本期 Medium 邮件聚焦 Agentic AI 安全领域的未来职业发展,重点推荐了 Taimur Ijlal 的文章《The Agentic AI Security Career Roadmap (2027 Edition)》。该文章前瞻性地规划了面向 2027 年的安全从业者成长路径,探讨了智能体 AI 带来的新兴安全趋势与核心技能需求。对 bug bounty 猎人及安全从业者而言,这份路线图极具战略参考价值,有助于提前布局并探索 Agentic AI 环境下的新型攻击面与漏洞挖掘机遇。
全部动态
2026年8月5日星期三 · Bug Bounty 相关资讯快照信息流
8月5日周三3 条
Medium宣布将在今年的Medium Day上为Friends of Medium推出专属互动活动,深度聚焦AI与写作(AI and writing)的核心议题。邮件探讨了AI时代下人类创作者的价值不降反升,指出平台正迎来一场“写作复兴”(Writing Revival)。对于安全从业者和Bug Bounty猎人而言,此话题有助于反思在利用AI辅助撰写漏洞报告和技术文章时,如何保持人类独有的批判性思维与深度洞察。这种探讨能帮助技术写作者在AI浪潮中找准定位,提升安全研究成果输出的不可替代性与传播价值。
Medium 推送了 Taimur Ijlal 的文章《The Cybersecurity Certifications That Still Matter in the AI Era》,探讨了在 AI 浪潮下从业者应如何明智地选择网络安全认证。文章指出,随着技术演进,部分传统证书的价值正在发生变化,安全人员需要更具前瞻性地规划学习路径。对 bug bounty 猎人和广大安全从业者而言,该内容有助于在 AI 时代优化技能投资,避免资源浪费,确保所考取的认证能真正转化为个人核心竞争力和职业优势。
8月4日周二1 条
自2026年9月1日起,Intigriti 将正式成为 Adobe 漏洞赏金项目的新托管平台。随着 AI 技术重塑产品开发流程,Adobe 希望借助 Intigriti 全球研究社区的力量,以应对不断演进的安全测试需求。此举旨在帮助 Adobe 更高效地发现并修复其各类产品中的安全漏洞。
8月1日周六1 条
腾讯开源了TencentDB Agent Memory,无需庞大的聊天记录库即可为AI智能体提供永久记忆。该工具采用可读的语义金字塔结构并通过ACL按需为不同智能体分配记忆,使Token消耗降低61%,记忆准确率从48%提升至76%。作者强调,这能让AI团队不仅记住上下文,还能在每次任务中不断进化。
7月31日周五2 条
本期 Bug Bytes 迎来 Intigriti 成立十周年特辑。文章重点披露了 GitHub.com 及 GitHub Enterprise Server 的 RCE 漏洞,介绍了新增 AI 代理功能的 Burp Suite Burp AT,并分享了黑客通过渗透 Gemini Enterprise 获得高达 15,000 美元赏金的案例。此外,还提到有研究人员通过扫描 GitHub Archive 发现了 3,708 条有效凭证。
depthfirst发布了基于GLM-5.2与强化学习的最新安全模型dfs-large1,在漏洞检测任务上达到同类最佳性能。作者表示该模型的训练提升尚未停滞,预计未来仍有性能增长,现已在其平台开启预览。
7月30日周四2 条
作者总结了十年的 XSS 绕过经验,分享了 30 多种技术及 10 个实战案例,曾成功突破 CloudFlare、Akamai、Imperva 和 Fortinet 等 WAF。作者强调,WAF 和公开的绕过载荷终会被修补,但存在于研究员脑中的系统性绕过方法论是无法被修复的。
漏洞赏金(Bug bounty)项目通常由安全研究员、漏洞分类团队和受影响企业多方协作完成。尽管大多数漏洞报告能得到妥善处理,但仍有少数报告会被误关、严重程度被降级或长期搁置。遇到此类情况时,掌握专业且有效的申诉应对方法至关重要。
7月29日周三2 条
在使用 subfinder 进行子域名枚举时,建议添加 -recursive 参数强制支持递归的数据源(如 Censys)进行更深层探测。配合速率限制功能,既能避免 API 被封禁,又能有效扩大资产覆盖范围。
作者探讨了安全循环工程师如何监控循环行为。他通过解析漏洞赏金活动中子智能体生成的 jsonl 文件,追踪文件读取差异、历史循环对比及 token 消耗等指标并获得惊人发现,正考虑将此监控工具作为本地工具开源。
7月28日周二2 条
RAG 系统通过引入外部可变内容扩大了应用的信任边界,攻击者一旦操纵索引或检索的数据,即可控制模型的输出与行为。在简单的问答系统中,这可能导致虚假信息或不安全建议;而在具备工具和权限的智能体系统中,则会引发数据泄露、越权操作或业务破坏。因此,组织必须针对 RAG 的数据摄入等环节部署专门的安全防护措施。
今天,我离开了毕业后便加入、工作了七年的腾讯玄武实验室,即将加入 MiniMax,开启一段新的旅程。值此人生的重要节点,我想写下这些年一路走来的思考,以及始终牵引着我的志向。
7月27日周一2 条
nirohfeld 的 AI 漏洞研究系统 Atlas 在 CyberGym 评测中排名第一。利用该系统,研究人员已在 gVisor、Linux 内核及 containerd 等项目中发现并负责任地披露了超 200 个已确认漏洞。
CrowdStrike发布博客披露18项新增提示词注入技术,使该项目累计覆盖超过200种注入技术。该团队声称维护着业内最大规模的提示词注入分类体系,通过结构化层级全面展示了AI威胁的风险全貌。
7月26日周日1 条
分析了 HackerOne 平台 313 份已披露的 SSRF 报告后发现,其中普遍存在 5 种模式,且有两条不同的利用链可导致完全 RCE。作者据此总结出一套可对所有端点运行的测试框架。
7月25日周六2 条
depthfirstlabs 团队今日披露了一个 GitLab 远程代码执行(RCE)漏洞,发布者评价该漏洞利用效果十分震撼。
本期安全情报汇总了多项实战漏洞案例,包括 Hugging Face 被 AI 智能体攻破、利用输入过滤黑名单缺陷实现 SSRF、绕过 WAF 客户端加密触发严重 SQL 注入,以及因 Base64 编码密钥泄露导致生产环境被接管。同时分享了在微软及政府机构系统中挖掘高危漏洞的实战经验。
7月24日周五1 条
作者认为AI安全的优势在于框架而非模型本身。VISA开源了其网络安全框架,支持灵活接入各类闭源或开源模型,支持本地或托管部署,此举有助于提升整体网络防御能力。
7月23日周四3 条
作者分析了中文区X平台高收入博主的变现模式,发现其高度依赖内容聚合器获取热门选题。文中分享了三个实用素材源:last30days用于抓取X和油管近30天热门讨论,TL1网站用于追踪中文圈热门推文,知乎今日热榜则提供知乎每日热点,以解决创作者的选题难题。
Recon-skills 工具将 169 项进攻性安全技能整合为适配 AI 的工具包,以提升侦察效率。该工具集覆盖子域名枚举、vhost 发现、JS 分析和 GitHub 密钥检索等功能,且已在 45 个以上行业的 600 多个真实目标中完成实战验证。
随着 AI 工具具备读取数据、接收指令和代为执行的能力,“致命三要素”带来的安全威胁正日益严峻。攻击者可通过投毒的邮件、网页或文档欺骗 AI,导致其泄露敏感信息或执行未经授权的操作。因此,随着 AI 在组织中扮演越来越核心的助手角色,企业必须为其访问权限和自主操作部署严格的安全防护机制。
7月22日周三3 条
作者精简了家庭实验室架构,改用虚拟机上的单一 tmux 搭建复古环境,并提到 GPT 5.6 让其短暂放弃了 Claude。此外,作者还分享了在 AI 智能体主导漏洞挖掘的当下,人工寻找漏洞的真实感受与思考。
HacktronAI 发现 CVE-2026-4296 漏洞,该漏洞可利用 OAuth 重定向机制接管 GitHub 代码库。
7月21日周二2 条
BRuteLogic 分享了 OAuth 授权绕过测试靶场,可供安全研究人员测试和复现此类授权漏洞。
阿里巴巴 Fastjson 被发现存在远程代码执行漏洞的 PoC。该漏洞源于 JSON 反序列化时对 @JSONType 机制的不安全处理,未授权的远程攻击者可通过发送恶意 JSON 请求触发加载远程 JAR 文件,导致任意 Java 类加载并执行攻击者控制的代码。
7月20日周一1 条
