A query language for HTTP traffic: what it would look like, and why nobody has built it
We have a declarative query language for almost every artifact a defender looks at, except the one this blog spends most of its time on. YARA matches on file...
We have a declarative query language for almost every artifact a defender looks at, except the one this blog spends most of its time on. YARA matches on file...
Most of the parser-differential work on this blog has been about two servers on one connection disagreeing over where a request ends. Request smuggling is th...
The 2019 request-smuggling work on this blog, the CL.TE / TE.CL / TE.TE matrix, was about HTTP/1.1 disagreeing with itself. Two servers on one connection, on...
This is a first look, not a results table. I have spent most of my writing on this blog on HTTP/1.1 request smuggling and, more recently, on the HTTP/2 downg...
This post is a 2026 follow-up to two 2019 articles I wrote on this blog: the Chinese-language HTTP Request Smuggling 研究笔记 and its English counterpart HTTP Re...
In March 2020 I published DOM Clobbering - An Underestimated Attack Vector, a brief introduction to clobbering as an HTML-injection-to-script-execution path....
本篇通过对 DownUnder CTF 2022 中一道题的讲解来介绍一种比较 trick 的通过侧信道读取文件内容的方法。 本篇通过对 DownUnder CTF 2022 中一道题的讲解来介绍一种比较 trick 的通过侧信道读取文件内容的方法。 文章首发于跳跳堂:The End of AFR? TL;DR ...
上周周末结束的 corCTF 中有一个题目提出了一种很有意思的攻击,该攻击方式可以利用 HTTP/2 Server Push 机制 XSS 到其他域,尽管利用条件有点苛刻,但是我个人非常喜欢这种 Magic 的攻击方式。(在征求了原作者 @ehhthing 同意下将该方法分享给大家) 文章首发于跳跳堂:A Mag...
Timing attacks on web applications have traditionally been unreliable due to network jitter. A 1ms difference in server processing time can be obscured by 50...
After publishing my novel LFI technique based on PHP filter chains, I received many questions about whether LFI is still a relevant vulnerability class. In t...
Local File Inclusion (LFI) is a well-studied vulnerability class, but new exploitation techniques continue to emerge. In this post, I present a novel approac...
After running this blog on Hexo for two years, I migrated to Hugo. This post documents the migration process and the reasons behind the switch.
1. TL;DR2. Reconnaissance3. Padding Oracle Attack4. Recovering the Entire Plaintext5. Arbitrary Plaintext Encryption6. The XSS Part This is the fork of my fr...
1. Empty LS2. GPU Shop3. Other Webs I played Google CTF Quals 2021 and here is my writeup.I played with the Tea Deliverers team in the Google CTF Quals 2021....
1. Introduction of FTPS1.1. Implicit Mode1.2. Explicit Mode2. TLS Poison In FTPS2.1. Explicit2.2. Implicit2.3. PASV3. HXP CTF - Security Scanner3.1. Descript...
1. Preface2. Background2.1. TLS Overview2.1.1. TLS Handshake2.1.2. TLS Record2.2. TLS 1.22.2.1. TLS 1.2 HankShake2.2.2. TLS 1.2 Session Resumption Overview2....
1. Information1.1. CSP2. Exp2.1. User Activation2.2. uBlock2.3. How to get the FLAG2.4. Text Fragments2.5. Lettering2.6. Spark Thinking2.7. uBlock & User...
1. TL;DR2. CRLF in FTP3. The active mode of FTP4. The mail server5. rabbitmq6. SSRF! Here is my write up of Contrived Web Problem in Plaid CTF 2020.[TOC]TL;D...
DOM Clobbering is a technique where HTML injection (without script execution) can be leveraged to manipulate JavaScript execution by polluting the DOM namesp...
This post documents my solutions to various XSS game challenges, analyzing the filter bypass techniques required for each level.
Writeups for the web challenges from 36C3 CTF (hxp CTF), held in December 2019 at the Chaos Communication Congress in Leipzig.
HTTP Request Smuggling is a technique that exploits parsing disagreements between front-end and back-end HTTP servers. When two servers in a chain disagree o...
本文是我对HTTP请求走私(HTTP Request Smuggling)技术的研究记录。英文版本请参考HTTP Request Smuggling - A Complete Guide。
1. Preparation1.1. INTRO1.1.1. Token1 - Get From Input1.1.2. Token1 - Auto Get From Input1.1.3. Token1 - Same Origin1.1.4. Token2 - Font1.1.5. Token2 - Get F...
1. Web1.1. babyblog1.2. babypress1.3. weiphp1.3.1. SSRF1.3.2. upload1.4. lfi20191.4.1. Trick 11.4.2. Trick 21.5. noxss1.6. tfboys2. Conclusion 我们 SU 这次一共做出了3...
