unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Game Hacking in Unity Games on Android
2026-9-24 09:0:0 | 阅读: 0 |
收藏
|
FireShell Security Team - fireshellsecurity.team
corCTF 2025 - Python URL Parsing Confusion
这篇文章介绍了CORCTF中的一个Web挑战`web-msfrognymize2`,展示了如何通过利用Python URL解析差异来实现SSRF攻击以获取API_TOKEN。文章详细分析了应用架构、代码逻辑及漏洞成因,并最终通过构造特殊URL成功获取了flag `corctf{why_4re_pyth0n_jo1n_funt10ns_s0_w3ird?!}`。...
2025-9-14 23:0:0 | 阅读: 39 |
收藏
|
FireShell Security Team - fireshellsecurity.team
netloc
fragment
urllib3
urljoin
BigIAMChallenge - Writeup
这篇文章介绍了六个与IAM策略相关的CTF挑战。每个挑战展示了不同的安全漏洞及其解决方法:包括S3桶权限过大、SQS消息泄露、SNS订阅绕过、条件限制绕过、Cognito身份验证绕过等。这些挑战帮助工程师理解IAM策略的风险与最佳实践。...
2025-8-9 09:0:0 | 阅读: 30 |
收藏
|
FireShell Security Team - fireshellsecurity.team
wiz
arn
cognito
UMD CTF 2025 - Web Writeups
UMDCTF 2025比赛中,参赛者通过文件名注入、HTTP头注入SQL和XSS漏洞等技术成功破解三个Web挑战。...
2025-5-3 23:0:0 | 阅读: 28 |
收藏
|
FireShell Security Team - fireshellsecurity.team
steve
brainrot
supposition
umdctf
est
Bypassing freeRASP Callbacks - Flag Validator Write Up - CTF BHack 2024
The FireShell Security Team was responsible for BHack CTF for one more year, and this yea...
2024-12-5 22:5:0 | 阅读: 45 |
收藏
|
FireShell Security Team - fireshellsecurity.team
rootbeer
exitprocess
freerasp
bypass
Intigriti’s August challenge by CryptoCat
Intigriti keeps challenging us with XSS fun time, this time with a challenge by CryptoCat.I had a...
2024-8-15 06:0:0 | 阅读: 26 |
收藏
|
FireShell Security Team - fireshellsecurity.team
noteid
45a7
205d
8cfd
corCTF 2024 - Challenge Dev write-up
corCTF is maintained by the Crusaders of Rust Team. The 2024 edition happened between 27/07/2024...
2024-8-15 06:0:0 | 阅读: 43 |
收藏
|
FireShell Security Team - fireshellsecurity.team
chrome
malicious
payload
Intigriti’s December challenge by protag
Intigriti brings us monthly web challenge with really interesting problems.The ChallengeThis cha...
2023-12-21 07:30:0 | 阅读: 24 |
收藏
|
FireShell Security Team - fireshellsecurity.team
smarty
php
intigriti
tmpfname
bypass
SEKAI CTF 2023 - Web Writeups - Frog-WAF and Chunky
SekaiCTF is a Capture The Flag event hosted by Team Project Sekai, with some hardcore members of...
2023-9-8 01:20:0 | 阅读: 73 |
收藏
|
FireShell Security Team - fireshellsecurity.team
gradle
jwks
frogwaf
payload
sekai
corCTF 2023 - harem-scarem write-up
Hello, folks! It’s been a long time since my last write-up and there goes a short one. Harem scar...
2023-8-6 20:0:0 | 阅读: 55 |
收藏
|
FireShell Security Team - fireshellsecurity.team
bufio
notep
remote
pof
fromutf8
corCTF 2023 - 3 Web Challenges
corCTF is maintained by the Crusaders of Rust Team. The 2023 edition happened between 28 and 30-...
2023-8-3 23:0:0 | 阅读: 39 |
收藏
|
FireShell Security Team - fireshellsecurity.team
frog
loader
anonymized
svgprops
The Dangers of Exposed Azure Blobs
Being one of the most widely used storage services on the web - probably only falling behind to...
2023-3-21 05:0:0 | 阅读: 26 |
收藏
|
FireShell Security Team - fireshellsecurity.team
blobs
containers
windows
cloud
goblob
UTCTF 2023 - Cracking the Random
UTCTF is maintained by the Information & Systems Security Society at the University of Texas at A...
2023-3-18 04:35:0 | 阅读: 51 |
收藏
|
FireShell Security Team - fireshellsecurity.team
624
0x80000000
builtins
subclasses
getstate
Mining Takeovers for Fun and Profit
IntroductionThis article describes an experiment aimed at finding domains likely vulnerable to D...
2023-3-1 17:0:0 | 阅读: 33 |
收藏
|
FireShell Security Team - fireshellsecurity.team
nameservers
subdomain
bigcorp
lame
HackTM CTF 2023 - cs2100 write-up
HackTM CTF was an event hosted by WreckTheLine. It was a really nice event and there were some v...
2023-2-20 06:0:0 | 阅读: 33 |
收藏
|
FireShell Security Team - fireshellsecurity.team
shellcode
imm
rs1
calculate
memory
NahamCon EU CTF 2022 - Welcome to Web3!
The eventNahamCon EU CTF started on December 16th and lasted 24 hours. It had all the most commo...
2022-12-20 06:11:0 | 阅读: 49 |
收藏
|
FireShell Security Team - fireshellsecurity.team
merkleproof
airdrop
mint
merkle
merkleroot
RCTF 2022 - Hacking File Uploads
RCTF 2022 is a Jeopardy-style Online Capture The Flag Competition presented by ROIS(Researcher Of...
2022-12-10 18:4:0 | 阅读: 35 |
收藏
|
FireShell Security Team - fireshellsecurity.team
payload
php
sockfd
rctf
blacklist
Explorando SQL Injection no INSERT - BHack CTF 2022 - Jogo da Velha - [PT-BR]
Tive o grande prazer de participar do evento de segurança BHack 2022 e ajudar na organização do CT...
2022-12-10 18:4:0 | 阅读: 35 |
收藏
|
FireShell Security Team - fireshellsecurity.team
jogo
velha
um
bhack
uma
Google CTF 2022 - Segfault Labyrinth
IntroductionIn this write-up I will describe the journey to finish one of the challenges from Goo...
2022-8-10 03:46:0 | 阅读: 67 |
收藏
|
fireshellsecurity.team
labyrinth
payload
corridor
doors
segfault
SEETF 2022 - Username Generator
SEETF is a cybersecurity Capture the Flag competition hosted by the Social Engineering Experts CTF...
2022-6-20 17:42:0 | 阅读: 56 |
收藏
|
fireshellsecurity.team
username
ngrok
payload
inject
distrib
Previous
-15
-14
-13
-12
-11
-10
-9
-8
Next