20210914 BinDiff 二进制比较简介 https://mp.weixin.qq.com/s/fPjqO_L5aHxzVUu8GtIgeA
20210914 Apple 发布 iOS 14.8 版本更新 https://support.apple.com/en-us/HT212807
20210914 利用 Root-Cause Clustering 的方案实现 Fuzz 过程中 Crash 样本的去重 https://nebelwelt.net/files/21CCS.pdf
20210914 VaultFuzzer: A state-based approach for Linux kernel https://www.reddit.com/r/netsec/comments/pnedi0/vaultfuzzer_a_statebased_approach_for_linux_kernel/
20210914 Go 语言实现的跨平台 CobaltStrike Beacon https://github.com/darkr4y/geacon
20210914 Oracle BI XML XXE 漏洞分析 https://testbnull.medium.com/linh-tinh-v%E1%BB%81-oracle-business-intelligence-part-1-5a050b48a193
20210914 通过分析 NSO Group Pegasus 间谍软件,CitizenLab 发现了一个针对 iMessage 的 Zero-Click 0Day Exploit - FORCEDENTRY,Apple 今天发布补丁更新修复该漏洞 https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/
20210914 Hacking CloudKit - 因 CloudKit 使用不当,导致可以删除 Apple Shortcuts https://labs.detectify.com/2021/09/13/hacking-cloudkit-how-i-accidentally-deleted-your-apple-shortcuts/

20210914 谈谈网络空间“行为测绘” https://mp.weixin.qq.com/s/THEdOpSu_bSPWo66sRDyPA
20210914 VaultFuzzer: 针对Linux内核的状态导向模糊测试方案 https://mp.weixin.qq.com/s/ZevJBJjANmBLPCG0RyC3eg
20210914 fapro: 协议模拟服务器 https://github.com/fofapro/fapro
20210914 攻击推理-安全知识图谱应用的困境思考 https://mp.weixin.qq.com/s/DOfrD7SGpoXP--zZPzf5bg
20210914 goblin: 一款适用于红蓝对抗中的仿真钓鱼系统 https://github.com/xiecat/goblin
20210914 网络空间资产安全管理实践与创新 https://mp.weixin.qq.com/s/3NWI-_qJZfTuqvFl3d2SAQ
20210914 Xcheck之PHP代码安全检查 https://mp.weixin.qq.com/s?__biz=Mzg2ODQ3ODE1NA==&mid=2247483818&idx=1&sn=f55330a128035ba29cc8f1eca2c56230&chksm=ceaafc0ff9dd7519397f4dc0f710c3901ad7b76436dbc7accbfc1a543c702f49dabefa0d7ea5&token=654851123&lang=zh_CN#rd
20210914 URL FIlter 绕过 - Python 之 Django https://github.com/CHYbeta/URLFilterBypassDemo/tree/master/python/django_demo
20210914 检测浏览器是否存在代理 https://github.com/ttttmr/checkproxy

20210914T12:47:34Z CVE-2021-40444 This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit https://github.com/aslitsecurity/CVE-2021-40444_builders 未查询到CVE信息
20210914T12:14:05Z 未知编号 Null https://github.com/mr-r3b00t/2021-BadPewCVEs 未查询到CVE信息
20210914T11:39:01Z CVE-2021-24499 Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme. https://github.com/RyouYoo/CVE-2021-24499 The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
20210914T08:18:40Z cve-2021-40444 Null https://github.com/Immersive-Labs-Sec/cve-2021-40444-analysis 未查询到CVE信息
20210914T06:44:49Z CVE-2021-40845 AlphaWeb XE, the embedded web server running on AlphaCom XE, has a vulnerability which allows to upload PHP files leading to RCE once the authentication is successful. https://github.com/ricardojoserf/CVE-2021-40845 未查询到CVE信息
20210914T03:21:25Z CVE-2021-32202 CVE-2021-32202 https://github.com/l00neyhacker/CVE-2021-32202 In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the %post description% filed in the blog post creation page.
20210914T03:17:26Z CVE-2021-36582 CVE-2021-36582 https://github.com/l00neyhacker/CVE-2021-36582 In Kooboo CMS, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.
20210914T03:12:30Z CVE-2021-36581 CVE-2021-36581 https://github.com/l00neyhacker/CVE-2021-36581 Kooboo CMS is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
20210914T02:47:28Z CVE-2021-40346 CVE-2021-40346 integer overflow enables http smuggling https://github.com/donky16/CVE-2021-40346-POC
20210914T02:33:43Z 未知编号 Null https://github.com/aydianosec/CVE2021-40444 未查询到CVE信息

