摘要:
This is the write up for the medium machine 'onlyrforyou'. Topic covered in this article are: LFI,commnad injection,neo4j cipher injection,malicious p 阅读全文
摘要:
Injections How to inject Injectable query Injection Macth (o) where o.Id='{input}' 'OR 1=1 with 0 as _l00 {...} RETURN 1 // MATCH (o) wehre '{input}' 阅读全文
摘要:
This text introduce a new domain lateral movement technology--PTC(certificate transport attack).Introducing a new kind of DC certification utiliz thin 阅读全文
摘要:
Ansible_vault hash decrypt Copy those ansible_vault hash to three file named pwm_admin_login_vault pwm_admin_password_vault ldap_admin_password_vault 阅读全文
摘要:
Initial Gobuster to discover the webcontents. When we brute-force a directory path, if one dictionary doesn't give us any useful information, we can c 阅读全文
摘要:
ImageMagick The ImageMagick is the tool modify the picture. The function of ImageMagick is ELF file named magick. The vulnerability version of ImageMa 阅读全文