unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Securing Firebase: Lessons Re-Learned from the Tea Breach, (Wed, Jul 30th)
文章讨论了Firebase数据库的安全隐患及其配置问题。由于现代应用常允许用户直接连接数据库,传统SQL中的细粒度访问控制缺失导致漏洞。建议开发者使用强规则或改用更安全的后端存储,并在CI/CD中验证配置以防止攻击。...
2025-7-30 20:19:26 | 阅读: 20 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
firebase
database
brandon
sadly
evans
ISC Stormcast For Wednesday, July 30th, 2025 https://isc.sans.edu/podcastdetail/9548, (Wed, Jul 30th)
ISC Stormcast 播客于 2025 年 7 月 30 日发布,值班处理员为 Xavier Mertens,当前威胁级别为绿色。播客介绍了应用安全课程及拉斯维加斯开课时间,并提供数据、工具和联系信息等服务。...
2025-7-30 02:0:3 | 阅读: 9 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
27th
isc
vegassep
papers
22nd
Apple Updates Everything: July 2025, (Tue, Jul 29th)
苹果发布了针对iOS、iPadOS、macOS等系统的更新,修复了89个安全漏洞。多数为DoS问题或权限提升漏洞。部分涉及隐私指示器显示错误及下载来源关联问题。无已知被利用情况。...
2025-7-29 21:24:55 | 阅读: 78 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
affects
maliciously
termination
memory
webkit
Triage is Key! Python to the Rescue!, (Tue, Jul 29th)
文章介绍了一种快速分析大量数据的方法,在法医调查中通过分类步骤筛选关键证据。作者编写了一个Python脚本,结合YARA规则扫描文件和ZIP存档中的关键词,并将匹配项复制到目标目录。...
2025-7-29 09:29:53 | 阅读: 23 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
triage
nocase
xlsx
pptx
ISC Stormcast For Tuesday, July 29th, 2025 https://isc.sans.edu/podcastdetail/9546, (Tue, Jul 29th)
ISC Stormcast播客于2025年7月29日发布,由值班处理员Johannes Ullrich主持,当前威胁级别为绿色。内容涉及网络安全动态、威胁情报及技术分析等信息。...
2025-7-29 02:0:2 | 阅读: 13 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
feeds
22nd
security
27th
Parasitic Sharepoint Exploits, (Mon, Jul 28th)
最近发现的SharePoint漏洞被广泛利用,攻击者通过后门文件如spinstall0.aspx等进行多次入侵,微软已列出相关变种文件名,扫描活动显示攻击行为持续增加,详细URL路径和时间记录已公开。...
2025-7-28 15:25:29 | 阅读: 17 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
layouts
toolpane
displaymode
backdoors
exploited
ISC Stormcast For Monday, July 28th, 2025 https://isc.sans.edu/podcastdetail/9544, (Mon, Jul 28th)
read file error: read notes: is a directory...
2025-7-28 02:0:2 | 阅读: 13 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
security
isc
papers
feeds
vegassep
Sinkholing Suspicious Scripts or Executables on Linux, (Fri, Jul 25th)
文章介绍如何利用Linux的网络命名空间和虚拟以太网接口创建隔离环境分析可疑代码的方法。通过配置默认路由和使用tcpdump捕获流量实现网络隔离。此方法有效但仅限于网络流量隔离。...
2025-7-25 04:54:48 | 阅读: 23 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
remnux
network
veth1
veth0
forever
ISC Stormcast For Friday, July 25th, 2025 https://isc.sans.edu/podcastdetail/9542, (Fri, Jul 25th)
ISC Stormcast 播客讨论网络威胁与安全趋势,值班员Xavier Mertens报告威胁等级为绿色。节目还介绍了即将举办的“应用安全:保护Web应用、API和微服务”课程,并提供导航链接及网站功能说明。...
