
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Guge&#39;sBlog</title>
      <link>https://gugesay.com/blog</link>
      <description>骨哥说事公众号首发地</description>
      <language>zh-CN</language>
      <managingEditor>undefined (Guge)</managingEditor>
      <webMaster>undefined (Guge)</webMaster>
      <lastBuildDate>Wed, 20 May 2026 02:03:57 GMT</lastBuildDate>
      <atom:link href="https://gugesay.com/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://gugesay.com/blog/国外网友创建了一个虚拟的操作系统博物馆，里面</guid>
    <title>国外网友创建了一个虚拟的操作系统博物馆</title>
    <link>https://gugesay.com/blog/国外网友创建了一个虚拟的操作系统博物馆，里面</link>
    undefined
    <pubDate>Wed, 20 May 2026 02:03:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>怀旧</category><category>操作系统</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/那个杀软狂叫、QQ被盗的“时代”，我居然有点想它了</guid>
    <title>那个杀软狂叫、QQ被盗的“时代”，我居然有点想它了</title>
    <link>https://gugesay.com/blog/那个杀软狂叫、QQ被盗的“时代”，我居然有点想它了</link>
    undefined
    <pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/遗忘密码11年，claude-帮男子找回-40-万美元比特币</guid>
    <title>遗忘密码11年，Claude 成功帮男子找回 40 万美元比特币</title>
    <link>https://gugesay.com/blog/遗忘密码11年，claude-帮男子找回-40-万美元比特币</link>
    undefined
    <pubDate>Thu, 14 May 2026 01:37:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>btc</category><category>claude</category><category>比特币</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/我用f构建了一个game-boy模拟器</guid>
    <title>我用F#构建了一个Game Boy模拟器</title>
    <link>https://gugesay.com/blog/我用f构建了一个game-boy模拟器</link>
    undefined
    <pubDate>Fri, 01 May 2026 01:49:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Game Boy</category><category>游戏</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/copy-fail-如何仅用732字节获得root权限</guid>
    <title>Copy Fail 如何仅用732字节获得Root权限</title>
    <link>https://gugesay.com/blog/copy-fail-如何仅用732字节获得root权限</link>
    undefined
    <pubDate>Fri, 01 May 2026 01:44:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>提权</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/mcp服务器安全：隐藏的ai攻击面</guid>
    <title>MCP服务器安全：隐藏的AI攻击面</title>
    <link>https://gugesay.com/blog/mcp服务器安全：隐藏的ai攻击面</link>
    undefined
    <pubDate>Thu, 16 Apr 2026 01:38:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>MCP</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai-在现实中寻找到真正n-day漏洞的表现如何？</guid>
    <title>AI 在现实中寻找到真正N-Day漏洞的表现如何？</title>
    <link>https://gugesay.com/blog/ai-在现实中寻找到真正n-day漏洞的表现如何？</link>
    undefined
    <pubDate>Tue, 14 Apr 2026 02:09:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/gemma4-vs-qwen3-5-测评</guid>
    <title>Gemma 4 VS Qwen 3.5 本地部署测评</title>
    <link>https://gugesay.com/blog/gemma4-vs-qwen3-5-测评</link>
    undefined
    <pubDate>Tue, 07 Apr 2026 09:02:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Gemma</category><category>LLM</category><category>qwen</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/用报废车零件运行特斯拉model-3-的电脑</guid>
    <title>用报废车零件运行特斯拉Model 3 的电脑</title>
    <link>https://gugesay.com/blog/用报废车零件运行特斯拉model-3-的电脑</link>
    undefined
    <pubDate>Thu, 26 Mar 2026 06:46:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>tesla</category><category>白帽故事</category><category>硬件黑客</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2026-26123】微软认证器未捕获的deeplink</guid>
    <title>【CVE-2026-26123】微软身份认证器 DeepLink 漏洞</title>
    <link>https://gugesay.com/blog/【cve-2026-26123】微软认证器未捕获的deeplink</link>
    undefined
    <pubDate>Thu, 26 Mar 2026 06:38:23 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2026-26123</category><category>Deeplink</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai辅助漏洞挖掘：四种方法的实测与挫败</guid>
    <title>AI辅助漏洞挖掘：四种方法的实测与挫败</title>
    <link>https://gugesay.com/blog/ai辅助漏洞挖掘：四种方法的实测与挫败</link>
    undefined
    <pubDate>Mon, 23 Mar 2026 08:01:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>漏洞挖掘</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/他用那一瞬间的电压波动，干碎微软13年安全神话！</guid>
    <title>他用那一瞬间的电压波动，干碎微软13年安全神话！</title>
    <link>https://gugesay.com/blog/他用那一瞬间的电压波动，干碎微软13年安全神话！</link>
    undefined
    <pubDate>Wed, 18 Mar 2026 08:22:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>xbox</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/linkedin领英最新高危（8-1）漏洞披露</guid>
    <title>LinkedIn(领英)最新高危（8.1）漏洞披露</title>
    <link>https://gugesay.com/blog/linkedin领英最新高危（8-1）漏洞披露</link>
    undefined
    <pubDate>Wed, 18 Mar 2026 01:17:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>LinkedIn</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pagejack实战：cve-2022-0995漏洞利用详解</guid>
    <title>PageJack实战：CVE-2022-0995漏洞利用详解</title>
    <link>https://gugesay.com/blog/pagejack实战：cve-2022-0995漏洞利用详解</link>
    undefined
    <pubDate>Thu, 12 Mar 2026 06:49:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2022-0995</category><category>UAF</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/四分钟内诱骗comet-ai浏览器陷入网络钓鱼诈骗</guid>
    <title>四分钟诱骗Comet AI浏览器陷入网络钓鱼诈骗</title>
    <link>https://gugesay.com/blog/四分钟内诱骗comet-ai浏览器陷入网络钓鱼诈骗</link>
    undefined
    <pubDate>Thu, 12 Mar 2026 06:04:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Comet AI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/大海捞针：openclaw如何革新漏洞挖掘新范式</guid>
    <title>大海捞针：LLMs如何革新漏洞挖掘新范式</title>
    <link>https://gugesay.com/blog/大海捞针：openclaw如何革新漏洞挖掘新范式</link>
    undefined
    <pubDate>Wed, 11 Mar 2026 08:05:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>OpenClaw</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/恶意软件，就在你身边！：威胁行为者如何通</guid>
    <title>“恶意软件就在你身边”：警惕假冒OpenClaw安装程序！</title>
    <link>https://gugesay.com/blog/恶意软件，就在你身边！：威胁行为者如何通</link>
    undefined
    <pubDate>Tue, 10 Mar 2026 07:23:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>OpenClaw</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/手无寸铁，智取三洞：一个渗透测试员的手动</guid>
    <title>手无寸铁，智取三“洞”：一个渗透测试员的手动狩猎纪实</title>
    <link>https://gugesay.com/blog/手无寸铁，智取三洞：一个渗透测试员的手动</link>
    undefined
    <pubDate>Thu, 05 Mar 2026 06:20:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深度追踪coruna：一款高端-ios-漏洞武器的暗网漂</guid>
    <title>深度追踪“Coruna”：一款高端 iOS 漏洞武器库的“暗网”漂流记</title>
    <link>https://gugesay.com/blog/深度追踪coruna：一款高端-ios-漏洞武器的暗网漂</link>
    undefined
    <pubDate>Thu, 05 Mar 2026 05:50:38 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Coruna</category><category>iOS</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai的灵魂，关于soul-md</guid>
    <title>AI的灵魂，关于Soul.md</title>
    <link>https://gugesay.com/blog/ai的灵魂，关于soul-md</link>
    undefined
    <pubDate>Tue, 03 Mar 2026 05:45:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>OpenClaw</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/30天内挖掘100内核漏洞：windows驱动安全大危机？</guid>
    <title>30天内挖掘100+内核漏洞：Windows驱动安全大危机？</title>
    <link>https://gugesay.com/blog/30天内挖掘100内核漏洞：windows驱动安全大危机？</link>
    undefined
    <pubDate>Mon, 02 Mar 2026 02:43:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从一份配置文档到安全漏洞：400美元赏金的实战挖</guid>
    <title>从一份配置文档到安全漏洞：400美元赏金的实战挖掘之旅</title>
    <link>https://gugesay.com/blog/从一份配置文档到安全漏洞：400美元赏金的实战挖</link>
    undefined
    <pubDate>Mon, 02 Mar 2026 02:14:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rxss</category><category>swagger</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/九年前的恐惧，今天的预演：为什么 2026 年的你更应该看《AlphaGo》这部纪录片</guid>
    <title>九年前的恐惧，今天的预演：为什么 2026 年的你更应该看《AlphaGo》这部纪录片</title>
    <link>https://gugesay.com/blog/九年前的恐惧，今天的预演：为什么 2026 年的你更应该看《AlphaGo》这部纪录片</link>
    undefined
    <pubDate>Fri, 27 Feb 2026 02:14:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>AlphaGo</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从提示注入到rce：剖析ai智能体中的参数注入攻击</guid>
    <title>从提示注入到RCE：剖析AI智能体中的参数注入攻击</title>
    <link>https://gugesay.com/blog/从提示注入到rce：剖析ai智能体中的参数注入攻击</link>
    undefined
    <pubDate>Thu, 26 Feb 2026 02:18:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>提示注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/自动化-dast-测试：burp-suite-ai-智能体实战指南</guid>
    <title>自动化 DAST 测试：Burp Suite + AI 智能体实战指南</title>
    <link>https://gugesay.com/blog/自动化-dast-测试：burp-suite-ai-智能体实战指南</link>
    undefined
    <pubDate>Tue, 24 Feb 2026 03:36:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Burp</category><category>DAST</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一次完整的kubernetes黑盒渗透测试实战记录</guid>
    <title>一次完整的Kubernetes黑盒渗透测试实战记录</title>
    <link>https://gugesay.com/blog/一次完整的kubernetes黑盒渗透测试实战记录</link>
    undefined
    <pubDate>Thu, 12 Feb 2026 06:18:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Kubernetes</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/手搓漏洞：5种无工具绕过邮箱验证的实战技法</guid>
    <title>手搓漏洞：4种无工具绕过邮箱验证的实战技法</title>
    <link>https://gugesay.com/blog/手搓漏洞：5种无工具绕过邮箱验证的实战技法</link>
    undefined
    <pubDate>Thu, 12 Feb 2026 02:11:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/10000美元赏金的炼成：在google-ai代码编辑器antigravity中实现远程</guid>
    <title>10000美元赏金的炼成：在Google AI代码编辑器Antigravity中实现远程代码执行的技术剖析</title>
    <link>https://gugesay.com/blog/10000美元赏金的炼成：在google-ai代码编辑器antigravity中实现远程</link>
    undefined
    <pubDate>Tue, 10 Feb 2026 08:25:23 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Antigravity</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/信任链条上的又一道裂痕：揭秘另一个安全启动绕.md</guid>
    <title>信任链条上的又一道裂痕：揭秘另一个安全启动绕过漏洞 (CVE-2025-3052)</title>
    <link>https://gugesay.com/blog/信任链条上的又一道裂痕：揭秘另一个安全启动绕.md</link>
    undefined
    <pubDate>Sat, 07 Feb 2026 15:34:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-40551】：solarwinds-web-help-desk又一处反序列化漏洞</guid>
    <title>【CVE-2025-40551】：Solarwinds Web Help Desk又一处反序列化漏洞</title>
    <link>https://gugesay.com/blog/【cve-2025-40551】：solarwinds-web-help-desk又一处反序列化漏洞</link>
    undefined
    <pubDate>Sat, 31 Jan 2026 02:10:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-40551</category><category>SolarWinds</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/云端moltbot（原clawdbot）-discord-手把手教程</guid>
    <title>云端Moltbot（原Clawdbot）+ Discord 手把手教程</title>
    <link>https://gugesay.com/blog/云端moltbot（原clawdbot）-discord-手把手教程</link>
    undefined
    <pubDate>Fri, 30 Jan 2026 02:41:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Clawdbot</category><category>Discord</category><category>Moltbot</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过沙箱逃逸在-n8n-上实现远程代码执行-cve-2026-1470-和-cve-2026-0863</guid>
    <title>通过沙箱逃逸在 n8n 上实现远程代码执行 - CVE-2026-1470 和 CVE-2026-0863</title>
    <link>https://gugesay.com/blog/通过沙箱逃逸在-n8n-上实现远程代码执行-cve-2026-1470-和-cve-2026-0863</link>
    undefined
    <pubDate>Thu, 29 Jan 2026 06:44:34 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2026-0863</category><category>CVE-2026-1470</category><category>n8n</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/windows-电话服务远程代码执行漏洞剖析</guid>
    <title>Windows 电话服务远程代码执行漏洞剖析</title>
    <link>https://gugesay.com/blog/windows-电话服务远程代码执行漏洞剖析</link>
    undefined
    <pubDate>Wed, 28 Jan 2026 06:08:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>Windows</category><category>电话服务</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2026-24061：gnu-telnetd-致命认证绕过漏洞</guid>
    <title>CVE-2026-24061：GNU telnetd 致命认证绕过漏洞</title>
    <link>https://gugesay.com/blog/cve-2026-24061：gnu-telnetd-致命认证绕过漏洞</link>
    undefined
    <pubDate>Wed, 28 Jan 2026 02:43:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2026-24061</category><category>Telent</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/instagram-漏洞，私密帖子可被任意访问</guid>
    <title>Instagram 漏洞，私密帖子可被任意访问</title>
    <link>https://gugesay.com/blog/instagram-漏洞，私密帖子可被任意访问</link>
    undefined
    <pubDate>Mon, 26 Jan 2026 08:03:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Instagram</category><category>Meta</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2026-23760】smartermail-特权账户接管</guid>
    <title>【CVE-2026-23760】SmarterMail 特权账户接管</title>
    <link>https://gugesay.com/blog/【cve-2026-23760】smartermail-特权账户接管</link>
    undefined
    <pubDate>Mon, 26 Jan 2026 02:34:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2026-23760</category><category>SmarterMail</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深埋api端点的掘金宝典</guid>
    <title>深埋API端点的掘金宝典</title>
    <link>https://gugesay.com/blog/深埋api端点的掘金宝典</link>
    undefined
    <pubDate>Sat, 24 Jan 2026 05:31:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cloudflare-零日漏洞：全球任意主机访问</guid>
    <title>Cloudflare 零日漏洞：全球任意主机访问</title>
    <link>https://gugesay.com/blog/cloudflare-零日漏洞：全球任意主机访问</link>
    undefined
    <pubDate>Fri, 23 Jan 2026 02:47:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>Cloudflare</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在-anthropic-官方的-git-mcp-服务器中发现代码执行漏洞</guid>
    <title>如何在 Anthropic 官方的 Git MCP 服务器中发现代码执行漏洞</title>
    <link>https://gugesay.com/blog/如何在-anthropic-官方的-git-mcp-服务器中发现代码执行漏洞</link>
    undefined
    <pubDate>Thu, 22 Jan 2026 02:21:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Anthropic</category><category>MCP</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从js文件到权限突破：前端代码如何让我获取后端访</guid>
    <title>从JS文件到权限突破：前端代码如何让我获取后端访问权限</title>
    <link>https://gugesay.com/blog/从js文件到权限突破：前端代码如何让我获取后端访</link>
    undefined
    <pubDate>Wed, 21 Jan 2026 01:48:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>JS泄漏</category><category>前端</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【3】cve-2025-38352-chronomaly-漏洞利用挖掘揭秘</guid>
    <title>【3】CVE-2025-38352 - Chronomaly 漏洞利用挖掘揭秘</title>
    <link>https://gugesay.com/blog/【3】cve-2025-38352-chronomaly-漏洞利用挖掘揭秘</link>
    undefined
    <pubDate>Tue, 20 Jan 2026 01:58:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-38352</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/武器化日历邀请：提示词注入如何绕过-google-gemini-的防护</guid>
    <title>武器化日历邀请：提示词注入如何绕过 Google Gemini 的防护控制</title>
    <link>https://gugesay.com/blog/武器化日历邀请：提示词注入如何绕过-google-gemini-的防护</link>
    undefined
    <pubDate>Tue, 20 Jan 2026 01:37:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Gemini</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai-辅助逆向工程之旅：如何从tp-link摄像头中挖掘漏洞</guid>
    <title>AI 辅助逆向工程之旅：如何从TP-Link摄像头中挖掘漏洞</title>
    <link>https://gugesay.com/blog/ai-辅助逆向工程之旅：如何从tp-link摄像头中挖掘漏洞</link>
    undefined
    <pubDate>Mon, 19 Jan 2026 02:22:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2】cve-2025-38352-在不打内核补丁的情况下扩展竞争窗口</guid>
    <title>【2】CVE-2025-38352 - 在不打内核补丁的情况下扩展竞争窗口</title>
    <link>https://gugesay.com/blog/【2】cve-2025-38352-在不打内核补丁的情况下扩展竞争窗口</link>
    undefined
    <pubDate>Sat, 17 Jan 2026 02:15:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-38352</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从微软开年第一裁说说我近期的思考</guid>
    <title>从微软开年第一裁说说我近期的思考</title>
    <link>https://gugesay.com/blog/从微软开年第一裁说说我近期的思考</link>
    undefined
    <pubDate>Thu, 15 Jan 2026 03:00:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深入解析cve-2025-38352：android内核漏洞实战分析与poc</guid>
    <title>【1】深入解析CVE-2025-38352：Android内核漏洞实战分析与PoC</title>
    <link>https://gugesay.com/blog/深入解析cve-2025-38352：android内核漏洞实战分析与poc</link>
    undefined
    <pubDate>Wed, 14 Jan 2026 10:01:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>Android内核漏洞</category><category>CVE-2025-38352</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深入dirtypipe（cve-2022-0847）：从内核到利用全解析</guid>
    <title>深入DirtyPipe（CVE-2022-0847）：从内核到利用全解析</title>
    <link>https://gugesay.com/blog/深入dirtypipe（cve-2022-0847）：从内核到利用全解析</link>
    undefined
    <pubDate>Wed, 14 Jan 2026 03:10:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2022-0847</category><category>DirtyPipe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/八招攻破claude-code权限模型</guid>
    <title>八招攻破Claude Code权限模型</title>
    <link>https://gugesay.com/blog/八招攻破claude-code权限模型</link>
    undefined
    <pubDate>Tue, 13 Jan 2026 04:27:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Claude Code</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/突破沙盒：一次逆向ubuntu命名空间限制机制的探索之</guid>
    <title>突破沙盒：一次逆向Ubuntu命名空间限制机制的探索之旅</title>
    <link>https://gugesay.com/blog/突破沙盒：一次逆向ubuntu命名空间限制机制的探索之</link>
    undefined
    <pubDate>Mon, 12 Jan 2026 06:15:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Namespace</category><category>ubuntu</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/揭秘-smartermail-沉寂三个月后才公开的满分rce-漏洞</guid>
