今日文章更新:
渗透测试网站检查表
https://pxiaoer.blog/2020/11/02/web-checklist/
学习资料
1.查找和验证代码里面的密钥和机密信息
https://blog.ostorlab.co/hardcoded-secrets.html
2. .git文件夹泄露导致RCE
https://james-clee.com/2020/11/01/leaked-git-folder-leads-to-rce/
3.因为响应操作导致账户接管
https://avanishpathak46.medium.com/tale-of-multiple-account-takeover-on-single-platform-19c019b1d1cb
4.垂直特权提升导致管理员账号接管
5.漏洞赏金工具
https://github.com/m4ll0k/Bug-Bounty-Toolz
AI安全
1.什么是数据中毒
https://bdtechtalks.com/2020/10/07/machine-learning-data-poisoning/
2.机器学习模型无触发后门研究