<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title>Y4er的博客</title>
        <link>https://y4er.com/</link>
        <description>Y4er的博客</description>
        <generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>chuyusec@gmail.com (Y4er)</managingEditor>
            <webMaster>chuyusec@gmail.com (Y4er)</webMaster><copyright>This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.</copyright><lastBuildDate>Thu, 26 Oct 2023 15:39:15 &#43;0800</lastBuildDate>
            <atom:link href="https://y4er.com/index.xml" rel="self" type="application/rss+xml" />
        <item>
    <title>dnlib使用</title>
    <link>https://y4er.com/posts/dnlib-usage/</link>
    <pubDate>Thu, 26 Oct 2023 15:39:15 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/dnlib-usage/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>Apache ActiveMQ RCE</title>
    <link>https://y4er.com/posts/apache-activemq-rce/</link>
    <pubDate>Thu, 26 Oct 2023 15:22:35 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/apache-activemq-rce/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>dotnet反序列化新链学习</title>
    <link>https://y4er.com/posts/dotnet-new-gadget/</link>
    <pubDate>Mon, 23 Oct 2023 16:51:13 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/dotnet-new-gadget/</guid>
    <description><![CDATA[<p>@chudyPB在Hexacon 2023会议上发布了他的dotnet反序列化的研究白皮书，一个长达124页的pdf，这是我看过最强的一篇关于dotnet序列化漏洞的文章。</p>]]></description>
</item><item>
    <title>CVE-2023-42793 JetBrains TeamCity 权限绕过</title>
    <link>https://y4er.com/posts/cve-2023-42793-jetbrains-teamcity-auth-bypass-rce/</link>
    <pubDate>Tue, 26 Sep 2023 15:20:26 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/cve-2023-42793-jetbrains-teamcity-auth-bypass-rce/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>LG Simple Editor 的几个RCE漏洞</title>
    <link>https://y4er.com/posts/lg-simple-editor-rce/</link>
    <pubDate>Sat, 09 Sep 2023 15:17:52 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/lg-simple-editor-rce/</guid>
    <description><![CDATA[<p>LG是一家专门搞LED的公司，旗下有一些产品，这次看的是zdi爆出来的LG Simple Editor，公网数量虽然不多，但是漏洞是未授权RCE。</p>
<p><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1208/" target="_blank" rel="noopener noreferrer">https://www.zerodayinitiative.com/advisories/ZDI-23-1208/</a></p>]]></description>
</item><item>
    <title>devtunnel 微软的隧道工具</title>
    <link>https://y4er.com/posts/devtunnel-the-tunneling-tool-of-microsoft/</link>
    <pubDate>Fri, 01 Sep 2023 11:30:36 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/devtunnel-the-tunneling-tool-of-microsoft/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>CVE-2023-39476 Inductive Automation Ignition JavaSerializationCodec Deserialization RCE</title>
    <link>https://y4er.com/posts/cve-2023-394760-inductive-automation-ignition-javaserializationcodec-deserialization-rce/</link>
    <pubDate>Tue, 29 Aug 2023 11:25:15 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/cve-2023-394760-inductive-automation-ignition-javaserializationcodec-deserialization-rce/</guid>
    <description><![CDATA[<p>文章首发在先知社区 <a href="https://xz.aliyun.com/t/12813" target="_blank" rel="noopener noreferrer">https://xz.aliyun.com/t/12813</a></p>]]></description>
</item><item>
    <title>CVE-2023-2611 Advantech R-SeeNet 硬编码密码</title>
    <link>https://y4er.com/posts/cve-2023-2611-advantech-r-seenet-hardcode/</link>
    <pubDate>Sat, 26 Aug 2023 11:22:48 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/cve-2023-2611-advantech-r-seenet-hardcode/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>CVE-2023-37895: Apache Jackrabbit RMI RCE</title>
    <link>https://y4er.com/posts/cve-2023-37895-apache-jackrabbit-rmi-rce/</link>
    <pubDate>Fri, 28 Jul 2023 11:11:10 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/cve-2023-37895-apache-jackrabbit-rmi-rce/</guid>
    <description><![CDATA[]]></description>
</item><item>
    <title>CVE-2023-38646 Metabase pre-auth rce</title>
    <link>https://y4er.com/posts/cve-2023-38646-metabase-pre-auth-rce/</link>
    <pubDate>Wed, 26 Jul 2023 11:20:21 &#43;0800</pubDate><author>
        <name>Y4er</name>
    </author><guid>https://y4er.com/posts/cve-2023-38646-metabase-pre-auth-rce/</guid>
    <description><![CDATA[]]></description>
</item></channel>
</rss>