    <title>揭秘 SmarterMail 沉寂三个月后才公开的“满分”RCE 漏洞</title>
    <link>https://gugesay.com/blog/揭秘-smartermail-沉寂三个月后才公开的满分rce-漏洞</link>
    undefined
    <pubDate>Sun, 11 Jan 2026 03:27:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>SmarterMail</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/chatgpt僵尸代理攻击：新型零点击漏洞如何窃取你</guid>
    <title>ChatGPT“僵尸代理”攻击：新型零点击漏洞如何窃取你的邮件、记忆与一切</title>
    <link>https://gugesay.com/blog/chatgpt僵尸代理攻击：新型零点击漏洞如何窃取你</link>
    undefined
    <pubDate>Sat, 10 Jan 2026 03:04:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0点击</category><category>chatgpt</category><category>攻击</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2026年重点关注的3类高价值漏洞</guid>
    <title>2026年重点关注的3类高价值漏洞</title>
    <link>https://gugesay.com/blog/2026年重点关注的3类高价值漏洞</link>
    undefined
    <pubDate>Sat, 10 Jan 2026 02:27:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/详析-n8n-超危漏洞（cve-2026-21858）如何从文件上传一路打到服</guid>
    <title>详析 n8n 超危漏洞（CVE-2026-21858）如何从文件上传一路打到服务器沦陷</title>
    <link>https://gugesay.com/blog/详析-n8n-超危漏洞（cve-2026-21858）如何从文件上传一路打到服</link>
    undefined
    <pubDate>Thu, 08 Jan 2026 06:33:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2026-21858</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/侦察之后做什么？从-javascript-到-burp-suite-的高效漏洞挖掘实战</guid>
    <title>侦察之后做什么？从 JavaScript 到 Burp Suite 的高效漏洞挖掘实战指南</title>
    <link>https://gugesay.com/blog/侦察之后做什么？从-javascript-到-burp-suite-的高效漏洞挖掘实战</link>
    undefined
    <pubDate>Wed, 07 Jan 2026 08:02:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Burp Suite</category><category>javascript</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/绝大多数白帽子都会踩的侦察误区</guid>
    <title>90%的白帽子都会踩的‘侦察’误区</title>
    <link>https://gugesay.com/blog/绝大多数白帽子都会踩的侦察误区</link>
    undefined
    <pubDate>Wed, 07 Jan 2026 03:00:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>侦察</category><category>工具</category><category>渗透</category><category>白帽子</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/react2shell-的-cve-2025-55182-深入技术分析</guid>
    <title>React2Shell 的 CVE-2025-55182 深入技术分析</title>
    <link>https://gugesay.com/blog/react2shell-的-cve-2025-55182-深入技术分析</link>
    undefined
    <pubDate>Tue, 06 Jan 2026 01:37:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-55182</category><category>React</category><category>React2Shell</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【文末有吐槽】如何将一个无害-xss-提升为现实中的</guid>
    <title>【文末有吐槽】如何将一个无害 XSS 提升为现实中的钓鱼Payload</title>
    <link>https://gugesay.com/blog/【文末有吐槽】如何将一个无害-xss-提升为现实中的</link>
    undefined
    <pubDate>Tue, 30 Dec 2025 02:47:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category><category>钓鱼</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/参数污染的艺术：用javascript注入绕过waf</guid>
    <title>机器“聪明”与人“狡黠”：黑客机器人如何用参数污染“突破”顶级WAF</title>
    <link>https://gugesay.com/blog/参数污染的艺术：用javascript注入绕过waf</link>
    undefined
    <pubDate>Mon, 08 Dec 2025 06:45:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>JS注入</category><category>WAF</category><category>XSS</category><category>参数污染</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-64755】如何在一个晚上发现-claude-code-命令执行漏洞</guid>
    <title>【CVE-2025-64755】如何在一个晚上发现 Claude Code 命令执行漏洞</title>
    <link>https://gugesay.com/blog/【cve-2025-64755】如何在一个晚上发现-claude-code-命令执行漏洞</link>
    undefined
    <pubDate>Wed, 03 Dec 2025 02:34:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Claude Code</category><category>命令执行</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/快速语音克隆和情感控制-macos-本地部署-indextts2-笔记</guid>
    <title>快速语音克隆和情感控制-macOS 本地部署 indexTTS2 笔记</title>
    <link>https://gugesay.com/blog/快速语音克隆和情感控制-macos-本地部署-indextts2-笔记</link>
    undefined
    <pubDate>Fri, 14 Nov 2025 06:59:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>indexTTS2</category><category>macos</category><category>克隆语音</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cosyvoice-本地部署（macos）笔记</guid>
    <title>CosyVoice 本地部署（macOS）笔记</title>
    <link>https://gugesay.com/blog/cosyvoice-本地部署（macos）笔记</link>
    undefined
    <pubDate>Tue, 11 Nov 2025 10:05:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CosyVoice</category><category>macos</category><category>克隆语音</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/高级-nosql-注入漏洞利用指南全解</guid>
    <title>高级 NoSQL 注入漏洞利用指南</title>
    <link>https://gugesay.com/blog/高级-nosql-注入漏洞利用指南全解</link>
    undefined
    <pubDate>Mon, 10 Nov 2025 01:32:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>NoSQL注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将提问变为攻击？claude-desktop-的严重-rce-漏洞</guid>
    <title>如何将提问变为攻击？Claude Desktop 的严重 RCE 漏洞</title>
    <link>https://gugesay.com/blog/如何将提问变为攻击？claude-desktop-的严重-rce-漏洞</link>
    undefined
    <pubDate>Thu, 06 Nov 2025 06:11:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Claude Desktop</category><category>MCP</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-cve-2025-21479-在三星-s23-手机上实现攻击的研究</guid>
    <title>利用 CVE-2025-21479 在三星手机上实现攻击的研究</title>
    <link>https://gugesay.com/blog/利用-cve-2025-21479-在三星-s23-手机上实现攻击的研究</link>
    undefined
    <pubDate>Wed, 05 Nov 2025 08:10:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-21479</category><category>三星</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【25000】cve-2025-52665-unifi-access-中的-rce</guid>
    <title>【$25,000】CVE-2025-52665 - Unifi Access 中的 RCE</title>
    <link>https://gugesay.com/blog/【25000】cve-2025-52665-unifi-access-中的-rce</link>
    undefined
    <pubDate>Mon, 03 Nov 2025 07:21:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一个简单的-ssti-如何变为-rce</guid>
    <title>一个简单的 SSTI 如何变为 RCE</title>
    <link>https://gugesay.com/blog/一个简单的-ssti-如何变为-rce</link>
    undefined
    <pubDate>Wed, 29 Oct 2025 06:25:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>SSTI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/whatsapp百万美元漏洞演示临时撤档</guid>
    <title>WhatsApp百万美元漏洞演示临时撤档</title>
    <link>https://gugesay.com/blog/whatsapp百万美元漏洞演示临时撤档</link>
    undefined
    <pubDate>Mon, 27 Oct 2025 07:22:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0click</category><category>Pwn2Own</category><category>WhatsApp</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/入侵世界扑克巡回赛</guid>
    <title>入侵世界扑克巡回赛</title>
    <link>https://gugesay.com/blog/入侵世界扑克巡回赛</link>
    undefined
    <pubDate>Fri, 17 Oct 2025 02:30:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>2FA bypass</category><category>2FA绕过</category><category>后台</category><category>扑克</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/5分钟挖出网站漏洞的高效排查法</guid>
    <title>5分钟挖出网站漏洞的高效排查法​​</title>
    <link>https://gugesay.com/blog/5分钟挖出网站漏洞的高效排查法</link>
    undefined
    <pubDate>Mon, 13 Oct 2025 02:59:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/特斯拉远程信息处理控制单元-adb-授权绕过</guid>
    <title>特斯拉远程信息处理控制单元 - ADB 授权绕过</title>
    <link>https://gugesay.com/blog/特斯拉远程信息处理控制单元-adb-授权绕过</link>
    undefined
    <pubDate>Fri, 10 Oct 2025 07:16:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ADB</category><category>特斯拉</category><category>白帽故事</category><category>绕过</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一种新奇另类的文件上传利用</guid>
    <title>Outlook Web 上一种新奇另类的文件上传利用</title>
    <link>https://gugesay.com/blog/一种新奇另类的文件上传利用</link>
    undefined
    <pubDate>Mon, 29 Sep 2025 02:08:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>outlook</category><category>XSS</category><category>文件上传</category><category>白帽故事</category><category>钓鱼</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用英雄无敌5自定义地图实现远程控制对方电脑</guid>
    <title>利用英雄无敌5自定义地图实现远程控制对方电脑</title>
    <link>https://gugesay.com/blog/利用英雄无敌5自定义地图实现远程控制对方电脑</link>
    undefined
    <pubDate>Wed, 24 Sep 2025 07:50:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>白帽故事</category><category>英雄无敌</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【天价漏洞】11-7万美元！一个文件攻破meta-messenger，实现远</guid>
    <title>【天价漏洞】11.7万美元！一个文件攻破Meta Messenger，实现远程代码执行</title>
    <link>https://gugesay.com/blog/【天价漏洞】11-7万美元！一个文件攻破meta-messenger，实现远</link>
    undefined
    <pubDate>Wed, 17 Sep 2025 06:52:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DLL劫持</category><category>facebook</category><category>Messenger</category><category>Meta</category><category>rce</category><category>白帽故事</category><category>远程代码执行</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/破盾·溯源：直面漏洞本身的sql注入艺术</guid>
    <title>穿透WAF屏障：追踪源站IP与SQL注入的艺术</title>
    <link>https://gugesay.com/blog/破盾·溯源：直面漏洞本身的sql注入艺术</link>
    undefined
    <pubDate>Mon, 15 Sep 2025 16:00:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/nuclei-配合-ai-发现漏洞</guid>
    <title>Nuclei 配合 AI 发现漏洞</title>
    <link>https://gugesay.com/blog/nuclei-配合-ai-发现漏洞</link>
    undefined
    <pubDate>Mon, 15 Sep 2025 02:36:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>nuclei</category><category>prompt</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/你的nano-banana，不止是ai绘画：看看别人脑洞大开的新奇</guid>
    <title>你的Nano-Banana，不止是AI绘画：看看别人脑洞大开的新奇玩法吧～</title>
    <link>https://gugesay.com/blog/你的nano-banana，不止是ai绘画：看看别人脑洞大开的新奇</link>
    undefined
    <pubDate>Thu, 11 Sep 2025 01:40:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>nano-banana</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ollama-desktop-v0-10-0-rce-漏洞分析：揭秘-drive-by-攻击链</guid>
    <title>​​Ollama Desktop v0.10.0 RCE 漏洞分析：揭秘 Drive-By 攻击链​</title>
    <link>https://gugesay.com/blog/ollama-desktop-v0-10-0-rce-漏洞分析：揭秘-drive-by-攻击链</link>
    undefined
    <pubDate>Tue, 09 Sep 2025 07:40:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>drive-by</category><category>LLM</category><category>Ollama</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【5000】app渗透测试-10-秒内破解银行应用-pin-码</guid>
    <title>​​10秒，5000美金：如何“秒破”银行AppPIN码</title>
    <link>https://gugesay.com/blog/【5000】app渗透测试-10-秒内破解银行应用-pin-码</link>
    undefined
    <pubDate>Thu, 28 Aug 2025 03:13:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>APP</category><category>Frida</category><category>iOS</category><category>白帽故事</category><category>逆向</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pwn笔记-3</guid>
    <title>PWN笔记-3</title>
    <link>https://gugesay.com/blog/pwn笔记-3</link>
    undefined
    <pubDate>Tue, 26 Aug 2025 16:01:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>PWN</category><category>堆栈</category><category>笔记</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pwn笔记-2</guid>
    <title>PWN笔记-2</title>
    <link>https://gugesay.com/blog/pwn笔记-2</link>
    undefined
    <pubDate>Mon, 25 Aug 2025 16:01:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>PWN</category><category>堆栈</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-9074】windows-docker-desktop-上完整-docker-逃逸漏洞</guid>
    <title>【CVE-2025-9074】Windows Docker Desktop 上完整 Docker 逃逸漏洞</title>
    <link>https://gugesay.com/blog/【cve-2025-9074】windows-docker-desktop-上完整-docker-逃逸漏洞</link>
    undefined
    <pubDate>Mon, 25 Aug 2025 08:51:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-9074</category><category>Docker</category><category>白帽故事</category><category>逃逸漏洞</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pwn笔记-1</guid>
    <title>PWN笔记-1</title>
    <link>https://gugesay.com/blog/pwn笔记-1</link>
    undefined
    <pubDate>Mon, 25 Aug 2025 01:15:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>PWN</category><category>堆栈</category><category>笔记</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/mac-m芯片使用pwntoolspwn环境搭建</guid>
    <title>鱼与熊掌就要兼得！M芯片使用pwntools&amp;PWN环境搭建</title>
    <link>https://gugesay.com/blog/mac-m芯片使用pwntoolspwn环境搭建</link>
    undefined
    <pubDate>Sat, 23 Aug 2025 07:48:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>PWN</category><category>pwntools</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cursor-mcp-秒解-flag-体验</guid>
    <title>Cursor + MCP 秒解 Flag 体验</title>
    <link>https://gugesay.com/blog/cursor-mcp-秒解-flag-体验</link>
    undefined
    <pubDate>Wed, 20 Aug 2025 06:54:02 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>Cursor</category><category>MCP</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【20k】隐藏api参数如何泄露youtube创作者邮箱？</guid>
    <title>【$20,000】隐藏API参数如何泄露YouTube创作者邮箱？</title>
    <link>https://gugesay.com/blog/【20k】隐藏api参数如何泄露youtube创作者邮箱？</link>
    undefined
    <pubDate>Tue, 19 Aug 2025 06:02:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>youtube</category><category>信息泄漏</category><category>漏洞利用</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深入解析ssti：像专家一样发现与利用服务器端模板</guid>
    <title>深入解析SSTI：像专家一样发现与利用服务器端模板注入漏洞</title>
    <link>https://gugesay.com/blog/深入解析ssti：像专家一样发现与利用服务器端模板</link>
    undefined
    <pubDate>Mon, 18 Aug 2025 06:10:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>SSTI</category><category>服务器端模板注入</category><category>漏洞利用</category><category>白帽故事</category><category>网络安全</category><category>远程代码执行（RCE）</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑客组织kimsuky内部数据泄露</guid>
    <title>黑客组织Kimsuky内部数据泄露</title>
    <link>https://gugesay.com/blog/黑客组织kimsuky内部数据泄露</link>
    undefined
    <pubDate>Fri, 15 Aug 2025 01:32:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Kimsuky</category><category>信息差</category><category>朝鲜</category><category>黑客组织</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/brother-打印机漏洞挖掘实录：stephen-fewer-如何在兄弟公司的多</guid>
    <title>Brother 打印机漏洞挖掘实录：Stephen Fewer 如何在兄弟公司的多款设备中发现漏洞</title>
    <link>https://gugesay.com/blog/brother-打印机漏洞挖掘实录：stephen-fewer-如何在兄弟公司的多</link>
    undefined
    <pubDate>Thu, 14 Aug 2025 02:22:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Brother</category><category>打印机</category><category>漏洞</category><category>物联网</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/群晖-diskstation-空字节写入漏洞</guid>
    <title>群晖 DiskStation 空字节写入漏洞</title>
    <link>https://gugesay.com/blog/群晖-diskstation-空字节写入漏洞</link>
    undefined
    <pubDate>Wed, 13 Aug 2025 09:04:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DiskStation</category><category>白帽故事</category><category>群晖</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/filejacking-如何让浏览器文件api成为初始入侵跳板</guid>
    <title>FileJacking – 如何让浏览器文件API成为初始入侵跳板</title>
    <link>https://gugesay.com/blog/filejacking-如何让浏览器文件api成为初始入侵跳板</link>
    undefined
    <pubDate>Tue, 12 Aug 2025 02:36:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>FileJacking</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/💣-google-赏金猎手的胜利：如何发现并利用一个价值10000</guid>
    <title>💣 Google 赏金猎手的胜利：如何发现并利用一个价值$10,000的反序列化RCE漏洞？</title>
    <link>https://gugesay.com/blog/💣-google-赏金猎手的胜利：如何发现并利用一个价值10000</link>
    undefined
    <pubDate>Mon, 11 Aug 2025 02:25:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AppSheet</category><category>Google</category><category>rce</category><category>反序列化</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一则图片上传到-getshell-的故事</guid>
    <title>一则图片上传到 GetShell 的故事</title>
    <link>https://gugesay.com/blog/一则图片上传到-getshell-的故事</link>
    undefined
    <pubDate>Fri, 08 Aug 2025 02:51:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>getshell</category><category>rce</category><category>图片上传</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/python自动化提取lsass凭证：后渗透的密码抓取实战</guid>
    <title>Python自动化提取LSASS凭证：后渗透的密码抓取实战​</title>
    <link>https://gugesay.com/blog/python自动化提取lsass凭证：后渗透的密码抓取实战</link>
    undefined
    <pubDate>Tue, 05 Aug 2025 04:25:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>LSASS</category><category>mimikatz</category><category>python</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2025-33073-深度分析</guid>
    <title>CVE-2025-33073 深度分析</title>
    <link>https://gugesay.com/blog/cve-2025-33073-深度分析</link>
    undefined
    <pubDate>Thu, 31 Jul 2025 08:56:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>cve-2025-33073</category><category>NTLM</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【6000】mozilla-vpn-客户端通过文件写入和路径遍历的-rce</guid>
    <title>【$6,000】Mozilla VPN 客户端通过文件写入和路径遍历的 RCE</title>
    <link>https://gugesay.com/blog/【6000】mozilla-vpn-客户端通过文件写入和路径遍历的-rce</link>
    undefined
