展示 195 / 全库 195

8月5日周三3

07:50
Medium 邮件
Medium:The Agentic AI Security Career Roadmap (2027 Edition) | Taimur Ijlal

本期 Medium 邮件聚焦 Agentic AI 安全领域的未来职业发展,重点推荐了 Taimur Ijlal 的文章《The Agentic AI Security Career Roadmap (2027 Edition)》。该文章前瞻性地规划了面向 2027 年的安全从业者成长路径,探讨了智能体 AI 带来的新兴安全趋势与核心技能需求。对 bug bounty 猎人及安全从业者而言,这份路线图极具战略参考价值,有助于提前布局并探索 Agentic AI 环境下的新型攻击面与漏洞挖掘机遇。

02:15
Medium 邮件
Medium:Become a Friend of Medium today to access our exclusive track at Medium Day

Medium宣布将在今年的Medium Day上为Friends of Medium推出专属互动活动,深度聚焦AI与写作(AI and writing)的核心议题。邮件探讨了AI时代下人类创作者的价值不降反升,指出平台正迎来一场“写作复兴”(Writing Revival)。对于安全从业者和Bug Bounty猎人而言,此话题有助于反思在利用AI辅助撰写漏洞报告和技术文章时,如何保持人类独有的批判性思维与深度洞察。这种探讨能帮助技术写作者在AI浪潮中找准定位,提升安全研究成果输出的不可替代性与传播价值。

00:50
Medium 邮件
Medium:The Cybersecurity Certifications That Still Matter in the AI Era

Medium 推送了 Taimur Ijlal 的文章《The Cybersecurity Certifications That Still Matter in the AI Era》,探讨了在 AI 浪潮下从业者应如何明智地选择网络安全认证。文章指出,随着技术演进,部分传统证书的价值正在发生变化,安全人员需要更具前瞻性地规划学习路径。对 bug bounty 猎人和广大安全从业者而言,该内容有助于在 AI 时代优化技能投资,避免资源浪费,确保所考取的认证能真正转化为个人核心竞争力和职业优势。

8月4日周二1

08:00
Intigriti Blog
Intigriti named new provider for Adobe's Bug Bounty Program

自2026年9月1日起,Intigriti 将正式成为 Adobe 漏洞赏金项目的新托管平台。随着 AI 技术重塑产品开发流程,Adobe 希望借助 Intigriti 全球研究社区的力量,以应对不断演进的安全测试需求。此举旨在帮助 Adobe 更高效地发现并修复其各类产品中的安全漏洞。

8月1日周六1

7月31日周五2

08:00
Intigriti Blog
Intigriti Bug Bytes #238 - July 2026 🚀

本期 Bug Bytes 迎来 Intigriti 成立十周年特辑。文章重点披露了 GitHub.com 及 GitHub Enterprise Server 的 RCE 漏洞,介绍了新增 AI 代理功能的 Burp Suite Burp AT,并分享了黑客通过渗透 Gemini Enterprise 获得高达 15,000 美元赏金的案例。此外,还提到有研究人员通过扫描 GitHub Archive 发现了 3,708 条有效凭证。

7月30日周四2

08:00
Intigriti Blog
How to appeal a bug bounty submission

漏洞赏金(Bug bounty)项目通常由安全研究员、漏洞分类团队和受影响企业多方协作完成。尽管大多数漏洞报告能得到妥善处理,但仍有少数报告会被误关、严重程度被降级或长期搁置。遇到此类情况时,掌握专业且有效的申诉应对方法至关重要。

7月29日周三2

7月28日周二2

08:00
Intigriti Blog
RAG and ruin: why your existing controls may miss AI poisoning attacks

RAG 系统通过引入外部可变内容扩大了应用的信任边界,攻击者一旦操纵索引或检索的数据,即可控制模型的输出与行为。在简单的问答系统中,这可能导致虚假信息或不安全建议;而在具备工具和权限的智能体系统中,则会引发数据泄露、越权操作或业务破坏。因此,组织必须针对 RAG 的数据摄入等环节部署专门的安全防护措施。

08:00
Atum
玄武七载,行将新程

今天,我离开了毕业后便加入、工作了七年的腾讯玄武实验室,即将加入 MiniMax,开启一段新的旅程。值此人生的重要节点,我想写下这些年一路走来的思考,以及始终牵引着我的志向。

7月27日周一2

11:27
X 收藏
@WolfTrainer_101:CrowdStrike 月初发表blog,揭露新的提示词注入技术。本次新增18项注入技术,项目累计覆盖200多种不同的注入技术。CrowdStrike AI安全研究团队号称维护业内最大规模的提示…

CrowdStrike发布博客披露18项新增提示词注入技术,使该项目累计覆盖超过200种注入技术。该团队声称维护着业内最大规模的提示词注入分类体系,通过结构化层级全面展示了AI威胁的风险全貌。

7月26日周日1

7月25日周六2

7月24日周五1

7月23日周四3

20:49
X 收藏
@jiroucaigou:终于知道为啥别人一个月推特创作者收入能赚5000美金了 最近不知道写什么内容,就钻研了中文区x收入最高的几位博主,收集了他们日常实用的内容素材聚合器 1.last30days 抓取30天内X、油…

作者分析了中文区X平台高收入博主的变现模式,发现其高度依赖内容聚合器获取热门选题。文中分享了三个实用素材源:last30days用于抓取X和油管近30天热门讨论,TL1网站用于追踪中文圈热门推文,知乎今日热榜则提供知乎每日热点,以解决创作者的选题难题。

08:00
Intigriti Blog
AI’s convenience cost. The impact of the lethal trifecta on organizations today

随着 AI 工具具备读取数据、接收指令和代为执行的能力,“致命三要素”带来的安全威胁正日益严峻。攻击者可通过投毒的邮件、网页或文档欺骗 AI,导致其泄露敏感信息或执行未经授权的操作。因此,随着 AI 在组织中扮演越来越核心的助手角色,企业必须为其访问权限和自主操作部署严格的安全防护机制。

7月22日周三3

15:46
Aituglo
Home setup, goodbye Claude, and motivation

作者精简了家庭实验室架构,改用虚拟机上的单一 tmux 搭建复古环境,并提到 GPT 5.6 让其短暂放弃了 Claude。此外,作者还分享了在 AI 智能体主导漏洞挖掘的当下,人工寻找漏洞的真实感受与思考。

7月21日周二2

7月20日周一1

08:00
Intigriti Blog
The between-reports problem: why security teams miss what attackers see

安全团队常因漏洞报告间的盲区而错失攻击者的真实视角,单纯依赖扫描器和资产清单无法揭示攻击意图。所谓“报告间可见性”是指填补两次报告之间的情报空白,而非依赖产品推销。未来安全团队需要更早期的预警信号,以便在下一份报告发布前采取行动。