安全团队常因漏洞报告间的盲区而错失攻击者的真实视角,单纯依赖扫描器和资产清单无法揭示攻击意图。所谓“报告间可见性”是指填补两次报告之间的情报空白,而非依赖产品推销。未来安全团队需要更早期的预警信号,以便在下一份报告发布前采取行动。
7月19日周日4 条
se1en 分享了构建基于 AI 的漏洞检测工作流的方法与实践。
wp2shell RCE 漏洞现已无需破解即可利用。攻击者可通过伪造 WP_Post 触发路由混淆,以现有管理员身份运行 customize_changeset,随后通过 POST /wp/v2/users 创建新管理员,最终登录系统获取 shell。
有机构评测了各大模型在重新发现CVE及漏洞挖掘方面的攻防能力。作者指出自部署的GLM5.2已达到安全团队实战可用水平,并期待半年后GLM及解锁后的K3能有更强表现。
作者披露了一个针对电信系统的后门。该后门附加于原始网络套接字上,能在防火墙规则生效前检查传入流量,从而绕过正确的防火墙配置。攻击者通过发送特定魔法字节即可获取反弹 Shell,作者同时分享了该后门的检测方法。
7月18日周六1 条
研究人员披露WordPress存在预认证远程代码执行漏洞,该漏洞无需任何前置条件即可被利用。建议用户尽快修补相关实例以防攻击。
7月17日周五4 条
作者近两年前在GitHub上发布了漏洞赏金挖掘方法论。尽管部分内容可能已过时,但其中的实用技巧仍可用于构建AI提示词或改进现有的漏洞挖掘方法。
Claude Code 在无提示盲测中成功映射应用并发现一个请求走私漏洞。但作者指出,证明漏洞的实际影响仍需安全研究员人工完成。
rez0 推出了一款名为 rez0’s rascals 的 K-5 学习应用。该产品主要面向家庭学校、合作办学及混合制学校的家庭,旨在满足相应的教育需求。
Capital One开源了漏洞分析工具VulnHunter。该工具可识别真正可利用的缺陷,映射潜在攻击路径,并提供基于证据的针对性修复方案。
7月16日周四4 条
试了一下,发现这是个好东西~ wigolo 一个免费、本地、私有的 MCP 服务,让你的 AI Agent 能搜索、抓取、研究网页,效果和付费服务相当,但永远不用花钱。 https://t.co/Sb2xj4b4Gb https://t.co/zj3QY3ijED
更新了利用大语言模型进行漏洞检测的相关论文汇总列表。
DeerFlow 团队推出一款面向 Agent 构建者的桌面应用,支持快速搭建、执行追踪、回放调试及性能评估。该工具将提示词编写、轨迹查看和本地线程存储整合在同一窗口,自 2023 年起便用于各版本 DeerFlow 的内部调试。
作者认为漏洞利用开发已走向终结,并警告能编写Chrome等软件漏洞利用的模型若落入恶意者手中将十分危险。其团队最新发文演示了如何利用n-day漏洞成功攻破PostHog生产数据库。
7月15日周三2 条
教大家如何在练英语的同时还能交外国女朋友/男朋友 首先下载一个hellotalk app, 然后随便做几个任务升下等级解锁语音房, 然后语音房里聊,最好选择中文英语交换的房间, 上次就有个马来西亚女生, 跟我吐槽有个中国渣男骗了她的感情 https://t.co/EOhKE2C0BB
我们耗费大量精力优化 Claude,却鲜少思考在它工作时自己该做些什么。本周探讨了 AI 如何悄然将我从内容创作者变成了纯粹的消费者,以及无限滚动为何让人感到空虚。此外,我还分享了一款为了对抗这种状态而冲动入手的昂贵小设备 BusyBar。
7月8日周三2 条
作者反思了对 Claude 的错误用法,指出不应像无休止循环般催促其继续,而应像指导实习生那样给予明确引导。此外,文章还强调了在漏洞赏金领域,真实的人际交流比任何事都更为重要,并分享了在孚日山脉度假的轻松时光。
AI 聊天机器人的应用扩大了系统攻击面,攻击者仅需单个恶意代码块即可劫持 Google DialogFlow 中的 AI 会话。研究人员通过接管聊天机器人,成功窃取数据并获取了发起后续攻击活动的立足点。
7月2日周四1 条
Mythos 的意义不只是模型能力突破,而是把 AI 自动化漏洞挖掘推成了一次行业动员。后 Mythos 时代,漏洞发现会继续变便宜,中垂果实会被快速释放;但真正稀缺的会转向仓库级覆盖、低噪声验证、修复、披露、维护者承接能力,以及对供应链投毒和变更入口攻击的治理。本文从七个趋势出发,讨论自动化漏洞挖掘从发现端扩产走向治理端重构的下一阶段。
7月1日周三3 条
LeHack 大会于巴黎 La Villette 重新举办,期间举办了 YesWeHack Live Event。此外,一场聚焦合规与 SOC 2 的圆桌讨论也同步进行。本周的核心议题聚焦于 LeHack 大会本身,以及人工智能技术将如何影响与改变黑客攻击的发展方向。
“Operation Floodlight”探讨了人工智能系统具备强大网络安全能力后所带来的下游影响。该研究重点关注 AI 在攻防两端的实际应用,及其对整体安全生态造成的连锁反应。
去年12月起,熟练黑客已能低成本部署自动化攻击智能体,以数百美元的 Token 开销换取数千美元的漏洞赏金,作者将此称为“Bug Bounty Singularity”。本文讲述了 JD(xssdoctor)与作者共同开发一款 Hackbot 的过程,该工具在过去5个月内成功发现了126个漏洞。
6月30日周二1 条
作者首次公开发布了一项名为“AI Safety For Parents”的10天邮件课程。该课程旨在帮助家长掌握必要知识,从而在AI时代更好地保护孩子的安全。
6月29日周一1 条
在 AI 时代,安全漏洞的发现速度与数量均大幅提升,使得人工研判与优先级排序变得愈发关键。然而,多数安全团队目前仍主要依赖“成功结果”进行经验总结与防御。这种滞后的情报获取模式已难以应对当前威胁,团队必须转向前置的暴露面侦察,通过掌握更全面的安全上下文来提升整体防御能力。
6月27日周六1 条
Cookie 是现代 Web 的基础组件,但其安全性常被忽视。配置不当的 Cookie 策略可能导致敏感会话数据泄露,引发多种客户端攻击,严重时甚至允许攻击者完全冒充用户。本文详细探讨了攻击者如何利用不安全的 Cookie 策略。
6月26日周五1 条
本期 Intigriti Bug Bytes 重点披露了 phpBB 长达 10 年的未授权 RCE 漏洞,以及 DOMPurify 解析器的最新绕过技术。此外,内容还涵盖了利用 AI 漏洞挖掘赚取 Google 50 万美元赏金的案例、读取任意 Salesforce Marketing Cloud 账户邮件的安全风险,以及通过接管废弃 S3 存储桶来大规模复刻 SolarWinds 供应链攻击的威胁分析。
6月24日周三2 条
今年的黑客之家活动在南部别墅举行,团队成员首次在引入 Claude 后重聚。如今大家只需将 AI 指向目标范围,便会挖掘出相同的漏洞。这次行程带来了全新的狩猎模式,但也产生了大量重复漏洞。
Web 缓存技术虽能优化页面加载速度,但配置不当会引入 Web 缓存中毒漏洞。本文介绍了该漏洞的成因、发现方法及实际利用过程。
6月17日周三3 条
Cristian Zot(网名 CristiVlad25)是一名资深渗透测试专家与安全研究员,同时也是 Intigriti 平台的黑客大使。他长期活跃于道德黑客社区,通过播客、线下聚会和教育内容积极分享安全经验。近期,他还作为特邀专家参与了 Intigriti 在 Discord 上的直播问答活动,解答社区提问。
Cristian Zot(CristiVlad25)是一名活跃的安全研究员、资深渗透测试专家及 Intigriti 黑客大使。他在道德黑客社区具有较高影响力,常通过播客、聚会和教育内容与 Intigriti 合作。近期他还作为客座专家参与了 Intigriti 的 Discord 直播播客,解答社区问题。
研究人员发现仅需个人ID即可在FIFA公开的 Agent Platform 上注册,进而获取 Football Data Platform 的 Streaming Management 面板访问权限。该漏洞允许攻击者提取2026年FIFA世界杯所有直播摄像头的RTMP推流地址和流密钥,甚至能劫持整个赛事直播。为上报此漏洞,研究人员耗时数小时多方联系才最终与FIFA、MediaKind、HBS、CISA及FBI取得沟通。
6月16日周二1 条
