<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RCE on Zeddy's Blog</title><link>https://zeddyu.github.io/tags/rce/</link><description>Recent content in RCE on Zeddy's Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 08 Mar 2019 23:31:42 +0000</lastBuildDate><atom:link href="https://zeddyu.github.io/tags/rce/atom.xml" rel="self" type="application/rss+xml"/><item><title>Web For Pentest</title><link>https://zeddyu.github.io/p/web-for-pentest/</link><pubDate>Fri, 08 Mar 2019 23:31:42 +0000</pubDate><guid>https://zeddyu.github.io/p/web-for-pentest/</guid><description>&lt;p&gt;很久之前就想做的靶机，一直没做，最近有空清理一下。地址在&lt;a class="link" href="https://pentesterlab.com/exercises?dir=desc&amp;amp;only=free&amp;amp;sort=published_at" target="_blank" rel="noopener"
 &gt;PentestLab&lt;/a&gt;&lt;/p&gt;</description></item><item><title>巧用命令注入的N种方式</title><link>https://zeddyu.github.io/p/%E5%B7%A7%E7%94%A8%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E7%9A%84n%E7%A7%8D%E6%96%B9%E5%BC%8F/</link><pubDate>Thu, 17 Jan 2019 18:55:27 +0000</pubDate><guid>https://zeddyu.github.io/p/%E5%B7%A7%E7%94%A8%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E7%9A%84n%E7%A7%8D%E6%96%B9%E5%BC%8F/</guid><description>&lt;blockquote&gt;
 &lt;p&gt;​	本文首发于补天平台，地址：https://mp.weixin.qq.com/s/Hm6TiLHiAygrJr-MGRq9Mw&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;在&lt;code&gt;NUAACTF_2018&lt;/code&gt;中，我出了一道比较水的采用&lt;code&gt;Spring&lt;/code&gt;框架的&lt;code&gt;SSRF&lt;/code&gt;+&lt;code&gt;Java Deserialization&lt;/code&gt;+&lt;code&gt;Command Injection&lt;/code&gt;。个人觉得在出题时候也学习到了不少知识，特别是在&lt;code&gt;Command Injection&lt;/code&gt;这一块让我对&lt;code&gt;Command Injection&lt;/code&gt;有了新的看法。&lt;/p&gt;</description></item></channel></rss>