    <pubDate>Wed, 30 Jul 2025 01:30:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Mozilla</category><category>rce</category><category>VPN</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/要来点-idor-吗？泄露-6400-万份麦当劳求职申请的漏洞</guid>
    <title>要来点 IDOR 吗？泄露 6400 万份麦当劳求职申请的漏洞</title>
    <link>https://gugesay.com/blog/要来点-idor-吗？泄露-6400-万份麦当劳求职申请的漏洞</link>
    undefined
    <pubDate>Tue, 29 Jul 2025 01:47:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category><category>麦当劳</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-orm-注入窃取在线射击游戏的加密货币</guid>
    <title>从游戏到钱包：ORM注入攻击如何窃取加密货币？</title>
    <link>https://gugesay.com/blog/利用-orm-注入窃取在线射击游戏的加密货币</link>
    undefined
    <pubDate>Mon, 28 Jul 2025 01:34:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ORM 注入</category><category>加密货币</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-cookie-同意到命令执行</guid>
    <title>从 Cookie 同意到命令执行</title>
    <link>https://gugesay.com/blog/从-cookie-同意到命令执行</link>
    undefined
    <pubDate>Fri, 25 Jul 2025 02:46:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>sql注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/🚨-警报！cve-2025-49706：sharepoint-欺骗漏洞正遭黑客大规模利用</guid>
    <title>🚨 警报！CVE-2025–49706：SharePoint 欺骗漏洞正遭黑客大规模利用</title>
    <link>https://gugesay.com/blog/🚨-警报！cve-2025-49706：sharepoint-欺骗漏洞正遭黑客大规模利用</link>
    undefined
    <pubDate>Wed, 23 Jul 2025 01:36:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025–49706</category><category>sharepoint</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/化腐朽为神奇：将-self-xss-升级为真正可利用的-xss-漏洞</guid>
    <title>化腐朽为神奇：将 Self-XSS 升级为真正可利用的 XSS 漏洞</title>
    <link>https://gugesay.com/blog/化腐朽为神奇：将-self-xss-升级为真正可利用的-xss-漏洞</link>
    undefined
    <pubDate>Mon, 21 Jul 2025 07:06:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一则绕过-cloudflare-waf-实现-xss-的案例</guid>
    <title>一则绕过 Cloudflare WAF 实现 XSS 的案例</title>
    <link>https://gugesay.com/blog/一则绕过-cloudflare-waf-实现-xss-的案例</link>
    undefined
    <pubDate>Tue, 15 Jul 2025 04:04:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/错过游戏时光，意外在-tiktok-赚取-3000-美元的故事</guid>
    <title>错过游戏时光，意外在 TikTok 赚取 3000 美元的故事</title>
    <link>https://gugesay.com/blog/错过游戏时光，意外在-tiktok-赚取-3000-美元的故事</link>
    undefined
    <pubDate>Mon, 14 Jul 2025 02:28:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>tiktok</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2025年仍在奏效的waf绕过技术</guid>
    <title>2025年仍然奏效的WAF绕过技术</title>
    <link>https://gugesay.com/blog/2025年仍在奏效的waf绕过技术</link>
    undefined
    <pubDate>Wed, 09 Jul 2025 02:50:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/从开放重定向到ssrf</guid>
    <title>从开放重定向到SSRF</title>
    <link>https://gugesay.com/blog/从开放重定向到ssrf</link>
    undefined
    <pubDate>Mon, 07 Jul 2025 01:12:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ssrf</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过篡改-websocket-响应获得管理员访问权限</guid>
    <title>通过篡改 WebSocket 响应获得管理员访问权限</title>
    <link>https://gugesay.com/blog/通过篡改-websocket-响应获得管理员访问权限</link>
    undefined
    <pubDate>Wed, 02 Jul 2025 01:36:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>websocket</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-49144】notepad-漏洞可实现系统完整入侵</guid>
    <title>【CVE-2025-49144】Notepad++ 漏洞可实现系统完整入侵</title>
    <link>https://gugesay.com/blog/【cve-2025-49144】notepad-漏洞可实现系统完整入侵</link>
    undefined
    <pubDate>Tue, 01 Jul 2025 05:56:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-49144</category><category>getshell</category><category>nodepad++</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2025 Log4Shell 利用指南</guid>
    <title>2025 Log4Shell 利用指南</title>
    <link>https://gugesay.com/blog/2025 Log4Shell 利用指南</link>
    undefined
    <pubDate>Mon, 30 Jun 2025 02:49:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2021-44228</category><category>log4j</category><category>Log4Shell</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-js-文件到-html-注入</guid>
    <title>从 JS 文件到 HTML 注入</title>
    <link>https://gugesay.com/blog/从-js-文件到-html-注入</link>
    undefined
    <pubDate>Tue, 24 Jun 2025 07:09:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>html注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/arc-浏览器：uxss本地文件窃取任意文件写入，路径穿越</guid>
    <title>Arc 浏览器：UXSS+本地文件窃取+任意文件写入，路径穿越直通RCE！​</title>
    <link>https://gugesay.com/blog/arc-浏览器：uxss本地文件窃取任意文件写入，路径穿越</link>
    undefined
    <pubDate>Mon, 23 Jun 2025 07:06:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Arc 浏览器</category><category>rce</category><category>UXSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/iphone-的玻璃笼漏洞：利用两枚零日漏洞的国</guid>
    <title>​​iPhone “玻璃笼”：利用两枚零日漏洞的国家级攻击链揭秘​​</title>
    <link>https://gugesay.com/blog/iphone-的玻璃笼漏洞：利用两枚零日漏洞的国</link>
    undefined
    <pubDate>Thu, 19 Jun 2025 06:54:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-32711】首个ai0-点击漏洞揭秘-如何利用微软-365-copilot</guid>
    <title>【CVE-2025-32711】首个AI“0 点击”漏洞揭秘--如何利用微软 365 Copilot 泄露敏感信息</title>
    <link>https://gugesay.com/blog/【cve-2025-32711】首个ai0-点击漏洞揭秘-如何利用微软-365-copilot</link>
    undefined
    <pubDate>Thu, 12 Jun 2025 04:38:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Copilot</category><category>CVE-2025-32711</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【1337】通过爆破获得任意-google-用户手机号码</guid>
    <title>【$1,337】通过爆破获得任意 Google 用户手机号码</title>
    <link>https://gugesay.com/blog/【1337】通过爆破获得任意-google-用户手机号码</link>
    undefined
    <pubDate>Tue, 10 Jun 2025 06:33:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Google</category><category>暴力破解</category><category>爆破</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【500】android-锁屏绕过漏洞</guid>
    <title>【$500】存在 2 年之久的 Android 锁屏绕过漏洞</title>
    <link>https://gugesay.com/blog/【500】android-锁屏绕过漏洞</link>
    undefined
    <pubDate>Mon, 09 Jun 2025 02:48:23 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>bypass</category><category>Deeplink</category><category>Gemini</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【3800】shopify-缓存中毒导致dos漏洞披露</guid>
    <title>【$3,800】Shopify 缓存中毒导致DoS漏洞披露</title>
    <link>https://gugesay.com/blog/【3800】shopify-缓存中毒导致dos漏洞披露</link>
    undefined
    <pubDate>Fri, 06 Jun 2025 02:41:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Cache Poisoning</category><category>dos</category><category>Shopify</category><category>白帽故事</category><category>缓存中毒</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/赚取5w刀的5个顶级xss-poc</guid>
    <title>赚取50000美元的5个顶级 XSS PoC</title>
    <link>https://gugesay.com/blog/赚取5w刀的5个顶级xss-poc</link>
    undefined
    <pubDate>Thu, 05 Jun 2025 02:12:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【6000】firefox-高危漏洞披露</guid>
    <title>【$6,000】Firefox 高危漏洞披露</title>
    <link>https://gugesay.com/blog/【6000】firefox-高危漏洞披露</link>
    undefined
    <pubDate>Wed, 04 Jun 2025 01:05:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>firefox</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-20188】思科上传漏洞分析</guid>
    <title>【CVE-2025-20188】思科上传漏洞分析</title>
    <link>https://gugesay.com/blog/【cve-2025-20188】思科上传漏洞分析</link>
    undefined
    <pubDate>Tue, 03 Jun 2025 02:45:23 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Cisco</category><category>CVE-2025-20188</category><category>rce</category><category>思科</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一处价值-2500-的-dom-xss-漏洞</guid>
    <title>一处价值 $2500 的 DOM XSS 漏洞</title>
    <link>https://gugesay.com/blog/一处价值-2500-的-dom-xss-漏洞</link>
    undefined
    <pubDate>Thu, 29 May 2025 07:30:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/白帽小哥：如何用一部手机开走任意一辆大众汽车</guid>
    <title>如何用一部手机开走任意一辆大众汽车</title>
    <link>https://gugesay.com/blog/白帽小哥：如何用一部手机开走任意一辆大众汽车</link>
    undefined
    <pubDate>Wed, 28 May 2025 02:50:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>APP</category><category>大众汽车</category><category>白帽故事</category><category>车联网</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用未授权的密码重置实现完全帐户接管</guid>
    <title>利用未授权的密码重置实现完全帐户接管</title>
    <link>https://gugesay.com/blog/利用未授权的密码重置实现完全帐户接管</link>
    undefined
    <pubDate>Tue, 27 May 2025 06:21:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category><category>账户接管</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/致命xss！利用存储xss窃取-oauth-凭证并泄露数据？</guid>
    <title>利用存储XSS窃取 Oauth 凭证并泄露数据</title>
    <link>https://gugesay.com/blog/致命xss！利用存储xss窃取-oauth-凭证并泄露数据？</link>
    undefined
    <pubDate>Mon, 26 May 2025 02:43:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-4123】：grafana-ssrf-和帐户接管利用</guid>
    <title>【CVE-2025–4123】：Grafana SSRF 和帐户接管利用</title>
    <link>https://gugesay.com/blog/【cve-2025-4123】：grafana-ssrf-和帐户接管利用</link>
    undefined
    <pubDate>Fri, 23 May 2025 03:16:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025–4123</category><category>Grafana</category><category>ssrf</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pwn2own-2025-柏林冬奥会三日成果一览</guid>
    <title>Pwn2Own 2025 柏林冬奥会战果一览</title>
    <link>https://gugesay.com/blog/pwn2own-2025-柏林冬奥会三日成果一览</link>
    undefined
    <pubDate>Tue, 20 May 2025 04:23:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Pwn2Own</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/严苛waf环境下如何实现sql注入？</guid>
    <title>严苛WAF环境下如何实现SQL注入？</title>
    <link>https://gugesay.com/blog/严苛waf环境下如何实现sql注入？</link>
    undefined
    <pubDate>Mon, 19 May 2025 02:02:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>sql注入</category><category>WAF</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/漏洞挖掘之-fofa-dork</guid>
    <title>漏洞挖掘之 FOFA 语法技巧</title>
    <link>https://gugesay.com/blog/漏洞挖掘之-fofa-dork</link>
    undefined
    <pubDate>Thu, 15 May 2025 06:04:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>dork</category><category>fofa</category><category>osint</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-soap-到-shell</guid>
    <title>从 SOAP 到 SHELL</title>
    <link>https://gugesay.com/blog/从-soap-到-shell</link>
    undefined
    <pubDate>Mon, 12 May 2025 07:56:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>shell</category><category>soap</category><category>提权</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/4月星球内容汇总</guid>
    <title>4月星球内容汇总</title>
    <link>https://gugesay.com/blog/4月星球内容汇总</link>
    undefined
    <pubDate>Wed, 07 May 2025 01:15:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>月度汇总</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值2500 美元的漏洞：通过供应链攻击实现远程代码执行（RCE）</guid>
    <title>价值2500 美元的漏洞：通过供应链攻击实现远程代码执行（RCE）</title>
    <link>https://gugesay.com/blog/价值2500 美元的漏洞：通过供应链攻击实现远程代码执行（RCE）</link>
    undefined
    <pubDate>Wed, 07 May 2025 01:00:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>供应链攻击</category><category>投毒</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/右键点击就能窃取-ntlm-密码？</guid>
    <title>右键点击就能窃取 NTLM 密码？- 技术分析与 PoC</title>
    <link>https://gugesay.com/blog/右键点击就能窃取-ntlm-密码？</link>
    undefined
    <pubDate>Wed, 30 Apr 2025 07:05:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>NTLM</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽狩猎日记】一个支付逻辑漏洞，爽赚-9000-赏金</guid>
    <title>【白帽狩猎日记】一个支付逻辑漏洞，怒赚 $9000 赏金</title>
    <link>https://gugesay.com/blog/【白帽狩猎日记】一个支付逻辑漏洞，爽赚-9000-赏金</link>
    undefined
    <pubDate>Tue, 29 Apr 2025 02:44:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>PayU</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-options-请求方法走私：hackerone赏金案例解析</guid>
    <title>通过 OPTIONS 请求+方法走私：HackerOne赏金案例解析</title>
    <link>https://gugesay.com/blog/通过-options-请求方法走私：hackerone赏金案例解析</link>
    undefined
    <pubDate>Mon, 28 Apr 2025 01:12:34 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>OPTIONS</category><category>白帽故事</category><category>请求走私</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2025 数据泄露调查报告（DBIR）</guid>
    <title>2025 数据泄露调查报告（DBIR）</title>
    <link>https://gugesay.com/blog/2025 数据泄露调查报告（DBIR）</link>
    undefined
    <pubDate>Fri, 25 Apr 2025 02:08:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DBIR</category><category>信息差</category><category>报告</category><category>数据泄露</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2025-24054：在野利用的-ntlm-漏洞</guid>
    <title>无需交互即可攻破？CVE-2025-24054正被利用绕过Windows身份验证&quot;</title>
    <link>https://gugesay.com/blog/cve-2025-24054：在野利用的-ntlm-漏洞</link>
    undefined
    <pubDate>Wed, 23 Apr 2025 06:43:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-24054</category><category>NTML</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值10000的ps5内核漏洞！theflow再曝索尼系统级缺陷</guid>
    <title>价值$10,000的PS5内核漏洞！TheFloW再曝索尼系统级缺陷</title>
    <link>https://gugesay.com/blog/价值10000的ps5内核漏洞！theflow再曝索尼系统级缺陷</link>
    undefined
    <pubDate>Mon, 21 Apr 2025 06:33:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>hackerone</category><category>PlayStation</category><category>白帽故事</category><category>越狱</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一个被遗忘的-api-端点让我赚了-500</guid>
    <title>一个被遗忘的 API 端点让我赚了 $500</title>
    <link>https://gugesay.com/blog/一个被遗忘的-api-端点让我赚了-500</link>
    undefined
    <pubDate>Thu, 17 Apr 2025 09:32:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>API endpoint</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-21298】严重级-0-click-的漏洞成因与复现</guid>
    <title>【CVE-2025-21298】严重级 0-Click 的漏洞成因与复现</title>
    <link>https://gugesay.com/blog/【cve-2025-21298】严重级-0-click-的漏洞成因与复现</link>
    undefined
    <pubDate>Tue, 15 Apr 2025 06:29:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0-click</category><category>CVE-2025-21298</category><category>OLE</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将高危的sql注入提升为严重</guid>
    <title>如何将高危的SQL注入提升为严重</title>
    <link>https://gugesay.com/blog/如何将高危的sql注入提升为严重</link>
    undefined
    <pubDate>Mon, 14 Apr 2025 06:42:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>sql注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/winafl安装与运行【记录于2022年1月】</guid>
    <title>WinAFL安装与运行【记录于2022年1月】</title>
    <link>https://gugesay.com/blog/winafl安装与运行【记录于2022年1月】</link>
    undefined
    <pubDate>Fri, 11 Apr 2025 16:01:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-self-xss-到-rce</guid>
    <title>从 Self XSS 到 RCE</title>
    <link>https://gugesay.com/blog/从-self-xss-到-rce</link>
    undefined
    <pubDate>Fri, 11 Apr 2025 01:47:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/android-原生组件的模糊测试</guid>
    <title>Android 原生组件模糊测试</title>
    <link>https://gugesay.com/blog/android-原生组件的模糊测试</link>
    undefined
    <pubDate>Thu, 10 Apr 2025 09:36:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AFL++</category><category>Android</category><category>fuzz</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/让ai帮你快速完成逆向分析工作-ghidramcp初体验</guid>
    <title>让AI帮你快速完成逆向分析工作--GhidraMCP初体验</title>
    <link>https://gugesay.com/blog/让ai帮你快速完成逆向分析工作-ghidramcp初体验</link>
    undefined
    <pubDate>Tue, 08 Apr 2025 04:07:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>GhidraMCP</category><category>MCP</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-api-和硬件黑客技术攻克数百万台智能电子秤</guid>
    <title>利用 API 和硬件黑客技术攻克数百万台智能电子秤</title>
    <link>https://gugesay.com/blog/利用-api-和硬件黑客技术攻克数百万台智能电子秤</link>
    undefined
    <pubDate>Tue, 25 Mar 2025 04:12:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>智能电子秤</category><category>白帽故事</category><category>硬件黑客</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/理解文件包含漏洞</guid>
    <title>理解文件包含漏洞</title>
    <link>https://gugesay.com/blog/理解文件包含漏洞</link>
    undefined
    <pubDate>Wed, 19 Mar 2025 07:42:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>LFI</category><category>RFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何通过搜索js文件找到存储xss的故事</guid>
    <title>如何通过搜索JS文件找到存储XSS的故事</title>
    <link>https://gugesay.com/blog/如何通过搜索js文件找到存储xss的故事</link>
    undefined
    <pubDate>Sat, 15 Mar 2025 09:35:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/tomcat-cve-2025-24813-从计算器到getshell</guid>
    <title>Tomcat CVE-2025-24813 从计算器到GetShell</title>
    <link>https://gugesay.com/blog/tomcat-cve-2025-24813-从计算器到getshell</link>
    undefined
    <pubDate>Fri, 14 Mar 2025 10:18:02 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-24813</category><category>rce</category><category>Tomcat</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xxe漏洞利用完全指南</guid>
    <title>XXE漏洞利用完全指南</title>