2026 年 6 月 11 日,我在上海 AGI Bar 与三十余位安全从业者深入讨论 Mythos 所展现的 Cyber 能力。当 Agent 可以连续完成资产发现、漏洞分析、PoC /EXP 编写、路径推演和作战调度时,网络安全该怎么做?本文从攻击链压缩出发,提出 AI 时代的防御者方程,并给出资产盘点、持续的红队验证与脆弱点扫描、自动化的安全运营等短期可建立能力,以及可达性治理、爆炸半径压缩和 Agent Skill 工程化的长期路径。
6月12日周五2 条
一位博主在其主要分享编程经验的博客中,披露了 VSCode 的一项安全漏洞。该漏洞允许攻击者通过一键操作窃取用户的 GitHub Token。开发人员需关注此类开发环境中的潜在安全风险。
研究人员将AI应用于Google全部基础设施进行安全测试。此次测试共发现1500个API和3600个密钥,并由此获得50万美元的漏洞赏金。本文分享了此次AI驱动安全测试的发现与经验。
6月11日周四1 条
本文探讨了 AI 与网络安全融合如何重塑漏洞的发现与修复机制。结合高级安全软件工程师 Leo Racanelli 的洞察,文章深入剖析了 AI 对一线安全工程师及企业数据防护的实际影响。内容旨在拨开炒作迷雾,真实呈现当前 AI 系统安全防护的实践现状。
6月10日周三1 条
上周探讨了虚假生产力,本周继续反思真正有效的工具。作者重新用起了简单的番茄钟计时器,并最终确定切换至 Hermes 智能体平台,同时持续优化其语音控制的 Onyx 系统。
6月9日周二1 条
Intigriti 在 2026 年 SC Awards Europe 中荣获“最佳安全公司(250人以下规模)”奖项。该奖项拥有超过25年历史,旨在表彰塑造网络安全行业未来的卓越组织与领导者。2026年6月3日,Intigriti 与众多安全行业杰出代表共同出席了此次盛会。
6月5日周五1 条
IBM i Management Central 存在未授权远程代码执行漏洞,攻击者可借此获取 QSECOFR(系统安全员)权限执行任意命令。该漏洞利用无需任何身份验证,攻击者可轻易借此完全接管目标系统。
6月4日周四1 条
安全研究机构 elttam 发布了 Golang 代码审查笔记的第二部分。该文章重点探讨了 Go 语言代码审查过程中的安全注意事项与常见漏洞模式。这些内容为开发和安全团队提供了实用的代码审计参考,有助于提升 Golang 项目的安全性。
6月3日周三3 条
作者反思了“伪生产力”现象,并指出家庭网络配置的不足。一次停电导致其自托管的博客宕机,暴露出基础设施在可用性方面的短板。文章最后更新了 Meetly 项目的最新进展。
本文介绍了作者在浏览器特性模糊测试工具 Shazzer 内部发现的一个 XSS 漏洞。与利用 Shazzer 进行测试不同,该漏洞直接存在于 Shazzer 平台自身。作者还分享了如何利用 Blob URL 技术绕过沙箱限制以释放恶意内容。
一个暴露 Grafana 实例的 Meta IP 最终演变为一条五跳漏洞链,成功触达 507 个私有仓库。该漏洞链发现者因此获得了 15.7 万美元的赏金。幸运的是,此次漏洞挖掘并未实际访问任何代码。
6月2日周二2 条
How HTTP/2’s multi-frame architecture allows attackers to bypass WAFs by exploiting timing delays, protocol translation flaws, and incomplete body inspection across various reverse proxies
Introduction Hello, I’m RyotaK ( @ryotkak ), a security researcher at GMO Flatt Security Inc. After publishing my previous article ( Pwning Claude Code in 8 Different Ways ), I continued investigating Claude-related products and found several more vulnerabilities. In this article, I will explain a vulnerability in Claude Code’s GitHub Actions that could allow an attacker to compromise any repository that uses the Claude Code workflow, including Anthropic’s own repositories.1 Note: Variants of th
6月1日周一2 条
Stefan Goossens(代号 G0053)是来自荷兰的独立安全研究员,同时兼任一家营销与网页开发公司的合伙人。他白天负责设计和构建用户友好的网站,业余时间则专注于测试这些网络应用以挖掘安全漏洞。这种双重身份使他完美地将网站的建设与攻防测试结合在一起。
Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-friendly websites, his free time is spent testing those very applications to see wha
5月30日周六1 条
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sanitized name field And so much more! Let's dive in! CEO insights: beyond the AI model card AI model cards have become a standard part of how organizations document their
5月28日周四1 条
Security teams running Bug Bounty programs often require similar insights and reporting to prove the value and ROSI for security initiatives, and often ask questions such as: What changed? Where are we spending? Are we improving? What needs attention right now? Until now, answering those questions often meant exporting data, stitching together spreadsheets, or pulling screenshots from multiple places. Insights is our revamped analytics dashboard experience inside Intigriti. I
5月26日周二3 条
As part of our recent AI series, I’ve been sharing my insights on the key topics, questions, and debates currently shaping the industry. I have covered my opinions regarding holding the human layer sacred in the AI era, where I explored what I deem is the beating heart of the Bug Bounty industry, AI strengths and weaknesses, where human hackers fit in, and what businesses will face in the next 3 to 5 years. I then looked beyond the AI Model card, where I discussed continuous
In March, our system detected a severe vulnerability in V8, the JavaScript engine used by Chrome. This vulnerability enabled remote code execution against billions of Chrome users worldwide.
