P3TERX ZONE
-
1
AdGuard Home 自建 DNS 防污染、去广告教程 #2 - 优化增强设置详解
-
2
群晖 NAS Docker 进阶教程 - 部署全能下载工具 Aria2 Pro
-
3
HE Tunnel Broker 教程:IPv4 VPS 服务器免费添加公网 IPv6 地址
-
4
Debian Linux VPS 服务器 WireGuard 安装教程
-
5
Cloudflare WARP 教程:给 VPS 额外添加“原生” IPv4/IPv6 双栈网络出口
-
6
CU VIP 是什么?AS4837、AS9929 线路 VPS 哪个好?
-
7
Cloudflare WARP 一键安装脚本 使用教程
-
8
Cloudflare WARP 脚本已知问题和解决方法
-
9
为什么 WARP 解锁 Netflix 失效了?
-
10
2026年国外高性价比便宜 VPS 推荐(稳定、好用、免费体验)
CXSECURITY Database
-
1
lnrbda - SQL Injection vulnerability
-
2
FreePBX 17.0.2 Remote Code Execution (RCE)
-
3
EVerest 2025.9.0 DoS
-
4
C-MOR 6.0104 Directory Traversal
-
5
Tenable Nessus 10.12.1 SQL Injection
-
6
ProFTPD mod_sql post-authentication SQLi RCE
-
7
Windows Defender (MsMpEng.exe) Race Condition
-
8
PCMan 2.0.7 Buffer Overflow
-
9
WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload
-
10
WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)
PHP Bugs
-
1
[$1500] Cloudflare Public Bug Bounty: HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers
-
2
Ruby on Rails: Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown
-
3
Tor: Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache
-
4
Tor: Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read
-
5
curl: 27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization
-
6
curl: IMAP connection reuse runs requests in the wrong case-sensitive mailbox
-
7
curl: 12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof
-
8
curl: 55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data
-
9
Myndr: CORS Misconfiguration / Broken Access Control
-
10
MariaDB: MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover
老罗的Android之旅
-
1
Chromium网页滑动和捏合手势处理过程分析
-
2
Chromium分发输入事件给WebKit处理的过程分析
-
3
Chromium视频标签<video>简要介绍和学习计划
-
4
Chromium为视频标签<video>创建播放器的过程分析
-
5
Chromium为视频标签<video>渲染视频画面的过程分析
-
6
Chromium为视频标签<video>全屏播放的过程分析
-
7
Chromium扩展(Extension)机制简要介绍和学习计划
-
8
Chromium扩展(Extension)加载过程分析
-
9
Chromium扩展(Extension)的页面(Page)加载过程分析
-
10
Chromium扩展(Extension)的Content Script加载过程分析
I hack, therefore I am
-
1
Linux/x86 Execve Python Interpreter with a Python Program Passed in as String Shellcode
-
2
Decoderless Shellcode Encoding
-
3
Modulation and Data Loss Prevention (DLP) Solutions
-
4
Automated Static Malware Analysis with Pythonect
-
5
Fuzzing Like A Boss with Pythonect
-
6
Scraping LinkedIn Public Profiles for Fun and Profit
-
7
Password Policy: You Are Doing It Wrong (When 2^56 Becomes 2^42)
-
8
Hackersh 0.1 Release Announcement
-
9
Pythonect Has New Graphs, Documentation, Tutorial, and More!
-
10
I See Your True ECHO_REQUEST Patterns (Pinging Data Away)
The Fuzzing Project
-
1
Use after free in my_login() function of DBD::mysql (Perl module)
-
2
Fun with Bignums: Crashing MatrixSSL and more
-
3
Multiple vulnerabilities in RPM – and a rant
-
4
Out of bounds heap bugs in glib, heap buffer overflow in gnome-session
-
5
Update on MatrixSSL miscalculation (CVE-2016-8671, incomplete fix for CVE-2016-6887)
-
6
Fuzzing Irssi with Perl Scripts
-
7
htpasswDoS: Local Denial of Service via Apache httpd password hashes
-
8
Diving into Control Flow Integrity
-
9
exiv2: multiple memory safety issues
-
10
Six year old PDF loop bug affects most major implementations
Cатсн²² (in)sесuяitу / ChrisJohn
-
1
[DeepSec 2014] Advanced Powershell Threat: Lethal Client Side Attacks using Powershell
-
2
All good things must come to an end
-
3
Taking out the Eurotrash
-
4
[LHS Microcast] Interview w/ Jen Ellis
-
5
[LHS Microcast] DeepSec 2015
-
6
[DeepSec 2015] Can societies manage the SIGINT monster?
-
7
[DeepSec 2015] Hacking Cookies in Modern Web Applications and Browsers
-
8
[DeepSec 2015]How to Break XML Encryption – Automatically
-
9
[DeepSec 2015] File Format Fuzzing in Android – Giving a Stagefright to the Android Installer
-
10
[DeepSec 2015]50 Shades of WAF
Black-Hole’s Blog
-
1
A 6.47 MB JS String Occupied 15.4 MB of Memory
-
2
XSS principles, dissected
-
3
Automated CSRF detection
-
4
Automated CSRF detection (part 2)
-
5
Notes on bypassing WAFs (Web Application Firewalls)
-
6
How to log in to Thunder under Debian
-
7
Browser plugin attack vectors
-
8
Company Wi-Fi security
-
9
Automated XSS intranet invasion
-
10
Some ideas based on URLProtocol attacks
w00tsec
-
1
Hello world
-
2
SIMET Box Firmware Analysis: Embedded Device Hacking & Forensics
-
3
Analyzing and Running binaries from Firmware Images - Part 1
-
4
Unpacking Firmware Images from Cable Modems
-
5
Binwally: Directory tree diff tool using Fuzzy Hashing
-
6
Analyzing Malware for Embedded Devices: TheMoon Worm
-
7
Wildcard DNS, Content Poisoning, XSS and Certificate Pinning
-
8
Foxit PDF Reader Stored XSS
-
9
Hacking Asus RT-AC66U and Preparing for SOHOpelesslyBroken CTF
-
10
Scan the Internet & Screenshot All the Things