    <link>https://gugesay.com/blog/xxe漏洞利用完全指南</link>
    undefined
    <pubDate>Tue, 11 Mar 2025 16:00:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>xxe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/acme-ssl-证书自动续证设置</guid>
    <title>acme SSL 证书自动续证设置</title>
    <link>https://gugesay.com/blog/acme-ssl-证书自动续证设置</link>
    undefined
    <pubDate>Tue, 11 Mar 2025 03:13:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>acme</category><category>SSL证书</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-31317】利用-android-zygote-的注入攻击</guid>
    <title>【CVE-2024–31317】利用 Android Zygote 的注入攻击</title>
    <link>https://gugesay.com/blog/【cve-2024-31317】利用-android-zygote-的注入攻击</link>
    undefined
    <pubDate>Mon, 10 Mar 2025 06:14:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>CVE-2024–31317</category><category>Zygote</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/esp32-芯片被爆暗藏命令，或影响数十亿台物联网</guid>
    <title>ESP32 芯片被发现隐藏“命令“，或影响数十亿台物联网设备</title>
    <link>https://gugesay.com/blog/esp32-芯片被爆暗藏命令，或影响数十亿台物联网</link>
    undefined
    <pubDate>Sun, 09 Mar 2025 14:04:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ESP32</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-50379-漏洞复现</guid>
    <title>CVE-2024-50379 漏洞复现</title>
    <link>https://gugesay.com/blog/cve-2024-50379-漏洞复现</link>
    undefined
    <pubDate>Wed, 05 Mar 2025 06:20:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apache</category><category>CVE-2024-50379</category><category>Tomcat</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cursor平替：clinedeepseek保姆级教程</guid>
    <title>Cursor平替：Cline+DeepSeek保姆级教程</title>
    <link>https://gugesay.com/blog/cursor平替：clinedeepseek保姆级教程</link>
    undefined
    <pubDate>Mon, 03 Mar 2025 08:26:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>Cline</category><category>Cursor</category><category>DeepSeek</category><category>VSCode</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/加速器暗藏木马！热门游戏中的新型病毒winos4-0揭秘</guid>
    <title>&quot;加速器&quot;暗藏木马！热门游戏中的新型病毒Winos4.0揭秘</title>
    <link>https://gugesay.com/blog/加速器暗藏木马！热门游戏中的新型病毒winos4-0揭秘</link>
    undefined
    <pubDate>Fri, 28 Feb 2025 07:10:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Winos4.0</category><category>后门</category><category>木马</category><category>病毒</category><category>白帽故事</category><category>银狐</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【15亿美元eth被盗，朝鲜黑客如何攻破bybit金库？】-教</guid>
    <title>【15亿美元ETH被盗，朝鲜黑客如何攻破Bybit金库？】--教科书级的社会工程学攻击与区块链安全启示录</title>
    <link>https://gugesay.com/blog/【15亿美元eth被盗，朝鲜黑客如何攻破bybit金库？】-教</link>
    undefined
    <pubDate>Thu, 27 Feb 2025 04:20:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/效率再提升！在obsidian中配置deepseek教程</guid>
    <title>效率再提升！在Obsidian中使用DeepSeek</title>
    <link>https://gugesay.com/blog/效率再提升！在obsidian中配置deepseek教程</link>
    undefined
    <pubDate>Mon, 24 Feb 2025 07:00:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DeepSeek</category><category>Obidian</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【200】一个速率限制不当的漏洞故事</guid>
    <title>【$200】一个速率限制不当的漏洞故事</title>
    <link>https://gugesay.com/blog/【200】一个速率限制不当的漏洞故事</link>
    undefined
    <pubDate>Fri, 21 Feb 2025 12:26:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category><category>速率限制</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-html-注入实现三星账户接管（ato）的故事</guid>
    <title>通过 HTML 注入实现三星账户接管（ATO）的故事</title>
    <link>https://gugesay.com/blog/通过-html-注入实现三星账户接管（ato）的故事</link>
    undefined
    <pubDate>Tue, 18 Feb 2025 06:44:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ATO</category><category>html注入</category><category>白帽故事</category><category>账户接管</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【墙裂推荐】一款无需部署就能让你与本地ai自由对</guid>
    <title>【墙裂推荐】一款无需部署就能让你与本地AI自由对话的超赞插件</title>
    <link>https://gugesay.com/blog/【墙裂推荐】一款无需部署就能让你与本地ai自由对</link>
    undefined
    <pubDate>Tue, 18 Feb 2025 01:48:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DeepSeek</category><category>Page Assist</category><category>插件</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-42327】zabbix-rce-poc-公布</guid>
    <title>【CVE-2024-42327】Zabbix RCE PoC 公布</title>
    <link>https://gugesay.com/blog/【cve-2024-42327】zabbix-rce-poc-公布</link>
    undefined
    <pubDate>Mon, 17 Feb 2025 01:05:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-42327</category><category>rce</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2500】通过无人认领的node包实施rce攻击</guid>
    <title>【$2500】通过无人认领的Node包实施RCE攻击</title>
    <link>https://gugesay.com/blog/【2500】通过无人认领的node包实施rce攻击</link>
    undefined
    <pubDate>Fri, 14 Feb 2025 06:57:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>NPM</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一个价值100的漏洞发现</guid>
    <title>一个价值$100的漏洞发现</title>
    <link>https://gugesay.com/blog/一个价值100的漏洞发现</link>
    undefined
    <pubDate>Thu, 13 Feb 2025 03:12:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XnlReveal</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-23359】研究人员发现绕过nvidia容器工具包修补后的新</guid>
    <title>【CVE-2025-23359】研究人员发现绕过NVIDIA容器工具包修补后的新漏洞利用</title>
    <link>https://gugesay.com/blog/【cve-2025-23359】研究人员发现绕过nvidia容器工具包修补后的新</link>
    undefined
    <pubDate>Thu, 13 Feb 2025 01:55:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025-23359</category><category>nvidia</category><category>信息差</category><category>容器逃逸</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/deepseek从入门到精通（pdf-104页）</guid>
    <title>DeepSeek:从入门到精通（PDF 104页）</title>
    <link>https://gugesay.com/blog/deepseek从入门到精通（pdf-104页）</link>
    undefined
    <pubDate>Mon, 10 Feb 2025 03:07:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>DeepSeek</category><category>信息差</category><category>清华大学</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/关于deepseek，少走弯路，拒绝忽悠～.md</guid>
    <title>【防忽悠】DeepSeek很简单，没你想象的那么复杂！</title>
    <link>https://gugesay.com/blog/关于deepseek，少走弯路，拒绝忽悠～.md</link>
    undefined
    <pubDate>Sat, 08 Feb 2025 03:01:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/unity游戏开发学习day1-2</guid>
    <title>Unity游戏开发学习Day1/2</title>
    <link>https://gugesay.com/blog/unity游戏开发学习day1-2</link>
    undefined
    <pubDate>Mon, 03 Feb 2025 14:04:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何利用-ai-发现-amazon-s3-存储桶接管漏洞</guid>
    <title>如何利用 AI 发现 Amazon S3 存储桶接管漏洞</title>
    <link>https://gugesay.com/blog/如何利用-ai-发现-amazon-s3-存储桶接管漏洞</link>
    undefined
    <pubDate>Mon, 20 Jan 2025 01:05:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>S3</category><category>接管漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/40000！如何从路径遍历升级rce！</guid>
    <title>$40,000！如何将路径遍历升级为RCE！</title>
    <link>https://gugesay.com/blog/40000！如何从路径遍历升级rce！</link>
    undefined
    <pubDate>Fri, 17 Jan 2025 06:34:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category><category>路径遍历</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-54887】tp-link路由器的逆向、发现与利用</guid>
    <title>【CVE-2024–54887】TP-Link路由器的逆向、发现与利用</title>
    <link>https://gugesay.com/blog/【cve-2024-54887】tp-link路由器的逆向、发现与利用</link>
    undefined
    <pubDate>Mon, 13 Jan 2025 06:55:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-54887</category><category>rce</category><category>TP-Link</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【爱折腾系列】如何在m芯片的mac上流畅游玩windows游戏</guid>
    <title>【爱折腾系列】如何在M芯片的Mac上流畅游玩Windows游戏</title>
    <link>https://gugesay.com/blog/【爱折腾系列】如何在m芯片的mac上流畅游玩windows游戏</link>
    undefined
    <pubDate>Mon, 06 Jan 2025 03:31:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CrossOver</category><category>Mac</category><category>游戏</category><category>跨平台</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2024年十大数据泄露事件概览</guid>
    <title>2024年十大数据泄露事件概览</title>
    <link>https://gugesay.com/blog/2024年十大数据泄露事件概览</link>
    undefined
    <pubDate>Mon, 06 Jan 2025 01:35:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>信息差</category><category>数据泄漏</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/意外发现谷歌slides的越权漏洞，获得赏金-3133-70的故事</guid>
    <title>意外发现谷歌Slides越权漏洞，获得赏金$3133.70的故事</title>
    <link>https://gugesay.com/blog/意外发现谷歌slides的越权漏洞，获得赏金-3133-70的故事</link>
    undefined
    <pubDate>Mon, 30 Dec 2024 07:07:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Google</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【优秀开源推荐】一款基于ai的pdf文档翻译工具</guid>
    <title>【优秀开源推荐】一款基于AI的PDF文档翻译神器！</title>
    <link>https://gugesay.com/blog/【优秀开源推荐】一款基于ai的pdf文档翻译工具</link>
    undefined
    <pubDate>Mon, 23 Dec 2024 06:30:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>PDFMathTranslate</category><category>PDF翻译</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/浏览器扩展逆向指北</guid>
    <title>浏览器扩展逆向指北</title>
    <link>https://gugesay.com/blog/浏览器扩展逆向指北</link>
    undefined
    <pubDate>Fri, 20 Dec 2024 06:03:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>浏览器扩展</category><category>浏览器插件</category><category>白帽故事</category><category>逆向</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-wayback-machine-到-aws-元数据：5-分钟内发现生产系统中的-ssrf</guid>
    <title>从 Wayback Machine 到 AWS 元数据：5 分钟内发现生产系统中的 SSRF</title>
    <link>https://gugesay.com/blog/从-wayback-machine-到-aws-元数据：5-分钟内发现生产系统中的-ssrf</link>
    undefined
    <pubDate>Wed, 18 Dec 2024 01:05:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/盲注的艺术：解锁内部秘密</guid>
    <title>盲注的艺术：解锁内部秘密</title>
    <link>https://gugesay.com/blog/盲注的艺术：解锁内部秘密</link>
    undefined
    <pubDate>Wed, 11 Dec 2024 01:51:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>sqli</category><category>白帽故事</category><category>盲注</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</guid>
    <title>发现关键漏洞获得 $4,000 赏金奖励</title>
    <link>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</link>
    undefined
    <pubDate>Wed, 11 Dec 2024 01:17:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>subdomain</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从js代码审计到graphql利用的管理账户接管</guid>
    <title>从JS代码审计到GraphQL利用的管理账户接管</title>
    <link>https://gugesay.com/blog/从js代码审计到graphql利用的管理账户接管</link>
    undefined
    <pubDate>Thu, 05 Dec 2024 04:11:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>GraphQL</category><category>JS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-pdf-打印功能利用ssrf访问内部数据</guid>
    <title>通过 PDF 打印功能利用SSRF访问内部数据</title>
    <link>https://gugesay.com/blog/通过-pdf-打印功能利用ssrf访问内部数据</link>
    undefined
    <pubDate>Tue, 26 Nov 2024 01:02:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>pdf</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将低危的-ssrf-盲注升级为严重漏洞</guid>
    <title>如何将低危的 SSRF 盲注升级为严重漏洞</title>
    <link>https://gugesay.com/blog/如何将低危的-ssrf-盲注升级为严重漏洞</link>
    undefined
    <pubDate>Sun, 17 Nov 2024 08:58:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>aws</category><category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</guid>
    <title>已修复漏洞？如何绕过并再次利用！</title>
    <link>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</link>
    undefined
    <pubDate>Thu, 14 Nov 2024 07:22:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/各大云-accesskey-特征整理</guid>
    <title>各大云 AccessKey 特征整理</title>
    <link>https://gugesay.com/blog/各大云-accesskey-特征整理</link>
    undefined
    <pubDate>Thu, 07 Nov 2024 01:37:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AccessKey</category><category>bugbounty</category><category>HaE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/信息收集技巧分享</guid>
    <title>信息收集技巧分享</title>
    <link>https://gugesay.com/blog/信息收集技巧分享</link>
    undefined
    <pubDate>Fri, 01 Nov 2024 03:07:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>信息收集</category><category>泄露</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何从iis欢迎页面中快速挖掘漏洞</guid>
    <title>如何从IIS欢迎页面中快速挖掘漏洞</title>
    <link>https://gugesay.com/blog/如何从iis欢迎页面中快速挖掘漏洞</link>
    undefined
    <pubDate>Thu, 31 Oct 2024 14:44:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IIS</category><category>shortscan</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用tor代理，设置每几分钟更换一次ip地址</guid>
    <title>使用TOR代理，设置定时更改IP地址</title>
    <link>https://gugesay.com/blog/使用tor代理，设置每几分钟更换一次ip地址</link>
    undefined
    <pubDate>Tue, 29 Oct 2024 13:01:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>tor</category><category>代理</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何利用js进行进一步漏洞挖掘【2024至尊版】</guid>
    <title>JS利用-2024至尊版</title>
    <link>https://gugesay.com/blog/如何利用js进行进一步漏洞挖掘【2024至尊版】</link>
    undefined
    <pubDate>Mon, 28 Oct 2024 12:30:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>JS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【20000】通过-devtools-实现-chrome-浏览器沙箱逃逸</guid>
    <title>【$20,000】通过 DevTools 实现 Chrome 浏览器沙箱逃逸</title>
    <link>https://gugesay.com/blog/【20000】通过-devtools-实现-chrome-浏览器沙箱逃逸</link>
    undefined
    <pubDate>Tue, 22 Oct 2024 04:01:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>Google</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事【2】</guid>
    <title>发现Facebook SSRF，收获31500美元赏金的故事【2】</title>
    <link>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事【2】</link>
    undefined
    <pubDate>Fri, 18 Oct 2024 01:21:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事</guid>
    <title>发现Facebook SSRF，收获31500美元赏金的故事【1】</title>
    <link>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事</link>
    undefined
    <pubDate>Thu, 17 Oct 2024 13:32:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【1060】gitlab-html-注入漏洞</guid>
    <title>【$1,060】GitLab HTML 注入漏洞</title>
    <link>https://gugesay.com/blog/【1060】gitlab-html-注入漏洞</link>
    undefined
    <pubDate>Tue, 15 Oct 2024 09:20:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Gitlab</category><category>hackerone</category><category>html注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【0day】通过-itunes-实现-windows-本地提权</guid>
    <title>【0day】通过 iTunes 实现 Windows 本地提权</title>
    <link>https://gugesay.com/blog/【0day】通过-itunes-实现-windows-本地提权</link>
    undefined
    <pubDate>Wed, 09 Oct 2024 03:11:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>CVE-2024–44193</category><category>iTunes</category><category>提权</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/gitlab-身份验证绕过cve-2024-45409</guid>
    <title>【CVE-2024-45409】GitLab 身份验证绕过分析</title>
    <link>https://gugesay.com/blog/gitlab-身份验证绕过cve-2024-45409</link>
    undefined
    <pubDate>Tue, 08 Oct 2024 06:54:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-45409</category><category>Gitlab</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何远程控制起亚汽车</guid>
    <title>如何远程控制起亚汽车</title>
    <link>https://gugesay.com/blog/如何远程控制起亚汽车</link>
    undefined
    <pubDate>Tue, 01 Oct 2024 04:00:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>kia</category><category>白帽故事</category><category>起亚汽车</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/wps-office攻击细节披露</guid>
    <title>WPS Office攻击细节披露</title>
    <link>https://gugesay.com/blog/wps-office攻击细节披露</link>
    undefined
    <pubDate>Fri, 27 Sep 2024 01:08:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>WPS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</guid>
    <title>【$2000】利用重置密码实现帐户接管</title>
    <link>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</link>
    undefined
    <pubDate>Thu, 26 Sep 2024 07:58:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category><category>重置密码</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-youtube-窃取文件</guid>
    <title>【$4133.70】利用 YouTube 窃取文件</title>
    <link>https://gugesay.com/blog/利用-youtube-窃取文件</link>
    undefined
    <pubDate>Tue, 24 Sep 2024 09:53:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何为任意-youtube-频道提供验证徽章</guid>
    <title>如何为任意 YouTube 频道提供验证徽章</title>
    <link>https://gugesay.com/blog/如何为任意-youtube-频道提供验证徽章</link>
    undefined
    <pubDate>Fri, 20 Sep 2024 06:30:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-url-解析器绕过-csp-混淆，实现-netlify-cdn-上的xss</guid>
    <title>绕过 CSP，实现 Netlify CDN 上XSS</title>
    <link>https://gugesay.com/blog/通过-url-解析器绕过-csp-混淆，实现-netlify-cdn-上的xss</link>
    undefined
    <pubDate>Thu, 19 Sep 2024 07:33:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csp bypass</category><category>Netlify</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/gmail-中的-html-表单注入漏洞</guid>