2025-7-25 02:0:2 | 阅读: 10 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
security
vegassep
27th
22nd
papers
New Tool: ficheck.py, (Thu, Jul 24th)
作者介绍了自己长期使用文件完整性监控工具(FIM)的经验,并分享了自己开发的Python工具ficheck.py。该工具用于监控文件创建、删除及属性变化,并支持邮件通知。作者提供了安装脚本和配置示例,并强调其高效性和灵活性。...
2025-7-24 03:7:53 | 阅读: 18 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
github
clausing
fcheck
perl
ficheck
ISC Stormcast For Thursday, July 24th, 2025 https://isc.sans.edu/podcastdetail/9540, (Thu, Jul 24th)
read file error: read notes: is a directory...
2025-7-24 02:0:2 | 阅读: 16 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
security
isc
feeds
papers
Analyzing Sharepoint Exploits (CVE-2025-53770, CVE-2025-53771), (Wed, Jul 23rd)
read file error: read notes: is a directory...
2025-7-23 19:36:36 | 阅读: 29 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
payload
cg
xmlschema
xsi
xsd
ISC Stormcast For Wednesday, July 23rd, 2025 https://isc.sans.edu/podcastdetail/9538, (Wed, Jul 23rd)
read file error: read notes: is a directory...
2025-7-23 02:0:2 | 阅读: 16 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
papers
vegassep
security
isc
WinRAR MoTW Propagation Privacy, (Tue, Jul 22nd)
自WinRAR 7.10起,提取文件时不再完整保留Mark-of-the-Web信息中的ReferredUrl和HostUrl字段,仅保留ZoneId字段以保护隐私,默认情况下该功能启用但可关闭。...
2025-7-22 04:5:56 | 阅读: 22 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
winrar
referredurl
propagated
zoneid
Wireshark 4.4.8 Released, (Tue, Jul 22nd)
Wireshark发布4.4.8版本,修复了9个已知问题。...
2025-7-22 04:5:15 | 阅读: 14 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
didier
stevens
senior
ISC Stormcast For Tuesday, July 22nd, 2025 https://isc.sans.edu/podcastdetail/9536, (Tue, Jul 22nd)
ISC Stormcast播客讨论网络安全威胁与防护,由Didier Stevens主持,当前威胁级别为绿色。...
2025-7-22 02:0:3 | 阅读: 11 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
22nd
isc
27th
security
papers
How quickly do we patch? A quick look from the global viewpoint, (Mon, Jul 21st)
文章分析了针对SharePoint服务器的“ToolShell”攻击活动,并通过Shodan数据研究CISA已知被利用漏洞的修复情况。结果显示多数漏洞修复缓慢且不完全,部分系统因支持结束而下线。整体来看,互联网暴露系统的漏洞修复速度仍不理想。...
2025-7-21 11:3:12 | 阅读: 19 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
microsoft
exchange
exploited
decrease
ISC Stormcast For Monday, July 21st, 2025 https://isc.sans.edu/podcastdetail/9534, (Mon, Jul 21st)
read file error: read notes: is a directory...
2025-7-21 02:0:3 | 阅读: 13 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
security
vegassep
isc
feeds
Critical Sharepoint 0-Day Vulnerablity Exploited CVE-2025-53770 (ToolShell), (Sun, Jul 20th)
read file error: read notes: is a directory...
2025-7-20 17:32:7 | 阅读: 37 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
microsoft
defender
security
originated
remote
Veeam Phishing via Wav File, (Fri, Jul 18th)
一篇关于网络钓鱼的文章描述了一次看似来自Veeam Software的语音信箱通知邮件,附件包含一个WAV文件,内容涉及过期的备份许可证。尽管接收者与Veeam无关,该邮件仍可能构成非定向钓鱼攻击。...
2025-7-18 07:39:5 | 阅读: 21 |
收藏
|
SANS Internet Storm Center, InfoCON: green - isc.sans.edu
veeam
wav
rootshell
voicemsg
software
Previous
10
11
12
13
14
15
16
17
Next