Some weeks ago, I was testing a mature and heavily audited application from a bug bounty program. Since I had previously found several interesting client-side vulnerabilities in that target, I decided to focus on the frontend again. What first looked like a safely sanitized name field eventually became one-click account takeover through a chain of bypasses.
5月22日周五5 条
Two minimal Node.js scripts demonstrating a SOCKS5 hostname null-byte injection that defeats Claude Code's wildcard network allowlist on vulnerable releases.
A chance Discord message, two missing pieces, and one hour before the window closed: From info leak to RCE on Google Cloud. Three months later, it happened again.
Some organisations’ most sensitive information is only ever discussed in person. Ironically, the equipment in meeting rooms, conference halls, and other physical locations is often among the least-monitored and most insecurely-configured attack surfaces in an organisation.
The Sanitizer API arrived with much fanfare in both Chrome 146 and Firefox 148 just a few months ago. The API provides two new ways to set HTML safely from within javascript; the default mode: node.setHTML(`Hello, world!`) And the more customizable mode: const config = { "elements": ["p", "span", "b"], "attributes": ["class"] }; const sanitizer
Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with PostgreSQL. It was reported upstream by Michael Maturi and a fix shipped across every supported branch (11.3.10,
5月21日周四3 条
Data exfiltration in Gemini via Android's volume settings, using a classification system.
Achieving consistent exploitation of prompt injections using client-side gadgets.
AI is changing the volume and accelerating the pace of vulnerability submissions. If you've been following our recent AI series, you already know that submission growth isn't a quality problem; it's a coordination problem. As Head of Triage, Lennaert Oudshoorn, outlines in his recent post, ‘The AI impact: A triager’s perspective’, the security industry is experiencing a surge in vulnerability discovery and a relative scarcity of triagers. Validating, classifying, and sorting
5月20日周三1 条
Two ways to use AI for bug bounty: full autonomy that drowns you in slop, or focused delegation that brings the fun back. Plus the 90 euros Claude burned on my card, and why the game still feels broken.
5月19日周二6 条
Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned (this page) Note: The vulnerab…
Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell image (this page)Bug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…
Quick navigation IntroductionBug #1 – The Python language server (this page)Bug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…
Quick navigation Introduction Bug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git clone (this page)Bug #4 – Go and get pwned Note: The vulnera…
Discover how attackers exploit HTTP redirect discrepancies to extract sensitive data embedded in URLs, and what you can do to prevent secret leakage in your web infrastructure.
Stealth Request That Bypasses CSP, Hides from DevTools, and Leaks the Real User-Agent
5月13日周三1 条
I came back to the concept of flow and how AI is quietly killing it. Then I built a full iOS meditation app in 24 hours with Claude. And a few thoughts on why sport changed everything for me.
5月12日周二1 条
Of course I took a peek at the Claude Code source 🙈. What I found was a very entertaining vulnerability which is now fixed since Claude Code version 2.1.118. Just wading through the massive codebase manually wasn’t really a feasible approach. So took an army of AI Agents to…. no wait actually I did not do that, the following was all manual work. :P I started by looking at different configuration options and tried to see what’s actually “useful” from an attacker’s perspective. On the way, in mai
5月6日周三6 条
How opening Chrome DevTools on a cross-site POST response can bypass SameSite=Strict cookie protections when a service worker is present.
I’m here to share my Self-XSS escalation write-up, one that took me multiple failed attempts before I finally cracked it with some much needed help.
Have you noticed that almost every marketing email you receive looks somewhat similar, or has functionality that seems centralised? This is because most corporations have moved to some form of marketing cloud to facilitate sending mass email campaigns. This shift appears to have happened in the last 10-15 years, and it doesn't seem to be
A high-severity CVE-2026-0628 in Chrome's Gemini allowed local file access and privacy invasion. Google quickly patched the flaw.
A week between a YouTube shoot, a hypnosis session, and thoughts on impact-driven goals in bug bounty and learning in the LLM era.
OpenCyvis: An Open-Source AI Phone OpenCyvis is an open-source AI phone created by me. Users choose their own LLM backend (cloud or local). The AI operates on a background virtual display without taking over the main screen. Apache 2.0 licensed, fully open source. Background Over the past year, several companies have launched "AI phone" products — Doubao, Samsung Galaxy AI, Google’s Gemini integration, and others. The core idea is the same: AI understands the screen and
4月29日周三2 条
I published my bug bounty methodology this week. Plus a few thoughts on why work discipline comes and goes, and how I got pulled back into Minecraft after years away.
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
4月23日周四1 条
让 AI 并行开发的真正门槛不是模型能力,而是能不能把"需求对齐 / 正确性验证 / 架构把控"这三件今天还得人做的事,改造成 Agent 自主能做的闭环。本文讲的是我烧了几千美金 token 换来的这套做法。
4月22日周三1 条
Why pentests still matter in the AI era, what I learned from an upcoming TV interview about the bubble we live in, and the projects I've dropped along the way.
4月15日周三1 条
My article on the state of bug bounty blew up. A massive welcome to all the new readers, what to expect from this blog, and why I'm stepping back from the noise.
4月13日周一1 条
AI agents are flooding bug bounty with noise, burning out triagers, and pushing companies away. But the hunters who adapt will come out stronger. A full-time hunter's honest take on what's changing and what comes next.
4月8日周三2 条
I stopped forcing myself into one direction. Bug bounty, AI, building, exploring. This is a logbook, not a niche.
