10it.io/posts/xxe-note/</link><guid isPermaLink="true">https://exp10it.io/posts/xxe-note/</guid><description>记录一下常用 xxe payload. 想到啥写啥, 只是一个备忘录</description><pubDate>Sat, 27 Aug 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 3</title><link>https://exp10it.io/posts/buuctf-web-writeup-3/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-3/</guid><description>BUUCTF 刷题记录...</description><pubDate>Sat, 27 Aug 2022 00:00:00 GMT</pubDate></item><item><title>2022 网鼎杯青龙组 Web 部分 Writeup</title><link>https://exp10it.io/posts/2022-wangding-cup-qinglong-group-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-wangding-cup-qinglong-group-web-writeup/</guid><description>web 三道题两道都是 java 呜呜呜</description><pubDate>Fri, 26 Aug 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 2</title><link>https://exp10it.io/posts/buuctf-web-writeup-2/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-2/</guid><description>BUUCTF 刷题记录...</description><pubDate>Wed, 24 Aug 2022 00:00:00 GMT</pubDate></item><item><title>Python SSTI 总结笔记</title><link>https://exp10it.io/posts/python-ssti-note/</link><guid isPermaLink="true">https://exp10it.io/posts/python-ssti-note/</guid><description>Python SSTI 的总结笔记, 不定期更新</description><pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate></item><item><title>BUUCTF Web Writeup 1</title><link>https://exp10it.io/posts/buuctf-web-writeup-1/</link><guid isPermaLink="true">https://exp10it.io/posts/buuctf-web-writeup-1/</guid><description>BUUCTF 刷题记录...</description><pubDate>Sun, 21 Aug 2022 00:00:00 GMT</pubDate></item><item><title>Phar 签名的修复与绕过</title><link>https://exp10it.io/posts/phar-signature-fix-and-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/phar-signature-fix-and-bypass/</guid><description>Phar 签名的修复与绕过</description><pubDate>Sat, 20 Aug 2022 00:00:00 GMT</pubDate></item><item><title>PHP 特性总结笔记</title><link>https://exp10it.io/posts/php-features-note/</link><guid isPermaLink="true">https://exp10it.io/posts/php-features-note/</guid><description>知不知道 PHP 语言的含金量啊?</description><pubDate>Tue, 16 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[反序列化] Writeup</title><link>https://exp10it.io/posts/ctfshow-web-deserialization-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-deserialization-writeup/</guid><description>PHP 和 Python 的反序列化</description><pubDate>Tue, 16 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[PHP特性] web138-150 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-php-138-150-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-php-138-150-writeup/</guid><description>PHP 特性最后几题, 过几天写个总结. 这次主要是各种函数的利用, 位运算绕过正则, 条件竞争等等</description><pubDate>Sat, 13 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[PHP特性] web111-137 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-php-111-137-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-php-111-137-writeup/</guid><description>变量覆盖, 无回显命令执行, 相关函数的绕过...</description><pubDate>Fri, 12 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[PHP特性] web89-110 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-php-89-110-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-php-89-110-writeup/</guid><description>PHP 的相关特性, 例如弱类型, 变量覆盖</description><pubDate>Wed, 10 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[命令执行] web56-77 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-exec-56-77-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-exec-56-77-writeup/</guid><description>剩下来的命令执行</description><pubDate>Tue, 09 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[命令执行] web29-55 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-exec-29-55-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-exec-29-55-writeup/</guid><description>命令执行及绕过技巧</description><pubDate>Mon, 08 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow 七夕杯 Web + OSINT Writeup</title><link>https://exp10it.io/posts/ctfshow-qixi-cup-web-osint-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-qixi-cup-web-osint-writeup/</guid><description>ctfshow 七夕杯 Web + OSINT Writeup</description><pubDate>Fri, 05 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[文件包含] Writeup</title><link>https://exp10it.io/posts/ctfshow-web-file-include-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-file-include-writeup/</guid><description>文件包含. 主要考察各种伪协议, 尤其是 php://filter</description><pubDate>Thu, 04 Aug 2022 00:00:00 GMT</pubDate></item><item><title>NSSCTF Round#4 Web Writeup</title><link>https://exp10it.io/posts/nssctf-round-4-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/nssctf-round-4-web-writeup/</guid><description>NSSCTF Round#4 Web Writeup</description><pubDate>Wed, 03 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[文件上传] Writeup</title><link>https://exp10it.io/posts/ctfshow-web-file-upload-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-file-upload-writeup/</guid><description>常见的上传漏洞</description><pubDate>Wed, 03 Aug 2022 00:00:00 GMT</pubDate></item><item><title>2022 强网杯 Web 部分 Writeup</title><link>https://exp10it.io/posts/2022-qiangwang-cup-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/2022-qiangwang-cup-web-writeup/</guid><description>2022 强网杯 Web 部分 Writeup</description><pubDate>Mon, 01 Aug 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[SQL注入] web198-220 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-sqli-198-220-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-sqli-198-220-writeup/</guid><description>肝不动了... 