7月19日周日4

00:56
X 收藏
@mtrainier2020:这是最近一个组织做的各个模型在再发现CVE方面的能力,评测各个模型的挖洞(攻防能力)。 GLM5.2是自己部署的。 GLM已经相当不错了,可以上桌吃饭了。 也就是说,安全团队可以拿来用了。 可以…

有机构评测了各大模型在重新发现CVE及漏洞挖掘方面的攻防能力。作者指出自部署的GLM5.2已达到安全团队实战可用水平,并期待半年后GLM及解锁后的K3能有更强表现。

7月18日周六1

7月17日周五4

08:00
josephthacker
Launching: rez0’s rascals

rez0 推出了一款名为 rez0’s rascals 的 K-5 学习应用。该产品主要面向家庭学校、合作办学及混合制学校的家庭,旨在满足相应的教育需求。

7月16日周四4

11:07
X 收藏
@geekbb:为 Agent 构建者提供一个桌面应用,用来快速搭建和调试验证 agent 想法、追踪执行过程、排查失败并评估性能。 这个工具是 DeerFlow 团队顺手做的姊妹项目,从 2023 年就开始,…

DeerFlow 团队推出一款面向 Agent 构建者的桌面应用,支持快速搭建、执行追踪、回放调试及性能评估。该工具将提示词编写、轨迹查看和本地线程存储整合在同一窗口,自 2023 年起便用于各版本 DeerFlow 的内部调试。

7月15日周三2

15:20
X 收藏
@Jack_FluxAI:教大家如何在练英语的同时还能交外国女朋友/男朋友 首先下载一个hellotalk app, 然后随便做几个任务升下等级解锁语音房, 然后语音房里聊,最好选择中文英语交换的房间, 上次就有个马来西…

教大家如何在练英语的同时还能交外国女朋友/男朋友 首先下载一个hellotalk app, 然后随便做几个任务升下等级解锁语音房, 然后语音房里聊,最好选择中文英语交换的房间, 上次就有个马来西亚女生, 跟我吐槽有个中国渣男骗了她的感情 https://t.co/EOhKE2C0BB

14:45
Aituglo
Waiting for Claude, infinite scroll, and BusyBar

我们耗费大量精力优化 Claude,却鲜少思考在它工作时自己该做些什么。本周探讨了 AI 如何悄然将我从内容创作者变成了纯粹的消费者,以及无限滚动为何让人感到空虚。此外,我还分享了一款为了对抗这种状态而冲动入手的昂贵小设备 BusyBar。

7月8日周三2

16:00
Aituglo
Why you're using Claude wrong, networking, and vacation

作者反思了对 Claude 的错误用法,指出不应像无休止循环般催促其继续,而应像指导实习生那样给予明确引导。此外,文章还强调了在漏洞赏金领域,真实的人际交流比任何事都更为重要,并分享了在孚日山脉度假的轻松时光。

7月2日周四1

08:00
Atum
后 Mythos 时代:自动化漏洞挖掘的七个趋势

Mythos 的意义不只是模型能力突破,而是把 AI 自动化漏洞挖掘推成了一次行业动员。后 Mythos 时代,漏洞发现会继续变便宜,中垂果实会被快速释放;但真正稀缺的会转向仓库级覆盖、低噪声验证、修复、披露、维护者承接能力,以及对供应链投毒和变更入口攻击的治理。本文从七个趋势出发,讨论自动化漏洞挖掘从发现端扩产走向治理端重构的下一阶段。

7月1日周三3

22:31
Aituglo
LeHack, a round table, and AI in hacking

LeHack 大会于巴黎 La Villette 重新举办,期间举办了 YesWeHack Live Event。此外,一场聚焦合规与 SOC 2 的圆桌讨论也同步进行。本周的核心议题聚焦于 LeHack 大会本身,以及人工智能技术将如何影响与改变黑客攻击的发展方向。

08:00
josephthacker
Operation Floodlight

“Operation Floodlight”探讨了人工智能系统具备强大网络安全能力后所带来的下游影响。该研究重点关注 AI 在攻防两端的实际应用,及其对整体安全生态造成的连锁反应。

08:00
josephthacker
The Bug Bounty Singularity: Our Hackbot

去年12月起,熟练黑客已能低成本部署自动化攻击智能体,以数百美元的 Token 开销换取数千美元的漏洞赏金,作者将此称为“Bug Bounty Singularity”。本文讲述了 JD(xssdoctor)与作者共同开发一款 Hackbot 的过程,该工具在过去5个月内成功发现了126个漏洞。

6月30日周二1

08:00
josephthacker
Launching: AI Safety For Parents

作者首次公开发布了一项名为“AI Safety For Parents”的10天邮件课程。该课程旨在帮助家长掌握必要知识,从而在AI时代更好地保护孩子的安全。

6月29日周一1

08:00
Intigriti Blog
Reconnaissance for exposure management: why context matters in the AI era

在 AI 时代,安全漏洞的发现速度与数量均大幅提升,使得人工研判与优先级排序变得愈发关键。然而,多数安全团队目前仍主要依赖“成功结果”进行经验总结与防御。这种滞后的情报获取模式已难以应对当前威胁,团队必须转向前置的暴露面侦察,通过掌握更全面的安全上下文来提升整体防御能力。

6月27日周六1

08:00
Intigriti Blog
Exploiting insecure cookie policies

Cookie 是现代 Web 的基础组件,但其安全性常被忽视。配置不当的 Cookie 策略可能导致敏感会话数据泄露,引发多种客户端攻击,严重时甚至允许攻击者完全冒充用户。本文详细探讨了攻击者如何利用不安全的 Cookie 策略。

6月26日周五1

08:00
Intigriti Blog
Intigriti Bug Bytes #237 - June 2026 🚀

本期 Intigriti Bug Bytes 重点披露了 phpBB 长达 10 年的未授权 RCE 漏洞,以及 DOMPurify 解析器的最新绕过技术。此外,内容还涵盖了利用 AI 漏洞挖掘赚取 Google 50 万美元赏金的案例、读取任意 Salesforce Marketing Cloud 账户邮件的安全风险,以及通过接管废弃 S3 存储桶来大规模复刻 SolarWinds 供应链攻击的威胁分析。

6月24日周三2

20:12
Aituglo
A hacker house, AI does the recon now, and dup land

今年的黑客之家活动在南部别墅举行,团队成员首次在引入 Claude 后重聚。如今大家只需将 AI 指向目标范围,便会挖掘出相同的漏洞。这次行程带来了全新的狩猎模式,但也产生了大量重复漏洞。

08:00
Intigriti Blog
Exploiting web cache poisoning vulnerabilities

Web 缓存技术虽能优化页面加载速度,但配置不当会引入 Web 缓存中毒漏洞。本文介绍了该漏洞的成因、发现方法及实际利用过程。

6月17日周三3

08:00
Intigriti Blog
Using AI the smart way. Interview with Cristian Zot (CristiVlad25)

Cristian Zot(网名 CristiVlad25)是一名资深渗透测试专家与安全研究员,同时也是 Intigriti 平台的黑客大使。他长期活跃于道德黑客社区,通过播客、线下聚会和教育内容积极分享安全经验。近期,他还作为特邀专家参与了 Intigriti 在 Discord 上的直播问答活动,解答社区提问。

08:00
Intigriti Blog
Using AI the smart way. Interview with Cristian Zot (CristiVlad25)

Cristian Zot(CristiVlad25)是一名活跃的安全研究员、资深渗透测试专家及 Intigriti 黑客大使。他在道德黑客社区具有较高影响力,常通过播客、聚会和教育内容与 Intigriti 合作。近期他还作为客座专家参与了 Intigriti 的 Discord 直播播客,解答社区问题。

01:57
Bug Bounty Daily
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.

