Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
collection-document — Collection of quality safety articles. Awesome articles. | Kitploit
Tools/GitHubGitHub/tom0li/collection-document
OSINT (Open Source Intelligence)Vulnerability AnalysisWeb SecurityFuzzingMalware AnalysisPenetration TestingCloud SecurityDevSecOpsMobile SecurityThreat IntelligenceLearning & EducationCurated Resources
2.1k5071 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubtom0li/collection-document

collection-document

Collection of quality safety articles. Awesome articles.

View RepositoryWebsite

Project Description

Collection of quality safety articles(To be rebuilt)``` Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome 以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io

root@kitploit:~
- [Project Description](#project-description)
  - [Github-list](#github-list)
    - [Awesome-list](#awesome-list)
    - [Development](#开发)
    - [Others](#其它)
  - [Security](#安全)
    - [Security list](#安全list)
    - [Security Market Insights](#安全市场洞察)
    - [Cloud Security](#云安全)
      - [Cloud Basics](#云基础知识)
      - [Cloud Native Security](#云原生安全)
      - [Cloud Attack and Defense](#云上攻防)
      - [VM](#vm)
        - [vCenter](#vcenter)
        - [SLP](#slp)
    - [AI Security](#ai安全)
    - [New Security Solutions](#新安全方案)
      - [Building Next-Generation Security](#构建下一代安全)
      - [Zero Trust](#零信任)
      - [DevSecOps](#devsecops)
    - [Threat Detection](#威胁检测)
      - [RASP](#rasp)
      - [HIDS](#hids)
      - [WAF](#waf)
        - [WAF Construction Guide](#waf建设指南)
        - [BypassWAF](#bypasswaf)
      - [Webshell Detection](#webshell检测)
      - [Reverse Shell Detection](#反弹shell检测)
      - [EDR](#edr)
      - [AV](#av)
      - [Lateral Movement Detection - Honeypot Approach](#横向移动检测-蜜罐思路)
      - [Malicious Traffic Detection](#恶意流量检测)
      - [IDS](#ids)
      - [Text Detection](#文本检测)
    - [Security Operations](#安全运营)
    - [Data Security](#数据安全)
      - [Network Mapping](#网络测绘)
    - [Communication Security](#通信安全)
      - [End-to-End Communication (First Edition)](#端对端通信初版)
      - [SNI](#sni)
    - [Personal Security](#个人安全)
    - [APT Research](#apt研究)
      - [Advanced Threat List](#高级威胁-list)
      - [Threat Intelligence](#威胁情报)
      - [Phishing](#钓鱼)
      - [C2-RAT](#c2-rat)
  - [Warning & Research](#预警研究)
    - [ImageMagick](#imagemagick)
    - [Exchange](#exchange)
    - [Privilege-Escalation](#privilege-escalation)
    - [VPN](#vpn)
      - [Sangfor](#sangfor)
      - [Pulse](#pulse)
      - [Palo](#palo)
      - [Fortigate](#fortigate)
      - [Citrix Gateway/ADC](#citrix-gatewayadc)
    - [Tomcat](#tomcat)
    - [FUZZING](#fuzzing)
  - [Code Audit - JAVA](#代码审计-java)
    - [Deserialization - Others](#反序列化-其他)
    - [RMI](#rmi)
    - [Shiro](#shiro)
    - [Fastjson](#fastjson)
    - [Dubbo](#dubbo)
    - [CAS](#cas)
    - [Solr Template Injection](#solr模版注入)
    - [Apache Skywalking](#apache-skywalking)
    - [Spring](#spring)
      - [Spring-boot](#spring-boot)
      - [Spring-cloud](#spring-cloud)
      - [Spring-data](#spring-data)
  - [Blockchain](#区块链)
  - [Penetration](#渗透)
    - [Perimeter Penetration](#边界渗透)
      - [Penetration Records and Summary](#渗透记录和总结)
      - [Information Gathering](#信息收集)
      - [Ranges](#靶场)
      - [Penetration Techniques](#渗透技巧)
    - [Intranet Penetration](#内网渗透)
      - [Exchange Exploitation (Old)](#exchange利用旧)
      - [hash ticket Credential](#hash-ticket-credential)
      - [Proxy Forwarding and Port Reuse](#代理转发与端口复用)
      - [Intranet Platform](#内网平台)
      - [Intranet Techniques](#内网技巧)
      - [Privilege Escalation Exploitation](#提权利用)
  - [Bug_Bounty](#bug_bounty)
  - [Web](#web)
    - [XXE](#xxe)
    - [XSS](#xss)
    - [Jsonp](#jsonp)
    - [CORS](#cors)
    - [CSRF](#csrf)
    - [SSRF](#ssrf)
    - [SQL](#sql)
    - [File Inclusion](#文件包含)
    - [Upload](#上传)
    - [Arbitrary File Read](#任意文件读取)
    - [Web Cache Deception](#web缓存欺骗)
    - [Web Cache Poisoning](#web缓存投毒)
    - [SSI](#ssi)
    - [SSTI](#ssti)
    - [JS](#js)
    - [DNS](#dns)
  - [Others](#其他)
      - [Git](#git)
      - [QR Code](#二维码)
      - [Crawler](#爬虫)
      - [Efficiency](#效率)
      - [Popular Science](#科普)
  - [Contribute](#contribute)
  - [Acknowledgments](#acknowledgments)
  - [Star](#star)

## Github-list
### Awesome-list

* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security) 
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - 10k-star list 
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - Collection of Android security related resources.
* [Security](https://github.com/sbilly/awesome-security) - Software, libraries, documents, and other resources.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - Curated list of security conferences.
* [OSINT](https://github.com/jivoi/awesome-osint) - Awesome OSINT list containing great resources.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - The toolbox of open source scanners
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - Official Black Hat Arsenal Security Tools Repository
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - The List of the Lists.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - Security related content
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - by CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - by CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - by JnuSimba notes 
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - notes
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - notes
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti info source](https://github.com/tanjiti/sec_profile) - by Baidu tanjiti, daily crawled security information sources
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - by 404notf0und, monitoring CVE incremental updates, CVE EXP prediction based on deep learning and automated push
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca's repository constantly updated with security-related content

### Development

* [Complete Guide to Advanced Java Knowledge for Internet Java Engineers](https://github.com/doocs/advanced-java)
* [Java Learning + Interview Guide: A guide covering the core knowledge that most Java programmers need to master](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, frontend, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [Python interview questions](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - good
* [Essential Basics for Interviews](https://github.com/CyC2018/CS-Notes)
* [CS Basics](https://github.com/selfboot/CS_Offer/)
* [Algorithm/Deep Learning/NLP Interview Notes](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [Algorithm Handbook](https://github.com/labuladong/fucking-algorithm)
* [50 Code Implementations for Data Structures and Algorithms](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference) 
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - Questions to ask the interviewer at the end of a technical interview

### Others

* [Recommended Book List for Information Security Practitioners](https://github.com/riusksk/secbook)
* [English Learning Guide Specially Written for Programmers v1.2](https://github.com/yujiangshui/A-Programmers-Guide-to-English)
* [Words Chinese Programmers Often Mispronounce](https://github.com/shimohq/chinese-programmer-wrong-pronunciation)
* [Laws, Theories, Principles, and Patterns Useful for Developers](https://github.com/nusr/hacker-laws-zh)
* [SecLists](https://github.com/danielmiessler/SecLists) - Collection of multiple types of lists used during security assessments.
* [A collection of web attack payloads](https://github.com/foospidy/payloads) payloads collection
* [Collection of Security Mind Maps](https://github.com/phith0n/Mind-Map) - by p niu 
* [Security Mind Map Collection](https://github.com/SecWiki/sec-chart) - by SecWiki
* [Android-Reports-and-Resources](https://github.com/B3nac/Android-Reports-and-Resources) - HackerOne Reports
* [AppSec](https://github.com/paragonie/awesome-appsec) - Resources for learning about application security.
* [Infosec](https://github.com/onlurking/awesome-infosec) - Information security resources for pentesting, forensics, and more.
* [YARA](https://github.com/InQuest/awesome-yara) - YARA rules, tools, and people.
* [macOS-Security-and-Privacy-Guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide)
* [awesome-security-weixin-official-accounts](https://github.com/DropsOfZut/awesome-security-weixin-official-accounts) 
* [2018-2020 Youth Security Circle - Active Technology Bloggers/Blogs](https://github.com/404notf0und/Security-Data-Analysis-and-Visualization) - by 404notf0und
* [996.Leave](https://github.com/623637646/996.Leave)
* [Renting Tips for Beijing, Shanghai, Guangzhou, Shenzhen, Hangzhou](https://github.com/soulteary/tenant-point)
* [Beijing House Buying](https://github.com/facert/beijing_house_knowledge)
* [Beijing House Buying Guide](https://github.com/yangyiRunning/Beijing-House)
* [Shanghai House Buying](https://github.com/ayuer/shanghai_house_knowledge)
* [Hangzhou House Buying](https://github.com/houshanren/hangzhou_house_knowledge)
* [awesome-macOS](https://github.com/iCHAIT/awesome-macOS) - mac software
* [awesome-mac](https://github.com/jaywcjlove/awesome-mac/blob/master/README-zh.md#%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7) - mac software
* [ruanyf](https://github.com/ruanyf/weekly) - Technology Lovers Weekly

