文章预览
Web安全 CVE-2024-4577:PHP CGI参数注入漏洞的Nuclei模板POC https://github.com/huseyinstif/CVE-2024-4577-Nuclei-Template 内网渗透 Conpass:持续进行密码喷射攻击而规避锁定风险 https://github.com/login-securite/conpass https://en.hackndo.com/password-spraying-lockout/ MAT:MSSQL服务器漏洞扫描与利用 https://github.com/SySS-Research/MAT chromedb:无需启动浏览器,直接读取Chrome浏览器数据 https://github.com/noperator/chromedb 针对F5 Big-IP的root权限提升与后渗透利用 https://offsec.almond.consulting/post-exploiting-f5-BIG-IP.html Windows Server 2025起将逐渐移除NTLM认证支持 https://learn.microsoft.com/en-us/windows-server/get-started/removed-deprecated-features-windows-server-2025 终端对抗 RflDllOb:自定义反射DLL与注入器项目 https://github.com/oldboy21/RflDllOb https://oldboy21.github.io/posts/2023/12/all-i-want-for-christmas-is-reflective-dll-injection/ MDE_Enum:Window Defender ASR规则提
………………………………