研究人员发现仅需个人ID即可在FIFA公开的 Agent Platform 上注册,进而获取 Football Data Platform 的 Streaming Management 面板访问权限。该漏洞允许攻击者提取2026年FIFA世界杯所有直播摄像头的RTMP推流地址和流密钥,甚至能劫持整个赛事直播。为上报此漏洞,研究人员耗时数小时多方联系才最终与FIFA、MediaKind、HBS、CISA及FBI取得沟通。

6月16日周二1

08:00
Atum
Mythos:当攻防进入火器时代,防御策略和人的技能栈,都要重写

2026 年 6 月 11 日,我在上海 AGI Bar 与三十余位安全从业者深入讨论 Mythos 所展现的 Cyber 能力。当 Agent 可以连续完成资产发现、漏洞分析、PoC /EXP 编写、路径推演和作战调度时,网络安全该怎么做?本文从攻击链压缩出发,提出 AI 时代的防御者方程,并给出资产盘点、持续的红队验证与脆弱点扫描、自动化的安全运营等短期可建立能力,以及可达性治理、爆炸半径压缩和 Agent Skill 工程化的长期路径。

6月12日周五2

21:13
Bug Bounty Daily
1-Click GitHub Token Stealing via a VSCode Bug

一位博主在其主要分享编程经验的博客中,披露了 VSCode 的一项安全漏洞。该漏洞允许攻击者通过一键操作窃取用户的 GitHub Token。开发人员需关注此类开发环境中的潜在安全风险。

01:10
Bug Bounty Daily
Hacking Google with A.I. for $500,000

研究人员将AI应用于Google全部基础设施进行安全测试。此次测试共发现1500个API和3600个密钥,并由此获得50万美元的漏洞赏金。本文分享了此次AI驱动安全测试的发现与经验。

6月11日周四1

08:00
Intigriti Blog
Securing the uncharted territories of AI systems. A discussion with Leo Racanelli

本文探讨了 AI 与网络安全融合如何重塑漏洞的发现与修复机制。结合高级安全软件工程师 Leo Racanelli 的洞察,文章深入剖析了 AI 对一线安全工程师及企业数据防护的实际影响。内容旨在拨开炒作迷雾,真实呈现当前 AI 系统安全防护的实践现状。

6月10日周三1

15:54
Aituglo
Minimal productivity, switching to Hermes, and building Onyx

上周探讨了虚假生产力,本周继续反思真正有效的工具。作者重新用起了简单的番茄钟计时器,并最终确定切换至 Hermes 智能体平台,同时持续优化其语音控制的 Onyx 系统。

6月9日周二1

08:00
Intigriti Blog
Intigriti named Best Security Company of 2026 at the SC Awards

Intigriti 在 2026 年 SC Awards Europe 中荣获“最佳安全公司(250人以下规模)”奖项。该奖项拥有超过25年历史,旨在表彰塑造网络安全行业未来的卓越组织与领导者。2026年6月3日,Intigriti 与众多安全行业杰出代表共同出席了此次盛会。

6月5日周五1

21:28
Bug Bounty Daily
Unauthenticated RCE as QSECOFR via IBM i Management Central

IBM i Management Central 存在未授权远程代码执行漏洞,攻击者可借此获取 QSECOFR(系统安全员)权限执行任意命令。该漏洞利用无需任何身份验证,攻击者可轻易借此完全接管目标系统。

6月4日周四1

20:37
Bug Bounty Daily
Golang code review notes II - elttam

安全研究机构 elttam 发布了 Golang 代码审查笔记的第二部分。该文章重点探讨了 Go 语言代码审查过程中的安全注意事项与常见漏洞模式。这些内容为开发和安全团队提供了实用的代码审计参考,有助于提升 Golang 项目的安全性。

6月3日周三3

14:35
Aituglo
Fake productivity, my home setup sucks, and Meetly

作者反思了“伪生产力”现象,并指出家庭网络配置的不足。一次停电导致其自托管的博客宕机,暴露出基础设施在可用性方面的短板。文章最后更新了 Meetly 项目的最新进展。

01:13
Bug Bounty Daily
Finding XSS on Shazzer (literally) | Jorian Woltjer

本文介绍了作者在浏览器特性模糊测试工具 Shazzer 内部发现的一个 XSS 漏洞。与利用 Shazzer 进行测试不同,该漏洞直接存在于 Shazzer 平台自身。作者还分享了如何利用 Blob URL 技术绕过沙箱限制以释放恶意内容。

01:13
Bug Bounty Daily
Grafana to 507 Meta Repos: A $157K Bug Chain | Sectricity

一个暴露 Grafana 实例的 Meta IP 最终演变为一条五跳漏洞链,成功触达 507 个私有仓库。该漏洞链发现者因此获得了 15.7 万美元的赏金。幸运的是,此次漏洞挖掘并未实际访问任何代码。

6月2日周二2

04:29
Bug Bounty Daily
WAF Bypasses via h2 framing

How HTTP/2’s multi-frame architecture allows attackers to bypass WAFs by exploiting timing delays, protocol translation flaws, and incomplete body inspection across various reverse proxies

01:30
Bug Bounty Daily
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain

Introduction Hello, I’m RyotaK ( @ryotkak ), a security researcher at GMO Flatt Security Inc. After publishing my previous article ( Pwning Claude Code in 8 Different Ways ), I continued investigating Claude-related products and found several more vulnerabilities. In this article, I will explain a vulnerability in Claude Code’s GitHub Actions that could allow an attacker to compromise any repository that uses the Claude Code workflow, including Anthropic’s own repositories.1 Note: Variants of th

6月1日周一2

08:00
Intigriti Blog
Marketer by day, bug hunter by night. Interview with Stefan Goossens (G0053)

Stefan Goossens(代号 G0053)是来自荷兰的独立安全研究员,同时兼任一家营销与网页开发公司的合伙人。他白天负责设计和构建用户友好的网站,业余时间则专注于测试这些网络应用以挖掘安全漏洞。这种双重身份使他完美地将网站的建设与攻防测试结合在一起。

