教学频道 第144页
教学频道 – 华盟网

SSRF中的绕过姿势

SSRF中的绕过姿势-华盟网
Learn about SSRF bypass techniques including URL encoding, domain manipulation, IP address conversion. Discover how to exploit these vulnerabilities for web app
AlexFrankly的头像-华盟网AlexFrankly8年前
01.8W+0

构造PPSX钓鱼文件

构造PPSX钓鱼文件-华盟网
Learn how to create a PPSX file for phishing purposes without using macros. This tutorial covers the steps to embed malicious programs in presentations, enhanci
AlexFrankly的头像-华盟网AlexFrankly8年前
06.2W+0

Hostscan – 用于网络扫描的PHP工具

Hostscan - 用于网络扫描的PHP工具-华盟网
Hostscan是一个用于网络扫描的PHP工具,主要用于信息收集和测试弱密码。它支持SSH、IMAP、MySQL等多种连接方式,并提供深度扫描功能。适用于网络安全研究者和技术爱好者。
AlexFrankly的头像-华盟网AlexFrankly8年前
06.7W+0

命令行下的信息搜集

命令行下的信息搜集-华盟网
Learn how to gather critical system information using WMIC commands in the command line. Explore tools for identifying installed patches, running services, star
AlexFrankly的头像-华盟网AlexFrankly8年前
07.3W+0

渗透过程中的端口反弹

渗透过程中的端口反弹-华盟网
Explore various methods of port rebinding in penetration testing using bash, perl, python, php, ruby, nc, and java. Learn how to establish a reverse shell conne
AlexFrankly的头像-华盟网AlexFrankly8年前
07.1W+0

windows命令执行漏洞不会玩? 看我!

windows命令执行漏洞不会玩? 看我!-华盟网
了解如何利用mssql注入点的命令执行漏洞获取meterpreter,掌握powershell、regsvr32、rundll32和mshta等多种注入技巧。
AlexFrankly的头像-华盟网AlexFrankly8年前
011010

Phan – PHP静态分析器

Phan - PHP静态分析器-华盟网
Phan is a PHP static analyzer that minimizes false positives by verifying type compatibility and checking various operations. It supports features like PHPDoc a
AlexFrankly的头像-华盟网AlexFrankly8年前
06.7W+0

Exec OS Command Via MSSQL

Exec OS Command Via MSSQL-华盟网
Explore advanced techniques for executing operating system commands via MSSQL, including xp_cmdshell, SP_OACreate, and more. This guide covers various methods t
AlexFrankly的头像-华盟网AlexFrankly8年前
05.4W+0

MS16-135 带参数版

MS16-135 带参数版-华盟网
Discover and learn about the Invoke-MS16-135 PowerShell implementation targeting vulnerable operating systems. This code allows you to run applications with spe
AlexFrankly的头像-华盟网AlexFrankly8年前
07.9W+0

渗透中的ADS

渗透中的ADS-华盟网
Explore the technique of using ADS for file execution during pentesting. Learn how to upload and execute files via CobaltStrike and Meterpreter, including comma
AlexFrankly的头像-华盟网AlexFrankly8年前
05.8W+0

OWTF – 攻击性Web测试框架

OWTF - 攻击性Web测试框架-华盟网
OWTF是一款强大的自动化Web渗透测试框架,支持OWASP测试指南和NIST标准。它提供灵活的风险评估、报告生成和多目标测试功能,适用于高级网络安全测试人员进行深入研究。
AlexFrankly的头像-华盟网AlexFrankly8年前
08W+0

MSWord Code Exec Without Macro

MSWord Code Exec Without Macro-华盟网
Discover how to execute code in MS Word without macros using DDE and DDEAUTO. Learn techniques for interactive shell access via Word documents.
AlexFrankly的头像-华盟网AlexFrankly8年前
02.4W+0