Phition | 离别歌 | 新加坡

A look at Jumpserver security: in-depth analysis of Sep series vulnerabilities

Original link: https://www.leavesongs.com/PENETRATION/jumpserver-sep-2023-multiple-vulnerabilities-go-through.html Jumpserver is an open source project developed by a domestic company in China and is the largest player in the field of open source bastion machines. In September 2023, a series of security issues were officially fixed, including the following security vulnerabilities: The vulnerability of JumpServer reset password verification code can be …

A look at Jumpserver security: in-depth analysis of Sep series vulnerabilities Read More »

Defense against Race Condition vulnerabilities under Django

Original link: https://www.leavesongs.com/PENETRATION/django-race-condition-defense.html This article is transferred from: https://www.leavesongs.com/PENETRATION/django-race-condition-defense.html This site is only for collection, and the copyright belongs to the original author.

Europe Travel 2022

Original link: https://www.leavesongs.com/THINK/europe-trip-2022.html This article records my travel experience with three friends in France and Switzerland. I probably made a plan to travel to Europe in July this year. It is not quite appropriate to say that it is a “plan”, but after a few friends searched for a more suitable air ticket, they decided …

Europe Travel 2022 Read More »

RCE journey from encounter with Flarum

Original link: https://www.leavesongs.com/PENETRATION/flarum-rce-tour.html This article is reprinted from: https://www.leavesongs.com/PENETRATION/flarum-rce-tour.html This site is for inclusion only, and the copyright belongs to the original author.

XRay 3rd Anniversary Event Message

Original link: https://www.leavesongs.com/THINK/xray-3-years.html Last week, XRay did a 3rd anniversary event and wrote a brief message and recorded it on the blog. Hello everyone, my name is phith0n. There are many people in the security community who call me Master P. I used to be very resistant to this title and always gave people a …

XRay 3rd Anniversary Event Message Read More »

An XSS story from my own blog

Original link: https://www.leavesongs.com/PENETRATION/xss-from-my-blog.html I received a few reminders this evening, and I opened it and saw that someone was testing XSS in the comment area of ​​my blog: Originally this kind of testing is commonplace, and this person failed to find XSS, I mostly closed the page before it was released. But tonight I didn’t …

An XSS story from my own blog Read More »