08:00
Intigriti Blog
Marketer by day, bug hunter by night. Interview with Stefan Goossens (G0053)

Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-friendly websites, his free time is spent testing those very applications to see wha

5月30日周六1

08:00
Intigriti Blog
Intigriti Bug Bytes #236 - May 2026 🚀

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sanitized name field And so much more! Let's dive in! CEO insights: beyond the AI model card AI model cards have become a standard part of how organizations document their

5月28日周四1

08:00
Intigriti Blog
Introducing Insights: self-serve reporting for security teams

Security teams running Bug Bounty programs often require similar insights and reporting to prove the value and ROSI for security initiatives, and often ask questions such as: What changed? Where are we spending? Are we improving? What needs attention right now? Until now, answering those questions often meant exporting data, stitching together spreadsheets, or pulling screenshots from multiple places. Insights is our revamped analytics dashboard experience inside Intigriti. I

5月26日周二3

08:00
Intigriti Blog
CEO insights: holding on to the human line in the age of AI adoption

As part of our recent AI series, I’ve been sharing my insights on the key topics, questions, and debates currently shaping the industry. I have covered my opinions regarding holding the human layer sacred in the AI era, where I explored what I deem is the beating heart of the Bug Bounty industry, AI strengths and weaknesses, where human hackers fit in, and what businesses will face in the next 3 to 5 years. I then looked beyond the AI Model card, where I discussed continuous

02:04
Bug Bounty Daily
From a Sanitized Name Field to One-Click Account Takeover

Some weeks ago, I was testing a mature and heavily audited application from a bug bounty program. Since I had previously found several interesting client-side vulnerabilities in that target, I decided to focus on the frontend again. What first looked like a safely sanitized name field eventually became one-click account takeover through a chain of bypasses.

5月22日周五5

19:54
Bug Bounty Daily
Discovering Vulnerabilities in Enterprise Audiovisual Hardware

Some organisations’ most sensitive information is only ever discussed in person. Ironically, the equipment in meeting rooms, conference halls, and other physical locations is often among the least-monitored and most insecurely-configured attack surfaces in an organisation.

18:34
Bug Bounty Daily
Two Bypasses for Chrome’s Sanitizer API › Searchlight Cyber

The Sanitizer API arrived with much fanfare in both Chrome 146 and Firefox 148 just a few months ago. The API provides two new ways to set HTML safely from within javascript; the default mode: node.setHTML(`Hello, world!`) And the more customizable mode: const config = { "elements": ["p", "span", "b"], "attributes": ["class"] }; const sanitizer

03:15
Bug Bounty Daily
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) › Searchlight Cyber

Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with PostgreSQL. It was reported upstream by Michael Maturi and a fix shipped across every supported branch (11.3.10,

5月21日周四3

08:00
Intigriti Blog
How Triage Assist is raising the bar in crowdsourced security

AI is changing the volume and accelerating the pace of vulnerability submissions. If you've been following our recent AI series, you already know that submission growth isn't a quality problem; it's a coordination problem. As Head of Triage, Lennaert Oudshoorn, outlines in his recent post, ‘The AI impact: A triager’s perspective’, the security industry is experiencing a surge in vulnerability discovery and a relative scarcity of triagers. Validating, classifying, and sorting

5月20日周三1

5月19日周二6

21:26
Bug Bounty Daily
4 Google Cloud Shell bugs explained – bug #4

Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned (this page) Note: The vulnerab…

21:15
Bug Bounty Daily
4 Google Cloud Shell bugs explained – bug #2

Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell image (this page)Bug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…

21:15
Bug Bounty Daily
4 Google Cloud Shell bugs explained – bug #1

Quick navigation IntroductionBug #1 – The Python language server (this page)Bug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…

19:22
Bug Bounty Daily
4 Google Cloud Shell bugs explained – bug #3

Quick navigation Introduction Bug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git clone (this page)Bug #4 – Go and get pwned Note: The vulnera…

5月13日周三1

18:12
Aituglo
Flow, 24h app, and Sport

I came back to the concept of flow and how AI is quietly killing it. Then I built a full iOS meditation app in 24 hours with Claude. And a few thoughts on why sport changed everything for me.

5月12日周二1

20:58
Bug Bounty Daily
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Of course I took a peek at the Claude Code source 🙈. What I found was a very entertaining vulnerability which is now fixed since Claude Code version 2.1.118. Just wading through the massive codebase manually wasn’t really a feasible approach. So took an army of AI Agents to…. no wait actually I did not do that, the following was all manual work. :P I started by looking at different configuration options and tried to see what’s actually “useful” from an attacker’s perspective. On the way, in mai

5月6日周三6

22:18
Bug Bounty Daily
Breaking SameSite=Strict in Chrome

How opening Chrome DevTools on a cross-site POST response can bypass SameSite=Strict cookie protections when a service worker is present.

22:16
Bug Bounty Daily
Escalating Self-XSS with Disk Cache

I’m here to share my Self-XSS escalation write-up, one that took me multiple failed attempts before I finally cracked it with some much needed help.

11:39
Flanker 博客
OpenCyvis: An Open-Source AI Phone

OpenCyvis: An Open-Source AI Phone OpenCyvis is an open-source AI phone created by me. Users choose their own LLM backend (cloud or local). The AI operates on a background virtual display without taking over the main screen. Apache 2.0 licensed, fully open source. Background Over the past year, several companies have launched "AI phone" products — Doubao, Samsung Galaxy AI, Google’s Gemini integration, and others. The core idea is the same: AI understands the screen and

4月29日周三2

4月23日周四1

4月22日周三1

15:29
Aituglo
Pentests, a TV shoot, and dropped projects

Why pentests still matter in the AI era, what I learned from an upcoming TV interview about the bubble we live in, and the projects I've dropped along the way.

4月15日周三1

4月13日周一1

18:57
Aituglo
The state of Bug Bounty in 2026

AI agents are flooding bug bounty with noise, burning out triagers, and pushing companies away. But the hunters who adapt will come out stronger. A full-time hunter's honest take on what's changing and what comes next.

4月8日周三2

08:00
Atum
#Claude Mythos 之后,安全从业者凭什么不会被淘汰

Anthropic 发布 Project Glasswing 与 Claude Mythos Preview,在 OpenBSD、FFmpeg、Linux 内核等场景展示出强悍的自动化漏洞能力。本文讨论:当执行层技能越来越可被 AI 接管时,安全从业者的价值锚点应移向何方——从「做事的人」到「决定做什么事的人」,为何高层判断更难被替代,以及如何驾驭 AI agent 作为新的基本功。

4月1日周三1

3月24日周二2

02:10
Bug Bounty Daily
Story of Abusing a Fully Secured redirect_uri in an OAuth Flow

The post describes how the author discovered a one-click account takeover vulnerability in a large automotive company’s OAuth implementation, despite apparently robust redirect_uri validation. By exploiting a subtle double-decoding inconsistency in URL parsing, they were able to redirect the authorization code to an attacker-controlled domain and hijack user accounts.

