File tree 1 file changed +8
-0
lines changed
1 file changed +8
-0
lines changed Original file line number Diff line number Diff line change 139
139
140
140
https://www.pytosquatting.org/
141
141
142
+ [ PyPI 官方仓库遭遇request恶意包投毒] ( https://mp.weixin.qq.com/s/dkPdXfGfSK097GI6Ln92lA )
143
+
142
144
143
145
144
146
### LDAP注入
@@ -167,6 +169,8 @@ https://www.pytosquatting.org/
167
169
168
170
[ 讨论PythonWeb开发中可能会遇到的安全问题之SQL注入] ( http://blog.neargle.com/2016/07/22/pythonweb-framework-dev-vulnerable/ )
169
171
172
+ [ Django JSONField SQL注入漏洞(CVE-2019 -14234)分析与影响] ( https://www.leavesongs.com/PENETRATION/django-jsonfield-cve-2019-14234.html )
173
+
170
174
171
175
172
176
### SSTI模版注入
@@ -185,10 +189,14 @@ https://github.com/evilcos/python-webshell
185
189
186
190
https://github.com/ahhh/Reverse_DNS_Shell
187
191
192
+
193
+
188
194
### paper
189
195
190
196
Python_Hack_知道创宇_北北(孙博).pdf
191
197
198
+
199
+
192
200
### 其他
193
201
194
202
[ 如何判断目标站点是否为Django开发] ( https://www.leavesongs.com/PENETRATION/detect-django.html )
You can’t perform that action at this time.
0 commit comments