盲注挺费时间的</description><pubDate>Fri, 29 Jul 2022 00:00:00 GMT</pubDate></item><item><title>SQL 盲注二分法</title><link>https://exp10it.io/posts/blind-sql-injection-dichotomy/</link><guid isPermaLink="true">https://exp10it.io/posts/blind-sql-injection-dichotomy/</guid><description>SQL 盲注二分法</description><pubDate>Thu, 28 Jul 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[SQL注入] web171-197 Writeup</title><link>https://exp10it.io/posts/ctfshow-web-sqli-171-197-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-sqli-171-197-writeup/</guid><description>肝不动了.... 休息会</description><pubDate>Mon, 25 Jul 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[爆破] Writeup</title><link>https://exp10it.io/posts/ctfshow-web-bruteforce-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-bruteforce-writeup/</guid><description>爆破类, 有个 PHP 伪随机数漏洞的知识点</description><pubDate>Fri, 22 Jul 2022 00:00:00 GMT</pubDate></item><item><title>CG CTF Web Writeup</title><link>https://exp10it.io/posts/cg-ctf-web-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/cg-ctf-web-writeup/</guid><description>CG CTF Web Writeup</description><pubDate>Wed, 20 Jul 2022 00:00:00 GMT</pubDate></item><item><title>CG CTF Web 综合2 Writeup</title><link>https://exp10it.io/posts/cgctf-web-comprehensive-2-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/cgctf-web-comprehensive-2-writeup/</guid><description>CG CTF Web 综合2 Writeup</description><pubDate>Wed, 20 Jul 2022 00:00:00 GMT</pubDate></item><item><title>ctfshow Web入门[信息搜集] Writeup</title><link>https://exp10it.io/posts/ctfshow-web-info-gather-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/ctfshow-web-info-gather-writeup/</guid><description>信息搜集类别, 题目挺简单的, 但是延申的方向很多</description><pubDate>Wed, 20 Jul 2022 00:00:00 GMT</pubDate></item><item><title>Cobalt Strike Malleable C2 配置</title><link>https://exp10it.io/posts/cobalt-strike-malleable-c2-configuration/</link><guid isPermaLink="true">https://exp10it.io/posts/cobalt-strike-malleable-c2-configuration/</guid><description>Cobalt Strike Malleable C2 配置</description><pubDate>Tue, 13 Aug 2019 00:00:00 GMT</pubDate></item><item><title>VBS 无文件执行 ShellCode</title><link>https://exp10it.io/posts/vbs-fileless-shellcode-exec/</link><guid isPermaLink="true">https://exp10it.io/posts/vbs-fileless-shellcode-exec/</guid><description>VBS 无文件执行 ShellCode</description><pubDate>Mon, 12 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Cobalt Strike 几种不常见的上线方式</title><link>https://exp10it.io/posts/cobalt-strike-uncommon-beacons/</link><guid isPermaLink="true">https://exp10it.io/posts/cobalt-strike-uncommon-beacons/</guid><description>Cobalt Strike 几种不常见的上线方式</description><pubDate>Sun, 11 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Windows DLL 劫持</title><link>https://exp10it.io/posts/windows-dll-hijacking/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-dll-hijacking/</guid><description>Windows DLL 劫持</description><pubDate>Fri, 09 Aug 2019 00:00:00 GMT</pubDate></item><item><title>绕过 360 对 PowerShell 的拦截</title><link>https://exp10it.io/posts/powershell-bypass-360/</link><guid isPermaLink="true">https://exp10it.io/posts/powershell-bypass-360/</guid><description>绕过 360 对 PowerShell 的拦截</description><pubDate>Tue, 06 Aug 2019 00:00:00 GMT</pubDate></item><item><title>C++ ShellCode 加载器</title><link>https://exp10it.io/posts/cpp-shellcode-loader/</link><guid isPermaLink="true">https://exp10it.io/posts/cpp-shellcode-loader/</guid><description>C++ ShellCode 加载器</description><pubDate>Mon, 05 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Meterpreter 流量免杀</title><link>https://exp10it.io/posts/meterpreter-traffic-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/meterpreter-traffic-bypass/</guid><description>Meterpreter 流量免杀</description><pubDate>Sun, 04 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Office CVE-2017-11882 复现</title><link>https://exp10it.io/posts/office-cve-2017-11882/</link><guid isPermaLink="true">https://exp10it.io/posts/office-cve-2017-11882/</guid><description>Office CVE-2017-11882 复现</description><pubDate>Sat, 03 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Office CVE-2017-8570 复现</title><link>https://exp10it.io/posts/office-cve-2017-8570/</link><guid isPermaLink="true">https://exp10it.io/posts/office-cve-2017-8570/</guid><description>Office CVE-2017-8570 复现</description><pubDate>Thu, 01 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Office CVE-2017-8759 复现</title><link>https://exp10it.io/posts/office-cve-2017-8759/</link><guid isPermaLink="true">https://exp10it.io/posts/office-cve-2017-8759/</guid><description>Office CVE-2017-8759 复现</description><pubDate>Thu, 01 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Office CVE-2017-0199 复现</title><link>https://exp10it.io/posts/office-cve-2017-0199/</link><guid isPermaLink="true">https://exp10it.io/posts/office-cve-2017-0199/</guid><description>Office CVE-2017-0199 复现</description><pubDate>Wed, 31 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Office 宏的利用</title><link>https://exp10it.io/posts/office-macro-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/office-macro-attack/</guid><description>Office 