## Security
### Security list

* [arxiv.org](https://arxiv.org/) Paper library
* [404notf0und Learning Records](https://github.com/404notf0und/Always-Learning#APT%E6%A3%80%E6%B5%8B) Focus on the security detection part
* [Donot's collection of intrusion detection related content](https://github.com/donot-wong/SecAcademic)
* [Zheng Han - Blog](https://www.cnblogs.com/littlehann/) Browse through
* [cdxy - Blog](https://www.cdxy.me/) Very handsome
* [zuozuovera - Blog](https://www.zuozuovera.com/) Deft and skillful
* [Security Academic Circle 2018 Annual Summary](https://mp.weixin.qq.com/s/eQ5os0Fdb498BoQLKUDmrA) - WeChat official account Security Academic Circle
* [security-hardening](https://github.com/decalage2/awesome-security-hardening) Complete security hardening guide

### Security Market Insights
Introduces security market overview, trends, patterns. Domestic and foreign security vendors.

* [XDef Security Summit 2021](https://mp.weixin.qq.com/s/RlEu_qVaj1rIhBuf0vQp8g)

### Cloud Security
#### Cloud Basics

* [Introduction to Virtualization](https://yuvaly0.github.io/2020/06/19/introduction-to-virtualization.html)
* [kvm](https://github.com/yifengyou/learn-kvm) yifengyou's kvm notes

#### Cloud Native Security

* [Google: BeyondProd Model](https://cloud.google.com/security/beyondprod?hl=zh-cn)
* [Meituan Cloud Native Container Security Practice](https://tech.meituan.com/2020/03/12/cloud-native-security.html) 
* [Cloud Native Intrusion Detection Trend Observation](https://xz.aliyun.com/t/7841)
* [Cloud Security Opportunities Brought by Cloud Native](https://www.freebuf.com/articles/network/242950.html) Cloud Native Security Market Overview (non-technical)
* [Alibaba Cloud Security White Paper](https://github.com/tom0li/collection-document/blob/master/%E9%98%BF%E9%87%8C%E4%BA%91%E5%AE%89%E5%85%A8%E7%99%BD%E7%9A%AE%E4%B9%A6.pdf)

#### Cloud Attack and Defense

* [Awesome-serverless](https://github.com/puresec/awesome-serverless-security/)
* [Cloud Native Penetration](https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g)  neargle's records on cloud native penetration, introducing services that may be encountered during cloud native penetration and corresponding testing ideas, currently the most comprehensive public introduction to cloud native penetration in China
* [Red Teaming for Cloud](https://mp.weixin.qq.com/s/lUHd6lmFl3m9BMdSC2wwcw) Clearly explains what red team is and some typical cloud pentest paths
* [tom0li: Docker Escape Summary](https://tom0li.github.io/Docker%E9%80%83%E9%80%B8%E5%B0%8F%E7%BB%93%E7%AC%AC%E4%B8%80%E7%89%88/) Introduces 3 types of Docker escape methods from an attack perspective, introduces some escape real-world scenarios and attack methods for engineers
* [Kubernetes security](https://github.com/kabachook/k8s-security) This repo is a collection of kubernetes security stuff and research.
* [serverless functions attack and defense preliminary exploration](https://www.cdxy.me/?p=836) Introduces serverless functions attack paths and defense detection techniques
* [RDS Database Attack and Defense](https://xz.aliyun.com/t/8451) Using leaked non-sub ACCESSKEY, can be configured to connect to RDS externally
* [Collision of Containers and Cloud: A Test on MinIO](https://mp.weixin.qq.com/s/X04IhY9Oau-kDOVbok8wEw) Mainly MinIO object storage SSRF vulnerability, POST SSRF 307 redirect construction exploitation
* [Security Risks of Using Helm2 in Kubernetes](http://rui0.cn/archives/1573) Explains specific operations for obtaining secrets through Helm2
* [K8s 6443 Batch Intrusion Investigation](https://www.cdxy.me/?p=833) Improper authentication configuration allows anonymous users to make privileged requests to k8s API, request pod creation of docker, execute malicious commands in docker, delete created pods
* [K8s Penetration Testing Exploiting kube-apiserver](https://www.cdxy.me/?p=839) Introduces classic attack path, finding high-privilege service accounts in acquired pods
* [K8s Penetration Testing Exploiting etcd](https://www.cdxy.me/?p=827) Introduces commands for unauthorized etcd and attackers with cert to exploit, read service account token, cluster takeover
* [K8s Data Security Secrets Protection Scheme](https://www.cdxy.me/?p=832)
* [Fantastic Conditional Access Policies and how to bypass them](https://dirkjanm.io/assets/raw/fantastic_policies_cloud_roundup.pdf) Dirk-jan's Azure topic
* [I’m in your cloud: A year of hacking Azure AD](https://dirkjanm.io/assets/raw/Im%20in%20your%20cloud%20bluehat-v1.0.pdf) Dirk-jan's Azure topic
* [Istio Access Authorization Exposes High-Risk Vulnerability CVE-2020-8595 Again](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247487481&idx=1&sn=02a38db691331634fe41a413beb58694&chksm=e84fa926df382030ac57be9c1ee9cb8836ec37fc79e3a2cef68acb6945a51f0ed94882e39611) Istio exact match mode improper matching leads to unauthorized access

#### VM 
##### vCenter
* [CVE-2021-21972 vCenter 6.5-7.0 RCE Vulnerability Analysis](http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/)
* [VMware vCenter RCE Vulnerability Pitfall Record—What Knowledge Can a Simple RCE Vulnerability Dig Out?](https://mp.weixin.qq.com/s/eamNsLY0uKHXtUw_fiUYxQ) Explains why you cannot upload files by modifying packets in Burp

##### SLP
* [CVE-2020-3992 & CVE-2021-21974: Pre-Auth Remote Code Execution in VMware ESXi ](https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi) Introduces two CVEs: VMware's SLP maintained on top of openSLP has a UAF vulnerability and can bypass patches

### AI Security
* [AI-for-Security-Learning](https://github.com/404notf0und/AI-for-Security-Learning) The power of AI - by 404notf0und
* [0xMJ:AI-Security-Learning](https://github.com/0xMJ/AI-Security-Learning#webshell%E6%A3%80%E6%B5%8B)
* [Adversarial ML Threat Matrix](https://github.com/mitre/advmlthreatmatrix)  Adversarial attacks against Machine Learning systems
* [Threat Risk Matrix for AI Security](https://ai.tencent.com/ailab/media/AI%E5%AE%89%E5%85%A8%E7%9A%84%E5%A8%81%E8%83%81%E9%A3%8E%E9%99%A9%E7%9F%A9%E9%98%B5.pdf)
* [Exploration of Machine Learning-Based Web Admin Background Identification Method](https://security.tencent.com/index.php/blog/msg/176) Introduces the design overview of Tencent's internal traffic system background identification module

### New Security Solutions
#### Building Next-Generation Security

* [Elastic Security Network - Building Next-Generation Secure Internet](https://mp.weixin.qq.com/s/epFSC88J7LF3BGwQdoZ-Rg)

#### Zero Trust

* [Zhang Ou: Trusted Network Practice for Digital Banks](https://mp.weixin.qq.com/s/VRG9LEbGTxhpMmCUTUSA8w) Zero trust concept
* [Zero Trust Proxy Tool](https://github.com/mandatoryprogrammer/CursedChrome/blob/master/README.md) Use Chrome as a proxy, can access web services that the victim can access through Chrome

#### DevSecOps

* [DevSecOps Concepts and Thoughts](https://mp.weixin.qq.com/s/_jBmFdtyXY5D_YrrTUP1iQ) Tencent Security Emergency Response Center
* [Awesome-DevSecOps](https://github.com/devsecops/awesome-devsecops)

### Threat Detection
* [Some Myths about Security Intelligence Applications](https://zhuanlan.zhihu.com/p/88042567)

#### RASP

* [Talking about RASP](https://lucifaer.com/2019/09/25/%E6%B5%85%E8%B0%88RASP/)
* [Based on OpenRASP - Elaborating on RASP Class Loading](https://xz.aliyun.com/t/8148)

