# SecurityExplained SecurityExplained 是继之前的学习挑战系列 #Learn365 之后推出的新系列。该系列的目标是以多种格式创建信息内容,并与社区分享,以促进知识创造和学习。
# Security Explained SecurityExplained 是继之前的学习挑战系列 #Learn365 之后推出的新系列。#SecurityExplained 系列旨在以多种形式创作信息内容并与社区分享,以促进知识的创造与学习。以下是 #SecurityExplained 系列计划开展的各种活动与形式: 1. 发布推文,讲解有趣的网络安全内容 2. 关于各种工具/技术/攻击的博客/教程/操作指南 3. 安全讨论空间/交流会 4. 每月思维导图/基于思维导图的不同攻击/技术讲解 5. 我的渗透测试方法论详解 6. 赠品活动与社区互动 7. 用于维护 "SecurityExplained" 的 GitHub 仓库 8. 公开且免费访问 9. 新闻通讯 在 Twitter 上关注我以获取定期更新:[Harsh Bothra](https://twitter.com/harshbothra_)。 **注意:** 请注意,本系列将按不固定的时间表运行,没有必要定期或每日制作与分享内容。 # Harsh 的内容 ___ 序号 | 主题 --- | --- **1** | [我的渗透测试方法论 [Web]](/resources/web-pentesting-methodology.md) **2** | [FeroxBuster 详解](https://github.com/harsh-bothra/securityexplained/blob/main/resources/feroxbuster-explained.md) **3** | [为内容发现创建自定义字典](https://github.com/harsh-bothra/securityexplained/blob/main/resources/custom-wordlist-for-contentdiscovery.md) **4** | [将 HTML 注入升级为云元数据 SSRF](https://github.com/harsh-bothra/securityexplained/blob/main/resources/htmli-to-cloud-ssrf.md) **5** | [利用批量赋值攻击绕过权限及其他限制](https://github.com/harsh-bothra/securityexplained/blob/main/resources/attacks-with-mass-assign.md) **6** | [使用 Objection 绕过 iOS 生物识别](https://github.com/harsh-bothra/securityexplained/blob/main/resources/bypassing-ios-biometrics.md) **7** | [我的高级功能测试方法论](https://github.com/harsh-bothra/securityexplained/blob/main/resources/premium-feature-testing-methodology.md) **8** | [通过视觉欺骗绕过过滤器(及其他)](https://github.com/harsh-bothra/securityexplained/blob/main/resources/bypassing-filters-visual-spoofing.md) **9** | [通过文件上传实现路径遍历](https://github.com/harsh-bothra/securityexplained/blob/main/resources/path-traversal-file-upload.md) **10** | [对 ZIP 上传功能发起 ZipSlip 攻击](https://github.com/harsh-bothra/securityexplained/blob/main/resources/zip-slip-file-upload.md) **11** | [RustScan - 现代端口扫描器](https://github.com/harsh-bothra/securityexplained/blob/main/resources/rustscan-portscanner.md) **12** | [漏洞代码片段 - 1](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-1.md) **13** | [漏洞代码片段 - 2](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-2.md) **14** | [漏洞代码片段 - 3](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-3.md) **15** | [漏洞代码片段 - 4](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-4.md) **16** | [漏洞代码片段 - 5](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-5.md) **17** | [漏洞代码片段 - 6](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-6.md) **18** | [漏洞代码片段 - 7](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-7.md) **19** | [漏洞代码片段 - 8](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-8.md) **20** | [漏洞代码片段 - 9](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-9.md) **21** | [漏洞代码片段 - 10](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-10.md) **22** | [漏洞代码片段 - 11](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-11.md) **23** | [漏洞代码片段 - 12](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-12.md) **24** | [漏洞代码片段 - 13](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-13.md) **25** | [漏洞代码片段 - 14](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-14.md) **26** | [漏洞代码片段 - 15](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-15.md) **27** | [漏洞代码片段 - 16](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-16.md) **28** | [漏洞代码片段 - 17](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-17.md) **29** | [漏洞代码片段 - 18](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-18.md) **30** | [漏洞代码片段 - 19](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-19.md) **31** | [漏洞代码片段 - 20](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-20.md) **32** | [账户接管方法论](https://github.com/harsh-bothra/securityexplained/blob/main/resources/account-takeovers-methodology.md) **33** | [漏洞代码片段 - 21](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-21.md) **34** | [漏洞代码片段 - 22](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-22.md) **35** | [漏洞代码片段 - 23](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-23.md) **36** | [漏洞代码片段 - 24](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-24.md) **37** | [漏洞代码片段 - 25](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-25.md) **38** | [漏洞代码片段 - 26](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-26.md) **39** | [漏洞代码片段 - 27](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-27.md) **40** | [漏洞代码片段 - 28](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-28.md) **41** | [漏洞代码片段 - 29](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-29.md) **42** | [漏洞代码片段 - 30](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-30.md) **43** | [漏洞代码片段 - 31](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-31.md) **44** | [漏洞代码片段 - 32](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-32.md) **45** | [漏洞代码片段 - 33](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-33.md) **46** | [漏洞代码片段 - 34](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-34.md) **47** | [漏洞代码片段 - 35](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-35.md) **48** | [漏洞代码片段 - 36](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-36.md) **49** | [漏洞代码片段 - 37](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-37.md) **50** | [漏洞代码片段 - 38](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-38.md) **51** | [漏洞代码片段 - 39](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-39.md) **52** | [漏洞代码片段 - 40](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-40.md) **53** | [漏洞代码片段 - 41](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-41.md) **54** | [漏洞代码片段 - 42](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-42.md) **55** | [漏洞代码片段 - 43](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-43.md) **56** | [漏洞代码片段 - 44](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-44.md) **57** | [漏洞代码片段 - 45](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-45.md) **58** | [漏洞代码片段 - 46](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-46.md) **59** | [Ruby ERB SSTI](https://github.com/harsh-bothra/securityexplained/blob/main/resources/ruby-erb-ssti.md) **60** | [CWE 简介](https://github.com/harsh-bothra/securityexplained/blob/main/resources/intro-to-cwe.md) **61** | [CWE-787:越界写入](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-787.md) **62** | [漏洞代码片段 - 47](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-47.md) **63** | [CWE-20:输入验证不当](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-20.md) **64** | [基于 Cookie 的身份验证中的漏洞](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerabilities-in-cookies.md) **65** | [我如何入门网络安全? — 我的观点与学习路径!](https://github.com/harsh-bothra/securityexplained/blob/main/resources/getting-into-cybersecurity.md) **66** | [基于范围的侦察方法论:探索智能侦察的战术](https://github.com/harsh-bothra/securityexplained/blob/main/resources/scope-based-recon.md) **67** | [MFA 绕过技术](https://github.com/harsh-bothra/securityexplained/blob/main/resources/mfa-bypass.md) **68** | [漏洞代码片段 - 47](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-47.md) **69** | [漏洞代码片段 - 48](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-48.md) **70** | [漏洞代码片段 - 49](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-49.md) **71** | [漏洞代码片段 - 50](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-50.md) **72** | [漏洞代码片段 - 51](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-51.md) **73** | [漏洞代码片段 - 52](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-52.md) **74** | [漏洞代码片段 - 53](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-53.md) **75** | [漏洞代码片段 - 54](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-54.md) **76** | [漏洞代码片段 - 55](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-55.md) **77** | [漏洞代码片段 - 56](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-56.md) **78** | [漏洞代码片段 - 57](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-57.md) **79** | [漏洞代码片段 - 58](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-58.md) **80** | [漏洞代码片段 - 59](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-59.md) **81** | [漏洞代码片段 - 