    <title>Gmail 中的 HTML 表单注入漏洞</title>
    <link>https://gugesay.com/blog/gmail-中的-html-表单注入漏洞</link>
    undefined
    <pubDate>Wed, 18 Sep 2024 14:18:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Gmail</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【赏金15000美元】通过监控调试模式实现-rce</guid>
    <title>【赏金15000美元】通过监控调试模式实现 RCE</title>
    <link>https://gugesay.com/blog/【赏金15000美元】通过监控调试模式实现-rce</link>
    undefined
    <pubDate>Sat, 14 Sep 2024 08:35:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>rce</category><category>白帽故事</category><category>调试模式</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-sql-注入绕过机场安检</guid>
    <title>利用 SQL 注入绕过机场安检</title>
    <link>https://gugesay.com/blog/通过-sql-注入绕过机场安检</link>
    undefined
    <pubDate>Tue, 03 Sep 2024 03:28:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>sql注入</category><category>机场安检</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/iis欢迎页的安全隐患：从源代码到lfi的攻防之道</guid>
    <title>IIS欢迎页的安全隐患：从源代码到LFI的攻防之道</title>
    <link>https://gugesay.com/blog/iis欢迎页的安全隐患：从源代码到lfi的攻防之道</link>
    undefined
    <pubDate>Mon, 02 Sep 2024 01:25:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IIS</category><category>LFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa【2】：从发现漏洞到荣登名人堂之旅</guid>
    <title>‘黑掉NASA’【2】：从发现漏洞到荣登名人堂之旅</title>
    <link>https://gugesay.com/blog/黑掉nasa【2】：从发现漏洞到荣登名人堂之旅</link>
    undefined
    <pubDate>Fri, 30 Aug 2024 08:04:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa【1】：从发现漏洞到荣登名人堂之旅</guid>
    <title>‘黑掉NASA’【1】：从发现漏洞到荣登名人堂之旅</title>
    <link>https://gugesay.com/blog/黑掉nasa【1】：从发现漏洞到荣登名人堂之旅</link>
    undefined
    <pubDate>Fri, 30 Aug 2024 07:45:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用开放式重定向、2fa-绕过等漏洞获取1600赏金奖励</guid>
    <title>利用开放式重定向、2FA 绕过等漏洞获取$1600赏金奖励</title>
    <link>https://gugesay.com/blog/利用开放式重定向、2fa-绕过等漏洞获取1600赏金奖励</link>
    undefined
    <pubDate>Tue, 27 Aug 2024 01:21:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>2FA bypass</category><category>bugbounty</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用内存分配的一种新型利用</guid>
    <title>巧妙利用内存分配的一种新型利用手段</title>
    <link>https://gugesay.com/blog/巧妙利用内存分配的一种新型利用</link>
    undefined
    <pubDate>Fri, 23 Aug 2024 05:46:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Chrome</category><category>CVE-2024-1283</category><category>内存分配</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2000】由于缓存配置错误导致授权绕过</guid>
    <title>【$2000】由于缓存配置错误导致授权绕过</title>
    <link>https://gugesay.com/blog/【2000】由于缓存配置错误导致授权绕过</link>
    undefined
    <pubDate>Thu, 22 Aug 2024 06:29:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/idor之如何打破订阅限制</guid>
    <title>IDOR之如何打破订阅限制</title>
    <link>https://gugesay.com/blog/idor之如何打破订阅限制</link>
    undefined
    <pubDate>Wed, 21 Aug 2024 01:48:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值-3500-美元的管理面板绕过漏洞</guid>
    <title>价值 3500 美元的管理面板绕过漏洞</title>
    <link>https://gugesay.com/blog/价值-3500-美元的管理面板绕过漏洞</link>
    undefined
    <pubDate>Tue, 20 Aug 2024 08:23:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</guid>
    <title>hackerone上TOP5的开放重定向漏洞</title>
    <link>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</link>
    undefined
    <pubDate>Fri, 16 Aug 2024 06:50:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>XSS</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/apache-cve-2023-25690-漏洞手动调试分析</guid>
    <title>Apache CVE-2023-25690 漏洞手动调试分析</title>
    <link>https://gugesay.com/blog/apache-cve-2023-25690-漏洞手动调试分析</link>
    undefined
    <pubDate>Thu, 15 Aug 2024 10:42:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apache</category><category>CVE-2023-25690</category><category>请求走私</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/sqlmap-payloads-定制</guid>
    <title>SQLMap Payloads 定制</title>
    <link>https://gugesay.com/blog/sqlmap-payloads-定制</link>
    undefined
    <pubDate>Tue, 13 Aug 2024 07:20:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>payloads</category><category>sqlmap</category><category>定制</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/打造绕过defender的windows-reverse_tcp-shell【部分】</guid>
    <title>打造绕过Defender的Windows reverse_tcp Shell【部分】</title>
    <link>https://gugesay.com/blog/打造绕过defender的windows-reverse_tcp-shell【部分】</link>
    undefined
    <pubDate>Mon, 12 Aug 2024 12:12:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>Windows Defender</category><category>反弹shell</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/blackhat-2024-usa-演讲ppt打包下载【62个】</guid>
    <title>Blackhat 2024 USA PPT打包下载【62个】</title>
    <link>https://gugesay.com/blog/blackhat-2024-usa-演讲ppt打包下载【62个】</link>
    undefined
    <pubDate>Fri, 09 Aug 2024 02:33:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>blackhat</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</guid>
    <title>巧妙利用业务逻辑漏洞，实现Google帐户接管</title>
    <link>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</link>
    undefined
    <pubDate>Thu, 08 Aug 2024 01:41:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>otp</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在-instagram-上查看任何人的私人电子邮件和生日</guid>
    <title>在 Instagram 上查看任何人的私人电子邮件和生日信息</title>
    <link>https://gugesay.com/blog/在-instagram-上查看任何人的私人电子邮件和生日</link>
    undefined
    <pubDate>Tue, 06 Aug 2024 01:24:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Instagram</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pixel7-8-pro-安卓-14-内核漏洞利用</guid>
    <title>Pixel7/8 Pro 安卓 14 内核漏洞利用</title>
    <link>https://gugesay.com/blog/pixel7-8-pro-安卓-14-内核漏洞利用</link>
    undefined
    <pubDate>Mon, 05 Aug 2024 05:49:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android内核漏洞</category><category>Pixel</category><category>root</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/沉浸式翻译调用本地ollama</guid>
    <title>沉浸式翻译调用本地Ollama</title>
    <link>https://gugesay.com/blog/沉浸式翻译调用本地ollama</link>
    undefined
    <pubDate>Mon, 05 Aug 2024 02:31:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Ollama</category><category>沉浸式翻译</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/手把手教你个人离线ai知识库搭建</guid>
    <title>手把手教你个人离线AI知识库搭建</title>
    <link>https://gugesay.com/blog/手把手教你个人离线ai知识库搭建</link>
    undefined
    <pubDate>Fri, 02 Aug 2024 02:45:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AnythingLLM</category><category>obsidian</category><category>Ollama</category><category>个人知识库</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/odt文件漏洞利用</guid>
    <title>ODT文件漏洞利用</title>
    <link>https://gugesay.com/blog/odt文件漏洞利用</link>
    undefined
    <pubDate>Thu, 01 Aug 2024 02:37:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/本地搭建gpt【ollama-gemma2】</guid>
    <title>本地搭建ChatGPT【Ollama + Gemma2】</title>
    <link>https://gugesay.com/blog/本地搭建gpt【ollama-gemma2】</link>
    undefined
    <pubDate>Tue, 30 Jul 2024 11:59:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>gemma2</category><category>Ollama</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用出色的侦察能力获得-2000-美元赏金</guid>
    <title>利用出色的侦察能力获得 2000 美元赏金</title>
    <link>https://gugesay.com/blog/利用出色的侦察能力获得-2000-美元赏金</link>
    undefined
    <pubDate>Tue, 30 Jul 2024 01:12:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/check-point【cve-2024-24919】漏洞分析</guid>
    <title>Check Point【CVE-2024-24919】漏洞分析</title>
    <link>https://gugesay.com/blog/check-point【cve-2024-24919】漏洞分析</link>
    undefined
    <pubDate>Fri, 26 Jul 2024 05:54:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>checkpoint</category><category>CVE-2024-24919</category><category>白帽故事</category><category>路径遍历</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/android-版-telegram-上的-evilvideo-漏洞</guid>
    <title>Android 版 Telegram 上的 EvilVideo 漏洞</title>
    <link>https://gugesay.com/blog/android-版-telegram-上的-evilvideo-漏洞</link>
    undefined
    <pubDate>Wed, 24 Jul 2024 06:52:34 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>EvilVideo</category><category>telegram</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外车企安全渗透案例【3】-发现法拉利、宝马、</guid>
    <title>国外车企安全渗透案例【3】– 发现法拉利、宝马、劳斯莱斯、保时捷等车企关键漏洞</title>
    <link>https://gugesay.com/blog/国外车企安全渗透案例【3】-发现法拉利、宝马、</link>
    undefined
    <pubDate>Wed, 24 Jul 2024 01:29:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>白帽故事</category><category>车企安全</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外车企安全渗透案例【2】-发现法拉利、宝马、</guid>
    <title>国外车企安全渗透案例【2】– 发现法拉利、宝马、劳斯莱斯、保时捷等车企关键漏洞</title>
    <link>https://gugesay.com/blog/国外车企安全渗透案例【2】-发现法拉利、宝马、</link>
    undefined
    <pubDate>Tue, 23 Jul 2024 04:17:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>保时捷</category><category>劳斯莱斯</category><category>宝马</category><category>法拉利</category><category>白帽故事</category><category>车企安全</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外车企安全渗透案例【1】-发现法拉利、宝马、</guid>
    <title>国外车企安全渗透案例【1】-- 发现法拉利、宝马、劳斯莱斯、保时捷等车企关键漏洞</title>
    <link>https://gugesay.com/blog/国外车企安全渗透案例【1】-发现法拉利、宝马、</link>
    undefined
    <pubDate>Mon, 22 Jul 2024 06:22:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>保时捷</category><category>劳斯莱斯</category><category>宝马</category><category>法拉利</category><category>白帽故事</category><category>车企安全</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-4879】servicenow-中的-jelly-模板注入漏洞</guid>
    <title>【CVE-2024-4879】ServiceNow 中的 Jelly 模板注入漏洞</title>
    <link>https://gugesay.com/blog/【cve-2024-4879】servicenow-中的-jelly-模板注入漏洞</link>
    undefined
    <pubDate>Mon, 22 Jul 2024 01:58:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-4879</category><category>Jelly</category><category>ServiceNow</category><category>SSTI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-22274】vmware-vcenter-server远程代码执行漏洞</guid>
    <title>【CVE-2024–22274】VMware vCenter Server远程代码执行漏洞</title>
    <link>https://gugesay.com/blog/【cve-2024-22274】vmware-vcenter-server远程代码执行漏洞</link>
    undefined
    <pubDate>Wed, 17 Jul 2024 06:45:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024–22274</category><category>rce</category><category>vCenter</category><category>VMWare</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-30078】windows-wifi-驱动程序中的-log4j-级漏洞</guid>
    <title>【CVE-2024–30078】Windows WiFi 驱动程序中的 Log4j 级漏洞</title>
    <link>https://gugesay.com/blog/【cve-2024-30078】windows-wifi-驱动程序中的-log4j-级漏洞</link>
    undefined
    <pubDate>Mon, 15 Jul 2024 01:45:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024–30078</category><category>log4j</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一则ssrf漏洞的故事</guid>
    <title>一则SSRF漏洞的故事</title>
    <link>https://gugesay.com/blog/一则ssrf漏洞的故事</link>
    undefined
    <pubDate>Wed, 10 Jul 2024 07:55:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>aws</category><category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-30104：office-365-rce【poc】</guid>
    <title>CVE-2024-30104：Office 365 RCE【PoC】</title>
    <link>https://gugesay.com/blog/cve-2024-30104：office-365-rce【poc】</link>
    undefined
    <pubDate>Tue, 09 Jul 2024 08:16:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-30104</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【h1最新披露】ups公司管理员身份验证绕过导致帐户</guid>
    <title>【H1最新披露】UPS公司管理员身份验证绕过导致帐户接管案例</title>
    <link>https://gugesay.com/blog/【h1最新披露】ups公司管理员身份验证绕过导致帐户</link>
    undefined
    <pubDate>Mon, 08 Jul 2024 08:54:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>ups</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新-openssh-漏洞：虽有潜在利用可能，但发生大规模攻</guid>
    <title>最新 OpenSSH 漏洞：虽有潜在利用可能，但发生大规模攻击的可能性不大</title>
    <link>https://gugesay.com/blog/最新-openssh-漏洞：虽有潜在利用可能，但发生大规模攻</link>
    undefined
    <pubDate>Fri, 05 Jul 2024 02:58:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-6387</category><category>openssh</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过操控会话绕过otp，实现未授权访问</guid>
    <title>通过操控会话绕过OTP，实现未授权访问</title>
    <link>https://gugesay.com/blog/通过操控会话绕过otp，实现未授权访问</link>
    undefined
    <pubDate>Wed, 03 Jul 2024 06:29:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>OTP bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/警惕利用git的钓鱼及社工攻击【cve-2024-32002】</guid>
    <title>警惕利用Git的钓鱼及社工攻击【CVE-2024-32002】</title>
    <link>https://gugesay.com/blog/警惕利用git的钓鱼及社工攻击【cve-2024-32002】</link>
    undefined
    <pubDate>Wed, 03 Jul 2024 05:59:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-32002</category><category>github</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/5g连接易受绕过与dos-攻击</guid>
    <title>攻破5G堡垒：窥探5G的脆弱深渊</title>
    <link>https://gugesay.com/blog/5g连接易受绕过与dos-攻击</link>
    undefined
    <pubDate>Fri, 28 Jun 2024 01:24:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>5g</category><category>aka bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/solarwinds-cve-2024-28995-漏洞分析</guid>
    <title>SolarWinds CVE-2024-28995 漏洞分析</title>
    <link>https://gugesay.com/blog/solarwinds-cve-2024-28995-漏洞分析</link>
    undefined
    <pubDate>Thu, 27 Jun 2024 07:07:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-28995</category><category>SolarWinds</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/apache-kafka-ui-远程代码执行漏洞：cve-2023-52251、cve-2024-32030</guid>
    <title>Apache Kafka UI 远程代码执行漏洞：CVE-2023-52251、CVE-2024-32030</title>
    <link>https://gugesay.com/blog/apache-kafka-ui-远程代码执行漏洞：cve-2023-52251、cve-2024-32030</link>
    undefined
    <pubDate>Wed, 26 Jun 2024 04:08:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2023-52251</category><category>CVE-2024-32030</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何大规模搜寻泄露的敏感文件</guid>
    <title>如何大规模搜寻泄露的敏感文件</title>
    <link>https://gugesay.com/blog/如何大规模搜寻泄露的敏感文件</link>
    undefined
    <pubDate>Tue, 25 Jun 2024 01:58:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>泄露</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/打造自己专属的漏洞赏金搜索引擎</guid>
    <title>打造自己专属的漏洞赏金搜索引擎</title>
    <link>https://gugesay.com/blog/打造自己专属的漏洞赏金搜索引擎</link>
    undefined
    <pubDate>Mon, 17 Jun 2024 02:10:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>搜索引擎</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss-waf绕过的一些基本思考</guid>
    <title>XSS WAF绕过的一些基本思考</title>
    <link>https://gugesay.com/blog/xss-waf绕过的一些基本思考</link>
    undefined
    <pubDate>Fri, 14 Jun 2024 11:55:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/某android-app中一处有趣的bug</guid>
    <title>某Android APP中一处国内不认国外认的有趣Bug</title>
    <link>https://gugesay.com/blog/某android-app中一处有趣的bug</link>
    undefined
    <pubDate>Wed, 12 Jun 2024 06:17:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>APP</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-4358，将反序列化变为未经身份验证的rce</guid>
    <title>CVE-2024-4358，将反序列化变为未经身份验证的RCE</title>
    <link>https://gugesay.com/blog/cve-2024-4358，将反序列化变为未经身份验证的rce</link>
    undefined
    <pubDate>Tue, 11 Jun 2024 04:16:34 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>cve-2024-4358</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在家用摄像头中利用-n-day</guid>
    <title>在家用摄像头中利用 N-Day</title>
    <link>https://gugesay.com/blog/在家用摄像头中利用-n-day</link>
    undefined
    <pubDate>Fri, 07 Jun 2024 02:26:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pixel4-刷android12kernelsu记录</guid>
    <title>Pixel4 刷Android12+KernelSU记录</title>
    <link>https://gugesay.com/blog/pixel4-刷android12kernelsu记录</link>
    undefined
    <pubDate>Thu, 06 Jun 2024 05:51:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Android</category><category>kernelSU</category><category>magisk</category><category>pixel4</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa：ssrf、子域接管以及xss</guid>
    <title>‘黑掉’NASA：SSRF、子域接管以及XSS</title>
    <link>https://gugesay.com/blog/黑掉nasa：ssrf、子域接管以及xss</link>
    undefined
    <pubDate>Sun, 02 Jun 2024 14:40:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</guid>
    <title>巧妙利用本地存储漏洞，轻松登录他人直播 App 账户</title>
    <link>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</link>
    undefined
    <pubDate>Wed, 29 May 2024 03:25:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Local Storage</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/空穴来宝：如何从一个空文件中找到登录凭据</guid>
    <title>空穴来&#39;宝&#39;：如何从一个空文件中找到登录凭据</title>
    <link>https://gugesay.com/blog/空穴来宝：如何从一个空文件中找到登录凭据</link>
    undefined