01:47
Bug Bounty Daily
Remote Command Execution in Google Cloud with Single Directory Deletion

Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During this event, I discovered a remote command execution vulnerability in one of Google Cloud’s services. As the vulnerability has now been fixed, I would like to share the technical details in this article. TL;DR Google Cloud has a product called Looker, and this product has a feature to manage Git rep

3月20日周五1

3月18日周三1

21:22
Bug Bounty Daily
how to do good research

Ignoring the obvious name, this blogpost is not tips that will help you “exploit” a bug or give you tips on how to find awesome bugs, it is obvious that you need technical knowledge.

3月13日周五3

06:23
Bug Bounty Daily
From self-XSS, through AI, to tenant takeover

While auditing a multi-tenant application, I came across an interesting chain leading to a full tenant takeover. It started innocuously - with a self-XSS in a rich-text editor. Exploitation would require the user to insert a dangerous element into the editor via its API themselves, which meant a minimal chance of success. Still, I decided to dig deeper into the application and look for functionality that could help escalate this vulnerability and reduce the exploitation complexity.

06:21
Bug Bounty Daily
Unauthenticated Chat Takeover in AI Chatbot – un1tycyb3r

A popular enterprise chatbot left an old, unauthenticated WebSocket endpoint active that still accepted full bidirectional messages using only a conversation UUID as “protection.” Anyone who obtained a conversation ID could connect, impersonate the user, read their chats, and exfiltrate sensitive data via a trivial HTML PoC. After disclosure, the vendor quickly disabled the legacy endpoint and paid modest bounties.

3月10日周二1

3月9日周一1

3月6日周五1

3月4日周三2

3月2日周一9

22:06
Bug Bounty Daily
depthfirst | 1-Click RCE To Steal Your OpenClaw Data and Keys (CVE-2026-25253)

A technical teardown of a 1-click RCE against OpenClaw (formerly Moltbot/ClawdBot), a viral open-source AI assistant trusted by 100,000+ developers with high-privilege access. See how a settings logic flaw and a WebSocket pivot turn a single webpage visit into token exfiltration, safety-control bypass, and arbitrary command execution.

21:29
Bug Bounty Daily
Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852 - Check Point Research

By Aviv Donenfeld and Oded Vanunu Executive Summary Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various configuration mechanisms including Hooks, Model Context Protocol (MCP) servers, and environment variables -executing arbitrary shell commands […]

18:53
Bug Bounty Daily
SvelteSpill: Critical Cache Deception Bug in SvelteKit + Vercel

SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnerable and how to mitigate risk.

18:52
Bug Bounty Daily
Can a Predicted window.open Target Really Be That Impactful?

This post walks through a real-world OAuth popup hijacking attack. The target had solid defenses origin validation, source checking, CSP but a single predictable window.open() target name created an exploitable gap. It also serves as a real-world case use of iframe hijacking, showing how I managed to squeeze a vulnerability with a useless behavior.

2月24日周二1

08:00
josephthacker
AI’s Impact on Software and Bug Bounty

I have a lot of thoughts on how AI will affect things, including bug bounty. And most of it is speculation, of course, but I have to put this out into the world because I want to know if this is correct in a year or two.

2月16日周一1

2月14日周六1

2月10日周二1

2月6日周五1

08:00
Atum
Opus 4.6 的 500 个 0day,对我们来说意味着什么?

在 Claude Opus 4.6 发布前的内部红队测试中,Anthropic 的前沿红队做了一件简单粗暴的事:把 Opus 4.6 扔进沙箱环境,给它 Python 和一套常规漏洞分析工具,不提供任何专门指令,不注入任何领域知识,让它自己去挖开源代码库的漏洞。结果:超过 500 个此前未知的高危零日漏洞。这个数字让不少安全从业者半开玩笑地说"要被 AI 淘汰了"。这个话题值得认真聊一聊。

2月4日周三2

23:20
Bug Bounty Daily
Shaking the MCP Tree: A Security Deep Dive

This article exposes how insecure Dynamic Client Registration and misconfigured OAuth in MCP servers can enable XSS, SSRF, and token theft. Through real-world examples, it shows how attackers can abuse open DCR, redirect URIs, and path normalization to gain direct access to MCP tools and internal services—and explains how to lock down these integrations to reduce AI-related security risks.

2月1日周日1

08:00
Atum
只要安装了OpenClaw,你的电脑就可以被黑客控制

只要部署了 OpenClaw 并与之对话,你的电脑就有可能被攻击者完全控制。 这是架构层面的根本性问题,不是 bug,而是"feature"。 本文系统分析了这一风险产生的根源、攻击成立的条件,以及为什么现有防护只能缓解而无法根治。

1月31日周六1

1月30日周五3

22:35
Bug Bounty Daily
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential

This research is an extension of Content-Type research from BlackFan. More specifically, the response Content-Type tricks. Unfortunately, the multiple Content-Type trick is not clearly explained by BlackFan. Therefore, I’ll explain and demonstrate how a single comma character can cause a parsing difference between the browser and different MIME type parser libraries.

01:04
Bug Bounty Daily
Draft of a night walk: the diagnosis of a researcher’s quest for success

I’m coming back from a long nighttime walk with a friend, during which we had several interesting discussions. One of them seemed relevant enough to turn into the short draft you’re reading now. This friend has been training in offensive web security for almost a year. He’s an intelligent and particularly studious person, yet despite that, he’s struggling to find his first vulnerability during his bug bounty sessions, and we were trying to identify the potential reasons behind it.

1月29日周四4

08:00
josephthacker
Hacking An AI Children’s Toy: Remote Access to Every Conversation

My neighbor texted me the other day and said she’d pre-ordered two AI toys for her kids that supposedly used an LLM to dynamically generate content for talking to the child. This was super fascinating to me. I’ve always thought something like that seemed awesome as kids can ask questions about anything, and get contextual answers back.

1月22日周四1

08:00
Atum
自动化漏洞挖掘:过去、现在与未来——AI 的上限在哪里?

2025 年,我们的系统已经在主流开源仓库自动发现了 60+ 个真实世界漏洞,半数以上都是高危漏洞,我们发现:**成功的关键并非某个单一技术突破,而是正确把握了 AI 演进的范式,并在每次范式转换中及时调整方法**。与此同时,我们也观察到,大量曾经发表于顶会的工作,因为未能跟上范式转移而逐渐失去现实影响力。这一现象促使我们写下这篇文章:系统梳理 2022–2025 年间自动化漏洞挖掘的三次范式跃迁——从「LLM 做代码分类」到「LLM 辅助传统工具」再到「Agent 主导的自动化审计」——帮助读者理解范式转换的规律,做出能够跨越范式的研究与工程决策。

1月18日周日9

05:38
Bug Bounty Daily
Leaking Meta FXAuth Token leading to 2 click Account Takeover

Introduction FXAuth is Meta’s shared authentication system used across Facebook, Instagram, and Meta (Horizon / VR). It is used by Accounts Center for account linking, re-authentication, and sensitive action confirmation.