60](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-60.md) **82** | [漏洞代码片段 - 61](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-61.md) **83** | [漏洞代码片段 - 62](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-62.md) **84** | [漏洞代码片段 - 63](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-63.md) **85** | [漏洞代码片段 - 64](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-64.md) **86** | [漏洞代码片段 - 65](https://github.com/harsh-bothra/securityexplained/blob/main/resources/vulnerable-code-65.md) **87** | [CWE-200:向未经授权的行为者暴露敏感信息](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-200.md) **88** | [CWE-732:关键资源的权限分配不正确](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-732.md) **89** | [CWE-522:凭据保护不足](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-522.md) **90** | [CWE-918:服务器端请求伪造 (SSRF)](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-918) **91** | [CWE-611:对 XML 外部实体引用的限制不当](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-611.md) **92** | [CWE-476:空指针解引用](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-476.md) **93** | [CWE-276:默认权限不正确](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-276.md) **94** | [CWE-862:缺少授权](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-862.md) **95** | [CWE-119:对内存缓冲区边界内操作的限制不当](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-119.md) **96** | [CWE-798:使用硬编码凭据](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-798.md) **97** | [CWE-287:身份验证不当](https://github.com/harsh-bothra/securityexplained/blob/main/resources/cwe-287.md) # SecurityExplained 新闻通讯 ___ 序号 | 主题 --- | --- **1** | [第 1 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-newsletter-315740) **2** | [第 2 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-2-969744) **3** | [第 3 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-3-979380) **4** | [第 4 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-4-990787) **5** | [第 5 期](https://t.co/MIS3cFYYtj) **6** | [第 6 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-6-1014382) **7** | [第 7 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-7-1026847) **8** | [第 8 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-8-1038241) **9** | [第 9 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-9-1049767) **10** | [第 10 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-10-1061802) **11** | [第 11 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-11-1073189) **12** | [第 12 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-12-1084203) **13** | [第 13 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-13-1095142) **14** | [第 14 期](https://www.getrevue.co/profile/harshbothra_/issues/securityexplained-issue-14-1106987) # AskMeAnything ___ 序号 | 主题 --- | --- **1** | [AMA-1:与 Harsh Bothra 的 AMA](https://twitter.com/harshbothra_/status/1497233820336418816) **2** | [AMA-2:与 Six2dez 的 AMA](https://twitter.com/harshbothra_/status/1499731408868179972) **3** | [AMA-3:与 Brumens 的 AMA](https://twitter.com/harshbothra_/status/1511327809733480451) # 推文串 ___ 序号 | 主题 --- | --- **1** | [你必读的 7 本黑客书籍](https://twitter.com/harshbothra_/status/1499346357227642886) **2** | [你的武器库中必备的 4 款子域枚举工具 💻](https://twitter.com/harshbothra_/status/1500101328978079744) **3** | [检查访问控制与权限提升问题的 6 款 Burp 扩展](https://twitter.com/harshbothra_/status/1500848764948389889) **4** | [你必须了解的 5 款强大 Web 模糊测试与内容发现工具](https://twitter.com/harshbothra_/status/1501928368521945090) **5** | [每位安全专业人士必须了解的 17 个搜索引擎](https://twitter.com/harshbothra_/status/1503332626580471808) **6** | [你必须关注的 7 个网络安全大会频道](https://twitter.com/harshbothra_/status/1505869341748723714) **7** | [掌握跨站脚本的 9 个免费练习实验室](https://twitter.com/harshbothra_/status/1508406052663934979) **8** | [我创建的 11 张思维导图,你可能会觉得有用!](https://twitter.com/harshbothra_/status/1509168580071329792) **9** | [14 个 Payload 仓库,助你找到所有所需的 Payload 与攻击向量](https://twitter.com/harshbothra_/status/1509870706347032579) # 思维导图 序号 | 主题 --- | --- **1** | [账户接管技术](https://www.xmind.net/m/M3WEqG/) **2** | [CWE 十大 (2021)](https://www.xmind.net/m/icrqti)