    <pubDate>Wed, 29 May 2024 01:33:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Credentials</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai黑客：使用-chatgpt-在浏览器中挖掘-xxe</guid>
    <title>AI黑客：使用 ChatGPT 在浏览器中挖掘 XXE</title>
    <link>https://gugesay.com/blog/ai黑客：使用-chatgpt-在浏览器中挖掘-xxe</link>
    undefined
    <pubDate>Tue, 28 May 2024 01:27:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>Safari</category><category>xxe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai黑客：chatgpt中的高级api攻击</guid>
    <title>AI黑客：ChatGPT中的高级API攻击</title>
    <link>https://gugesay.com/blog/ai黑客：chatgpt中的高级api攻击</link>
    undefined
    <pubDate>Sun, 26 May 2024 04:24:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>chatgpt</category><category>http请求走私</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-34359【严重级】可能威胁软件供应链</guid>
    <title>【严重级】CVE-2024-34359 超过 6000 个 AI 模型容易受到攻击</title>
    <link>https://gugesay.com/blog/cve-2024-34359【严重级】可能威胁软件供应链</link>
    undefined
    <pubDate>Wed, 22 May 2024 08:32:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2024-34359</category><category>SSTI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在侦察阶段如何快速找到-rce</guid>
    <title>在侦察阶段如何快速找到 RCE</title>
    <link>https://gugesay.com/blog/在侦察阶段如何快速找到-rce</link>
    undefined
    <pubDate>Wed, 22 May 2024 01:27:38 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apache</category><category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/black-hat-2024-asia-ppt打包</guid>
    <title>Black Hat 2024 Asia PPT打包</title>
    <link>https://gugesay.com/blog/black-hat-2024-asia-ppt打包</link>
    undefined
    <pubDate>Mon, 20 May 2024 01:48:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>blackhat</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/d-link-路由器正遭受0day攻击，可被远程接管【附poc】</guid>
    <title>D-Link 路由器正遭受0day攻击，可被远程接管【附PoC】</title>
    <link>https://gugesay.com/blog/d-link-路由器正遭受0day攻击，可被远程接管【附poc】</link>
    undefined
    <pubDate>Thu, 16 May 2024 02:23:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>D-Link</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-31747】microsoft-teams-电话锁定绕过利用</guid>
    <title>【CVE-2024–31747】Microsoft Teams 电话锁定绕过利用</title>
    <link>https://gugesay.com/blog/【cve-2024-31747】microsoft-teams-电话锁定绕过利用</link>
    undefined
    <pubDate>Wed, 15 May 2024 01:59:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>Yealink</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外4大众测平台优缺点对比</guid>
    <title>国外4大众测平台优缺点对比</title>
    <link>https://gugesay.com/blog/国外4大众测平台优缺点对比</link>
    undefined
    <pubDate>Tue, 14 May 2024 01:45:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bugcrowd</category><category>hackerone</category><category>Intigriti</category><category>Yeswehack</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/微软amsi写入raid绕过利用【附poc】</guid>
    <title>微软AMSI绕过利用【附PoC】</title>
    <link>https://gugesay.com/blog/微软amsi写入raid绕过利用【附poc】</link>
    undefined
    <pubDate>Mon, 13 May 2024 03:21:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>amsi</category><category>bypss</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉-apple-系列-从-sql-注入到远程代码执行</guid>
    <title>黑掉 Apple 系列 - 从 SQL 注入到远程代码执行</title>
    <link>https://gugesay.com/blog/黑掉-apple-系列-从-sql-注入到远程代码执行</link>
    undefined
    <pubDate>Thu, 09 May 2024 03:13:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>rce</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/18 岁少年如何发现虚拟机逃逸漏洞</guid>
    <title>18 岁少年如何发现虚拟机逃逸漏洞</title>
    <link>https://gugesay.com/blog/18 岁少年如何发现虚拟机逃逸漏洞</link>
    undefined
    <pubDate>Wed, 08 May 2024 06:40:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2019-2703</category><category>OOB</category><category>VirtualBox</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/10秒以内窃取你的telegram帐户</guid>
    <title>10秒以内窃取你的Telegram帐户</title>
    <link>https://gugesay.com/blog/10秒以内窃取你的telegram帐户</link>
    undefined
    <pubDate>Tue, 07 May 2024 01:38:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>telegram</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2k-star的漏洞检查表</guid>
    <title>2K+ Star的漏洞检查表</title>
    <link>https://gugesay.com/blog/2k-star的漏洞检查表</link>
    undefined
    <pubDate>Mon, 06 May 2024 04:27:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>checklist</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/端口扫描，你真的会用了吗？</guid>
    <title>端口扫描，你真的会用了吗？</title>
    <link>https://gugesay.com/blog/端口扫描，你真的会用了吗？</link>
    undefined
    <pubDate>Sun, 05 May 2024 03:54:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>nmap</category><category>白帽故事</category><category>端口扫描</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</guid>
    <title>最新H1越权漏洞披露，获得15000美元奖励</title>
    <link>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</link>
    undefined
    <pubDate>Mon, 29 Apr 2024 11:25:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/入侵高露洁智能牙刷</guid>
    <title>入侵高露洁智能牙刷</title>
    <link>https://gugesay.com/blog/入侵高露洁智能牙刷</link>
    undefined
    <pubDate>Fri, 26 Apr 2024 01:54:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IoT</category><category>智能牙刷</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cisa：两年前的windows-print-spooler漏洞或成apt新宠</guid>
    <title>CISA：两年前的Windows Print Spooler漏洞或成APT新宠</title>
    <link>https://gugesay.com/blog/cisa：两年前的windows-print-spooler漏洞或成apt新宠</link>
    undefined
    <pubDate>Thu, 25 Apr 2024 06:27:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2022-38028</category><category>信息差</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-0333，针对chrome扩展的zip嵌入攻击</guid>
    <title>CVE-2024-0333，针对Chrome扩展的ZIP嵌入攻击</title>
    <link>https://gugesay.com/blog/cve-2024-0333，针对chrome扩展的zip嵌入攻击</link>
    undefined
    <pubDate>Tue, 23 Apr 2024 02:46:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Chrome</category><category>CVE-2024-0333</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用Auth0错误配置，获得$1600赏金奖励</guid>
    <title>利用Auth0错误配置，获得$1600赏金奖励</title>
    <link>https://gugesay.com/blog/利用Auth0错误配置，获得$1600赏金奖励</link>
    undefined
    <pubDate>Mon, 22 Apr 2024 08:26:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>Auth0</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</guid>
    <title>凭借一手Apple 存储XSS赚取5000美元的故事</title>
    <link>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 16:00:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</guid>
    <title>如何将 DOM XSS升级为一键帐户接管（下集）</title>
    <link>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 02:21:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</guid>
    <title>如何将DOM XSS升级为一键帐户接管（上集）</title>
    <link>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</link>
    undefined
    <pubDate>Wed, 17 Apr 2024 16:00:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【漏洞预警】putty爆严重漏洞，允许攻击者进行私钥</guid>
    <title>【漏洞预警】PuTTY爆严重漏洞，允许攻击者进行私钥恢复</title>
    <link>https://gugesay.com/blog/【漏洞预警】putty爆严重漏洞，允许攻击者进行私钥</link>
    undefined
    <pubDate>Wed, 17 Apr 2024 07:23:34 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>漏洞预警</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/踏上全栈征程：15个晚上，从0手撸一个网站</guid>
    <title>踏上全栈征程：15个晚上，从0手撸一个网站</title>
    <link>https://gugesay.com/blog/踏上全栈征程：15个晚上，从0手撸一个网站</link>
    undefined
    <pubDate>Wed, 17 Apr 2024 02:44:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ctftool</category><category>next.js</category><category>nextjs</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/网络安全信息差-2024年4月15日</guid>
    <title>网络安全信息差-2024年4月15日</title>
    <link>https://gugesay.com/blog/网络安全信息差-2024年4月15日</link>
    undefined
    <pubDate>Tue, 16 Apr 2024 02:18:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>信息差</category><category>信息差</category><category>网络安全</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/意外发现dos攻击并获得25000美元奖励的故事</guid>
    <title>意外发现DoS攻击斩获$25,000赏金的故事</title>
    <link>https://gugesay.com/blog/意外发现dos攻击并获得25000美元奖励的故事</link>
    undefined
    <pubDate>Tue, 16 Apr 2024 01:44:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>dos</category><category>rce</category><category>区块链</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/五种用来挖掘API端点的方法</guid>
    <title>五种用来挖掘API端点的方法</title>
    <link>https://gugesay.com/blog/五种用来挖掘API端点的方法</link>
    undefined
    <pubDate>Sun, 14 Apr 2024 02:44:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API endpoint</category><category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/网络安全信息差-2024年4月13日</guid>
    <title>网络安全信息差-2024年4月13日</title>
    <link>https://gugesay.com/blog/网络安全信息差-2024年4月13日</link>
    undefined
    <pubDate>Sat, 13 Apr 2024 16:13:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>信息差</category><category>信息差</category><category>网络安全</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2024-24576-rust-命令注入漏洞，已有poc</guid>
    <title>CVE-2024-24576 Rust 命令注入漏洞【PoC已公布】</title>
    <link>https://gugesay.com/blog/cve-2024-24576-rust-命令注入漏洞，已有poc</link>
    undefined
    <pubDate>Fri, 12 Apr 2024 00:25:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rust</category><category>漏洞预警</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/重置密码绕过的n种利用姿势</guid>
    <title>重置密码绕过的N种利用姿势</title>
    <link>https://gugesay.com/blog/重置密码绕过的n种利用姿势</link>
    undefined
    <pubDate>Tue, 09 Apr 2024 01:38:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-3273】预计超过-92000-台-d-link-nas-设备存有后门帐户</guid>
    <title>【CVE-2024-3273】预计超过 92000 台 D-Link NAS 设备存在后门帐户</title>
    <link>https://gugesay.com/blog/【cve-2024-3273】预计超过-92000-台-d-link-nas-设备存有后门帐户</link>
    undefined
    <pubDate>Sun, 07 Apr 2024 06:16:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>D-Link</category><category>NAS</category><category>漏洞预警</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用ai大模型打造模糊测试工具</guid>
    <title>使用AI大模型打造模糊测试工具</title>
    <link>https://gugesay.com/blog/使用ai大模型打造模糊测试工具</link>
    undefined
    <pubDate>Sun, 07 Apr 2024 01:37:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>fuzz</category><category>LLMs</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过重置密码token泄露收获e2500赏金</guid>
    <title>通过重置密码token泄露收获€2500赏金</title>
    <link>https://gugesay.com/blog/通过重置密码token泄露收获e2500赏金</link>
    undefined
    <pubDate>Wed, 03 Apr 2024 01:11:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ATO</category><category>bugbounty</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/白帽应如何避免攻击性扫描行为</guid>
    <title>白帽应如何避免攻击性扫描行为</title>
    <link>https://gugesay.com/blog/白帽应如何避免攻击性扫描行为</link>
    undefined
    <pubDate>Tue, 02 Apr 2024 01:26:01 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将selfxss升级为存储xss</guid>
    <title>将SelfXSS升级为存储XSS</title>
    <link>https://gugesay.com/blog/将selfxss升级为存储xss</link>
    undefined
    <pubDate>Mon, 01 Apr 2024 01:38:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【尝鲜】免费的开源图片翻译神器！不可以涩涩哦</guid>
    <title>【尝鲜】免费的开源图片翻译神器！不可以涩涩哦～</title>
    <link>https://gugesay.com/blog/【尝鲜】免费的开源图片翻译神器！不可以涩涩哦</link>
    undefined
    <pubDate>Wed, 27 Mar 2024 16:00:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ocr</category><category>工具</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</guid>
    <title>在一个Web网站中获得$7000赏金奖励</title>
    <link>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</link>
    undefined
    <pubDate>Wed, 27 Mar 2024 01:32:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>rce</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/生成式ai生态系统中安全问题</guid>
    <title>生成式AI生态系统中安全问题</title>
    <link>https://gugesay.com/blog/生成式ai生态系统中安全问题</link>
    undefined
    <pubDate>Mon, 25 Mar 2024 03:36:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>chatgpt</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在outlook上寻找远程代码执行漏洞【部分】</guid>
    <title>在Outlook上寻找远程代码执行漏洞【部分】</title>
    <link>https://gugesay.com/blog/在outlook上寻找远程代码执行漏洞【部分】</link>
    undefined
    <pubDate>Fri, 22 Mar 2024 16:00:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>outlook</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过子域模糊测试收获35000赏金奖励</guid>
    <title>通过子域模糊测试收获$35,000赏金奖励</title>
    <link>https://gugesay.com/blog/通过子域模糊测试收获35000赏金奖励</link>
    undefined
    <pubDate>Fri, 22 Mar 2024 00:25:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/继续citrix传奇：cve-2023-5914和cve-2023-6184</guid>
    <title>继续Citrix传奇：CVE-2023-5914和CVE-2023-6184</title>
    <link>https://gugesay.com/blog/继续citrix传奇：cve-2023-5914和cve-2023-6184</link>
    undefined
    <pubDate>Wed, 20 Mar 2024 01:41:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Citrix</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一周三步曲：从开放重定向到远程代码执行！</guid>
    <title>一周三步曲：从开放重定向到远程代码执行！</title>
    <link>https://gugesay.com/blog/一周三步曲：从开放重定向到远程代码执行！</link>
    undefined
    <pubDate>Tue, 19 Mar 2024 14:28:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/无需高额订阅费，一站式享用所有ai模型！</guid>
    <title>无需高额订阅费，一站式享用所有流行AI大模型！</title>
    <link>https://gugesay.com/blog/无需高额订阅费，一站式享用所有ai模型！</link>
    undefined
    <pubDate>Tue, 19 Mar 2024 01:43:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/200小时挑战，最终收获20300赏金的故事</guid>
    <title>200小时挑战，最终收获$20,300赏金的故事</title>
    <link>https://gugesay.com/blog/200小时挑战，最终收获20300赏金的故事</link>
    undefined
    <pubDate>Fri, 15 Mar 2024 01:51:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/效率倍增！让你从运动员变裁判员的强大vs</guid>
    <title>效率倍增！让你从“运动员”变“裁判员”的强大VS插件～</title>
    <link>https://gugesay.com/blog/效率倍增！让你从运动员变裁判员的强大vs</link>
    undefined
    <pubDate>Wed, 13 Mar 2024 01:28:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>插件</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/免费！一键复刻目标网站的开源神器</guid>
    <title>免费！一键复刻目标网站的开源神器</title>
    <link>https://gugesay.com/blog/免费！一键复刻目标网站的开源神器</link>
    undefined
    <pubDate>Fri, 08 Mar 2024 02:06:01 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/服务器端原型污染检测插件</guid>
    <title>【工具推荐】服务器端原型污染检测插件</title>
    <link>https://gugesay.com/blog/服务器端原型污染检测插件</link>
    undefined
    <pubDate>Wed, 06 Mar 2024 04:48:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Prototype Pollution</category><category>原型污染</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉谷歌ai，获取-50000-赏金奖励</guid>
    <title>黑掉谷歌AI，获得 $50,000 赏金奖励</title>
    <link>https://gugesay.com/blog/黑掉谷歌ai，获取-50000-赏金奖励</link>
    undefined
    <pubDate>Tue, 05 Mar 2024 02:36:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    
  </item>

  <item>
    <guid>https://gugesay.com/blog/2023 年十佳 Web 黑客技术</guid>
    <title>2023 年十佳 Web 黑客技术</title>
    <link>https://gugesay.com/blog/2023 年十佳 Web 黑客技术</link>
    undefined
    <pubDate>Wed, 28 Feb 2024 08:38:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</guid>
    <title>使用 Google 脚本资源绕过 PortSwigger上的 CSP</title>
    <link>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</link>
    undefined
    <pubDate>Tue, 27 Feb 2024 07:46:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>csp</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</guid>
    <title>在ChatGPT中挖掘XSS漏洞实现任意账户接管</title>
    <link>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</link>
    undefined
    <pubDate>Fri, 23 Feb 2024 03:19:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>chatgpt</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用nfc中继攻击特斯拉-model-y</guid>
    <title>利用NFC中继攻击特斯拉 Model Y</title>
    <link>https://gugesay.com/blog/利用nfc中继攻击特斯拉-model-y</link>
    undefined
    <pubDate>Thu, 22 Feb 2024 02:13:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>NFC</category><category>tesla</category><category>特斯拉</category><category>白帽故事</category><category>白皮书</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/hello-lucee-让我们再次黑掉apple～</guid>
    <title>Hello Lucee! 让我们再次黑掉Apple～</title>
    <link>https://gugesay.com/blog/hello-lucee-让我们再次黑掉apple～</link>
    undefined
    <pubDate>Wed, 21 Feb 2024 07:24:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>Lucee</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/开箱即用-payloads</guid>
    <title>开箱即用的Payloads</title>
    <link>https://gugesay.com/blog/开箱即用-payloads</link>
    undefined
    <pubDate>Tue, 20 Feb 2024 01:22:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Payload</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/任意chatgpt-帐户接管-利用通配符进行网络缓存欺骗</guid>