05:38
Bug Bounty Daily
Instagram account takeover via Meta Pixel script abuse

Introduction Meta’s web ecosystem relies on cross-window messaging between first-party websites. In many cases, the only security control enforced is an origin check validating that messages originate from facebook.com or its subdomains.

05:37
Bug Bounty Daily
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery

Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.

05:33
Bug Bounty Daily
Privilege Escalation via a service account impersonation chain

Table of Contents Preface TLDR Live Hacking Event 101 Getting invited Picking the target Why Google SecOps SOAR? Reading the docs Methodology SOAR Integrations Python execution environment aka RCE-as-a-Service IDE custom code validation bypass We are in, what next? Fetching the OAuth Access Token Access token introspection What is gke-init-python used for? Service Account impersonation Prior art What can gke-init-python do? Malachite enters the scene Revised architecture diagram Auth flow is com

1月17日周六1

1月16日周五4

05:10
Bug Bounty Daily
Datr cookie theft and AI leads to Facebook account takeover via trusted device recovery

Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.

1月14日周三2

05:55
Bug Bounty Daily
Command Injection in VS Code Go Extension

A Remote Code Execution (RCE) vulnerability was discovered in the Visual Studio Code Go extension. This vulnerability bypasses VS Code's 'Restricted Mode,' the security boundary for Untrusted Workspaces. The root cause is that certain settings, such as go.buildFlags, were not properly blocked in Restricted Mode.

00:21
Bug Bounty Daily
Bypass firewalls with of-CORs and typo-squatting ◆ Truffle Security Co.

We used a new Appsec combo to get a few thousand dollars from exploiting Cross-Origin Resource Sharing (CORS) misconfigurations on internal networks in bug bounties. Check out this example of hacking Tesla. It was so much fun that we’re here to share our tooling and techniques with everyone. Rest assured that this same approach will work for plenty of other bug bounty targets.

1月13日周二1

00:34
Bug Bounty Daily
Pwning Claude Code in 8 Different Ways

A few months ago, I came across an interesting behavior while using Claude Code—it executed a command without my approval. Since I wasn’t using the permission bypass mode, I decided to investigate further to understand why it was able to execute commands without explicit approval. TL;DR I discovered 8 ways to execute arbitrary commands in Claude Code without user approval.

1月12日周一4

20:00
Bug Bounty Daily
Hijacking Netflix SMS

This blog post explains a security vulnerability in Netflix’s SMS login system that let attackers send fake OTP messages from Netflix’s official short code. By exploiting an unvalidated androidAppHash, the bug enabled SMS phishing and malware distribution at scale. The author details the bug bounty report, Netflix’s fix, and key lessons on SMS security and server-side validation.

19:50
Bug Bounty Daily
Spring Boot Actuator - Using misconfigurations to your advantage: paths, bypasses, techniques

Discover how to find and exploit misconfigured Spring Boot Actuator endpoints in real-world penetration tests and bug bounty programs. This in-depth guide covers advanced discovery techniques, header-based bypasses, path traversal tricks, sensitive endpoints like mappings, metrics, httptrace, and heapdump, plus concrete remediation steps for securing Spring Boot applications.

08:00
josephthacker
Words I Live By

Over 10 years ago, I put together a self “liturgy” of sorts (basically just a prayer) that I love reading. It takes a bunch of my favorite verses but changes them to the first-person perspective. There’s something about first person that makes it much more powerful and personal. As you read this, I pray it encourages you greatly.

11月14日周五1

08:00
Atum
量子计算机距离攻破 RSA-2048 还有多远

在当今数字世界中,RSA‑2048 与 ECC 等经典公钥密码是最广泛应用的加密标准,支撑着网络安全、金融交易和隐私保护的底层信任。然而,这一基石正面临量子计算的潜在威胁。理论上,量子计算机能够以远快于经典计算机的速度分解大整数和离散对数求解,从而在短时间内破解 RSA 和 ECC 加密。这一前景既令人兴奋,也令人担忧。问题在于:量子计算机的发展究竟到了什么阶段?有人乐观地认为经典公钥密码的“倒计时”已经开始;也有人怀疑,受限于制造难度,真正可用的量子计算机还遥遥无期。市面上相关论调不一,往往乐观或悲观,但核心疑问始终萦绕:量子计算机距离破解经典公钥密码还有多远?我们将尝试以拆解和分析量子计算机的制造瓶颈与突破希望方式回答这一问题。

11月10日周一1

08:00
Atum
我们用AI发现了一个零知识证明库的漏洞,Sam Altman的项目也用了这个库

我们研发的AI自动化漏洞挖掘引擎已经在各种类型的重要开源软件中挖出了30多个漏洞,其中近半数都是具有较高的实际危害(如RCE)。这篇文章将分享一个比较有趣的漏洞:"零知识证明库 gnark 中发现了一个高危漏洞(CVE-2025-57801,CVSS 8.6)",后续我们也会分享更多有意思的漏洞出来。

10月9日周四1

08:00
Atum
如何让VibeCoding真正好用起来

最近 VibeCoding 成为开发圈的新风潮。借助 Cursor、Claude Code 等工具,开发者只需描述需求,AI 就能自动生成代码。从批量完成重复性代码,到快速搭建原型、重构陈旧代码,极大地提升了研发效率。我们在尝试过程中,发现它完全可以胜任中等难度的工程开发工作。其带来生产力的提升令人印象深刻。然而,也有不少人初次接触时感到失望:AI 写出的代码无法运行,改动还把项目弄得一团糟,最终只好回到「祖传手写」或在普通AI对话界面里边问边写。这就形成了一种落差——一边是爱好者对提效体验的热情分享,另一边却是新用户的挫败与困惑。为什么会这样?原因在于,VibeCoding Agent本质上只是一个工具,它确实拥有强大的潜力,但前提是用户需要掌握一定的使用方法。目前各平台虽然提供了不少“最佳实践”清单,但大多零散琐碎,很难直接套用,让人难以形成系统的理解。本文将尝试回到根本,从几个最核心的原则出发,解释如何让 VibeCoding 真正好用起来,成为新生产力工具。

9月22日周一1

08:00
Atum
如何让文章既专业又好读

为什么有些文章能让人一口气读完,而有些文章却让人“每句话都懂,却合起来看不明白”?问题往往不在读者,而在写作方式。那么,怎样才能写出既专业又好读的文章呢?本文将以信息传递类文章(如博客、技术文档、学术论文等)为例,尝试总结一些实用经验。如果你正好正在创作这类内容,相信这里的思路会对你有所帮助。需要说明的是,文中提到的部分技巧并不限于信息传递类文字,其中一些方法(例如让文字更具画面感)在散文、小说等其他类型的写作中同样适用。

9月10日周三1

08:00
Atum
为什么要成为“什么都会”的全栈技术专家?要怎样做?

