Mrxn's Blog - focus on web security and love hacker technology
 article cover

Introduction to XML format of. NET RSA algorithm and its conversion to PEM format Technical Articles

Recently, code audit encountered source code hard coding public and private keys. Take the opportunity to learn XML format of RSA algorithm in ASP.NET and its conversion to common PEM format


admin Published on 2024-4-9 22:39 
 article cover

Security Problems Caused by the Priority of the AND/OR Operator in PHP PHP

Preface In PHP,&&and | | are logical operators, which are used for logical AND and logical OR operations respectively. And and and or are also logical operators. They perform the same basic logical operations, but their priority is different. In brief,&&and | | have higher priority, while and and or have lower priority. This means that in the expression,&&and | | will be calculated before other low priority operators (such as assignment operator=)


admin Published on 2024-3-28 21:43 
 article cover

View open cameras around the world through search engines and space mapping tools Resource sharing

preface

With the continuous progress of network technology, tens of thousands of IP cameras around the world are connected to the Internet, some of which are not fully protected and can be viewed by the public. These video streams may come from security monitoring, public surveillance, or even private cameras. But the problem is, how to find these open IP cameras? In this article, we will introduce how to use two powerful tools - Google search engine and Shodan - to uncover the hidden horizon of the network through some simple and effective search syntax.


admin Published on 2024-1-2 21:22 
 article cover

admin Published on 2023-11-18 21:47 
 article cover

The latest version of sqlmap system comes with the interpreter in Chinese Technical Articles

preface

Up to now, the latest version is 1.7.10.1#dev Version. The system comes with 69 stamps in total. Compared with the author's earlier article SQLMAP dumper WAF bypass script list comment The changes are still large, so the following are English and Chinese translations

english

Use the following command to obtain [sqlmap] (//mrxn. net/tag/sqlm


admin Published on 2023-10-17 22:16 
 article cover

Risk warning of LNMP supply chain poisoning event Industry News

introduction

Recently, Anheng Information CERT monitored an LNMP poisoning attack on the supply chain. We found that malicious programs were implanted in the installation package downloaded from the official website of lnmp.org. Up to now, most threat intelligence platforms have not marked relevant malicious IoC intelligence. It is recommended that RedHat system users who download and deploy LNMP on the official website of lnmp.org in the near future conduct self inspection.

The LNMP one click installation package is a Linux shell package that can be used for CentOS/Debian/Ubuntu, etc


admin Published on 2023-9-20 20:33 
 article cover

Scorpio Behinder 4.1 Double click prompt: no compilation environment found on the local machine Technical Articles

preface

A few days ago, Icy Scorpion updated version 4.1. After the new version was updated, double-click Behinder.jar to prompt The compilation environment is not found on the local machine. In order to use the custom transport protocol function normally, please use the JDK (not JRE) environment to open the software. . Those who are accustomed to double click startup may not be particularly suited to software directory command line startup. Finally, they saw the solution in t00ls and shared it with everyone for convenience


admin Published on 2023-8-27 12:42 

HCMendetool HCM macro scene encryption and decryption tool Technical Articles

brief introduction

It is applicable to the encryption and decryption of Hongjing HCM, such as its sql injection vulnerability or arbitrary file reading


admin Published on 2023-8-5 09:47 
 article cover

One click to activate the bursuite pro of the Mac installation version Technical Articles

preface

The prerequisite is that the bursuite pro (installed in. dmg format) has been installed
The initial reason is that each upgrade is completed burpsuite Pro needs to go through the activation process again (maybe it's my environment?)
I just saw that the BurpLoaderKeygen project of h3110w0r1d-y was updated recently. It supports command line activation! Then just write<< EOF >


admin Published on 2023-6-18 21:28 

Nmap error Couldn't open a raw socket Error: Permission denied (13) Linux

Nmap Introduction

Give a brief introduction to unknown friends

Nmap (Network Mapper) is a network scanner and host detector


admin Published on 2023-5-28 22:27