Anthropic 发布 Project Glasswing 与 Claude Mythos Preview,在 OpenBSD、FFmpeg、Linux 内核等场景展示出强悍的自动化漏洞能力。本文讨论:当执行层技能越来越可被 AI 接管时,安全从业者的价值锚点应移向何方——从「做事的人」到「决定做什么事的人」,为何高层判断更难被替代,以及如何驾驭 AI agent 作为新的基本功。
4月1日周三1 条
How I found my first vulnerability in Google - a way to leak private customer data for all cases in Google's internal support systems
3月24日周二2 条
The post describes how the author discovered a one-click account takeover vulnerability in a large automotive company’s OAuth implementation, despite apparently robust redirect_uri validation. By exploiting a subtle double-decoding inconsistency in URL parsing, they were able to redirect the authorization code to an attacker-controlled domain and hijack user accounts.
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During this event, I discovered a remote command execution vulnerability in one of Google Cloud’s services. As the vulnerability has now been fixed, I would like to share the technical details in this article. TL;DR Google Cloud has a product called Looker, and this product has a feature to manage Git rep
3月20日周五1 条
3月18日周三1 条
Ignoring the obvious name, this blogpost is not tips that will help you “exploit” a bug or give you tips on how to find awesome bugs, it is obvious that you need technical knowledge.
3月13日周五3 条
How WHATWG URL compliance in Bun creates a normalization desync with POSIX utilities, enabling double-slash and partial-path middleware bypasses.
While auditing a multi-tenant application, I came across an interesting chain leading to a full tenant takeover. It started innocuously - with a self-XSS in a rich-text editor. Exploitation would require the user to insert a dangerous element into the editor via its API themselves, which meant a minimal chance of success. Still, I decided to dig deeper into the application and look for functionality that could help escalate this vulnerability and reduce the exploitation complexity.
A popular enterprise chatbot left an old, unauthenticated WebSocket endpoint active that still accepted full bidirectional messages using only a conversation UUID as “protection.” Anyone who obtained a conversation ID could connect, impersonate the user, read their chats, and exfiltrate sensitive data via a trivial HTML PoC. After disclosure, the vendor quickly disabled the legacy endpoint and paid modest bounties.
3月10日周二1 条
A deep dive into chaining DOM XSS, drag-and-drop abuse, postMessage hijacking, and cookie bombs to steal OAuth tokens — all from one drag and one click.
3月9日周一1 条
怎样让 OpenClaw 成为带来数倍效率提升的私人团队?本文总结五条核心原则:给 Agent 定三观、拆专业团队、配趁手工具、建经验沉淀机制、让系统自我进化。管 AI Agent 是一个管理问题,不是一个提示词工程问题。
3月6日周五1 条
A few weeks ago I wrote about how AI is going to impact bug bounty. That post was mostly predictions. This one is about what’s actually happening right now.
3月4日周三2 条
Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning - Security research by adnanthekhan
How three overlooked flaws in a postMessage + MessageChannel login architecture combine into a zero-click, cross-origin account takeover affecting hundreds of millions of users — and why PKCE couldn't save it.
3月2日周一9 条
Cloudflare built a Next.js replacement in a week with AI for $1100. We pointed Hacktron at it to find what the tests missed.
Achieving path traversal and even RCE via developer oversights in using os.path.join, urljoin, Python object handling and more functions besides.
A technical teardown of a 1-click RCE against OpenClaw (formerly Moltbot/ClawdBot), a viral open-source AI assistant trusted by 100,000+ developers with high-privilege access. See how a settings logic flaw and a WebSocket pivot turn a single webpage visit into token exfiltration, safety-control bypass, and arbitrary command execution.
By Aviv Donenfeld and Oded Vanunu Executive Summary Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various configuration mechanisms including Hooks, Model Context Protocol (MCP) servers, and environment variables -executing arbitrary shell commands […]
SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnerable and how to mitigate risk.
This post walks through a real-world OAuth popup hijacking attack. The target had solid defenses origin validation, source checking, CSP but a single predictable window.open() target name created an exploitable gap. It also serves as a real-world case use of iframe hijacking, showing how I managed to squeeze a vulnerability with a useless behavior.
RCEs, RCEs…they are all around and Total.js framework will be in our scope this time
Pivoting from a compromised Windows VM to the cloud by intercepting Azure DevOps Agent traffic
当用户选择了「方便 > 安全」,AI Agent 安全的出路到底在哪里?本文从安卓权限、Cambridge Analytica、云计算三个历史案例出发,推导 Openclaw 安全治理的可能路径。
2月24日周二1 条
I have a lot of thoughts on how AI will affect things, including bug bounty. And most of it is speculation, of course, but I have to put this out into the world because I want to know if this is correct in a year or two.
2月16日周一1 条
接下来的时代,很可能是人类有史以来变化最剧烈的时代。惯性越大,我们就可能在错误的路上滑行得越远。打破惯性,拥抱变化,是2026以及之后最重要的事情。
2月14日周六1 条
Novel data exfiltration in Google Gemini via the Phone tool call.
2月10日周二1 条
Hacktron AI Research Team discovered a critical RCE in Google’s Antigravity IDE that lets attackers take over your system just by opening a malicious website.
2月6日周五1 条
在 Claude Opus 4.6 发布前的内部红队测试中,Anthropic 的前沿红队做了一件简单粗暴的事:把 Opus 4.6 扔进沙箱环境,给它 Python 和一套常规漏洞分析工具,不提供任何专门指令,不注入任何领域知识,让它自己去挖开源代码库的漏洞。结果:超过 500 个此前未知的高危零日漏洞。这个数字让不少安全从业者半开玩笑地说"要被 AI 淘汰了"。这个话题值得认真聊一聊。
2月4日周三2 条
This article exposes how insecure Dynamic Client Registration and misconfigured OAuth in MCP servers can enable XSS, SSRF, and token theft. Through real-world examples, it shows how attackers can abuse open DCR, redirect URIs, and path normalization to gain direct access to MCP tools and internal services—and explains how to lock down these integrations to reduce AI-related security risks.
A technical step-by-step writeup about finding CVE-2025-13292, a cross-tenant vulnerability in Google Cloud's Apigee. This vulnerability allowed an attacker to gain read/write access to verbose cross-tenant access logs and analytics data that could contain access tokens of end users.
2月1日周日1 条
只要部署了 OpenClaw 并与之对话,你的电脑就有可能被攻击者完全控制。 这是架构层面的根本性问题,不是 bug,而是"feature"。 本文系统分析了这一风险产生的根源、攻击成立的条件,以及为什么现有防护只能缓解而无法根治。
1月31日周六1 条
A bug bounty target that unexpectedly felt like a CTF. What began as simple recon turned into a nice chain of discoveries that ultimately led to a valid XSS
1月30日周五3 条
This research is an extension of Content-Type research from BlackFan. More specifically, the response Content-Type tricks. Unfortunately, the multiple Content-Type trick is not clearly explained by BlackFan. Therefore, I’ll explain and demonstrate how a single comma character can cause a parsing difference between the browser and different MIME type parser libraries.
An authorization bypass in Kubernetes RBAC allows for nodes/proxy GET permissions to execute commands in any Pod in the cluster.