宏的利用</description><pubDate>Tue, 30 Jul 2019 00:00:00 GMT</pubDate></item><item><title>带有 HTTP 请求的 CredentialsPhish</title><link>https://exp10it.io/posts/credentials-phish-with-http-request/</link><guid isPermaLink="true">https://exp10it.io/posts/credentials-phish-with-http-request/</guid><description>带有 HTTP 请求的 CredentialsPhish</description><pubDate>Mon, 29 Jul 2019 00:00:00 GMT</pubDate></item><item><title>MSFvenom 几种不常见的 Payload 格式</title><link>https://exp10it.io/posts/msfvenom-uncommon-payloads/</link><guid isPermaLink="true">https://exp10it.io/posts/msfvenom-uncommon-payloads/</guid><description>MSFvenom 几种不常见的 Payload 格式</description><pubDate>Mon, 29 Jul 2019 00:00:00 GMT</pubDate></item><item><title>后渗透框架 nishang</title><link>https://exp10it.io/posts/nishang-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/nishang-usage/</guid><description>后渗透框架 nishang</description><pubDate>Fri, 26 Jul 2019 00:00:00 GMT</pubDate></item><item><title>PowerView 域内信息收集</title><link>https://exp10it.io/posts/powerview-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/powerview-usage/</guid><description>PowerView 域内信息收集</description><pubDate>Fri, 26 Jul 2019 00:00:00 GMT</pubDate></item><item><title>后渗透框架 PowerSploit</title><link>https://exp10it.io/posts/powersploit-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/powersploit-usage/</guid><description>后渗透框架 PowerSploit</description><pubDate>Thu, 25 Jul 2019 00:00:00 GMT</pubDate></item><item><title>加载 PowerShell 脚本</title><link>https://exp10it.io/posts/load-powershell-script/</link><guid isPermaLink="true">https://exp10it.io/posts/load-powershell-script/</guid><description>加载 PowerShell 脚本</description><pubDate>Wed, 24 Jul 2019 00:00:00 GMT</pubDate></item><item><title>金银票据的利用</title><link>https://exp10it.io/posts/gold-and-silver-tickets-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/gold-and-silver-tickets-attack/</guid><description>金银票据的利用</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Metasploit 常用维权方式</title><link>https://exp10it.io/posts/metasploit-persistence/</link><guid isPermaLink="true">https://exp10it.io/posts/metasploit-persistence/</guid><description>Metasploit 常用维权方式</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate></item><item><title>针对域环境的权限维持</title><link>https://exp10it.io/posts/windows-domain-persistence/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-domain-persistence/</guid><description>针对域环境的权限维持</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 单机权限维持</title><link>https://exp10it.io/posts/windows-local-persistence/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-local-persistence/</guid><description>Windows 单机权限维持</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Meterpreter 内存加载执行</title><link>https://exp10it.io/posts/meterpreter-memory-load-exec/</link><guid isPermaLink="true">https://exp10it.io/posts/meterpreter-memory-load-exec/</guid><description>Meterpreter 内存加载执行</description><pubDate>Sun, 21 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows SPN 攻击</title><link>https://exp10it.io/posts/windows-spn-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-spn-attack/</guid><description>Windows SPN 攻击</description><pubDate>Fri, 19 Jul 2019 00:00:00 GMT</pubDate></item><item><title>SMB 重放攻击</title><link>https://exp10it.io/posts/smb-relay-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/smb-relay-attack/</guid><description>SMB 重放攻击</description><pubDate>Wed, 17 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Mimikatz 哈希与票据传递</title><link>https://exp10it.io/posts/mimikatz-pth-and-ptt/</link><guid isPermaLink="true">https://exp10it.io/posts/mimikatz-pth-and-ptt/</guid><description>Mimikatz 哈希与票据传递</description><pubDate>Tue, 16 Jul 2019 00:00:00 GMT</pubDate></item><item><title>域内 MS14-068 的利用</title><link>https://exp10it.io/posts/ms14-068-attack/</link><guid isPermaLink="true">https://exp10it.io/posts/ms14-068-attack/</guid><description>域内 MS14-068 的利用</description><pubDate>Mon, 15 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 常用远程执行命令的手段</title><link>https://exp10it.io/posts/windows-remote-exec-methods/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-remote-exec-methods/</guid><description>Windows 常用远程执行命令的手段</description><pubDate>Mon, 15 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 绕过 UAC 策略</title><link>https://exp10it.io/posts/windows-bypass-uac-policy/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-bypass-uac-policy/</guid><description>Windows 绕过 UAC 策略</description><pubDate>Fri, 12 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 绕过 AppLocker 限制</title><link>https://exp10it.io/posts/windows-applocker-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-applocker-bypass/</guid><description>Windows 绕过 AppLocker 限制</description><pubDate>Fri, 12 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 域内信息收集</title><link>https://exp10it.io/posts/windows-domain-info-gather/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-domain-info-gather/</guid><description>Windows 域内信息收集</description><pubDate>Wed, 10 Jul 2019 00:00:00 GMT</pubDate></item><item><title>导出 Chrome 中的凭据与信息</title><link>https://exp10it.io/posts/chrome-credentials-dump/</link><guid