logo

2021

Using CloudFront Relay Cobalt Strike Traffic
Static Program Analysis Intruction
Google 是如何落地静态代码分析的
为 CodeQL 自定义规则编写测试文件
AWS S3 subdomain takeover
HTTP/2 Header Field Re-used Attack Trick

2020

This is a test page for testing Github Action
Smogcloud - AWS external network asset discovery platform
Write a simple HTTPS server use Go
Hack The Box - Postman Writeup - Linux
使用 CloudWatch Event 监控 ElasticSearch 事件
CobaltStrike Aggressor Script 实现 Beacon 上线告警功能
HashCat:如何利用HashCat破解NTLMv2 hash?
我也来喷一喷零信任
如何实现一个基于 Golang 的 webshell?

2019

如何配置Policy强制AWS控制台使用MFA,CLI不用MFA?
如何限制IAM User只能在指定的IP登录?
S3 pre-signed URL 与 KMS 加密那些事
S3 Bucket 如何配置才能做到只允许某一个IAM User操作?
聊一聊AssumeRole和Trust Relationship
AWS Lambda Node.js 反弹shell
ECS Fargate 初体验
S3FS 简介及部署
EBS卷挂载不用UUID导致的EC2实例无法正常启动的问题
聊一聊AWS S3的版本控制
AWS S3 Multipart Upload
AWS ALB Access log与KMS加密S3 Bucket的那些恩怨情仇
几个关于AWS NLB的有趣问题
KMS:如果A账号的AMI使用AWS managed key加密需要将其共享给B账号应该如何操作?
OSCP:Vulnhub Kioptrix Level 2 Writeup
OSCP:Vulnhub Kioptrix Level 1 Writeup
如何配置ADFS使域账号可以登陆多个AWS账户
一个信息安全从业人员的自我修养——我的安全技术栈
OSCP Note - Common use of Netcat(nc) and Ncat
A command similar to wget in Windows: Invoke-WebRequest
Use AWS SSM(Systems Manager) execute remote script file at EC2 instance
AWS VPC DHCP Options Set change Effective immediately
How do I set the S3 bucket policy so that it can only be accessed by the specified IP
How Winodws Escalation Privilege from administrator privilege to system privilege

2018

Gogs RCE Vulnerability Analysis
Enterprise Cyber security build of Windows lateral movement attacks detection

2017

Flask debug mode PIN code generation mechanism security research notes

2016

An example of network security problems in the IoT era