I’m coming back from a long nighttime walk with a friend, during which we had several interesting discussions. One of them seemed relevant enough to turn into the short draft you’re reading now. This friend has been training in offensive web security for almost a year. He’s an intelligent and particularly studious person, yet despite that, he’s struggling to find his first vulnerability during his bug bounty sessions, and we were trying to identify the potential reasons behind it.
1月29日周四4 条
Web challenge from UofTCTF 2026, chaining DOM Clobbering and Chromedriver RCE.
Discover how a security loophole in Instagram's oEmbed feature enabled unauthorized access to private posts. Journey from BountyCon(Edu) to the vulnerability's discovery, exploitation, and resolution.
Copilot or Coconspirator - Tricking GitHub Copilot and Stealing all Your Secrets - Security research by adnanthekhan
My neighbor texted me the other day and said she’d pre-ordered two AI toys for her kids that supposedly used an LLM to dynamically generate content for talking to the child. This was super fascinating to me. I’ve always thought something like that seemed awesome as kids can ask questions about anything, and get contextual answers back.
1月22日周四1 条
2025 年,我们的系统已经在主流开源仓库自动发现了 60+ 个真实世界漏洞,半数以上都是高危漏洞,我们发现:**成功的关键并非某个单一技术突破,而是正确把握了 AI 演进的范式,并在每次范式转换中及时调整方法**。与此同时,我们也观察到,大量曾经发表于顶会的工作,因为未能跟上范式转移而逐渐失去现实影响力。这一现象促使我们写下这篇文章:系统梳理 2022–2025 年间自动化漏洞挖掘的三次范式跃迁——从「LLM 做代码分类」到「LLM 辅助传统工具」再到「Agent 主导的自动化审计」——帮助读者理解范式转换的规律,做出能够跨越范式的研究与工程决策。
1月18日周日9 条
Facebook Javascript SDK and Facebook plugins
Introduction FXAuth is Meta’s shared authentication system used across Facebook, Instagram, and Meta (Horizon / VR). It is used by Accounts Center for account linking, re-authentication, and sensitive action confirmation.
Introduction Meta’s web ecosystem relies on cross-window messaging between first-party websites. In many cases, the only security control enforced is an origin check validating that messages originate from facebook.com or its subdomains.
Introduction This write-up consolidates several XS-Leak issues discovered across Meta-owned platforms, including Facebook, Workplace, Meta for Work, and internal Meta surfaces.
Introduction Facebook and Instagram accounts are deeply integrated through Accounts Center, allowing users to link identities, share authentication methods, and manage security settings across platforms.
Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.
Introduction Facebook’s payments and billing flows rely heavily on third-party financial service providers. To facilitate bank-based payments, Facebook embeds external services inside privileged Facebook pages and allows cross-window communication between those services and facebook.com.
Introduction
Table of Contents Preface TLDR Live Hacking Event 101 Getting invited Picking the target Why Google SecOps SOAR? Reading the docs Methodology SOAR Integrations Python execution environment aka RCE-as-a-Service IDE custom code validation bypass We are in, what next? Fetching the OAuth Access Token Access token introspection What is gke-init-python used for? Service Account impersonation Prior art What can gke-init-python do? Malachite enters the scene Revised architecture diagram Auth flow is com
1月17日周六1 条
CVE-2025-67647
1月16日周五4 条
Writeup on a security flaw I found, giving me read/write access to other Heroku Postgres databases in multi-tenant clusters.
Introduction Facebook’s payments and billing flows rely heavily on third-party financial service providers. To facilitate bank-based payments, Facebook embeds external services inside privileged Facebook pages and allows cross-window communication between those services and facebook.com.
Introduction Facebook and Instagram accounts are deeply integrated through Accounts Center, allowing users to link identities, share authentication methods, and manage security settings across platforms.
Introduction Facebook relies on long-lived device identifiers to reduce friction for returning users and to distinguish legitimate activity from suspicious logins. Over time, devices that repeatedly authenticate to the same account are treated as trusted, allowing Facebook to relax certain security requirements during sensitive flows such as account recovery.
1月14日周三2 条
A Remote Code Execution (RCE) vulnerability was discovered in the Visual Studio Code Go extension. This vulnerability bypasses VS Code's 'Restricted Mode,' the security boundary for Untrusted Workspaces. The root cause is that certain settings, such as go.buildFlags, were not properly blocked in Restricted Mode.
We used a new Appsec combo to get a few thousand dollars from exploiting Cross-Origin Resource Sharing (CORS) misconfigurations on internal networks in bug bounties. Check out this example of hacking Tesla. It was so much fun that we’re here to share our tooling and techniques with everyone. Rest assured that this same approach will work for plenty of other bug bounty targets.
1月13日周二1 条
A few months ago, I came across an interesting behavior while using Claude Code—it executed a command without my approval. Since I wasn’t using the permission bypass mode, I decided to investigate further to understand why it was able to execute commands without explicit approval. TL;DR I discovered 8 ways to execute arbitrary commands in Claude Code without user approval.
1月12日周一4 条
This blog post explains a security vulnerability in Netflix’s SMS login system that let attackers send fake OTP messages from Netflix’s official short code. By exploiting an unvalidated androidAppHash, the bug enabled SMS phishing and malware distribution at scale. The author details the bug bounty report, Netflix’s fix, and key lessons on SMS security and server-side validation.
Discover how to find and exploit misconfigured Spring Boot Actuator endpoints in real-world penetration tests and bug bounty programs. This in-depth guide covers advanced discovery techniques, header-based bypasses, path traversal tricks, sensitive endpoints like mappings, metrics, httptrace, and heapdump, plus concrete remediation steps for securing Spring Boot applications.
The recent React made quite a buzz in the industry. It was a pretty powerful vulnerability, which directly leads to Pre-auth RCE (one of the most ...
Over 10 years ago, I put together a self “liturgy” of sorts (basically just a prayer) that I love reading. It takes a bunch of my favorite verses but changes them to the first-person perspective. There’s something about first person that makes it much more powerful and personal. As you read this, I pray it encourages you greatly.