isPermaLink="true">https://exp10it.io/posts/chrome-credentials-dump/</guid><description>导出 Chrome 中的凭据与信息</description><pubDate>Tue, 09 Jul 2019 00:00:00 GMT</pubDate></item><item><title>导出 RDP 连接凭据</title><link>https://exp10it.io/posts/rdp-credentials-dump/</link><guid isPermaLink="true">https://exp10it.io/posts/rdp-credentials-dump/</guid><description>导出 RDP 连接凭据</description><pubDate>Tue, 09 Jul 2019 00:00:00 GMT</pubDate></item><item><title>dnscat2 代理隧道</title><link>https://exp10it.io/posts/dnscat2-tunnel/</link><guid isPermaLink="true">https://exp10it.io/posts/dnscat2-tunnel/</guid><description>dnscat2 代理隧道</description><pubDate>Mon, 08 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Windows 常用命令</title><link>https://exp10it.io/posts/windows-commands/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-commands/</guid><description>Windows 常用命令</description><pubDate>Mon, 08 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Procdump 导出密码</title><link>https://exp10it.io/posts/procdump-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/procdump-usage/</guid><description>Procdump 导出密码</description><pubDate>Sun, 07 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Cobalt Strike 重定向器</title><link>https://exp10it.io/posts/cobalt-strike-redirector/</link><guid isPermaLink="true">https://exp10it.io/posts/cobalt-strike-redirector/</guid><description>Cobalt Strike 重定向器</description><pubDate>Sat, 06 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Cobalt Strike DNS Beacon</title><link>https://exp10it.io/posts/cobalt-strike-dns-beacon/</link><guid isPermaLink="true">https://exp10it.io/posts/cobalt-strike-dns-beacon/</guid><description>Cobalt Strike DNS Beacon</description><pubDate>Fri, 05 Jul 2019 00:00:00 GMT</pubDate></item><item><title>常见的端口转发方法</title><link>https://exp10it.io/posts/port-forwarding/</link><guid isPermaLink="true">https://exp10it.io/posts/port-forwarding/</guid><description>常见的端口转发方法</description><pubDate>Fri, 21 Jun 2019 00:00:00 GMT</pubDate></item><item><title>SQLite Attach Getshell</title><link>https://exp10it.io/posts/sqlite-attach-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/sqlite-attach-getshell/</guid><description>SQLite Attach Getshell</description><pubDate>Mon, 04 Feb 2019 00:00:00 GMT</pubDate></item><item><title>Django 快速入门</title><link>https://exp10it.io/posts/django-quickstart/</link><guid isPermaLink="true">https://exp10it.io/posts/django-quickstart/</guid><description>Django 快速入门</description><pubDate>Tue, 28 Aug 2018 00:00:00 GMT</pubDate></item><item><title>模拟 BugScan Node 的通信机制</title><link>https://exp10it.io/posts/emulate-bugscan-node-communication-mechanism/</link><guid isPermaLink="true">https://exp10it.io/posts/emulate-bugscan-node-communication-mechanism/</guid><description>模拟 BugScan Node 的通信机制</description><pubDate>Fri, 24 Aug 2018 00:00:00 GMT</pubDate></item><item><title>XSS 绕过安全狗</title><link>https://exp10it.io/posts/xss-bypass-safedog/</link><guid isPermaLink="true">https://exp10it.io/posts/xss-bypass-safedog/</guid><description>XSS 绕过安全狗</description><pubDate>Wed, 15 Aug 2018 00:00:00 GMT</pubDate></item><item><title>Windows 下载文件的几种方式</title><link>https://exp10it.io/posts/windows-download-file/</link><guid isPermaLink="true">https://exp10it.io/posts/windows-download-file/</guid><description>Windows 下载文件的几种方式</description><pubDate>Tue, 14 Aug 2018 00:00:00 GMT</pubDate></item><item><title>JBoss 本地 Getshell</title><link>https://exp10it.io/posts/jboss-local-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/jboss-local-getshell/</guid><description>JBoss 本地 Getshell</description><pubDate>Mon, 13 Aug 2018 00:00:00 GMT</pubDate></item><item><title>Celery 学习笔记</title><link>https://exp10it.io/posts/celery-note/</link><guid isPermaLink="true">https://exp10it.io/posts/celery-note/</guid><description>Celery 学习笔记</description><pubDate>Sun, 12 Aug 2018 00:00:00 GMT</pubDate></item><item><title>Manjaro Linux 入坑指南</title><link>https://exp10it.io/posts/manjaro-linux-guide/</link><guid isPermaLink="true">https://exp10it.io/posts/manjaro-linux-guide/</guid><description>Manjaro Linux 入坑指南</description><pubDate>Fri, 10 Aug 2018 00:00:00 GMT</pubDate></item><item><title>通达 OA 变量覆盖及 getshell</title><link>https://exp10it.io/posts/tongda-oa-variable-overwrite-and-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/tongda-oa-variable-overwrite-and-getshell/</guid><description>通达 OA 变量覆盖及 getshell</description><pubDate>Mon, 06 Aug 2018 00:00:00 GMT</pubDate></item><item><title>xss.tv Writeup</title><link>https://exp10it.io/posts/xss-tv-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/xss-tv-writeup/</guid><description>xss.tv Writeup</description><pubDate>Sat, 04 Aug 2018 00:00:00 GMT</pubDate></item><item><title>RSA 算法原理</title><link>https://exp10it.io/posts/rsa-algorithm-note/</link><guid isPermaLink="true">https://exp10it.io/posts/rsa-algorithm-note/</guid><description>RSA 算法原理</description><pubDate>Fri, 03 Aug 2018 00:00:00 GMT</pubDate></item><item><title>XSS Challenges Writeup</title><link>https://exp10it.io/posts/xss-challenges-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/xss-challenges-writeup/</guid><description>XSS Challenges Writeup</description><pubDate>Wed, 01 Aug 2018 00:00:00 GMT</pubDate></item><item><title>Xor 