#### HIDS

* [Distributed HIDS Cluster Architecture Design](https://www.cnxct.com/distributed-hids-cluster-architecture-design/) Meituan Technology Team

#### WAF
##### WAF Construction Guide

* [WAF Construction, Operation, and AI Application Practice](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651199346&idx=1&sn=99f470d46554149beebb8f89fbcb1578&chksm=bd2cf2d48a5b7bc2b3aecb501855cc2efedc60f6f01026543ac2df5fa138ab2bf424fc5ab2b0&scene=21#wechat_redirect)

##### BypassWAF

* [Menshen WAF Crowdtesting Summary](https://mp.weixin.qq.com/s/w5TwFl4Ac1jCTX0A1H_VbQ)
* [Personal Summary of WAF Bypass Injection Ideas (With 6 Common WAF Bypass Methods)](https://www.t00ls.net/viewthread.php?tid=43687&extra=&page=1)
* [Veteran Drives You Through Common WAF](https://www.secpulse.com/archives/69983.html)
* [Some Tips for SQL Injection ByPass](https://mp.weixin.qq.com/s/fSBZPkO0-HNYfLgmYWJKCg)
* [Bypassing WAF at the HTTP Protocol Level](https://www.freebuf.com/news/193659.html)
* [Using Chunked Transfer to Defeat All WAF](https://www.anquanke.com/post/id/169738)
* [Shortcuts and Methods for WAF Bypass](https://www.qiaoyue.net/2019/WAF%E7%BB%95%E8%BF%87%E7%9A%84%E6%8D%B7%E5%BE%84%E4%B8%8E%E6%96%B9%E6%B3%95/)
* [Some Understanding of Bypassing WAF](http://static.anquanke.com/download/b/security-geek-2019-q2/article-18.html)
* [WAF Bypass: Webshell Upload jsp and Tomcat](https://www.anquanke.com/post/id/210630#)
* [Various Ways jsp webshell](https://xz.aliyun.com/t/7798)

#### Webshell Detection

* [Killing Java web filter-type Memory Webshell](http://gv7.me/articles/2020/kill-java-web-filter-memshell/)
* [Scanning, Capturing, and Killing Filter/Servlet Type Memory Webshells](https://gv7.me/articles/2020/filter-servlet-type-memshell-scan-capture-and-kill/)
* [Miscellaneous Talk: Java Memory Webshell Attack and Defense](https://mp.weixin.qq.com/s/DRbGeVOcJ8m9xo7Gin45kQ) 
* [JSP Webshell Those Things -- Attack Chapter](https://mp.weixin.qq.com/s/YhiOHWnqXVqvLNH7XSxC9w)
* [Webshell Attack and Defense PHP](https://github.com/qiyeboy/kill_webshell_detect/blob/master/%E7%9F%A5%E8%AF%86%E6%98%9F%E7%90%83-webshell%E6%94%BB%E4%B8%8E%E9%98%B2.pdf) 
* [Application of Taint Tracking Theory in Webshell Detection - PHP Chapter](https://mp.weixin.qq.com/s/MFmSliCQaaVEQ0E66vN5Xg)
* [New Start: Webshell Detection](https://iami.xyz/New-Begin-For-Nothing/)
* [Inject Spring Memory Webshell Using Interceptor](https://github.com/LandGrey/webshell-detect-bypass/blob/master/docs/inject-interceptor-hide-webshell/inject-interceptor-hide-webshell.md) Article is from an attack exploitation perspective

#### Reverse Shell Detection

* [Reverse Shell Principle and Detection Technology Research](https://www.cnblogs.com/LittleHann/p/12038070.html) - by LittleHann
* [Reverse Shell Analysis](https://cloud.tencent.com/developer/article/1645464)
* [Detailed Explanation of Multi-dimensional Reverse Shell Detection Technology](https://www.freebuf.com/articles/network/263684.html)

#### EDR

* [Lets-create-an-edr-and-bypass](https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/)
* [openedr](https://github.com/ComodoSecurity/openedr) Open source product edr

#### AV

* [exploiting-almost-every-antivirus-software](https://www.rack911labs.com/research/exploiting-almost-every-antivirus-software/) Counter AV, use link method to borrow AV high privilege to achieve arbitrary file deletion
* [Bypassing Windows Defender Runtime Scanning](https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/) Enumerate and test which API calls trigger Defender detection. Found that creating CreateProcess and CreateRemoteThread triggers Defender. Proposes three solutions: rewrite API calls, add/modify instructions for dynamic decryption loading, make Defender not scan that area. Author analyzes Defender's scanning mechanism (virtual memory is large, only scans MEM_PRIVATE or RWX page permissions). When suspicious APIs are called, dynamically set PAGE_NOACCESS memory permission so Defender does not perform security scanning.
* [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)
* [Bypass Windows Defender Attack Surface Reduction](https://data.hackinn.com/ppt/OffensiveCon2019/Bypass%20Windows%20Exploit%20Guard%20ASR.pdf)
* [Defender scanning filename issue](http://2016.eicar.org/85-0-Download.html)
* [herpaderping](https://github.com/jxy-s/herpaderping) A new type bypass defender 
* [Implement a shellcodeLoader](https://paper.seebug.org/1413/) Introduces some shellcode execution methods, bypass sandbox methods
* [Malware_development_part](https://0xpat.github.io/Malware_development_part_5/) Malware series tutorial
* [Antivirus Detection and Its Hook Point List](https://github.com/D3VI5H4/Antivirus-Artifacts/blob/main/ANTIVURUS_ARTIFACTS.pdf)

#### Lateral Movement Detection - Honeypot Approach

* [Honeypots](https://github.com/paralax/awesome-honeypots) - Honeypots, tools, components, and more.
* [Hunting for Skeleton Key Implants](https://riccardoancarani.github.io/2020-08-08-hunting-for-skeleton-keys/) Detect Skeleton Key persistence
* [Creating Honeypot Accounts to Detect Kerberoast](https://www.pentestpartners.com/security-blog/honeyroasting-how-to-detect-kerberoast-breaches-with-honeypots/)

#### Malicious Traffic Detection

* [DataCon2020 Solution: Tracking Botnet via Honeypots and DNS Traffic](https://www.cdxy.me/?p=829)
* [DNS Tunnel Covert Communication Experiment && Attempt to Reproduce Feature Vectorization Detection Method](https://www.cnblogs.com/LittleHann/p/8656621.html#_label0)
* [maltrail](https://github.com/stamparm/maltrail#introduction) Open source traffic detection product
* [cobalt-strike-default-modules-via-named-pipe detection](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) Detect memory pipe of CS default module after execution after shell
* [Using DNS Data for Threat Discovery](https://mp.weixin.qq.com/s/6CtRd7o4IjreLaU-hFt9vQ) Introduces 360 DNSMON using DNS monitoring to find skidmap backdoor, some analysis techniques
* [DNSMon: Using DNS Data for Threat Discovery](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence-2/) Monitor events through DNSMON, correlate analysis of events
* [evading-sysmon-dns-monitoring](https://blog.xpnsec.com/evading-sysmon-dns-monitoring/)
* [use-dns-data-produce-threat-intelligence](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence/)



#### IDS

* [Let's Talk About IDS Signatures](https://www.anquanke.com/post/id/102948#h2-0)
* [Out-of-Order TCP Packets](https://strcpy.me/index.php/archives/789/)
* [Some Explorations on Network Layer Bypassing IDS/IPS](https://paper.seebug.org/1173/)

#### Text Detection

* [Application of Machine Learning in Binary Code Similarity Analysis](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458303210&idx=1&sn=345f8cec156ada8fa9bf6a6d6de83906&chksm=b1818a6086f60376e766baf472171d8e2c780b2913568b46b683e3112fcc5f86c9bf4c19e38b&mpshare=1&scene=1&srcid=&sharer_sharetime=1580984631757&sharer_shareid=5dc01f49f38fd64ff3e64844bc7d2ea7&exportkey=A0qHBeUryuXO6zhGWt5OJNw%3D&pass_ticket=gjTFXl4hPMTBWzlKpWZWqK8HivXQ8q7ChNndmw4I8JrdAK0jWWFvKIq7OMnO3BhL#rd)



### Security Operations

* [How to Evaluate the Quality of Security Work](https://zhuanlan.zhihu.com/p/226493047) Tencent 'Professional Owe Money' some sharing on upward management

### Data Security

* [Internet Enterprise Data Security System Construction](https://tech.meituan.com/2018/05/24/data-security-system-construction.html)
* [Talking about Data Security](https://iami.xyz/Talk-about-data-security/)

#### Network Mapping
* [Brief Discussion on the Art of Cyberspace Mapping](https://www.anquanke.com/post/id/226007)
* [Making Cyberspace Mapping Technology No Longer Unstable](https://mp.weixin.qq.com/s/lr39F9kNOfHlMimgymzVwg) by Zhao Wu, focus points of network mapping
* [Record Some Materials Related to Cyberspace Mapping/Search Engines](https://github.com/EXHades/CyberSpaceSearchEngine-Research)