红帽杯(Red Hat Cup)2019 CTF比赛Web方向题解。
因为 Insomnihack 2019 l33t-hoster 这道题跟 XNUCA 2019 Qualifier Ezphp 如出一辙,比较类似,并且也是比较有意思的一题,所以两个题就放在一起写了
在今年的 WCTF 2019 上,Tokyo Westerns 出了一道与 Windows Defender 侧信道攻击相关的题目,在 Tokyo Westerns CTF 2019 上也有一道与之有关的题目 PHP Note,看了感觉比较有趣,但是我看的网络文章写的都比较粗略,这里我就记录一下自己的分析。
周末自己打了一会 Byte CTF ,队里其他师傅都没啥时间,自己做题比较慢,就只做了几个题。
这次我给 SUCTF 出了三道 Web,分别是 CheckIn 、 pythonginx 、 Upload Labs 2,下面聊一下出题时候的一些思路以及随想,还有最近对于 phar 的一些深入挖掘。 文章首发于先知社区:https://xz.aliyun.com/t/6057
Writeups from the ISITDTU CTF 2019 Quals, focusing on the web challenges.
这是一个绿盟弄的 CTF ,因为在复习考试所以没怎么玩…随便玩了一下顺手写个 wp
最近要写个端口扫描器,学习整理了一下目前的端口扫描器技术。 文章首发于先知社区:https://xz.aliyun.com/t/5376
最近遇到了比较多的通过 LFI 提到 RCE 的漏洞利用方法。尤其是在遇到有 phpinfo 的情况下,这里做一个简单的总结与介绍。
Pwn 网杯再一次用实践行动谁才是 CTF 中爸爸级别的人物!(当然还是 Crypto 爷爷啦
2019 ISCC Web wp,没什么太大意义…原题比较多…没学到啥…
国赛中 RefSpace 那道题的 wp 与研究。
2019 DDCTF web writeup
国赛 Web wp
近期有小伙伴问了我一道题,然后自己发掘到了一些关于 PHP 复杂变量不太被关注的问题。 文章首发于先知社区:https://xz.aliyun.com/t/4785
2019西湖论剑线上赛 Web wp。除了最后一道原题没时间做,其他都弄出来了。
这是给A2OS做的关于 Web 安全的分享内容概要
上周末抽空佛系打了一下 TCTF/0CTF ,跟马师傅一起做了 web1 ,web 2 没来得及看就关闭了。这里就记录一下。
之前看到了 35c3 的比赛,但是没时间打,看了看题,发现这个题还是不错的,单独拿出来学习一下
1. CISP-PTE1.1. 介绍1.1.1. What is CISP1.2. 体系结构1.2.1. 单选题1....
1. Upload-Labs1.1. Pass-011.2. Pass-021.3. Pass-031.4. Pass-041.5. Pass-051.6. Pass-061.7. Pass-071.8. Pass-081.9. Pass-091.10. Pass-101.11. Pass-111.12. Pas...
1. 3601.1. 笔试2. 腾讯2.1. 第一次一面2.2. 第二次一面2.3. 第二次二面2.4. 第二次三面2.5. 总结3. 阿里3.1. 能力测评3.2. 吐槽4. 华为4.1. 机试4.1.1. 第一题4.1.2. 第二题4.1.3. 第三题4.1.4. 总结4.2. 能力测评4.3. 面试 这篇写...
这是自己写的 Web 安全从零开始系列之 XSS 篇。第四篇讲 XSS 防御。
这是自己写的 Web 安全从零开始系列之 XSS 篇。第三篇讲解 CSP 与 XSS
这是自己写的 Web 安全从零开始系列之 XSS 篇。第二篇讲解同源策略与XSS
这是Web安全入门系列的第一篇,主要讲解跨站脚本攻击(XSS)的基础知识。
文章首发于先知社区:https://xz.aliyun.com/t/4309 之前在补天平台首发了巧用命令注入的N种方式,看到了有几个师傅衍生出了不同的几个后续版本,都感觉挺不错的,对我的版本进行了一些补充。本来这个总结应该算是前半部分,想写的还没写完,当时又是在考试周,原本想在考试结束后就来写后半...
Write up of Pentesterlab’s XSS and MySQL FILE
接Web For Pentest,这里是它的第二版
很久之前就想做的靶机,一直没做,最近有空清理一下。地址在PentestLab
SQL注入(SQL Injection)速查手册,记录常用的注入技巧和payload。
1. Preparation2. Basic3. SQLi-LABS Page-1(Basic Challenges)3.1. Less-13.2. Less-23.3. Less-33.4. Less-43.5. Less-53.5.1. 使用left()3.5.2. 使用substr()、ascii()3.5...
起因是年前看了一篇How To Exploit PHP Remotely To Bypass Filters & WAF Rules,现在搜了一下发现已经有翻译了。感觉升华也没什么好扩展的,也不太好拿去投稿了,思考了一下,感觉还是当作学习笔记来写算了。
安恒1月月赛复现wp
HackIM-2019 Web记录 文章首发于安全客,地址:https://www.anquanke.com/post/id/170708 过年前做了一下,感觉还是挺有意思的。比赛官方也开源了比赛源码。
本文首发于补天平台,地址:https://mp.weixin.qq.com/s/Hm6TiLHiAygrJr-MGRq9Mw 在NUAACTF_2018中,我出了一道比较水的采用Spring框架的SSRF+Java Deserialization+Command Injection。个人觉得在出题时...