    <title>任意ChatGPT 帐户接管 - 利用通配符进行网络缓存欺骗</title>
    <link>https://gugesay.com/blog/任意chatgpt-帐户接管-利用通配符进行网络缓存欺骗</link>
    undefined
    <pubDate>Sun, 18 Feb 2024 01:28:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>chatgpt</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2024打工人常备的6款ai神器</guid>
    <title>2024打工人常备的6款AI神器</title>
    <link>https://gugesay.com/blog/2024打工人常备的6款ai神器</link>
    undefined
    <pubDate>Tue, 06 Feb 2024 17:00:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/树莓派4b-openwrt避坑</guid>
    <title>树莓派4B Openwrt避坑（非旁路）</title>
    <link>https://gugesay.com/blog/树莓派4b-openwrt避坑</link>
    undefined
    <pubDate>Tue, 06 Feb 2024 02:32:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>openwrt</category><category>树莓派</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/自动ssrf漏洞扫描与利用工具</guid>
    <title>自动SSRF漏洞扫描与利用工具</title>
    <link>https://gugesay.com/blog/自动ssrf漏洞扫描与利用工具</link>
    undefined
    <pubDate>Thu, 01 Feb 2024 09:01:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ssrf</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/独家揭秘：巧妙利用akamai，透过f5窃取用户内部数据！</guid>
    <title>&quot;独家揭秘：请求走私高级利用，利用组合链获取用户内部敏感数据！&quot;</title>
    <link>https://gugesay.com/blog/独家揭秘：巧妙利用akamai，透过f5窃取用户内部数据！</link>
    undefined
    <pubDate>Wed, 31 Jan 2024 08:22:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category><category>请求走私</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/burpsuite-bambda-新功能-bug-bounty-pro-2-7-0</guid>
    <title>BurpSuite Bambda 新功能 &amp; BurpBounty Pro 2.7.0</title>
    <link>https://gugesay.com/blog/burpsuite-bambda-新功能-bug-bounty-pro-2-7-0</link>
    undefined
    <pubDate>Wed, 31 Jan 2024 02:23:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</guid>
    <title>Chrome 最新XSS攻击向量：CVE-2023-5480</title>
    <link>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</link>
    undefined
    <pubDate>Tue, 30 Jan 2024 01:51:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>CVE</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/node-js安全指南：防范xss、csrf和sql注入攻击</guid>
    <title>Node.js安全指南：防范XSS、CSRF和SQL注入攻击</title>
    <link>https://gugesay.com/blog/node-js安全指南：防范xss、csrf和sql注入攻击</link>
    undefined
    <pubDate>Mon, 29 Jan 2024 01:23:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用工具从cloudflare中发现源ip</guid>
    <title>利用工具从Cloudflare中发现源IP</title>
    <link>https://gugesay.com/blog/利用工具从cloudflare中发现源ip</link>
    undefined
    <pubDate>Thu, 25 Jan 2024 08:29:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/逆向分析混淆-js-代码处理签名哈希并实现工具化</guid>
    <title>手把手逆向分析混淆 JS 代码&amp;amp;处理签名哈希并实现工具化</title>
    <link>https://gugesay.com/blog/逆向分析混淆-js-代码处理签名哈希并实现工具化</link>
    undefined
    <pubDate>Tue, 23 Jan 2024 01:37:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category><category>逆向分析</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/绕过双因素认证至账户接管</guid>
    <title>绕过双因素认证至账户接管</title>
    <link>https://gugesay.com/blog/绕过双因素认证至账户接管</link>
    undefined
    <pubDate>Mon, 22 Jan 2024 08:56:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/新域名即将启用</guid>
    <title>新域名正式启用</title>
    <link>https://gugesay.com/blog/新域名即将启用</link>
    undefined
    <pubDate>Mon, 22 Jan 2024 05:48:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>未分类</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/必备收藏！国外整理收集的网络安全资源</guid>
    <title>必备收藏！国外整理收集的网络安全资源</title>
    <link>https://gugesay.com/blog/必备收藏！国外整理收集的网络安全资源</link>
    undefined
    <pubDate>Fri, 19 Jan 2024 06:56:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/创新拳法：漏洞链的艺术</guid>
    <title>组合拳法：漏洞利用链的艺术</title>
    <link>https://gugesay.com/blog/创新拳法：漏洞链的艺术</link>
    undefined
    <pubDate>Wed, 10 Jan 2024 04:23:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在epic-games上赚到7000赏金</guid>
    <title>如何在Epic Games上赚到$7,000赏金</title>
    <link>https://gugesay.com/blog/如何在epic-games上赚到7000赏金</link>
    undefined
    <pubDate>Thu, 04 Jan 2024 12:07:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/三角测量行动：最后的（硬件）谜团</guid>
    <title>三角测量行动：最后的（硬件）谜团</title>
    <link>https://gugesay.com/blog/三角测量行动：最后的（硬件）谜团</link>
    undefined
    <pubDate>Wed, 03 Jan 2024 05:32:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>Apple</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</guid>
    <title>从Adobe的VIP赏金计划中获得近50,000美元奖励的故事</title>
    <link>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</link>
    undefined
    <pubDate>Tue, 02 Jan 2024 09:52:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</guid>
    <title>【$500】如何将DOM XSS升级为存储型XSS</title>
    <link>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</link>
    undefined
    <pubDate>Mon, 25 Dec 2023 08:20:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/突破语言屏障：8款工具助你轻松将外文文档翻译成</guid>
    <title>突破语言屏障：8款工具助你轻松将外文文档翻译成中文</title>
    <link>https://gugesay.com/blog/突破语言屏障：8款工具助你轻松将外文文档翻译成</link>
    undefined
    <pubDate>Sun, 24 Dec 2023 08:13:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从self-xss-到账户接管</guid>
    <title>从Self XSS 到账户接管</title>
    <link>https://gugesay.com/blog/从self-xss-到账户接管</link>
    undefined
    <pubDate>Fri, 22 Dec 2023 06:54:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</guid>
    <title>最新Twitter XSS + CSRF 漏洞完整披露</title>
    <link>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</link>
    undefined
    <pubDate>Wed, 20 Dec 2023 02:03:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/我的2023年macos效率工具推荐</guid>
    <title>我的2023年macOS效率工具推荐</title>
    <link>https://gugesay.com/blog/我的2023年macos效率工具推荐</link>
    undefined
    <pubDate>Mon, 18 Dec 2023 02:33:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>macos</category><category>效率工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用关键-0day-xxe-漏洞实现全面-ssrf-攻击</guid>
    <title>利用关键 0day XXE 漏洞实现 SSRF 攻击</title>
    <link>https://gugesay.com/blog/利用关键-0day-xxe-漏洞实现全面-ssrf-攻击</link>
    undefined
    <pubDate>Wed, 13 Dec 2023 01:27:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/挖掘开发环境隐藏的秘密：一次-oauth-凭证从泄露到利</guid>
    <title>挖掘开发环境隐藏的秘密：一次 OAuth 凭证从泄露到利用的旅程</title>
    <link>https://gugesay.com/blog/挖掘开发环境隐藏的秘密：一次-oauth-凭证从泄露到利</link>
    undefined
    <pubDate>Tue, 12 Dec 2023 10:12:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>OAuth</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/卫星黑客与ctf相关学习资源推荐</guid>
    <title>卫星黑客与CTF相关学习资源推荐</title>
    <link>https://gugesay.com/blog/卫星黑客与ctf相关学习资源推荐</link>
    undefined
    <pubDate>Mon, 11 Dec 2023 09:27:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/gpts-prompot泄露合集</guid>
    <title>GPTs Prompts泄露合集</title>
    <link>https://gugesay.com/blog/gpts-prompot泄露合集</link>
    undefined
    <pubDate>Sun, 10 Dec 2023 02:38:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>github</category><category>prompt</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/攻击google-bard-从实时注入到数据外泄</guid>
    <title>攻击Google Bard-从实时注入到数据外泄</title>
    <link>https://gugesay.com/blog/攻击google-bard-从实时注入到数据外泄</link>
    undefined
    <pubDate>Mon, 04 Dec 2023 01:39:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Bard</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/具有邀请功能的账户劫持思路</guid>
    <title>具有邀请功能的账户劫持思路</title>
    <link>https://gugesay.com/blog/具有邀请功能的账户劫持思路</link>
    undefined
    <pubDate>Thu, 30 Nov 2023 02:14:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过反向代理劫持oauth代码的账户接管之旅</guid>
    <title>通过反向代理劫持OAuth代码的帐户接管之旅</title>
    <link>https://gugesay.com/blog/通过反向代理劫持oauth代码的账户接管之旅</link>
    undefined
    <pubDate>Wed, 29 Nov 2023 12:57:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>OAuth</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ubuntu18-04-pwndbg-libgcc-s1i386-问题</guid>
    <title>Ubuntu18.04 pwndbg libgcc-s1:i386 问题</title>
    <link>https://gugesay.com/blog/ubuntu18-04-pwndbg-libgcc-s1i386-问题</link>
    undefined
    <pubDate>Tue, 28 Nov 2023 06:07:01 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>libgcc-s1:i386</category><category>pwndbg</category><category>ubuntu</category><category>UTM</category><category>x86</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/突破google的bug跟踪系统，获得15600美元赏金之旅</guid>
    <title>突破Google的Bug跟踪系统，获得15,600美元赏金之旅</title>
    <link>https://gugesay.com/blog/突破google的bug跟踪系统，获得15600美元赏金之旅</link>
    undefined
    <pubDate>Fri, 24 Nov 2023 15:41:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从LFI到RCE</guid>
    <title>从LFI到RCE</title>
    <link>https://gugesay.com/blog/从LFI到RCE</link>
    undefined
    <pubDate>Mon, 20 Nov 2023 02:38:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/m3-调教手记</guid>
    <title>M3 ‘调教’手记</title>
    <link>https://gugesay.com/blog/m3-调教手记</link>
    undefined
    <pubDate>Fri, 17 Nov 2023 08:53:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>macos</category><category>PWN</category><category>x86</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一次通过fuzz-api发现漏洞的旅程</guid>
    <title>一次通过Fuzz API发现漏洞的旅程</title>
    <link>https://gugesay.com/blog/一次通过fuzz-api发现漏洞的旅程</link>
    undefined
    <pubDate>Tue, 07 Nov 2023 04:22:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一起全账户接管漏洞案例</guid>
    <title>一起全帐户接管漏洞案例</title>
    <link>https://gugesay.com/blog/一起全账户接管漏洞案例</link>
    undefined
    <pubDate>Fri, 03 Nov 2023 02:07:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/查询背后：通过sql注入挖掘ntlm哈希</guid>
    <title>查询背后：通过SQL注入挖掘NTLM哈希</title>
    <link>https://gugesay.com/blog/查询背后：通过sql注入挖掘ntlm哈希</link>
    undefined
    <pubDate>Thu, 02 Nov 2023 07:48:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>NTLM</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/citrix滴血：cve-2023-4966-泄漏citrix会话token</guid>
    <title>Citrix滴血：CVE-2023-4966 泄漏Citrix会话Token</title>
    <link>https://gugesay.com/blog/citrix滴血：cve-2023-4966-泄漏citrix会话token</link>
    undefined
    <pubDate>Wed, 01 Nov 2023 03:18:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Citrix</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</guid>
    <title>XSS！一次对抗Akamai WAF的经历</title>
    <link>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</link>
    undefined
    <pubDate>Mon, 30 Oct 2023 03:27:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>akamai</category><category>bugbounty</category><category>bypass</category><category>XSS</category><category>未分类</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/远程文件包含（rfi）小技巧</guid>
    <title>远程文件包含（RFI）小技巧</title>
    <link>https://gugesay.com/blog/远程文件包含（rfi）小技巧</link>
    undefined
    <pubDate>Sun, 22 Oct 2023 13:10:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>RFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/pwn思维导图【转】</guid>
    <title>PWN思维导图【转】</title>
    <link>https://gugesay.com/blog/pwn思维导图【转】</link>
    undefined
    <pubDate>Thu, 19 Oct 2023 09:25:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>PWN</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/快速发现未授权页面及sql注入漏洞，获得1500奖励</guid>
    <title>快速发现未授权页面及SQL注入漏洞，获得$1500奖励</title>
    <link>https://gugesay.com/blog/快速发现未授权页面及sql注入漏洞，获得1500奖励</link>
    undefined
    <pubDate>Thu, 19 Oct 2023 08:26:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2022-4908：使用导航-api-绕过-chrome-sop</guid>
    <title>CVE-2022-4908：使用导航 API 绕过 Chrome SOP</title>
    <link>https://gugesay.com/blog/cve-2022-4908：使用导航-api-绕过-chrome-sop</link>
    undefined
    <pubDate>Tue, 17 Oct 2023 08:30:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>SOP</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/graphql黑客：如何使用简单的探测查询找到1000漏洞</guid>
    <title>&quot;GraphQL黑客：如何使用简单的探测获得$1000赏金&quot;</title>
    <link>https://gugesay.com/blog/graphql黑客：如何使用简单的探测查询找到1000漏洞</link>
    undefined
    <pubDate>Mon, 16 Oct 2023 07:01:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>GraphQL</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2023 Microsoft Office XSS</guid>
    <title>2023 Microsoft Office XSS</title>
    <link>https://gugesay.com/blog/2023 Microsoft Office XSS</link>
    undefined
    <pubDate>Sat, 07 Oct 2023 01:38:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>MSRC</category><category>Office</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/lfi-从高危升级为严重</guid>
    <title>LFI -从高危升级为严重</title>
    <link>https://gugesay.com/blog/lfi-从高危升级为严重</link>
    undefined
    <pubDate>Fri, 22 Sep 2023 09:29:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/vulnerability-wiki-ctf-练习平台搭建-2</guid>
    <title>Vulnerability Wiki &amp; CTF 练习平台搭建-2</title>
    <link>https://gugesay.com/blog/vulnerability-wiki-ctf-练习平台搭建-2</link>
    undefined
    <pubDate>Wed, 20 Sep 2023 06:16:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>平台</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/vulnerability-wiki-ctf-练习平台搭建-1</guid>
    <title>Vulnerability Wiki &amp; CTF 练习平台搭建-1</title>
    <link>https://gugesay.com/blog/vulnerability-wiki-ctf-练习平台搭建-1</link>
    undefined
    <pubDate>Mon, 18 Sep 2023 07:23:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>漏洞库</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/二进制漏洞挖掘与利用&胖(Pwn)选手养成路线</guid>
    <title>二进制漏洞挖掘与利用&amp;胖(Pwn)选手养成路线</title>
    <link>https://gugesay.com/blog/二进制漏洞挖掘与利用&胖(Pwn)选手养成路线</link>
    undefined
    <pubDate>Thu, 14 Sep 2023 08:04:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>PWN</category><category>二进制</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/web-缓存欺骗：在意想不到的地方发现漏洞</guid>
    <title>Web 缓存欺骗：在意想不到的地方发现漏洞</title>
    <link>https://gugesay.com/blog/web-缓存欺骗：在意想不到的地方发现漏洞</link>
    undefined
    <pubDate>Wed, 13 Sep 2023 01:42:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Web缓存</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/彻底弄懂-http-request-smuggling（http-请求走私）攻击以及实战演示</guid>
    <title>HTTP Request Smuggling（HTTP 请求走私）攻击及案例说明</title>
    <link>https://gugesay.com/blog/彻底弄懂-http-request-smuggling（http-请求走私）攻击以及实战演示</link>
    undefined
    <pubDate>Tue, 12 Sep 2023 09:13:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>HTTP Request Smuggler</category><category>白帽故事</category><category>请求走私</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/为快乐而玩，为自己而玩！</guid>
    <title>为快乐而玩，为自己而玩！</title>
    <link>https://gugesay.com/blog/为快乐而玩，为自己而玩！</link>
    undefined
    <pubDate>Fri, 08 Sep 2023 01:40:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>内卷</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</guid>
    <title>一次白嫖LinkedIn Premium会员资格的经历</title>
    <link>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</link>
    undefined
    <pubDate>Thu, 07 Sep 2023 08:15:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Linkedln</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/越权拿下超级管理员权限</guid>
    <title>一个简单的越权漏洞成功拿下Admin权限</title>
    <link>https://gugesay.com/blog/越权拿下超级管理员权限</link>
    undefined
    <pubDate>Tue, 05 Sep 2023 03:17:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/prompt-injection-primer-for-engineers-提示注入入门指南</guid>
    <title>Prompt Injection Primer for Engineers- 提示注入入门指南</title>
    <link>https://gugesay.com/blog/prompt-injection-primer-for-engineers-提示注入入门指南</link>
    undefined
    <pubDate>Mon, 04 Sep 2023 09:44:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>prompt</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/vmware-aria-网络操作静态-ssh-密钥-rce【cve-2023-34039】</guid>
    <title>研究人员公布VMware Aria【CVE-2023-34039】漏洞利用PoC</title>
    <link>https://gugesay.com/blog/vmware-aria-网络操作静态-ssh-密钥-rce【cve-2023-34039】</link>
    undefined
    <pubDate>Sat, 02 Sep 2023 07:53:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE</category><category>poc</category><category>VMWare</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/api-黑客</guid>
    <title>API 攻击与防御</title>
    <link>https://gugesay.com/blog/api-黑客</link>
    undefined
    <pubDate>Wed, 30 Aug 2023 07:13:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</guid>
    <title>使用工具快速发现 SSRF、LFI、XSS</title>
    <link>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</link>
    undefined
    <pubDate>Tue, 29 Aug 2023 03:15:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>ssrf</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/自建dnslog</guid>
    <title>自建DNSlog</title>
    <link>https://gugesay.com/blog/自建dnslog</link>