### Communication Security
#### End-to-End Communication (First Edition)
* [The Most Comprehensive Introduction to Zoom Vulnerabilities and Fixes](https://mp.weixin.qq.com/s/a7mN0lTeXxA3YmZZxIGNRg)
* [Traffic Analysis Attack Against Secure Instant Messaging Software](https://www.anquanke.com/post/id/208678#)
* [Analysis of Data Confidentiality Principle of Shadowsocks Based on Secondary Obfuscation Encryption Transmission](https://www.secrss.com/articles/18469)

#### SNI
* [ESNI](https://www.cloudflare.com/zh-cn/learning/ssl/what-is-encrypted-sni/)  what-is-encrypted-sni
* [encrypted-client-hello-the-future-of-esni-in-firefox](https://blog.mozilla.org/security/2021/01/07/encrypted-client-hello-the-future-of-esni-in-firefox/)
* [encrypted-client-hello](https://blog.cloudflare.com/encrypted-client-hello/)

### Personal Security* [Tor-0day-Finding-IP-Addresses](https://www.hackerfactor.com/blog/index.php?/archives/896-Tor-0day-Finding-IP-Addresses.html)
* [lcamtuf: Disaster Plan](https://lcamtuf.coredump.cx/prep/)
* [tom0li: Personal Privacy Protection](https://tom0li.github.io/%E4%B8%AA%E4%BA%BA%E9%9A%90%E7%A7%81%E4%BF%9D%E6%8A%A4/) Privacy protection ideas for ordinary people
* [Protect Privacy](https://github.com/No-Github/Digital-Privacy) A list of methods for digital privacy collection
* [Supercookie Browser Fingerprinting](https://supercookie.me/workwise) Supercookie uses favicons to assign a unique identifier to website visitors. Uses multiple visited URLs to distinguish users.

### APT Research
Most of the content listed earlier is offensive in nature, including APT tracking reports, etc.

#### Advanced Threat List

* [Red-Team-Infrastructure-Wiki](https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki)
* [Collection of APT Analysis Reports](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections) Highly recommended
* [On the Nature of Advanced Threats and Quantitative Research on Attack Capabilities](http://www.vxjump.net/files/aptr/aptr.txt)
* [OffensiveCon Conference](https://www.offensivecon.org/) (Will not list them one by one)
* [ATT&CK](https://attack.mitre.org/matrices/enterprise/)
* [Red Team Practice and Thinking from 0 to 1](https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg) Introduces what Red Team is, suitable for internal red team building
* [MITRE | ATT&CK Chinese Site](https://huntingday.github.io) Knowledge map, no longer updated
* [FireEye Threat Research](https://www.fireeye.com/blog/threat-research.html) Well-known threat analysis company
* [red-team-and-the-next](https://devco.re/blog/2019/10/24/evolution-of-DEVCORE-red-team-and-the-next/) -by DEVCORE

Anti Threat articles by redrain and their team
* [Noah blog](http://noahblog.360.cn/)  Anti Threat and Threat Actors through Noah Lab Analysts
* [Beacon Lab blog](https://blogs.360.cn/)
* [APT analysis and TTPs extraction](https://paper.seebug.org/1132/)
* [Discussion on ATT&CK/APT/Attribution](https://weibo.com/ttarticle/p/show?id=2309404450471736639616)
* [Legends Always Die -- Brief description of the League of Legends supply chain attack at FireEye Summit](https://card.weibo.com/article/m/show/id/2309404426957856047151) Tracing a supply chain attack, basic information such as domain/IP/email, linking to historical APT activities
* [XShellGhost Incident Technical Review Report](https://cert.360.cn/static/files/XShellGhost%E4%BA%8B%E4%BB%B6%E6%8A%80%E6%9C%AF%E5%9B%9E%E9%A1%BE%E6%8A%A5%E5%91%8A.pdf)
* [Kingslayer A supply chain attack](http://www.hackdog.me/article/Kingslayer-A_supply_chain_attack--Part_1.html)

SolarWinds Supply Chain Analysis
* [Looking at covert operations in APT activities from the SolarWinds supply chain attack (Golden Chain Bear)](https://mp.weixin.qq.com/s/UqXC1vovKUu97569LkYm2Q) Representing Qianxin's analysis of SolarWinds attack behavior
* [SolarWinds Analysis](https://go.recordedfuture.com/hubfs/reports/pov-2020-1230.pdf) 
* [Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)
* [SUNBURST analysis other details](https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html)

#### Threat Intelligence
* [Indictment against North Korea](https://www.justice.gov/opa/press-release/file/1092091/download) A categorization process that took ten years
* [A brief discussion on 'attribution' of cyber attacks](https://www.secrss.com/articles/14864) Introduces some indicators and methods for APT attribution (reference Cyber Attribution documents) and some attribution documents
* [What is threat intelligence](https://www.secrss.com/articles/16577) Introduces the definition, classification, and indicators of threat intelligence, and explains the attribution and categorization process through some cases

#### Phishing
* [Introduction to SMTP user enumeration and related tools](http://www.freebuf.com/articles/web/182746.html) - Used to obtain user dictionary
* [Spear Phishing Attack](https://payloads.online/archivers/2020-02-05/1)
* [On how to counter hackers using AWVS](http://www.freebuf.com/news/136476.html)
* [The path of counterattack starting from MySQL](https://xz.aliyun.com/t/3277)
* [Mysql Client arbitrary file read attack chain expansion](https://paper.seebug.org/1112/)
* [Malicious MySQL Server reads files from MySQL Client](http://scz.617.cn/network/202001101612.txt)
* [https://github.com/BloodHoundAD/BloodHound/issues/267](https://github.com/BloodHoundAD/BloodHound/issues/267) -xss
* [Ghidra from XXE to RCE](https://xlab.tencent.com/cn/2019/03/18/ghidra-from-xxe-to-rce/) Targeting engineers
* [Security risks from WeChat cheats](https://xlab.tencent.com/cn/2018/10/23/weixin-cheater-risks/) Targeting individuals
* [Node.js repository phishing](https://www.cnblogs.com/index-html/p/npm_package_phishing.html) Targeting engineers
* [Creating malicious Visual Studio Code extensions](https://d0n9.github.io/2018/01/17/vscode%20extension%20%E9%92%93%E9%B1%BC/#) Targeting engineers
* [VS Code phishing](https://blog.doyensec.com/2020/03/16/vscode_codeexec.html) Targeting engineers
* [Python package phishing](https://paper.seebug.org/326/)   Targeting engineers
* [Docker client phishing](https://www.blackhat.com/docs/us-17/thursday/us-17-Cherny-Well-That-Escalated-Quickly-How-Abusing-The-Docker-API-Led-To-Remote-Code-Execution-Same-Origin-Bypass-And-Persistence.pdf) Targeting engineers
* [Attacking local Xdebug using malicious pages](https://xlab.tencent.com/cn/2018/03/)   Targeting engineers
* [Huawei HG532 router phishing RCE](https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/) Targeting individuals
* [Intranet phishing]()```
RMI反序列化
WIN远程连接漏洞CVE-2019-1333
Mysql读文件&反序列化
Dubbo反序列化
IDE反序列化
恶意vpn
恶意控件
笔记软件rce
社交软件rce
NodeJS库rce
Python package 钓鱼
VSCODE EXTENSION 钓鱼
VS Studio钓鱼
Twitter钓鱼
红包插件钓鱼防撤回插件
解压rce
破解软件钓鱼
docker客户端钓鱼
docker镜像钓鱼
Xdebug
Ghidra钓鱼
bloodhound钓鱼
AWVS钓鱼
蚁剑
浏览器插件
云盘污染
  • ..etc

Email Spoofing

  • Exploration Triggered by a Forged Email (Involving Phishing Emails, SPF, DKIM, etc.)
  • SPF Record: Introduction to Principles, Syntax, and Configuration Methods
  • Email Spoofing Techniques and Detection
  • Discussion on Forging Emails and Creating Email Bombs
  • Bypassing DKIM Verification to Forge Phishing Emails
  • Best Practices on Email Protection: SPF, DKIM and DMARC
  • Cobalt Strike Spear Phish
  • Gsuite SMTP inject

C2-RAT

For now, just a simple listing

  • Koadic C3 COM Command & Control - JScript RAT
  • QuasarRAT
  • CS

Alerts & Research

  • Top 10 Web Hacking Techniques of 2017 - an awesome website
  • Top-10-web-hacking-techniques-of-2018
  • Security PPT Collection
  • us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA -Orange pwn vpn
  • Bypassing Sandbox -yuange
  • Application of Compiler Principles in Security
  • Application of Software-Defined Radio and Open Source Base Stations in Vulnerability Discovery PART 4: Some Exploration and Learning Resource Integration on Baseband Security by Xuebi 0xroot
  • recovering-passwords-from-pixelized-screenshots-sipke-mellema Removing text mosaics, but test conditions are too restrictive: requires same screenshot software, xy coordinates, font, and color