加密</title><link>https://exp10it.io/posts/xor-encryption/</link><guid isPermaLink="true">https://exp10it.io/posts/xor-encryption/</guid><description>Xor 加密</description><pubDate>Mon, 30 Jul 2018 00:00:00 GMT</pubDate></item><item><title>MySQL load data local</title><link>https://exp10it.io/posts/mysql-load-data-local/</link><guid isPermaLink="true">https://exp10it.io/posts/mysql-load-data-local/</guid><description>MySQL load data local</description><pubDate>Sun, 22 Jul 2018 00:00:00 GMT</pubDate></item><item><title>Web.config 突破权限限制</title><link>https://exp10it.io/posts/web-config-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/web-config-bypass/</guid><description>Web.config 突破权限限制</description><pubDate>Thu, 19 Jul 2018 00:00:00 GMT</pubDate></item><item><title>MSF 派生 Cobalt Strike 会话</title><link>https://exp10it.io/posts/msfvenom-spawn-cobalt-strike-session/</link><guid isPermaLink="true">https://exp10it.io/posts/msfvenom-spawn-cobalt-strike-session/</guid><description>MSF 派生 Cobalt Strike 会话</description><pubDate>Wed, 18 Jul 2018 00:00:00 GMT</pubDate></item><item><title>powereasy 后台 getshell</title><link>https://exp10it.io/posts/powereasy-post-auth-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/powereasy-post-auth-getshell/</guid><description>powereasy 后台 getshell</description><pubDate>Thu, 12 Jul 2018 00:00:00 GMT</pubDate></item><item><title>Mstsc tscon 后门</title><link>https://exp10it.io/posts/mstsc-tscon-backdoor/</link><guid isPermaLink="true">https://exp10it.io/posts/mstsc-tscon-backdoor/</guid><description>Mstsc tscon 后门</description><pubDate>Wed, 11 Jul 2018 00:00:00 GMT</pubDate></item><item><title>信息收集中常见端口的整理</title><link>https://exp10it.io/posts/common-ports/</link><guid isPermaLink="true">https://exp10it.io/posts/common-ports/</guid><description>信息收集中常见端口的整理</description><pubDate>Sun, 08 Jul 2018 00:00:00 GMT</pubDate></item><item><title>BurpSuite 攻击模式</title><link>https://exp10it.io/posts/burpsuite-intruder-attack-types/</link><guid isPermaLink="true">https://exp10it.io/posts/burpsuite-intruder-attack-types/</guid><description>BurpSuite 攻击模式</description><pubDate>Fri, 06 Jul 2018 00:00:00 GMT</pubDate></item><item><title>命令行语法格式</title><link>https://exp10it.io/posts/cli-options-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/cli-options-usage/</guid><description>命令行语法格式</description><pubDate>Thu, 05 Jul 2018 00:00:00 GMT</pubDate></item><item><title>dedecms 前台通杀上传 0day</title><link>https://exp10it.io/posts/dedecms-upload-0day/</link><guid isPermaLink="true">https://exp10it.io/posts/dedecms-upload-0day/</guid><description>dedecms 前台通杀上传 0day</description><pubDate>Thu, 28 Jun 2018 00:00:00 GMT</pubDate></item><item><title>Python AsyncIO 学习笔记</title><link>https://exp10it.io/posts/python-asyncio-note/</link><guid isPermaLink="true">https://exp10it.io/posts/python-asyncio-note/</guid><description>Python AsyncIO 学习笔记</description><pubDate>Tue, 26 Jun 2018 00:00:00 GMT</pubDate></item><item><title>ChaBug Upload Writeup</title><link>https://exp10it.io/posts/chabug-upload-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chabug-upload-writeup/</guid><description>ChaBug Upload Writeup</description><pubDate>Fri, 22 Jun 2018 00:00:00 GMT</pubDate></item><item><title>msfvenom 多重编码</title><link>https://exp10it.io/posts/msfvenom-multiple-encode/</link><guid isPermaLink="true">https://exp10it.io/posts/msfvenom-multiple-encode/</guid><description>msfvenom 多重编码</description><pubDate>Wed, 20 Jun 2018 00:00:00 GMT</pubDate></item><item><title>简单的渗透测试报告</title><link>https://exp10it.io/posts/easy-pentest-report/</link><guid isPermaLink="true">https://exp10it.io/posts/easy-pentest-report/</guid><description>简单的渗透测试报告</description><pubDate>Mon, 18 Jun 2018 00:00:00 GMT</pubDate></item><item><title>DREAD 风险评估</title><link>https://exp10it.io/posts/dread-model/</link><guid isPermaLink="true">https://exp10it.io/posts/dread-model/</guid><description>DREAD 风险评估</description><pubDate>Fri, 15 Jun 2018 00:00:00 GMT</pubDate></item><item><title>SQLmap udf dll 解码</title><link>https://exp10it.io/posts/sqlmap-udf-dll-decode/</link><guid isPermaLink="true">https://exp10it.io/posts/sqlmap-udf-dll-decode/</guid><description>SQLmap udf dll 解码</description><pubDate>Thu, 07 Jun 2018 00:00:00 GMT</pubDate></item><item><title>MS17-010 Attack bat</title><link>https://exp10it.io/posts/ms17-010-attack-bat/</link><guid isPermaLink="true">https://exp10it.io/posts/ms17-010-attack-bat/</guid><description>MS17-010 Attack bat</description><pubDate>Sun, 03 Jun 2018 00:00:00 GMT</pubDate></item><item><title>绕过 360 添加用户</title><link>https://exp10it.io/posts/add-user-bypass-360/</link><guid isPermaLink="true">https://exp10it.io/posts/add-user-bypass-360/</guid><description>绕过 360 添加用户</description><pubDate>Sat, 02 Jun 2018 00:00:00 GMT</pubDate></item><item><title>MSSQL 读取文件</title><link>https://exp10it.io/posts/mssql-read-file/</link><guid isPermaLink="true">https://exp10it.io/posts/mssql-read-file/</guid><description>MSSQL 读取文件</description><pubDate>Thu, 31 May 2018 00:00:00 GMT</pubDate></item><item><title>ISCC 2018 Misc Writeup</title><link>https://exp10it.io/posts/iscc-2018-misc-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/iscc-2018-misc-writeup/</guid><description>ISCC 2018 Misc Writeup</description><pubDate>Sun, 20 May 