unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Host & Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)
A walkthrough covering SMB brute-forcing, Pass-the-Hash attacks, FTP credential reuse, and ASPX webs...
2026-7-4 04:37:5 | 阅读: 30 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ine
gave
nancy
tom
nmap
Demonstrating LLMNR Poisoning in Active Directory
LLMNR refers to Link Local Multicast Name Resolution which is a protocol that acts as a fallback for...
2026-7-4 04:33:44 | 阅读: 29 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
attacker
machine
network
llmnr
responder
Post-Compromise Attacks in AD: Credential Validation with CrackMapExec
“P.S. I wrote this article while still learning Active Directory penetration testing myself, so ther...
2026-7-4 04:32:56 | 阅读: 29 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
fcastle
sizeas
marvel
spiderman
I found North Korean (DPRK) malware hiding in my tailwind.config.js
I almost closed the file without reading it. Three days later I was killing processes in production...
2026-7-4 04:24:18 | 阅读: 29 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
shouldn
tailwind
processes
diffed
scrolled
TryHackMe — Simple CTF: The Note That Gave Everything Away
The FTP server was anonymous. The password was “secret”. The vim binary was sudo. This box didn’t hi...
2026-7-3 13:19:42 | 阅读: 25 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
mitch
tryhackme
username
teach
wordlists
TryHackMe — Pickle Rick: Rick Left the Door Open. I Just Walked In.
The Web App — Index.php and a Dead EndNavigating to http://10.0.0.4 lands on index.php, a Rick and M...
2026-7-3 13:19:38 | 阅读: 22 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
php
username
robots
rick
r1ckrul3s
TryHackMe: Checkpoint Walkthrough
Press enter or click to view image in full sizeTryhackme Premium room — armank8000Four candidates. T...
2026-7-3 13:19:29 | 阅读: 19 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
candidate
candidates
guardrail
safetensors
security
Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up
Press enter or click to view image in full sizeAuthor: GitHub: alisalive LinkedIn: camalzads Platfor...
2026-7-3 13:19:23 | 阅读: 29 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
exchange
mailbox
machine
telecom
viewstate
Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High
TL;DR: Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. T...
2026-7-3 13:17:39 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
nex
wp
attacker
sanitize
wordpress
Suricata Caught It. Zeek Explained It. Here’s Why You Need Both.
| Cybesecurity | Suricata | Zeek | Blue Teaming | SOC|An alarm tells you something happened. A camer...
2026-7-3 13:17:5 | 阅读: 20 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
suricata
alarm
zeek
compares
distinction
Host & Network Penetration Testing: Exploitation CTF 1 — eJPT (INE)
A walkthrough covering flatCore CMS exploitation, SSH brute-forcing, WordPress plugin enumeration, a...
2026-7-3 13:16:46 | 阅读: 24 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ine
target2
flatcore
ssh
nmap
I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few…
Press enter or click to view image in full sizeDisclosure Notice: This research was conducted entire...
2026-7-3 13:16:20 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
download
cdm
wp
php
wordpress
How I Found an Email Verification Bypass on an AI Freelance Platform
A simple implementation flaw allowed email verification to be completed without ever opening the ver...
2026-7-1 10:20:40 | 阅读: 21 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
security
mailbox
ownership
guarantee
became
How I Found an Email Verification Bypass on an AI Freelance Platform
A simple implementation flaw allowed email verification to be completed without ever opening the ver...
2026-7-1 10:20:40 | 阅读: 25 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
security
mailbox
guarantee
ownership
inbox
Hack Smarter — City Council (Active Directory)
Press enter or click to view image in full sizeCan an application for public service requests lead t...
2026-7-1 10:19:48 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
microsoft
emma
Why Being in the Docker Group Is a Backdoor to Your Whole System
Press enter or click to view image in full sizeIf you’ve worked with Docker on Linux, you’ve probabl...
2026-7-1 10:17:11 | 阅读: 26 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
grants
development
machine
runners
membership
Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App
2026-7-1 10:17:4 | 阅读: 39 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App
Press enter or click to view image in full sizeImage generated by Google GeminiNOTE: As of the publi...
2026-7-1 10:17:4 | 阅读: 27 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
security
analysis
bypassed
keyguard
notebooklm
ChatGPT: Guardrail Bypass to LFI Vulnerability POC
EXPLOITATION STEPS:Upload a file to the system for review.Request a download link this step requires...
2026-7-1 10:16:35 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
download
bypass
sizecapture
gpt
chatgpt
Auth Bypass is it?
Target, domains, API keys, bearer tokens, SSO IDs, and organisation names are redacted. This writeup...
2026-7-1 10:16:29 | 阅读: 21 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
mspace
deeplink
bearer
outer
client
Previous
4
5
6
7
8
9
10
11
Next