ImageMagick

  • ImageMagick Vulnerability Exploration Notes
  • How to Use Fuzzing to Discover ImageMagick Vulnerabilities
  • ImageMagick-CVE-2016-3714 Command Execution Analysis
  • The Story of Imagemagick Encountering getimagesize

Exchange

  • Microsoft Exchange Vulnerability Record (Pwning Domain Controller) - CVE-2018-8581
  • Using Exchange SSRF Vulnerability and NTLM Relay to Compromise Domain Controller
  • Microsoft Exchange Vulnerability Analysis CVE-2018-8581
  • Analysis of Microsoft Exchange Arbitrary User Forge Vulnerability (CVE-2018-8581)
  • .Net Deserialization: ViewState Exploitation
  • proxylogon
  • Program Implementation for Generating ViewState

Privilege-Escalation

  • Ubuntu-gdm3-accountsservice-LPE

VPN

Sangfor

  • Sangfor Backend RCE
  • Sangfor Frontend RCE - No link because it's not public

Pulse

  • Pulse-secure-read-passwd-to-rce -by orange
  • Pulse Connect Secure RCE CVE-2020-8218
  • Pulse Connect Secure – RCE via Template Injection (CVE-2020-8243)

Palo

  • Attacking SSL VPN - Part 1: PreAuth RCE on Palo Alto GlobalProtect, with Uber as Case Study!

Fortigate

  • Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN

Citrix Gateway/ADC

  • Citrix Gateway/ADC Remote Code Execution Vulnerability Analysis

Tomcat

  • Apache Tomcat 8.x vulnerabilities

FUZZING

  • Awesome-Fuzzing
  • Research and Design of Fuzzing Platform Construction by Quange
  • Exploring Shortcomings in Advanced Automated Vulnerability Discovery Techniques Coverage issues
  • Fuzzing War: From Swords and Bows to Star Wars Flanker explains the historical trends of Fuzzing
  • Fuzzing War Series Part 2: Fear Not the Clouds Blocking the View Coverage-Guided Fuzzing solves closed-source ideas: Static or Dynamic & Dynamic Tracing

Code Audit - JAVA

  • javasec.org -by Yuanzhang
  • Some Tips for Java Code Audit (with Scripts)
  • Minxin Java Code Audit - Step by Step
  • Java Vulnerable Code
  • Code Audit Knowledge Planet Selected

Deserialization - Other

  • Java-Deserialization-Cheat-Sheet
  • Tomcat No-Outbound Echo
  • Multiple Ways of Java Deserialization Echo
  • Semi-automatic Mining of Request to Implement Multiple Middleware Echo
  • Post-Deserialization Exploitation Ideas in Java
  • URL ECCENTRICITIES IN JAVA SSRF, LFI, and Java version disclosure caused by Java URL class requests
  • HSQLDB Security Testing Guide HSQLDB (HyperSQL DataBase) is a small embedded database fully written in Java

RMI

  • Introduction to Java RMI
  • attacking-java-rmi-services-after-jep-290
  • Nine Layers of Attack on RMI Services - Part 1
  • Nine Layers of Attack on RMI Services - Part 2
  • Reflections on an Attack on Internal Network RMI Service Resolving REJECTED Error

Shiro

  • The Exploration Path of Shiro RememberMe Vulnerability Detection From using empty SimplePrincipalCollection to detect keys, to Tomcat universal echo, to various difficulties encountered in the detection process
  • Viewing the Correct Use of Shiro from a Development Vulnerability
  • Shiro RememberMe 1.2.4 Command Execution via Deserialization
  • Qiangwang Cup 'Easter Egg' – Divergent Thinking on Shiro 1.2.4 (SHIRO-550) Vulnerability
  • Analysis of Shiro 721 Padding Oracle Attack Vulnerability
  • Analysis of Shiro Permission Bypass Vulnerability
  • Application of Dynamic Class Loading in Java Code Execution Vulnerabilities Registering filter reGeorg proxy without outbound network

Fastjson

  • Fastjson Deserialization Exploitation
  • Brief Analysis of FastJson <= 1.2.47 Deserialization Vulnerability
  • Fastjson Deserialization: JNDI-Based Exploitation Method
  • Debugging Analysis of Fastjson Deserialization Vulnerability
  • Learning FastJson Deserialization
  • A Brief Discussion on the History of Bypassing Fastjson RCE Vulnerabilities
  • Several Methods to Detect Fastjson via DNSLog
  • A Discovery Approach for Fastjson 1.2.68 Autotype Bypass Gadget

Dubbo

  • Analysis of Dubbo 2.7.7 Deserialization Vulnerability Bypass Yunding Lab
  • Multiple Remote Code Execution Vulnerabilities in Dubbo 2.7.8
  • How to Bypass High-Version JDK Restrictions for JNDI Injection Bypass high-version JDK restrictions by using LDAP to return serialized data, triggering local gadgets. Why under Dubbo? Because the problem was encountered in Dubbo.

CAS

  • Analysis of Apereo CAS 4.X execution Parameter Deserialization Vulnerability
  • Analysis and Echo Exploitation of Apereo CAS Deserialization Vulnerability

Solr Template Injection

  • Apache Solr Injection Research
  • In-depth Analysis of Apache Solr Velocity Template Injection Vulnerability
  • Analysis of Apache Solr Velocity Template Remote Command Execution Vulnerability
  • solr-injection

Apache Skywalking

  • Analysis of Apache Skywalking Remote Code Execution Vulnerability

Spring

Spring-boot

  • Spring Boot Vulnerability Exploit CheckList
  • Java Secure Development: Spring Boot Thymeleaf Template Injection

Spring-cloud

  • Spring Cloud Config Server Path Traversal and Arbitrary File Read Vulnerability CVE-2019-3799

Spring-data

  • Spring Data Redis <=2.1.0 Deserialization Vulnerability

Blockchain

  • Knowledge Base SlowMist Security Team Knowledge Base
  • SlowMist Security Team GitHub

Penetration

Boundary Penetration

Penetration Records and Summaries

  • hacked-Facebook -by Orange
  • Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out -Orange's Pandora's Box
  • Penetration Testing Standard
  • pentest-bookmarks
  • awesome-pentest - A collection of awesome penetration testing resources.
  • Pentest Cheat Sheets - Awesome Pentest Cheat Sheets.
  • Pentesting checklists for various engagements
  • pentest-wiki
  • Micropoor
  • Penetration Testing Practice Third Edition (Red Team Edition)
  • Web Service Penetration Testing from Beginner to Master
  • Old Article: A Difficult Penetration Record
  • The Process of Penetrating Hacking Team
  • SSRF Internal Network Roaming
  • Penetration Record 1
  • Penetration Record 2
  • tom0li: Summary of Logic Vulnerabilities
  • Common Vulnerabilities in Web Middleware Summary

Information Gathering

  • Information Gathering Techniques from a Red Team Perspective
  • Penetration Tool Series: Search Engines
  • Google Hacking Database
  • Google Hacking
  • Automated Exploitation with Shodan
  • Some Uses of Shodan in Penetration Testing and Vulnerability Discovery
  • Detailed Explanation and Usage Tips for Shodan's http.favicon.hash Syntax
  • Shodan Manual - Chinese
  • Shodan Manual dorks

Labs

  • vulhub
  • vulfocus

Penetration Techniques

  • BurpSuite Multi-Proxy
  • Frida.Android.Practice (ssl unpinning)
  • Bypassing Script Execution Permission Restrictions on IIS7 and Above
  • Combined Use of SQL Second-Order Injection and Truncation
  • Supplementary Explanation of SQL Second-Order Injection and Truncation
  • New Way to Get Shell via phpMyAdmin - Requires ROOT privileges to set parameters
  • phpMyAdmin 4.8.1 Backend GetShell
  • Bypassing Lighttpd Rewrite Rules with Invalid HTTP Requests
  • RFI Bypass URL Inclusion Restrictions to Get Shell Windows server PHP file inclusion bypassing allow_url_fopen and allow_url_include = off
  • 2 Ideas - Read system info from connected MySQL client, upload
  • PayloadsAllTheThings - Complete Payloads Collection
  • Using JNI Technology to Bypass RASP Protection and Implement JSP Webshell
  • Improper Proxy Leads to Internal Network Access
  • Brief Analysis of Reverse Proxy
  • Introduction to iptables
  • Combining Direct System Calls and sRDI to Bypass AV/EDR
  • FB Django Debug Stacktrace RCE

Internal Network Penetration

Some of the previously provided articles contain errors and need practical verification.