11月14日周五1 条
在当今数字世界中,RSA‑2048 与 ECC 等经典公钥密码是最广泛应用的加密标准,支撑着网络安全、金融交易和隐私保护的底层信任。然而,这一基石正面临量子计算的潜在威胁。理论上,量子计算机能够以远快于经典计算机的速度分解大整数和离散对数求解,从而在短时间内破解 RSA 和 ECC 加密。这一前景既令人兴奋,也令人担忧。问题在于:量子计算机的发展究竟到了什么阶段?有人乐观地认为经典公钥密码的“倒计时”已经开始;也有人怀疑,受限于制造难度,真正可用的量子计算机还遥遥无期。市面上相关论调不一,往往乐观或悲观,但核心疑问始终萦绕:量子计算机距离破解经典公钥密码还有多远?我们将尝试以拆解和分析量子计算机的制造瓶颈与突破希望方式回答这一问题。
11月10日周一1 条
我们研发的AI自动化漏洞挖掘引擎已经在各种类型的重要开源软件中挖出了30多个漏洞,其中近半数都是具有较高的实际危害(如RCE)。这篇文章将分享一个比较有趣的漏洞:"零知识证明库 gnark 中发现了一个高危漏洞(CVE-2025-57801,CVSS 8.6)",后续我们也会分享更多有意思的漏洞出来。
10月9日周四1 条
最近 VibeCoding 成为开发圈的新风潮。借助 Cursor、Claude Code 等工具,开发者只需描述需求,AI 就能自动生成代码。从批量完成重复性代码,到快速搭建原型、重构陈旧代码,极大地提升了研发效率。我们在尝试过程中,发现它完全可以胜任中等难度的工程开发工作。其带来生产力的提升令人印象深刻。然而,也有不少人初次接触时感到失望:AI 写出的代码无法运行,改动还把项目弄得一团糟,最终只好回到「祖传手写」或在普通AI对话界面里边问边写。这就形成了一种落差——一边是爱好者对提效体验的热情分享,另一边却是新用户的挫败与困惑。为什么会这样?原因在于,VibeCoding Agent本质上只是一个工具,它确实拥有强大的潜力,但前提是用户需要掌握一定的使用方法。目前各平台虽然提供了不少“最佳实践”清单,但大多零散琐碎,很难直接套用,让人难以形成系统的理解。本文将尝试回到根本,从几个最核心的原则出发,解释如何让 VibeCoding 真正好用起来,成为新生产力工具。
9月22日周一1 条
为什么有些文章能让人一口气读完,而有些文章却让人“每句话都懂,却合起来看不明白”?问题往往不在读者,而在写作方式。那么,怎样才能写出既专业又好读的文章呢?本文将以信息传递类文章(如博客、技术文档、学术论文等)为例,尝试总结一些实用经验。如果你正好正在创作这类内容,相信这里的思路会对你有所帮助。需要说明的是,文中提到的部分技巧并不限于信息传递类文字,其中一些方法(例如让文字更具画面感)在散文、小说等其他类型的写作中同样适用。
9月10日周三1 条
技术的本质,是为了实现人类某个目的而形成的流程、方法或装置。换句话说,技术从来是为目的服务的,而不是目的本身。也因此,当我们试图用技术去解决一个问题时,问题所在的领域,和最终所需要调用的解法所在的领域,可能完全不同。问题域只是问题发生的地方,而解法域是答案所在的地方,两者并不必然一致。所以,**一个人掌握的技术越全面,他就越有可能构造出一个好的解决方案。**
8月6日周三1 条
大语言模型(LLM)正在从简单的对话工具演化为能够编写代码、操作浏览器、执行系统命令的智能体。随着大模型应用的演进,提示词注入攻击的威胁也在不断升级。设想这样一个场景:你让AI助手帮你编写代码,它却突然开始执行恶意指令,控制了你的电脑。这种看似科幻的情节,如今正在变为现实。本文将介绍一种新型的提示词注入攻击范式。攻击者只需掌握一套“通用触发器”,就能精确控制大模型输出任意攻击者指定的内容,从而利用AI智能体实现远程代码执行等高风险操作。
8月1日周五1 条
在当今数字化时代,5G、4G和Wi-Fi等无线通信技术已成为我们日常生活的重要基础设施。这些网络普遍采用先进的加密协议,理论上能够有效保护用户通信安全。然而,近期由我们腾讯玄武实验室与清华大学陈建军老师团队在EuroS&P 2025上发表的研究成果LenOracle揭示了一个新的安全隐患:攻击者可能将空口数据帧(radio frame)长度信息作为侧信道,在不破解无线加密的情况下劫持加密网络中的TCP/UDP连接。我们在真实的商用LTE网络和Wi-Fi环境中进行了测试,成功在TCP场景下利用该攻击向受害设备注入了一条伪造的短消息,并在UDP场景下污染了受害设备的DNS缓存,展示了该攻击对关键网络服务的潜在破坏力。
2月23日周日1 条
2月16日周日1 条
作为理科生,我在相当长的时间都觉得逻辑是唯一值得相信的东西。因此也曾觉得中国哲学,诸如心经的“空即是色,色即是空”这种看起来没有逻辑的东西实在是令人遗憾。甚至认为东方哲学是走偏了,还是西方认识论、本体论才是哲学的正道。后来随着学习的深入,才发现逻辑也有其局限,而中国哲学的方法正好可以能其所不能。
2月9日周日1 条
春节后开始读庄子,先秦时期的文言文比唐宋之后要难读的多,对照着各级注解讲述,读了一个多周也只读完了“逍遥游”和一半的“齐物论”。光这部分就让我受益匪浅,于是今天且分享一下。
12月31日周二1 条
2024年,是我读书最多的一年,也是我自我感觉成长最大的一年。我读的书大体可以分为三大话题:哲学、理财,以及一些偏向实用性的内容。我会在本文分享一下我在这些话题上的一些感悟。
10月21日周一1 条
Abstract This article analyzes the cause of CVE-2024-31317, an Android user-mode universal vulnerability, and shares our exploitation research and methods. Through this vulnerability, we can obtain code-execution for any uid, similar to breaking through the Android sandbox to gain permissions for any app. This vulnerability has effects similar to the Mystique vulnerability discovered by the author years ago (which is the little horse in the title image – the Pwnie Award
9月17日周二1 条
这可太方便了《真实地址生成器》,能生成不同国家地图上的真实随机地址,以及手机号、姓名和性别,支持 Cloudflare Workers 部署。 Web https://t.co/FHuO53eh1X GitHub https://t.co/uy8DvvB4Nk https://t.co/pQ9cDDOQu2
8月21日周三1 条
摘要 本文分析了CVE-2024-31317这个Android用户态通杀漏洞的起因,并分享了笔者的利用研究和方法。通过这个漏洞,我们可以获取任意uid的权限,近似于突破Android沙箱获取任意app的权限。这个漏洞具有类似于笔者当年发现的 魔形女漏洞 (黑客奥斯卡 Pwnie Award最佳提权漏洞 )的效果,但又各有千秋。 漏洞缘起 数月之前, Meta X Red Team 发表了两篇非常有意思的,可以用来提权到任意UID的Android Framework漏洞,其中CVE-2024-0044因简单直接,在技术社区已经有了广泛的分析和公开的exp,但CVE-2024-31317仍然没有公开的详细分析和exp,虽然后者比前者有着更大的威力(能获取system-uid权限)。这个漏洞也颇为令人惊讶,因为这已经是2024年了,我们居然还能在Android的心脏组件(Zygote)中发现命令注入。 这让我们想起了当年我们所发现的 mystique漏洞 ,这个漏洞同样能让攻击者获得任意uid的权限。需要注意的是,两个漏洞都有一定的前提条件,例如CVE
6月16日周日1 条
当我们说“我自由地做出了选择”,这句话究竟意味着什么?在一个由物理定律支配的宇宙中,自由真的存在吗?而如果世界本身没有目标与意义,人类的选择又有什么价值?人的一生,似乎都在会在一个追问中前行:我的人生是为了什么。本文将尝试从科学、哲学与意识层面展开思考,在理性与困惑之间,寻找一个“自由而有意义的生存
3月16日周六1 条
作者经实测发现,在 Cloudflare Worker 上部署 VLESS 代理可跑满带宽,认为其性能足以替代传统 VPS 线路。作者分享了相关搭建项目,并实测该代理方案能与 OpenWrt PassWall 结合实现多线路负载均衡。
11月10日周四1 条
1月20日周三1 条
