Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
LiquidFiles漏洞:从发现到披露
projectblack.io
| 研究 |
#vulnerability-research
|
#ruby
|
#semgrep
|
#disclosure
|
#liquidfiles
摘要
LiquidFiles 漏洞挖掘实录:对 v4.1.1 运行 Semgrep 得到 623 条结果,一次命令注入尝试被 shellescape 拦截,文章完整记录了从发现、深入到最终披露的研究过程。
发布时间
2025-02-12 21:00
收录时间
2026-07-05 06:06
原文 ↗
相关内容
35个新的Semgrep规则:基础设施、供应链和Ruby
(blog.trailofbits.com)
本地 AI 在渗透测试与安全研究中的表现
(projectblack.io)
脆弱的锁:SAML 认证的新型绕过技术
(portswigger.net)
GitLab RCE 的背后:depthfirst 的 Ruby 生态系统深度之旅
(depthfirst.com)
Going depthfirst:通过两个 Ruby 内存损坏漏洞实现 GitLab RCE
(depthfirst.com)
使用 LibAFL 扩展 Ruzzy 模糊测试工具
(blog.trailofbits.com)
返回