  • AD-Attack-Defense
  • l3m0n: Learning Internal Network Penetration from Scratch
  • uknowsec / Active-Directory-Pentest-Notes
  • Intranet_Penetration_Tips
  • A Summary of an Internal Network Penetration Against a Foreign Target - Old article for beginners to practice
  • Post-Exploitation Against a Major Domestic Company – Continuous - Practical beginner
  • A Record of a Lateral Penetration
  • Internal Network Penetration Record Keywords: delegation, relay, bypassAV, webdev XXE - by A-TEAM
  • Introduction to Windows Internal Network Penetration - by Tencent Security Department
  • NTLM-Relay

Exchange Exploitation (Old)

  • In-depth Exploration of Exchange Server Exploitation in Network Penetration
  • Exploitation of Exchange in Penetration Testing
  • Microsoft Exchange Vulnerability Record (Pwning Domain Controller) - CVE-2018-8581
  • Using Exchange SSRF Vulnerability and NTLM Relay to Compromise Domain Controller
  • Microsoft Exchange Vulnerability Analysis
  • Analysis of Microsoft Exchange Arbitrary User Forge Vulnerability (CVE-2018-8581)
  • Reproduction and Analysis of Exchange Server Remote Code Execution Vulnerability

hash ticket Credential

  • Methods of Stealing NetNTLM Hashes in Various Ways
  • The Open Gates of Hell: Abuse of the Kerberos Protocol
  • NTLM-Relay
  • Practical guide to NTLM Relaying in 2017
  • The worst of both worlds: Combining NTLM Relaying and Kerberos delegation
  • Red Team and Theory: Credential Relay and EPA
  • Advanced Domain Penetration Technique: Pass-the-Hash is Dead, Long Live LocalAccountTokenFilterPolicy
  • Learning Windows Internal Network Protocols: NTLM Vulnerability Overview
  • Introduction to Kerberos

Proxy Forwarding and Port Reuse

  • Penetration Testing Techniques: Summary of Internal Network Tunneling Methods and Ideas
  • Internal Network Roaming: The End of SOCKS Proxy
  • iptables Port Reuse
  • Driver-Level Port Reuse
  • Web Service Middleware Port Reuse
  • Windows IIS Port Reuse

Internal Network Platforms

Recommend reading the official manuals

  • Three Swordsmen of Internal Network
  • Penetration Weapon Cobalt Strike - Part 2: Comprehensive Bypass of AV at APT Level and Confrontation with Enterprise Defense-in-Depth
  • Cobalt Strike Modification Guide
  • Metasploit Gallops Through Internal Network Straight to Domain Admin's Head
  • Master PowerShell Empire 2.3 in One Article (Part 1)
  • Master PowerShell Empire 2.3 in One Article (Part 2)
  • PowerShell Attack Guide: Hacker Post-Exploitation Series – Basics
  • PowerShell Attack Guide: Hacker Post-Exploitation Series – Advanced Exploitation
  • PowerShell Attack Guide: Hacker Post-Exploitation Series – Practical
  • nishang-ps
  • Practical Empire Domain Penetration

Internal Network Techniques* Penetration Tip - Multi-user Login for Windows Remote Desktop

  • Penetration Tip - Hiding Your Tools
  • A Technique for Downloading Malicious Code from Whitelist
  • Download Malicious Code from Whitelist
  • One Command to Achieve a Fileless and Highly Compatible Reverse Backdoor, Collected from the Powerful Former WooYun
  • Penetration Tip - Multiple Methods to Download Files from GitHub
  • Penetration Tip - Switching from Admin to System Privilege
  • Penetration Tip - Launching Programs with Reduced Privileges
  • Force VPN for Internet Access, Disconnect when VPN Drops
  • IP Proxy Tool shadowProxy - Proxy Pool
  • Penetration Tip - Hiding Accounts in Windows Systems
  • Penetration Tip - More Tests on "Hiding" the Registry
  • Penetration Tip - Deleting and Bypassing Windows Logs
  • Penetration Tip - Token Theft and Exploitation
  • Domain Penetration - Obtaining the NTDS.dit File of the Domain Controller
  • Penetration Tip - Obtaining Windows Remote Desktop Connection History

Privilege Escalation

  • linux-kernel-exploitation - A must-read for Linux kernel exploitation
  • Windows Privilege Escalation Helper Tool
  • windows-kernel-exploits - Collection of Windows Privilege Escalation Vulnerabilities
  • linux-kernel-exploits - Collection of Linux Privilege Escalation Vulnerabilities
  • Detailed Explanation of Linux Privilege Escalation Attacks and Defense - Getting started guide

Bug_Bounty

  • bug bounty writeups - Similar to WooYun vulnerability database.
  • hackone-hacktivity - If you finish this, you don't need to look at the Bug_Bounty section below.
  • awesome-bug-bounty - A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug Bounty hunters
  • Recon
  • bugbounty-cheatsheet
  • bug-bounty-reference
  • Web Hacking 101 Chinese Edition
  • Webmin <=1.920 Remote Command Execution Vulnerability - CVE-2019-15107 - Concise
  • Webmin CVE-2019-15642
  • Getting Started with Chrome Ext Security (Part 1) -- Understanding a Chrome Ext
  • Getting Started with Chrome Ext Security (Part 2) -- Secure Chrome Ext
  • Security Issues of URL Schemes on PC from CVE-2018-8495
  • Brief Discussion on Short URL Security

Web

XXE

  • XXE (XML External Entity Injection) Vulnerability Practice
  • How to Discover XXE Injection Vulnerability on Uber's Website
  • What Do We Think of When XXE is Mentioned
  • Simple Understanding and Testing of XXE Vulnerability
  • XXE Vulnerability Detection and Code Execution Process
  • Discussion on XXE Vulnerability Attack and Defense
  • XXE Vulnerability Analysis
  • XML Entity Injection Vulnerability Attack and Defense
  • Exploitation and Learning of XML Entity Injection Vulnerability
  • XXE Injection: Attack and Prevent
  • Hunting in the Dark - Blind XXE
  • Hunting in the Dark - Blind XXE
  • XML External Entity Vulnerability Training Module
  • My View on XXE Vulnerability Attack and Defense
  • Some Techniques for Exploiting XXE Vulnerabilities
  • Magical Content-Type - Playing XXE Attacks in JSON
  • XXE-DTD Cheat Sheet
  • Bypassing XXE Detection in Some CMSs via Encoding

XSS

  • AwesomeXSS
  • Discussion on XSS - Character Encoding and Browser Parsing Principles
  • Deep Understanding of XSS Encoding - Browser Parsing Principles
  • Common XSS Exploitation Code and Principles
  • Front-end Defense from Beginner to Abandon - CSP Evolution
  • XSS Testing Memo
  • Discussion on Cross-Site Scripting Attack and Defense
  • The Art of XSS: Fuzzing Techniques
  • From Swiss Army Knife to Transformer - Expanding XSS Attack Surface
  • Penetration Testing Technique: Exploitation and Reflection Triggered by an XSS
  • XSS Bypass Using Uppercase
  • XSS Payload Exchange and Research
  • A Record of Discovering a Stored XSS Vulnerability
  • An Adventure in XSS Bypassing
  • Fragrant XSS Notes (Part 1)
  • Black-Hole's Special Topic - Read carefully
  • Intranet XSS Worm
  • Breaking the Black Market: Taking Down Phishing Site Groups for Games like PUBG and DNF
  • Front-end Security Series (1): How to Prevent XSS Attacks?
  • Upload Word File to Create Stored XSS Path

JSONP

  • JSONP Injection Analysis
  • Cross-domain Information Collection Using JSONP
  • Discussion on Same-Origin Policy Attack and Defense
  • Discussion on Cross-domain 11
  • Using Request Merging to Bypass Referer (JSONP) Detection

CORS

  • JSONP and CORS Vulnerability Mining
  • Discussion on Potential Vulnerabilities from CORS
  • Complete Guide to CORS Security

CSRF

  • Some Thoughts on JSON CSRF
  • Discussion on CSRF Attacks in JSON Format

SSRF

  • Some SSRF Techniques
  • Thoughts on SSRF Vulnerability Mining
  • SSRF in Java
  • DNS Auto Rebinding
  • Analysis of Attacking Transmission via DNS Rebinding Bypassing Same-Origin Policy
  • Experience in Mining SSRF Vulnerabilities
  • Understanding SSRF
  • SSRF & Redis
  • Gopher Attack Surfaces
  • Use DNS Rebinding to Bypass SSRF in Java