2018 00:00:00 GMT</pubDate></item><item><title>ChaBug Web2 Writeup</title><link>https://exp10it.io/posts/chabug-web2-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/chabug-web2-writeup/</guid><description>ChaBug Web2 Writeup</description><pubDate>Wed, 16 May 2018 00:00:00 GMT</pubDate></item><item><title>LDAP 学习笔记</title><link>https://exp10it.io/posts/ldap-note/</link><guid isPermaLink="true">https://exp10it.io/posts/ldap-note/</guid><description>LDAP 学习笔记</description><pubDate>Mon, 14 May 2018 00:00:00 GMT</pubDate></item><item><title>PHP 对象注入</title><link>https://exp10it.io/posts/php-object-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/php-object-injection/</guid><description>PHP 对象注入</description><pubDate>Sun, 13 May 2018 00:00:00 GMT</pubDate></item><item><title>PHP PDO 参数化查询</title><link>https://exp10it.io/posts/php-pdo-query/</link><guid isPermaLink="true">https://exp10it.io/posts/php-pdo-query/</guid><description>PHP PDO 参数化查询</description><pubDate>Sat, 12 May 2018 00:00:00 GMT</pubDate></item><item><title>SQLMap Tamper 编写</title><link>https://exp10it.io/posts/sqlmap-tamper/</link><guid isPermaLink="true">https://exp10it.io/posts/sqlmap-tamper/</guid><description>SQLMap Tamper 编写</description><pubDate>Sat, 12 May 2018 00:00:00 GMT</pubDate></item><item><title>无字母 PHP Shell</title><link>https://exp10it.io/posts/no-letters-php-webshell/</link><guid isPermaLink="true">https://exp10it.io/posts/no-letters-php-webshell/</guid><description>无字母 PHP Shell</description><pubDate>Sat, 05 May 2018 00:00:00 GMT</pubDate></item><item><title>Python WeakFileScan</title><link>https://exp10it.io/posts/python-weakfilescan/</link><guid isPermaLink="true">https://exp10it.io/posts/python-weakfilescan/</guid><description>Python WeakFileScan</description><pubDate>Sat, 05 May 2018 00:00:00 GMT</pubDate></item><item><title>绕过 PowerShell 的执行策略</title><link>https://exp10it.io/posts/powershell-execution-policy-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/powershell-execution-policy-bypass/</guid><description>绕过 PowerShell 的执行策略</description><pubDate>Fri, 04 May 2018 00:00:00 GMT</pubDate></item><item><title>MSF ShellCode Bypass</title><link>https://exp10it.io/posts/msf-shellcode-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/msf-shellcode-bypass/</guid><description>MSF ShellCode Bypass</description><pubDate>Thu, 03 May 2018 00:00:00 GMT</pubDate></item><item><title>阿里云 WAF 绕过</title><link>https://exp10it.io/posts/aliyun-waf-bypass/</link><guid isPermaLink="true">https://exp10it.io/posts/aliyun-waf-bypass/</guid><description>阿里云 WAF 绕过</description><pubDate>Sat, 21 Apr 2018 00:00:00 GMT</pubDate></item><item><title>帝国 cms 后台 getshell</title><link>https://exp10it.io/posts/empire-cms-post-auth-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/empire-cms-post-auth-getshell/</guid><description>帝国 cms 后台 getshell</description><pubDate>Thu, 12 Apr 2018 00:00:00 GMT</pubDate></item><item><title>vssown.vbs</title><link>https://exp10it.io/posts/vssown-vbs-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/vssown-vbs-usage/</guid><description>vssown.vbs</description><pubDate>Sat, 07 Apr 2018 00:00:00 GMT</pubDate></item><item><title>wmiexec.vbs</title><link>https://exp10it.io/posts/wmiexec-vbs-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/wmiexec-vbs-usage/</guid><description>wmiexec.vbs</description><pubDate>Fri, 06 Apr 2018 00:00:00 GMT</pubDate></item><item><title>JBoss Deploy Getshell</title><link>https://exp10it.io/posts/jboss-deploy-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/jboss-deploy-getshell/</guid><description>JBoss Deploy Getshell</description><pubDate>Thu, 05 Apr 2018 00:00:00 GMT</pubDate></item><item><title>Zabbix SQL 注入</title><link>https://exp10it.io/posts/zabbix-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/zabbix-sql-injection/</guid><description>Zabbix SQL 注入</description><pubDate>Wed, 04 Apr 2018 00:00:00 GMT</pubDate></item><item><title>大米 CMS 任意文件删除</title><link>https://exp10it.io/posts/damicms-arbitrary-file-delete/</link><guid isPermaLink="true">https://exp10it.io/posts/damicms-arbitrary-file-delete/</guid><description>大米 CMS 任意文件删除</description><pubDate>Mon, 02 Apr 2018 00:00:00 GMT</pubDate></item><item><title>dedecms 后台代码执行</title><link>https://exp10it.io/posts/dedecms-post-auth-rce/</link><guid isPermaLink="true">https://exp10it.io/posts/dedecms-post-auth-rce/</guid><description>dedecms 后台代码执行</description><pubDate>Fri, 30 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Ubuntu 提权 EXP</title><link>https://exp10it.io/posts/ubuntu-lpe-exploit/</link><guid isPermaLink="true">https://exp10it.io/posts/ubuntu-lpe-exploit/</guid><description>Ubuntu 提权 EXP</description><pubDate>Fri, 30 Mar 2018 00:00:00 GMT</pubDate></item><item><title>dedecms 友链 getshell</title><link>https://exp10it.io/posts/dedecms-friend-link-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/dedecms-friend-link-getshell/</guid><description>dedecms 友链 getshell</description><pubDate>Sun, 25 Mar 2018 00:00:00 GMT</pubDate></item><item><title>aspcms SQL 注入</title><link>https://exp10it.io/posts/aspcms-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/aspcms-sql-injection/</guid><description>aspcms SQL 注入</description><pubDate>Wed, 21 Mar 2018 00:00:00 