技术的本质,是为了实现人类某个目的而形成的流程、方法或装置。换句话说,技术从来是为目的服务的,而不是目的本身。也因此,当我们试图用技术去解决一个问题时,问题所在的领域,和最终所需要调用的解法所在的领域,可能完全不同。问题域只是问题发生的地方,而解法域是答案所在的地方,两者并不必然一致。所以,**一个人掌握的技术越全面,他就越有可能构造出一个好的解决方案。**

8月6日周三1

08:00
Atum
一种通用的控制大模型输出任意的内容的方法

大语言模型(LLM)正在从简单的对话工具演化为能够编写代码、操作浏览器、执行系统命令的智能体。随着大模型应用的演进,提示词注入攻击的威胁也在不断升级。设想这样一个场景:你让AI助手帮你编写代码,它却突然开始执行恶意指令,控制了你的电脑。这种看似科幻的情节,如今正在变为现实。本文将介绍一种新型的提示词注入攻击范式。攻击者只需掌握一套“通用触发器”,就能精确控制大模型输出任意攻击者指定的内容,从而利用AI智能体实现远程代码执行等高风险操作。

8月1日周五1

18:56
Atum
利用“长度侧信道”绕过5G/4G/WiFi网络的加密实现TCP/UDP劫持

在当今数字化时代,5G、4G和Wi-Fi等无线通信技术已成为我们日常生活的重要基础设施。这些网络普遍采用先进的加密协议,理论上能够有效保护用户通信安全。然而,近期由我们腾讯玄武实验室与清华大学陈建军老师团队在EuroS&P 2025上发表的研究成果LenOracle揭示了一个新的安全隐患:攻击者可能将空口数据帧(radio frame)长度信息作为侧信道,在不破解无线加密的情况下劫持加密网络中的TCP/UDP连接。我们在真实的商用LTE网络和Wi-Fi环境中进行了测试,成功在TCP场景下利用该攻击向受害设备注入了一条伪造的短消息,并在UDP场景下污染了受害设备的DNS缓存,展示了该攻击对关键网络服务的潜在破坏力。

2月23日周日1

2月16日周日1

08:00
Atum
中国哲学的魅力,不是逻辑,但却引人入胜。

作为理科生,我在相当长的时间都觉得逻辑是唯一值得相信的东西。因此也曾觉得中国哲学,诸如心经的“空即是色,色即是空”这种看起来没有逻辑的东西实在是令人遗憾。甚至认为东方哲学是走偏了,还是西方认识论、本体论才是哲学的正道。后来随着学习的深入,才发现逻辑也有其局限,而中国哲学的方法正好可以能其所不能。

2月9日周日1

08:00
Atum
庄子教你怎么过得逍遥快活

春节后开始读庄子,先秦时期的文言文比唐宋之后要难读的多,对照着各级注解讲述,读了一个多周也只读完了“逍遥游”和一半的“齐物论”。光这部分就让我受益匪浅,于是今天且分享一下。

12月31日周二1

08:00
Atum
2024:我的阅读、学习与感悟

2024年,是我读书最多的一年,也是我自我感觉成长最大的一年。我读的书大体可以分为三大话题:哲学、理财,以及一些偏向实用性的内容。我会在本文分享一下我在这些话题上的一些感悟。

10月21日周一1

15:17
Flanker 博客
The Return of Mystique? Possibly the most valuable userspace Android vulnerability in recent years: CVE-2024-31317

Abstract This article analyzes the cause of CVE-2024-31317, an Android user-mode universal vulnerability, and shares our exploitation research and methods. Through this vulnerability, we can obtain code-execution for any uid, similar to breaking through the Android sandbox to gain permissions for any app. This vulnerability has effects similar to the Mystique vulnerability discovered by the author years ago (which is the little horse in the title image – the Pwnie Award

9月17日周二1

8月21日周三1

16:23
Flanker 博客
魔形女再袭?最新Android通杀漏洞CVE-2024-31317分析与利用研究

摘要 本文分析了CVE-2024-31317这个Android用户态通杀漏洞的起因,并分享了笔者的利用研究和方法。通过这个漏洞,我们可以获取任意uid的权限,近似于突破Android沙箱获取任意app的权限。这个漏洞具有类似于笔者当年发现的 魔形女漏洞 (黑客奥斯卡 Pwnie Award最佳提权漏洞 )的效果,但又各有千秋。 漏洞缘起 数月之前, Meta X Red Team 发表了两篇非常有意思的,可以用来提权到任意UID的Android Framework漏洞,其中CVE-2024-0044因简单直接,在技术社区已经有了广泛的分析和公开的exp,但CVE-2024-31317仍然没有公开的详细分析和exp,虽然后者比前者有着更大的威力(能获取system-uid权限)。这个漏洞也颇为令人惊讶,因为这已经是2024年了,我们居然还能在Android的心脏组件(Zygote)中发现命令注入。 这让我们想起了当年我们所发现的 mystique漏洞 ,这个漏洞同样能让攻击者获得任意uid的权限。需要注意的是,两个漏洞都有一定的前提条件,例如CVE

6月16日周日1

08:00
Atum
论自由与人生意义

当我们说“我自由地做出了选择”,这句话究竟意味着什么?在一个由物理定律支配的宇宙中,自由真的存在吗?而如果世界本身没有目标与意义,人类的选择又有什么价值?人的一生,似乎都在会在一个追问中前行:我的人生是为了什么。本文将尝试从科学、哲学与意识层面展开思考,在理性与困惑之间,寻找一个“自由而有意义的生存

3月16日周六1

14:26
X 收藏
@geekbb:最初大家在 Cloudflare 上薅梯子行为我是嗤之以鼻的,甚至有些鄙视,兄弟们都缺成什么样了?再不济 Cloudflare 还提供了 WARP+ 服务呢。作为搭🪜技术资深学者,我出于纯研究…

作者经实测发现,在 Cloudflare Worker 上部署 VLESS 代理可跑满带宽,认为其性能足以替代传统 VPS 线路。作者分享了相关搭建项目,并实测该代理方案能与 OpenWrt PassWall 结合实现多线路负载均衡。

11月10日周四1

1月20日周三1

21:53
Flanker 博客
Fuzzing战争系列之二:不畏浮云遮望眼

本文 拨开二进制Fuzzing的迷雾 为Fuzzing战争系列的第二篇,也是 Fuzzing战争:从刀剑弓斧到星球大战 的续篇。 每个人都期待有全图点亮的体验,然而现实中安全研究的目标却更多是编译好的二进制binary而没有源码。迷雾之下崇山峻岭羊肠小道,但应许之地却往往也隐藏其中。本文将以目前最为主流的Android on ARM/AARCH64为例,综合笔者在 MOSEC 2020 和 RWCTF Tech Forum 2021 的演讲内容,首次系统性地阐述如何实现无源码情况下的大规模Coverage-Guided Fuzzing理论、工程和实践,和小试牛刀即发现的主流移动终端中广泛存在的真实漏洞。出于阅读体验,本篇可能会分多次发出,持续更新中。 前方预警:本文为硬核技术导向,非技术人员请直接划到最后篇后随笔一节 。 Let’s rock n’ roll ! 温故而知新 就像简陋的纸带机模型却能描述出完备的图灵机一样,一个五行的bash脚本甚至也可以成为fuzzer,当然作为一个dumb fuzzer,直到宇宙毁灭,它

9月11日周五1

18:56
Atum
给SIM卡上PIN、锁屏不显示通知详情后,你就安全了吗?