本文 拨开二进制Fuzzing的迷雾 为Fuzzing战争系列的第二篇,也是 Fuzzing战争:从刀剑弓斧到星球大战 的续篇。 每个人都期待有全图点亮的体验,然而现实中安全研究的目标却更多是编译好的二进制binary而没有源码。迷雾之下崇山峻岭羊肠小道,但应许之地却往往也隐藏其中。本文将以目前最为主流的Android on ARM/AARCH64为例,综合笔者在 MOSEC 2020 和 RWCTF Tech Forum 2021 的演讲内容,首次系统性地阐述如何实现无源码情况下的大规模Coverage-Guided Fuzzing理论、工程和实践,和小试牛刀即发现的主流移动终端中广泛存在的真实漏洞。出于阅读体验,本篇可能会分多次发出,持续更新中。 前方预警:本文为硬核技术导向,非技术人员请直接划到最后篇后随笔一节 。 Let’s rock n’ roll ! 温故而知新 就像简陋的纸带机模型却能描述出完备的图灵机一样,一个五行的bash脚本甚至也可以成为fuzzer,当然作为一个dumb fuzzer,直到宇宙毁灭,它
9月11日周五1 条
我昨天晚上在微信群中看到了一篇文章,文章作者家人一部手机被盗,被黑产犯罪团伙以SIM卡(主要是短信验证码)为起点,完成了对文章作者家人展开了一系列的攻击。虽然文章作者做了一些及时的补救,但这些攻击仍使得受害者损失惨重,如被刷了各种小额贷款等。我思考了一下这套攻击能成功的原因,以及如何才能防御这类攻击,在此分享给大家。
5月28日周四1 条
Fuzzing这个事物大概可以上溯到1950年,当计算机还在读取打孔卡作为输入的时候。那时候的工程师会从垃圾箱里随机检出一些废弃卡片,或者在卡上随机打孔作为输入来测试自己的程序。在1988年,Barton Miller在课堂上将Fuzzing这个名词正式确定,从此拉开三十年波澜壮阔的序幕。 广义上的fuzzing并不是漏洞挖掘中的专属内容,而是DevSecOps和Continous Integration质量保证中必不可少的一环,甚至可以延伸到完备图灵自动机的美妙梦想。在起初,人们通常以monkey testing来指代最原始的fuzz,就像著名的无限猴子定理一样:让一只猴子在打字机上随机地按键,当按键时间达到无穷时,几乎必然能够打出任何给定的文字,比如莎士比亚的全套著作,当然也有可能包含一套Nginx RCE。 但很显然,随机化的输入虽然终究能覆盖所有的输入空间,在人类未来可预见的算力水平下近乎天方夜谭。刘慈欣在《诗云》中有一个宏大的故事:宇宙神级文明为了写出最优雅的诗,而把整个太阳系的物质作为存储器,采用枚举遍历的办法把所有文字的排列组合全部
11月7日周四1 条
Text-To-Speech engine is a default enabled module in all Android phones, and exists up to Android 1.5 HTC era, even acting as a selling point at that time. But various vendor implementations may lead to various interesting stuff, i.e. CVE-2019-16253, a seemly harmless language pack, or nearly any seemly benign application, without requring any permission, can obtain a persistent SYSTEM shell through the TTS bug (or feature?). Vulnerability Briefing TL;DR: Samsung TTS componen
10月16日周三1 条
Vendor binder services proved to be an interesting part of android devices nature. They usually remains close-source, but sometimes open new attack surface for privilege escalation. In these articles I will first describe how to locate interesting binder service and a reversing quirk, then two typical CVEs will be discussed about their nature and exploitation, and how to find them. Locating interesting binder services Before Android N, all binder services were registered to s
10月11日周五1 条
安卓生态多姿多彩,在AOSP之外各大厂商的binder service也同样各式各样。这些自行实现的service通常来说是闭源的,常常成为会被人忽略的提权攻击面。在这一系列文章中,我会先描述如何定位可能有问题的binder service进行后续研究,以及逆向中一些有意思的发现,随后会以之前发现的两个典型的CVE为例,讨论这些漏洞是如何产生的,如何发现它们,以及如何进行利用。 寻找潜在的分析目标 在Android N之前,所有的binder service都是在 servicemanager 中进行注册的,client通过 /dev/binder 与service进行通讯。Android N对binder服务引入了domain切分的概念,常规的服务依然使用/dev/binder,而vendor domain则转换为使用 /dev/vndbinder , hardware domain转换为使用 /dev/hwbinder 。常规的untrusted_app访问被限制在了/dev/binder。 通过 service list ,我们可以查看设备
8月6日周二2 条
在最近的一系列文章中,我会介绍这些年以来通过Pwn2Own和官方渠道所报告的在各种Android厂商设备中发现的各种CVE,包括通过fuzz和代码审计发现的各式各样的内存破坏漏洞和逻辑漏洞。第一篇文章将会介绍在2017年末我们用来远程攻破Galaxy S8并安装应用的利用链,一个V8漏洞来获取最开始的沙箱内代码执行,和五个逻辑漏洞来最终实现沙箱逃逸和提权来安装任意应用,demo视频可以在 这里 看到。 所有的漏洞均已经报告并以CVE-2018-10496,CVE-2018-10497,CVE-2018-10498,CVE-2018-10499,CVE-2018-10500来标示。本文将主要介绍整个利用链,V8漏洞将在另外的文章中介绍。 English version writeup here Bug 0: Pwning and Examining the browser’s renderer process 通过第一个V8漏洞(CVE-2018-10496,credit to Gengming Liu and Zhen Feng),我
Hello everyone, long time no see! Now begins a series of blog posts about bugs I found before and now on Android vendors, including memory corruption and logical bugs, reported and fixed via Pwn2Own or official bug channel. This very first post is about the chain of bugs we used in the end of 2017 to get remote arbitrary application install via clicking malicious link on newest Galaxy S8 at that time, prepared for Mobile Pwn2Own, with a V8 bug to get initial code execution in
6月2日周日1 条
我们战队 r3kapig 为刚刚结束的 DEFCON 外卡赛之一的 Baidu CTF 提供了 10 道赛题(一共 13 道),并作为比赛的总裁判把控了比赛的赛制、部分规则以及赛题质量。 Baidu CTF 是一个新生的外卡赛,我们也做了一些尝试,比如让 AEG 战队和人类顶尖战队在比赛中同场 PK。虽然在不断试新的过程中出现了不少小问题,但是在大家的共同努力下,我们还是贡献出了一场合格的外卡赛。今天,我想以这场比赛为契机,来谈一谈我个人对 CTF赛题的理解