GMT</pubDate></item><item><title>discuz 任意文件删除</title><link>https://exp10it.io/posts/discuz-arbitrary-file-delete/</link><guid isPermaLink="true">https://exp10it.io/posts/discuz-arbitrary-file-delete/</guid><description>discuz 任意文件删除</description><pubDate>Mon, 19 Mar 2018 00:00:00 GMT</pubDate></item><item><title>PHP 加密 Bypass WAF</title><link>https://exp10it.io/posts/php-encode-bypass-waf/</link><guid isPermaLink="true">https://exp10it.io/posts/php-encode-bypass-waf/</guid><description>PHP 加密 Bypass WAF</description><pubDate>Mon, 19 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Typecho Writeup</title><link>https://exp10it.io/posts/typecho-writeup/</link><guid isPermaLink="true">https://exp10it.io/posts/typecho-writeup/</guid><description>Typecho Writeup</description><pubDate>Sat, 17 Mar 2018 00:00:00 GMT</pubDate></item><item><title>MSSQL Log Getshell</title><link>https://exp10it.io/posts/mssql-log-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/mssql-log-getshell/</guid><description>MSSQL Log Getshell</description><pubDate>Wed, 14 Mar 2018 00:00:00 GMT</pubDate></item><item><title>siteserver 管理员密码重置</title><link>https://exp10it.io/posts/siteserver-admin-password-reset/</link><guid isPermaLink="true">https://exp10it.io/posts/siteserver-admin-password-reset/</guid><description>siteserver 管理员密码重置</description><pubDate>Sat, 10 Mar 2018 00:00:00 GMT</pubDate></item><item><title>siteserver SQL 注入</title><link>https://exp10it.io/posts/siteserver-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/siteserver-sql-injection/</guid><description>siteserver SQL 注入</description><pubDate>Sat, 10 Mar 2018 00:00:00 GMT</pubDate></item><item><title>HTTP 头伪造 IP</title><link>https://exp10it.io/posts/http-header-fake-ip/</link><guid isPermaLink="true">https://exp10it.io/posts/http-header-fake-ip/</guid><description>HTTP 头伪造 IP</description><pubDate>Tue, 06 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Web 密码记录脚本</title><link>https://exp10it.io/posts/web-password-record-scripts/</link><guid isPermaLink="true">https://exp10it.io/posts/web-password-record-scripts/</guid><description>Web 密码记录脚本</description><pubDate>Tue, 06 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Redis Getshell</title><link>https://exp10it.io/posts/redis-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/redis-getshell/</guid><description>Redis Getshell</description><pubDate>Mon, 05 Mar 2018 00:00:00 GMT</pubDate></item><item><title>dedecms 后台爆破</title><link>https://exp10it.io/posts/dedecms-bruteforce/</link><guid isPermaLink="true">https://exp10it.io/posts/dedecms-bruteforce/</guid><description>dedecms 后台爆破</description><pubDate>Sat, 03 Mar 2018 00:00:00 GMT</pubDate></item><item><title>MSF Webshell 上线</title><link>https://exp10it.io/posts/msf-webshell/</link><guid isPermaLink="true">https://exp10it.io/posts/msf-webshell/</guid><description>MSF Webshell 上线</description><pubDate>Sat, 24 Feb 2018 00:00:00 GMT</pubDate></item><item><title>teamviewer 提权</title><link>https://exp10it.io/posts/teamviewer-lpe/</link><guid isPermaLink="true">https://exp10it.io/posts/teamviewer-lpe/</guid><description>teamviewer 提权</description><pubDate>Fri, 23 Feb 2018 00:00:00 GMT</pubDate></item><item><title>reGeorg 内网穿透</title><link>https://exp10it.io/posts/regeorg-tunnel/</link><guid isPermaLink="true">https://exp10it.io/posts/regeorg-tunnel/</guid><description>reGeorg 内网穿透</description><pubDate>Thu, 22 Feb 2018 00:00:00 GMT</pubDate></item><item><title>termite 跳板机管理</title><link>https://exp10it.io/posts/termite-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/termite-usage/</guid><description>termite 跳板机管理</description><pubDate>Thu, 22 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Nmap 脚本列表</title><link>https://exp10it.io/posts/nmap-scripts/</link><guid isPermaLink="true">https://exp10it.io/posts/nmap-scripts/</guid><description>Nmap 脚本列表</description><pubDate>Tue, 20 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Python 实现单向链表</title><link>https://exp10it.io/posts/python-linked-list/</link><guid isPermaLink="true">https://exp10it.io/posts/python-linked-list/</guid><description>Python 实现单向链表</description><pubDate>Mon, 19 Feb 2018 00:00:00 GMT</pubDate></item><item><title>EarthWorm 内网穿透</title><link>https://exp10it.io/posts/earthworm-tunnel/</link><guid isPermaLink="true">https://exp10it.io/posts/earthworm-tunnel/</guid><description>EarthWorm 内网穿透</description><pubDate>Sun, 18 Feb 2018 00:00:00 GMT</pubDate></item><item><title>pstools 使用详解</title><link>https://exp10it.io/posts/pstools-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/pstools-usage/</guid><description>pstools 使用详解</description><pubDate>Sat, 17 Feb 2018 00:00:00 GMT</pubDate></item><item><title>获得 Linux 交互式 Shell</title><link>https://exp10it.io/posts/linux-interactive-shell/</link><guid isPermaLink="true">https://exp10it.io/posts/linux-interactive-shell/</guid><description>获得 Linux 交互式 Shell</description><pubDate>Fri, 16 Feb 2018 00:00:00 GMT</pubDate></item><item><title>netcat 使用技巧</title><link>https://exp10it.io/posts/netcat-usage/</link><guid isPermaLink="true">https://exp10it.io/posts/netcat-usage/</guid><description>netcat 使用技巧</description><pubDate>Wed, 14 Feb 2018 00:00:00 GMT</pubDate></item><item><title>PHP 