我昨天晚上在微信群中看到了一篇文章,文章作者家人一部手机被盗,被黑产犯罪团伙以SIM卡(主要是短信验证码)为起点,完成了对文章作者家人展开了一系列的攻击。虽然文章作者做了一些及时的补救,但这些攻击仍使得受害者损失惨重,如被刷了各种小额贷款等。我思考了一下这套攻击能成功的原因,以及如何才能防御这类攻击,在此分享给大家。

5月28日周四1

16:37
Flanker 博客
Fuzzing战争: 从刀剑弓斧到星球大战

Fuzzing这个事物大概可以上溯到1950年,当计算机还在读取打孔卡作为输入的时候。那时候的工程师会从垃圾箱里随机检出一些废弃卡片,或者在卡上随机打孔作为输入来测试自己的程序。在1988年,Barton Miller在课堂上将Fuzzing这个名词正式确定,从此拉开三十年波澜壮阔的序幕。 广义上的fuzzing并不是漏洞挖掘中的专属内容,而是DevSecOps和Continous Integration质量保证中必不可少的一环,甚至可以延伸到完备图灵自动机的美妙梦想。在起初,人们通常以monkey testing来指代最原始的fuzz,就像著名的无限猴子定理一样:让一只猴子在打字机上随机地按键,当按键时间达到无穷时,几乎必然能够打出任何给定的文字,比如莎士比亚的全套著作,当然也有可能包含一套Nginx RCE。 但很显然,随机化的输入虽然终究能覆盖所有的输入空间,在人类未来可预见的算力水平下近乎天方夜谭。刘慈欣在《诗云》中有一个宏大的故事:宇宙神级文明为了写出最优雅的诗,而把整个太阳系的物质作为存储器,采用枚举遍历的办法把所有文字的排列组合全部

11月7日周四1

00:02
Flanker 博客
Text-To-Speech speaks pwned

Text-To-Speech engine is a default enabled module in all Android phones, and exists up to Android 1.5 HTC era, even acting as a selling point at that time. But various vendor implementations may lead to various interesting stuff, i.e. CVE-2019-16253, a seemly harmless language pack, or nearly any seemly benign application, without requring any permission, can obtain a persistent SYSTEM shell through the TTS bug (or feature?). Vulnerability Briefing TL;DR: Samsung TTS componen

10月16日周三1

22:23
Flanker 博客
Examining and exploiting android vendor binder services – part1

Vendor binder services proved to be an interesting part of android devices nature. They usually remains close-source, but sometimes open new attack surface for privilege escalation. In these articles I will first describe how to locate interesting binder service and a reversing quirk, then two typical CVEs will be discussed about their nature and exploitation, and how to find them. Locating interesting binder services Before Android N, all binder services were registered to s

10月11日周五1

23:55
Flanker 博客
Examining and exploiting android vendor binder services – part 1

安卓生态多姿多彩,在AOSP之外各大厂商的binder service也同样各式各样。这些自行实现的service通常来说是闭源的,常常成为会被人忽略的提权攻击面。在这一系列文章中,我会先描述如何定位可能有问题的binder service进行后续研究,以及逆向中一些有意思的发现,随后会以之前发现的两个典型的CVE为例,讨论这些漏洞是如何产生的,如何发现它们,以及如何进行利用。 寻找潜在的分析目标 在Android N之前,所有的binder service都是在 servicemanager 中进行注册的,client通过 /dev/binder 与service进行通讯。Android N对binder服务引入了domain切分的概念,常规的服务依然使用/dev/binder,而vendor domain则转换为使用 /dev/vndbinder , hardware domain转换为使用 /dev/hwbinder 。常规的untrusted_app访问被限制在了/dev/binder。 通过 service list ,我们可以查看设备

8月6日周二2

22:40
Flanker 博客
Galaxy Leapfrogging盖乐世蛙跳: Pwning the Galaxy S8

在最近的一系列文章中,我会介绍这些年以来通过Pwn2Own和官方渠道所报告的在各种Android厂商设备中发现的各种CVE,包括通过fuzz和代码审计发现的各式各样的内存破坏漏洞和逻辑漏洞。第一篇文章将会介绍在2017年末我们用来远程攻破Galaxy S8并安装应用的利用链,一个V8漏洞来获取最开始的沙箱内代码执行,和五个逻辑漏洞来最终实现沙箱逃逸和提权来安装任意应用,demo视频可以在 这里 看到。 所有的漏洞均已经报告并以CVE-2018-10496,CVE-2018-10497,CVE-2018-10498,CVE-2018-10499,CVE-2018-10500来标示。本文将主要介绍整个利用链,V8漏洞将在另外的文章中介绍。 English version writeup here Bug 0: Pwning and Examining the browser’s renderer process 通过第一个V8漏洞(CVE-2018-10496,credit to Gengming Liu and Zhen Feng),我

20:50
Flanker 博客
Galaxy Leapfrogging: Pwning the Galaxy S8

Hello everyone, long time no see! Now begins a series of blog posts about bugs I found before and now on Android vendors, including memory corruption and logical bugs, reported and fixed via Pwn2Own or official bug channel. This very first post is about the chain of bugs we used in the end of 2017 to get remote arbitrary application install via clicking malicious link on newest Galaxy S8 at that time, prepared for Mobile Pwn2Own, with a V8 bug to get initial code execution in

6月2日周日1

08:00
Atum
怎样出一道高质量的CTF赛题

我们战队 r3kapig 为刚刚结束的 DEFCON 外卡赛之一的 Baidu CTF 提供了 10 道赛题(一共 13 道),并作为比赛的总裁判把控了比赛的赛制、部分规则以及赛题质量。 Baidu CTF 是一个新生的外卡赛,我们也做了一些尝试,比如让 AEG 战队和人类顶尖战队在比赛中同场 PK。虽然在不断试新的过程中出现了不少小问题,但是在大家的共同努力下,我们还是贡献出了一场合格的外卡赛。今天,我想以这场比赛为契机,来谈一谈我个人对 CTF赛题的理解