SQL

  • MySQL Injection Memo
  • Analysis of Character Encoding and SQL Injection in White-Box Auditing
  • In-depth Explanation of Wide Character Injection
  • Several Methods to Write Shell Based on MySQL
  • MSSQL Injection Attack and Defense
  • Process of Obtaining WEB Shell with MSSQL DBA Privileges
  • SQLite Manual Injection GETSHELL Technique

File Inclusion

  • PHP File Inclusion Vulnerability

Upload

  • Upload Vulnerability Range

Arbitrary File Read

  • Research on Novel Arbitrary File Read Vulnerabilities
  • A Record of an Arbitrary File Read Vulnerability
  • Common Dictionary for Arbitrary File Read

Web Cache Deception

  • Web Cache Deception Attack
  • Web Cache Deception Testing

Web Cache Poisoning

  • Practical Web Cache Poisoning

SSI

  • Summary of Server-Side Include Injection (SSI) Analysis

SSTI

  • Research on Server-Side Injection Issues Encountered in Flask Jinja2 Development
  • Research on Server-Side Injection Issues Encountered in Flask Jinja2 Development II

JS

  • The Thing About Websites Forcibly Hijacking Your Clipboard
  • The Dangers and Defense of Referencing External Scripts
  • Two Summaries of Frontend Bypass Penetration
  • How to Brute Force Data Encrypted by the Frontend
  • Thoughts and Methods for Brute Forcing Encrypted Login Credentials

DNS

  • DNS Zone Transfer Vulnerability Learning Summary
  • Implementing DGA Domain Detection with Python
  • DNS-Persist: Remote Control Communication Using DNS Protocol
  • Principles and Examples of Local DNS Attacks
  • Error DNS Response
  • Civilian Solution for DNS Tunnel Detection
  • How DNS Wildcard Resolution Gets Abused by Hackers
  • DNS Tunneling and Related Implementations
  • DNS Zone Transfer Tools
  • Dnslog in SQL Injection Practice

Miscellaneous

Git

  • Methods to Undo Various Git Mistakes
  • Git Tips

QR Code

  • WeChat Netting - QRLJacking Analysis and Exploitation - Scan My QR Code to Get Your Account Permissions
  • Discussion on QR Code Vulnerability Attacks on Android Platform
  • Analysis of Common Defects in QR Code Login
  • QR Code Security - Taobao Example

Crawler

  • Discussion on Dynamic Crawlers and Deduplication
  • Discussion on Dynamic Crawlers and Deduplication (Continued)
  • Crawler Basics [Web Vulnerability Scanner]

Efficiency

Previous ones will be added later

  • chrome-is-bad Reason why Chrome slows down Mac
  • Optimizing zsh and oh-my-zsh Cold Start Speed

Popular Science

  • Top 10 Deep Web Search Engines
  • Seeing Tens of Thousands of Car Owner Information, Enterprise and Government Executive Information, Various Data on Baidu Cloud
  • New Technique Learned from a CTF Challenge
  • iPhone Lockscreen Doesn't Lock Personal Information - Is iOS Really That Secure?
  • Xian Ge's Black Magic Commands Imported from HITB Hacker Conference in Singapore
  • The Importance of Programming: sqlmap Source Code
  • News: More Than 400 Popular Sites Record User Keystrokes, Potentially Leaking Personal Sensitive Information
  • Understanding HTTPS Hijacking
  • Common TCP Troubleshooting
  • Bank Card QuickPass Contactless Chip Reads Private Information via EMV/PBOC
  • Deduplication and Database Import of Text Files
  • Analysis of USB Virus Propagation via File Deception
  • Deep Analysis: The Maginot Line of Mobile Fingerprints
  • Web Scam Slang + Technique Encyclopedia | Qi'an Low-Key Share
  • 1.4 Billion Foreign Data
  • After Word File Encryption
  • Tencent 2017 Annual Report on Cyber Black-Hat Threats

Old```

建设

  • Enterprise_Security_Build--Open_Source
  • 一个人的安全部
  • 没有钱的安全部之资产安全
  • 一个人的企业安全建设实践
  • 单枪匹马搞企业安全建设
  • “一个人”的互金企业安全建设总结
  • 低成本企业安全建设部分实践
  • 饿了么运维基础设施进化史
  • B站日志系统的前世今生
  • 爱奇艺业务安全风控体系的建设实践
  • 美团外卖自动化业务运维系统建设
  • 携程安全自动化测试之路
  • 企业安全中DevSecOps的一些思考
  • 企业安全经验 应急响应的战争
  • 企业安全项目架构实践分享
  • 以溯源为目的蜜罐系统建设
  • 蜜罐与内网安全从0到1(一)
  • 蜜罐与内网安全从0到1(二)
  • 蜜罐与内网安全从0到1(三)
  • 蜜罐与内网安全从0到1(四)
  • 蜜罐与内网安全从0到1(五)
  • 企业安全建设—模块化蜜罐平台的设计思路与想法

加固

  • Linux基线加固
  • 基线检查表&安全加固规范
  • 浅谈linux安全加固
  • CentOS 7 主机加固
  • APACHE 常见加固
  • Apache服务器安全配置
  • GNU/Linux安全基线与加固
  • windows服务器安全配置策略
  • 15步打造一个安全的Linux服务器
  • Tomcat7 加固清单
  • Tomcat安全设置和版本屏蔽
  • IIS服务器安全配置
  • 企业常见服务漏洞检测&修复整理
  • 运维安全概述
  • 浅谈Linux系统MySQL安全配置
  • Hardening Ubuntu
  • Tomcat Config Security
  • 安全运维中基线检查的自动化之ansible工具巧用
  • https://github.com/netxfly/sec_check

响应 溯源

  • awesome-incident-response - A curated list of tools and resources for security incident response, aimed to help security analysts and DFIR teams.
  • 黑客入侵应急分析手工排查
  • 应急tools
  • Linux服务器应急事件溯源报告
  • 应急响应小记链接已挂
  • 大型互联网企业入侵检测实战总结
  • Linux应急响应姿势浅谈
  • 安全应急姿势
  • Web日志安全分析浅谈
  • 域名劫持事件发生后的应急响应策略
  • 我的日志分析之道:简单的Web日志分析脚本
  • 攻击检测和防范方法之日志分析
  • Tomcat日志如何记录POST数据
  • 邮件钓鱼攻击与溯源
  • 应急响应实战笔记 - Bypass007
  • 某云用户网站入侵应急响应
  • IP 定位逆向追踪溯源访客真实身份调查取证
  • 域名背后的真相,一个黑产团伙的沦陷
  • 看我如何从54G日志中溯源web应用攻击路径

综合

  • 企业安全实践(基础建设)之部分资产收集
  • 企业安全实践(基础建设)之IP资产监控
  • 企业安全实践(基础建设)之主动分布式WEB资产扫描
  • 企业安全实践(基础建设)之被动扫描自动化(上)
  • 企业安全实践(基础建设)之被动扫描自动化(中)
  • 企业安全实践(基础建设)之被动扫描自动化(下)
  • 企业安全实践(基础建设)之WEB安全检查
  • 企业安全实践(基础建设)之HIDS(上)
  • 企业安全实践(基础建设)之HIDS(下)
  • 0xA1: 新官上任三把火
  • 0xA2 应急响应、防御模型与SDL
  • 0xA3 安全域划分和系统基本加固
  • 0xB1 微观安全——一台服务器做安全
  • 0xB2 事件应急——企业内网安全监控概览
  • 0xB3 再谈应急响应Pt.1 unix主机应急响应 elknot
  • 0xB4 企业安全建设中评估业务潜在风险的思路
  • 企业安全体系建设之路之系统安全篇
  • 企业安全体系建设之路之网络安全篇
  • 企业安全体系建设之路之产品安全篇
  • SOC异闻录
  • 开源软件创建SOC的一份清单
  • 开源SOC的设计与实践
  • F5 BIG-IP Security Cheatsheet

原bug bounty

  • SRC漏洞挖掘小见解

  • 面向SRC的漏洞挖掘总结

  • 漏洞挖掘经验分享Saviour

  • 我的SRC之旅

  • 浅析通过"监控"来辅助进行漏洞挖掘

  • 威胁情报-生存在SRC平台中的刷钱秘籍

  • 威胁情报

  • YSRC众测之我的漏洞挖掘姿势

  • SRC的漏洞分析

  • 众测备忘手册

  • 挖洞技巧:如何绕过URL限制

  • 挖洞技巧:APP手势密码绕过思路总结

  • 挖洞技巧:支付漏洞之总结

  • 挖洞技巧:绕过短信&邮箱轰炸限制以及后续

  • 挖洞技巧:信息泄露之总结

  • 阿里云oss key利用

  • 任意文件下载引发的思考

  • 任意文件Getshell

  • 通用性业务逻辑组合拳劫持你的权限

  • 组合漏洞导致的账号劫持

  • 我的通行你的证

root@kitploit:~
## Contribute
We welcome everyone to contribute,you can open an issue for this if you have some new idea about this project or you have found some quality safety articles,and then I will add your name to Acknowledgments.