常用伪协议</title><link>https://exp10it.io/posts/php-pesudo-protocols/</link><guid isPermaLink="true">https://exp10it.io/posts/php-pesudo-protocols/</guid><description>PHP 常用伪协议</description><pubDate>Tue, 13 Feb 2018 00:00:00 GMT</pubDate></item><item><title>利用 dnslog 回显</title><link>https://exp10it.io/posts/dnslog-output/</link><guid isPermaLink="true">https://exp10it.io/posts/dnslog-output/</guid><description>利用 dnslog 回显</description><pubDate>Sat, 10 Feb 2018 00:00:00 GMT</pubDate></item><item><title>MySQL updatexml 注入</title><link>https://exp10it.io/posts/mysql-updatexml-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/mysql-updatexml-sql-injection/</guid><description>MySQL updatexml 注入</description><pubDate>Wed, 07 Feb 2018 00:00:00 GMT</pubDate></item><item><title>PHP Bypass D盾</title><link>https://exp10it.io/posts/php-bypass-dsafe/</link><guid isPermaLink="true">https://exp10it.io/posts/php-bypass-dsafe/</guid><description>PHP Bypass D盾</description><pubDate>Tue, 06 Feb 2018 00:00:00 GMT</pubDate></item><item><title>WebLogic RCE 复现</title><link>https://exp10it.io/posts/weblogic-rce-reproduce/</link><guid isPermaLink="true">https://exp10it.io/posts/weblogic-rce-reproduce/</guid><description>WebLogic RCE 复现</description><pubDate>Tue, 06 Feb 2018 00:00:00 GMT</pubDate></item><item><title>phpcms authkey 注入</title><link>https://exp10it.io/posts/phpcms-authkey-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/phpcms-authkey-sql-injection/</guid><description>phpcms authkey 注入</description><pubDate>Sun, 04 Feb 2018 00:00:00 GMT</pubDate></item><item><title>phpcms SQL 注入</title><link>https://exp10it.io/posts/phpcms-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/phpcms-sql-injection/</guid><description>phpcms SQL 注入</description><pubDate>Sat, 03 Feb 2018 00:00:00 GMT</pubDate></item><item><title>phpcms 后台 getshell</title><link>https://exp10it.io/posts/phpcms-post-auth-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/phpcms-post-auth-getshell/</guid><description>phpcms 后台 getshell</description><pubDate>Fri, 02 Feb 2018 00:00:00 GMT</pubDate></item><item><title>PHP 菜刀中转脚本</title><link>https://exp10it.io/posts/php-caidao-forward-scripts/</link><guid isPermaLink="true">https://exp10it.io/posts/php-caidao-forward-scripts/</guid><description>PHP 菜刀中转脚本</description><pubDate>Wed, 31 Jan 2018 00:00:00 GMT</pubDate></item><item><title>星外虚拟主机跨目录</title><link>https://exp10it.io/posts/freehost-path-traversal/</link><guid isPermaLink="true">https://exp10it.io/posts/freehost-path-traversal/</guid><description>星外虚拟主机跨目录</description><pubDate>Sat, 27 Jan 2018 00:00:00 GMT</pubDate></item><item><title>Linux 的几种后门</title><link>https://exp10it.io/posts/linux-backdoors/</link><guid isPermaLink="true">https://exp10it.io/posts/linux-backdoors/</guid><description>Linux 的几种后门</description><pubDate>Fri, 26 Jan 2018 00:00:00 GMT</pubDate></item><item><title>dirtyc0w linux 提权</title><link>https://exp10it.io/posts/dirtyc0w-linux-lpe/</link><guid isPermaLink="true">https://exp10it.io/posts/dirtyc0w-linux-lpe/</guid><description>dirtyc0w linux 提权</description><pubDate>Sun, 21 Jan 2018 00:00:00 GMT</pubDate></item><item><title>MSSQL 显错注入</title><link>https://exp10it.io/posts/mssql-error-based-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/mssql-error-based-sql-injection/</guid><description>MSSQL 显错注入</description><pubDate>Mon, 15 Jan 2018 00:00:00 GMT</pubDate></item><item><title>MySQL Log Getshell</title><link>https://exp10it.io/posts/mysql-log-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/mysql-log-getshell/</guid><description>MySQL Log Getshell</description><pubDate>Tue, 09 Jan 2018 00:00:00 GMT</pubDate></item><item><title>ecshop 后台 getshell</title><link>https://exp10it.io/posts/ecshop-post-auth-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/ecshop-post-auth-getshell/</guid><description>ecshop 后台 getshell</description><pubDate>Sun, 07 Jan 2018 00:00:00 GMT</pubDate></item><item><title>Fckeditor PHP Exp</title><link>https://exp10it.io/posts/fckeditor-php-exploit/</link><guid isPermaLink="true">https://exp10it.io/posts/fckeditor-php-exploit/</guid><description>Fckeditor PHP Exp</description><pubDate>Sat, 06 Jan 2018 00:00:00 GMT</pubDate></item><item><title>树洞外链 insert 注入</title><link>https://exp10it.io/posts/tree-hole-insert-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/tree-hole-insert-sql-injection/</guid><description>树洞外链 insert 注入</description><pubDate>Mon, 01 Jan 2018 00:00:00 GMT</pubDate></item><item><title>MySQL 盲注</title><link>https://exp10it.io/posts/mysql-blind-sql-injection/</link><guid isPermaLink="true">https://exp10it.io/posts/mysql-blind-sql-injection/</guid><description>MySQL 盲注</description><pubDate>Mon, 25 Dec 2017 00:00:00 GMT</pubDate></item><item><title>discuz 后台 getshell</title><link>https://exp10it.io/posts/discuz-post-auth-getshell/</link><guid isPermaLink="true">https://exp10it.io/posts/discuz-post-auth-getshell/</guid><description>discuz 后台 getshell</description><pubDate>Thu, 07 Dec 2017 00:00:00 GMT</pubDate></item><item><title>Git 学习笔记</title><link>https://exp10it.io/posts/git-note/</link><guid isPermaLink="true">https://exp10it.io/posts/git-note/</guid><description>Git 学习笔记</description><pubDate>Tue, 05 Dec 2017 00:00:00 GMT</pubDate></item></channel></rss>