## Acknowledgments
* @[tom0li](https://github.com/tom0li)
* @[neargle](https://github.com/neargle)
* @[r4v3zn](https://github.com/0nise)

## Star
Thanks for the stars

[![Stargazers over time](https://starchart.cc/tom0li/collection-document.svg)](https://starchart.cc/tom0li/collection-document)
Download Tool
  • MySQL Database Penetration and Vulnerability Exploitation Summary by Simeon
  • Various Host Header Attacks
  • Redis Master-Slave Exploitation PPT
  • Web Attack and Defense: Brute Force Edition by He Zu Dao
  • A Brief Discussion on Middleware Vulnerabilities and Protection
  • NFS Attack and Defense
  • Obtaining Sensitive Information via Hidden Folders and Files in Web Applications
  • Whitepaper: Security Cookies
  • Security Issues with Debug Mode Enabled on Servers
  • Introduction to Kubernetes Security
  • OOB
  • H2 Database Penetration Summary
  • Summary of Atlassian Product Vulnerabilities
  • Exploration of Redis on Windows Outbound Exploitation Awesome
  • Tool | The Path of Modifying sqlmap Payloads
  • Tool | The Path of Modifying sqlmap Payloads (Part 2)
  • sqlmap Source Code Analysis
  • sqlmap Source Code Analysis Part 1
  • sqlmap Source Code Analysis Part 2
  • sqlmap Source Code Analysis Part 3
  • sqlmap Source Code Analysis Part 4
  • Customizing nmap: First Encounter with NSE
  • Customizing nmap: Advanced NSE
  • Burpsuite Tips You Might Not Know
  • awesome-burp-extensions
  • A Simple Analysis of AWVS
  • Erasing Some AWVS Signatures
  • Discussing Experience and Principles of Port Scanning with nmap
  • My Path to Web Application Security Fuzzing
  • Getting Started with Wfuzz
  • Wfuzz Basic Skills
  • Wfuzz Advanced Techniques 1
  • Wfuzz Advanced Techniques 2
  • xray Advanced Edition Crack
  • Domain Penetration - Using SYSVOL to Recover Passwords Stored in Group Policy
  • Windows Log Attack and Defense - Attack Perspective
  • Simple Handling of Intrusion Logs for Windows
  • 6 Ways to Obtain Domain Admin Privileges from Active Directory
  • 3gstudent/Pentest-and-Development-Tips
  • Summary and Organization of Common Tips in Penetration Testing
  • 60 Bytes - Fileless Penetration Test Experiment
  • Cannot Add 3389 User
  • Ditch PSEXEC and Use WMI for Lateral Movement
  • Summary of ms14-068 Domain Privilege Escalation Series
  • Build a Bypass UAC Automated Testing Tool, Can Bypass the Latest Win10
  • DoubleAgent - Post-penetration injection into antivirus software
  • Extracting NTLM Hashes from keytab files
  • Offline Export of Passwords Saved in Chrome Browser
  • Penetration Tip - Using Masterkey to Offline Export Passwords Saved in Chrome Browser
  • Domain Penetration - Kerberoasting
  • A Trivial Detail of the Veteran Tool PsExec
  • Using CrackMapExec to Get What We Want in Domain Penetration
  • Kerberos Protocol Exploration Series - Delegation
  • Reverse Attack on mstsc via RDP - Monitor clipboard
  • Remote Credential Extraction
  • Rethinking Credential Theft
  • Practical Exploitation of Ghost Potato
  • PowerView
  • The Importance of WMI in Penetration Testing
  • BloodHound
  • BloodHound Official User Guide
  • Antimalware Scan Interface Provider for Persistence - Persistence via AMSI Provider
  • Task Scheduler Lateral Movement - Exploiting scheduled tasks with a smaller footprint
  • XXE Attacks Using EXCEL
  • Vulnerability Analysis of XXE Attacks Using EXCEL Files
  • EXCEL Dependency Libraries
  • Uploading DOC Files for XXE
  • An Article to Deeply Understand the XXE Vulnerability
  • XSS without parentheses and semi-colons
  • Money Laundering Tool "Mobile Top-Up Cards" - Grey Industry Cash-out Chain
  • Request Method Issues
  • Using Python Tools for Risk Data Analysis
  • Technical Discussion | Building a Small Caller ID Spoofing Tool
  • google.com/machine-learning/crash-course/
  • Remote Tracking and Exploitation Analysis of Connected Vehicles
  • Smart Lock Attack and Defense Series Part 1: Preliminary Exploration
  • My Worldview
  • Tool for Stealing Files from USB Drives
  • Summary of Intranet Security Checks/Penetration
  • Linux Intranet Penetration
  • Exploring New Ideas for Intranet Penetration - Verification of New Approaches
  • Beginner Domain Penetration Series - 01. Basic Introduction & Information Gathering
  • Beginner Domain Penetration Series - 02. Common Attack Methods - 1
  • Beginner Domain Penetration Series 03. Common Attack Methods
  • Intranet Penetration Knowledge Basics and Process
  • RemTeam Attack Techniques and Security Defense
  • Web-Security-Note
  • Good Articles on Web Security - Mainly for beginners
  • Fuzzing Automation to Bypass WAF (Soft WAF) Techniques
  • Grey Hat 2017
  • A Red Team Journey - Beginner
  • Unconventional Hard Drive Decryption Method
  • Linux SUID Privilege Escalation
  • Hard_winGuide.md
  • Enterprise-Registration-Data-of-Chinese-Mainland
  • Dao Ge's Blackboard Newspaper - A young person with deep thinking, truly a master
  • Why ping uses UDP port 1025 - Exists only socket/connect/getsockname/close, purpose is to get source IP
  • 蜜罐调研与内网安全
  • Real-timeDetectionAD - https://bithack.io/forum/505 - 域内蜜罐
  • HFish - 蜜罐框架
  • opencanary_web
  • tpotce
  • ElastAlert监控日志告警Web攻击行为
  • OSSIM分布式安装实践
  • 企业信息安全团队建设
  • 一个人的安全部之ELK接收Paloalto日志并用钉钉告警
  • 账号安全的异常检测
  • 一般型网站日志接入大数据日志系统的实现
  • 基础设施的攻击日志 – 第1部分:日志服务器的设置
  • 基础设施的攻击日志记录 – 第2部分:日志聚合
  • 基础设施攻击日志记录 – 第3部分:Graylog仪表板
  • 基础设施的攻击日志记录 – 第4部分:日志事件警报
  • 宜信防火墙自动化运维之路
  • 证书锁定
  • 中通内部安全通讯实践
  • 那些年我们堵住的洞 – OpenRASP纪实
  • 源头之战,不断升级的攻防对抗技术 —— 软件供应链攻击防御探索
  • 网络空间安全时代的红蓝对抗建设
  • 那些年我们刷过的SRC之企业邮箱暴破

  • 各大SRC中的CSRF技巧

  • 一些逻辑

  • 一个登陆框引起的血案

  • OAuth回调参数漏洞案例解析

  • 子域名接管指南

  • Subdomain Takeover

  • Subdomain Takeover/can-i-take-over-xyz

  • Subdomain-takeover

  • 过期链接劫持的利用方法探讨

  • 国外赏金之路 - 老司机赏金见解,历史赏金文章 list

  • 记一次失败的0元单的挖掘历程与一处成功的XSS案例

  • 看我如何发现谷歌漏洞跟踪管理平台漏洞获得$15600赏金

  • 看我如何利用简单的配置错误“渗透”BBC新闻网

  • 分享一个近期遇到的逻辑漏洞案例

  • 我是如何挖掘热门“约P软件”漏洞的

  • 新手上路 | 德国电信网站从LFI到命令执行漏洞

  • Taking over Facebook accounts using Free Basics partner portal

  • The bug bounty program that changed my life

  • 挖洞经验 | 看我如何免费获取价值€120的会员资格

  • Scrutiny on the bug bounty

  • 1hack0/Facebook-Bug-Bounty-Write-ups

  • Java反序列化漏洞-金蛇剑之hibernate(上)

  • Java反序列化漏洞-金蛇剑之hibernate(下)

  • Java反序列化漏洞-玄铁重剑之CommonsCollection(上)

  • Java反序列化漏洞-玄铁重剑之CommonsCollection(下)

  • Java反序列化漏洞从入门到深入

  • Java反序列化备忘录

  • Java反序列化漏洞之殇

  • Java反序列化漏洞学习实践一:从Serializbale接口开始,先弹个计算器

  • Java反序列化漏洞学习实践二:Java的反射机制(Java Reflection)

  • Java反序列化漏洞学习实践三:理解Java的动态代理机制