    undefined
    <pubDate>Mon, 28 Aug 2023 06:42:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>dnslog</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【25300】绕过-facebook-双因素身份验证</guid>
    <title>【$25,300】绕过 Facebook 双因素身份验证</title>
    <link>https://gugesay.com/blog/【25300】绕过-facebook-双因素身份验证</link>
    undefined
    <pubDate>Wed, 23 Aug 2023 08:50:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>2FA</category><category>bugbounty</category><category>facebook</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/效率工具chatdoc体验</guid>
    <title>效率工具ChatDOC体验</title>
    <link>https://gugesay.com/blog/效率工具chatdoc体验</link>
    undefined
    <pubDate>Tue, 22 Aug 2023 01:51:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>ChatDOC</category><category>工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/每个白帽都不应错过的酷炫侦察技巧！总有一</guid>
    <title>每个白帽都不应错过的酷炫‘侦察’技巧！总有一个你不知道～</title>
    <link>https://gugesay.com/blog/每个白帽都不应错过的酷炫侦察技巧！总有一</link>
    undefined
    <pubDate>Sun, 20 Aug 2023 02:46:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>侦察</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/havocharriet，绕过edr方案</guid>
    <title>Havoc+Harriet，绕过EDR方案</title>
    <link>https://gugesay.com/blog/havocharriet，绕过edr方案</link>
    undefined
    <pubDate>Sat, 19 Aug 2023 03:07:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Harriet</category><category>havoc</category><category>shellcode</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【3400】一次点击，攻击者轻松窃取用户余额！</guid>
    <title>【$3400】一次点击，攻击者轻松窃取用户余额！</title>
    <link>https://gugesay.com/blog/【3400】一次点击，攻击者轻松窃取用户余额！</link>
    undefined
    <pubDate>Thu, 17 Aug 2023 08:27:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>paypal</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/玩转rdp文件：隐蔽shellcode解析与防御对抗</guid>
    <title>玩转RDP文件：隐蔽ShellCode的解析与防御对抗</title>
    <link>https://gugesay.com/blog/玩转rdp文件：隐蔽shellcode解析与防御对抗</link>
    undefined
    <pubDate>Mon, 14 Aug 2023 07:21:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>RDP</category><category>shellcode</category><category>攻防对抗</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/企业微信溯源-证实可用</guid>
    <title>企业微信溯源-证实可用</title>
    <link>https://gugesay.com/blog/企业微信溯源-证实可用</link>
    undefined
    <pubDate>Mon, 14 Aug 2023 01:42:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>安全</category><category>微信</category><category>溯源</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/云原生安全学习笔记</guid>
    <title>云原生安全学习笔记</title>
    <link>https://gugesay.com/blog/云原生安全学习笔记</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 09:21:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>云原生安全</category><category>笔记</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/这俩工具真的香！</guid>
    <title>这俩工具真的香！</title>
    <link>https://gugesay.com/blog/这俩工具真的香！</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 08:09:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从100页的gpt-4技术报告中我收获了什么？</guid>
    <title>从100页的GPT-4技术报告中我收获了什么？</title>
    <link>https://gugesay.com/blog/从100页的gpt-4技术报告中我收获了什么？</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:55:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AI</category><category>gpt4</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/释放shodan潜能：你需要的知道的基本技巧</guid>
    <title>释放 Shodan 潜能：你需要的知道的基本技巧</title>
    <link>https://gugesay.com/blog/释放shodan潜能：你需要的知道的基本技巧</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:48:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>shodan</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何更加专业地使用-burp-suite！</guid>
    <title>如何更加专业地使用 Burp Suite！</title>
    <link>https://gugesay.com/blog/如何更加专业地使用-burp-suite！</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:41:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>burpsuite</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-github-最大化你的漏洞数量-2</guid>
    <title>利用 GitHub 最大化你的漏洞数量</title>
    <link>https://gugesay.com/blog/利用-github-最大化你的漏洞数量-2</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:38:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/更专业地打破403访问控制</guid>
    <title>$2,100!更专业地打破403访问控制</title>
    <link>https://gugesay.com/blog/更专业地打破403访问控制</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:32:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>403</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/csgo-从0到0day！</guid>
    <title>CS:GO 从0到0day！</title>
    <link>https://gugesay.com/blog/csgo-从0到0day！</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 06:53:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CS:GO</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/没有swaggerui的swag怎么破</guid>
    <title>没有SwaggerUI的Swag怎么破？</title>
    <link>https://gugesay.com/blog/没有swaggerui的swag怎么破</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 06:15:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>SwaggerUI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</guid>
    <title>将赏金从$50变为$1000的帐户接管漏洞</title>
    <link>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 05:59:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用-aquatone-配合狩猎</guid>
    <title>使用 Aquatone 配合&#39;狩猎&#39;</title>
    <link>https://gugesay.com/blog/使用-aquatone-配合狩猎</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 05:45:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Aquatone</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</guid>
    <title>【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</title>
    <link>https://gugesay.com/blog/【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 03:03:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AAD</category><category>bugbounty</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/逆向-citrix-gateway-发现-xss-漏洞</guid>
    <title>逆向 Citrix Gateway 发现 XSS 漏洞</title>
    <link>https://gugesay.com/blog/逆向-citrix-gateway-发现-xss-漏洞</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 02:49:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Citrix</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在两个不同的网站中发现sql注入</guid>
    <title>如何在两个不同的网站中发现SQL注入</title>
    <link>https://gugesay.com/blog/如何在两个不同的网站中发现sql注入</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 01:37:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用非云-ssrf-获得更多乐趣和赏金</guid>
    <title>利用非云 SSRF 获得更多乐趣和赏金</title>
    <link>https://gugesay.com/blog/利用非云-ssrf-获得更多乐趣和赏金</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 00:48:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/citrix-adc-和-netscaler-gateway-中的-cve-2023-3519-分析</guid>
    <title>Citrix ADC 和 NetScaler Gateway 中的 CVE-2023-3519 分析</title>
    <link>https://gugesay.com/blog/citrix-adc-和-netscaler-gateway-中的-cve-2023-3519-分析</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 09:24:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Citrix</category><category>漏洞分析</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过链式攻击劫持会话获得2500奖励</guid>
    <title>通过链式攻击劫持会话获得$2500奖励</title>
    <link>https://gugesay.com/blog/通过链式攻击劫持会话获得2500奖励</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 09:17:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/blackhat-2023-asia-所见所得</guid>
    <title>Blackhat 2023 Asia 所见所得</title>
    <link>https://gugesay.com/blog/blackhat-2023-asia-所见所得</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 08:38:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>blackhat</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/macos优化与渗透环境部署</guid>
    <title>MacOS优化与渗透环境部署</title>
    <link>https://gugesay.com/blog/macos优化与渗透环境部署</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 08:06:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>macos</category><category>工具</category><category>渗透</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/计算机:黑客题材影视推荐</guid>
    <title>计算机/黑客题材影视推荐</title>
    <link>https://gugesay.com/blog/计算机:黑客题材影视推荐</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 07:45:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>影片推荐</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/计算机黑客题材影视推荐</guid>
    <title>计算机/黑客题材影视推荐</title>
    <link>https://gugesay.com/blog/计算机黑客题材影视推荐</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 07:45:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>影片推荐</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/推荐一部纪录片-《代码奔腾》</guid>
    <title>推荐一部纪录片--《代码奔腾》</title>
    <link>https://gugesay.com/blog/推荐一部纪录片-《代码奔腾》</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 06:50:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>影片推荐</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/谈谈知识积累</guid>
    <title>谈谈知识积累</title>
    <link>https://gugesay.com/blog/谈谈知识积累</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 05:58:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>学习</category><category>心得</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/回答一位读者的问题</guid>
    <title>回答一位读者的问题，关于职业规划</title>
    <link>https://gugesay.com/blog/回答一位读者的问题</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 05:00:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>职业规划</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一份值得收藏的书单</guid>
    <title>一份值得收藏的书单</title>
    <link>https://gugesay.com/blog/一份值得收藏的书单</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 04:56:38 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>书单</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/新晋世界首富-jeff-bezos</guid>
    <title>新晋世界首富-Jeff Bezos</title>
    <link>https://gugesay.com/blog/新晋世界首富-jeff-bezos</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 04:47:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Jeff Bezos</category><category>人物</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用操作顺序漏洞实现 Oracle Opera RCE</guid>
    <title>利用操作顺序漏洞实现 Oracle Opera RCE</title>
    <link>https://gugesay.com/blog/利用操作顺序漏洞实现 Oracle Opera RCE</link>
    undefined
    <pubDate>Fri, 11 Aug 2023 11:33:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Oracle Opera</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/仅用google-dork快速发现2枚微软xss</guid>
    <title>仅用Google Dork快速发现2枚微软XSS</title>
    <link>https://gugesay.com/blog/仅用google-dork快速发现2枚微软xss</link>
    undefined
    <pubDate>Fri, 11 Aug 2023 11:29:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>google dork</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/眼见就为实吗？</guid>
    <title>眼见就为实吗？</title>
    <link>https://gugesay.com/blog/眼见就为实吗？</link>
    undefined
    <pubDate>Fri, 11 Aug 2023 04:46:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>vulnerable</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最适合渗透人员的15款浏览器插件推荐</guid>
    <title>适合渗透人员的15款浏览器插件推荐</title>
    <link>https://gugesay.com/blog/最适合渗透人员的15款浏览器插件推荐</link>
    undefined
    <pubDate>Thu, 10 Aug 2023 07:13:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/读书焦虑之我见</guid>
    <title>读书焦虑之我见</title>
    <link>https://gugesay.com/blog/读书焦虑之我见</link>
    undefined
    <pubDate>Thu, 10 Aug 2023 05:00:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>读书</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/有感国内ctf发展，十年再回望的一些感想</guid>
    <title>有感国内CTF发展，十年再回望的一些感想</title>
    <link>https://gugesay.com/blog/有感国内ctf发展，十年再回望的一些感想</link>
    undefined
    <pubDate>Thu, 10 Aug 2023 04:39:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CTF</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/google-bard首尝鲜</guid>
    <title>Google Bard首尝鲜</title>
    <link>https://gugesay.com/blog/google-bard首尝鲜</link>
    undefined
    <pubDate>Wed, 09 Aug 2023 11:47:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Bard</category><category>Google</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用本机函数指针绕过最新-chrome-v8-沙箱（issue1378239-exp）</guid>
    <title>使用本机函数指针绕过最新 Chrome v8 沙箱（issue1378239 EXP）</title>
    <link>https://gugesay.com/blog/使用本机函数指针绕过最新-chrome-v8-沙箱（issue1378239-exp）</link>
    undefined
    <pubDate>Wed, 09 Aug 2023 11:37:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Chrome</category><category>v8</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/演绎黑客之术：2000引爆响应操控之力</guid>
    <title>&quot;演绎黑客之术：$2000引爆响应操控之力&quot;</title>
    <link>https://gugesay.com/blog/演绎黑客之术：2000引爆响应操控之力</link>
    undefined
    <pubDate>Wed, 09 Aug 2023 11:18:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2023-36934：moveit-transfer-sql注入分析</guid>
    <title>CVE-2023-36934：MOVEit Transfer SQL注入分析</title>
    <link>https://gugesay.com/blog/cve-2023-36934：moveit-transfer-sql注入分析</link>
    undefined
    <pubDate>Tue, 18 Jul 2023 02:20:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/30000美元赏金事件</guid>
    <title>30000美元赏金事件</title>
    <link>https://gugesay.com/blog/30000美元赏金事件</link>
    undefined
    <pubDate>Tue, 06 Jun 2023 07:47:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过更改logo进行命令注入的故事</guid>
    <title>通过更改LOGO进行命令注入的故事</title>
    <link>https://gugesay.com/blog/通过更改logo进行命令注入的故事</link>
    undefined
    <pubDate>Mon, 06 Mar 2023 02:17:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>命令注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新h1漏洞披露通过作用域标签绕过-csp-的存储-xss，获</guid>
    <title>通过作用域标签绕过 CSP 的存储 XSS，获得$13,950赏金奖励</title>
    <link>https://gugesay.com/blog/最新h1漏洞披露通过作用域标签绕过-csp-的存储-xss，获</link>
    undefined
    <pubDate>Tue, 21 Feb 2023 08:25:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</guid>
    <title>另一处XSS！荣登微软MSRC 2022 Q3排行榜</title>
    <link>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</link>
    undefined
    <pubDate>Wed, 15 Feb 2023 16:00:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</guid>
    <title>利用Param Miner挖掘基于缓存中毒的XSS漏洞</title>
    <link>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</link>
    undefined
    <pubDate>Fri, 10 Feb 2023 02:46:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2022-38627：通过sqlite注入破坏整个企业大楼之旅</guid>
    <title>CVE-2022-38627：通过SQLite注入破坏整个企业大楼之旅</title>
    <link>https://gugesay.com/blog/cve-2022-38627：通过sqlite注入破坏整个企业大楼之旅</link>
    undefined
    <pubDate>Tue, 07 Feb 2023 01:50:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/挖掘p1漏洞最受欢迎的8款猎杀工具</guid>
    <title>挖掘P1漏洞最受欢迎的8款&#39;猎杀&#39;工具</title>
    <link>https://gugesay.com/blog/挖掘p1漏洞最受欢迎的8款猎杀工具</link>
    undefined
    <pubDate>Wed, 01 Feb 2023 07:55:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【$20000】通过发送消息黑掉任意公司-cve-2021-34506</guid>
    <title>【$ 20,000】通过发送消息黑掉任意公司-CVE-2021–34506</title>
    <link>https://gugesay.com/blog/【$20000】通过发送消息黑掉任意公司-cve-2021-34506</link>
    undefined
    <pubDate>Sat, 28 Jan 2023 02:54:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2022-41076】exchange-owa-ssrf-tabshell漏洞利用链分析【含poc】</guid>
    <title>【CVE-2022-41076】Exchange OWA SSRF + TabShell漏洞利用链分析【含PoC】</title>
    <link>https://gugesay.com/blog/【cve-2022-41076】exchange-owa-ssrf-tabshell漏洞利用链分析【含poc】</link>
    undefined
    <pubDate>Wed, 11 Jan 2023 16:00:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE</category><category>poc</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</guid>
    <title>致命组合--利用IDOR实现CSRF攻击</title>
    <link>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</link>
    undefined
    <pubDate>Wed, 11 Jan 2023 02:03:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【50000】发现0day漏洞，渗透apple</guid>
    <title>【$50,000】发现0day漏洞，渗透Apple</title>
    <link>https://gugesay.com/blog/【50000】发现0day漏洞，渗透apple</link>
    undefined
    <pubDate>Mon, 09 Jan 2023 16:00:02 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>Apple</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从youtube演示视频获得启发，通过sql注入成功拿下4324漏洞</guid>
    <title>从Youtube演示视频获得启发，通过SQL注入成功拿下$4324漏洞赏金奖励</title>
    <link>https://gugesay.com/blog/从youtube演示视频获得启发，通过sql注入成功拿下4324漏洞</link>
    undefined
    <pubDate>Tue, 03 Jan 2023 07:25:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在侦查阶段快速发现ssrf</guid>
    <title>如何在侦察阶段快速发现SSRF</title>
    <link>https://gugesay.com/blog/如何在侦查阶段快速发现ssrf</link>
    undefined
    <pubDate>Tue, 27 Dec 2022 04:23:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/给我一个浏览器，还你一个shell！</guid>
    <title>给我一个浏览器，还你一个Shell！</title>
    <link>https://gugesay.com/blog/给我一个浏览器，还你一个shell！</link>
    undefined
    <pubDate>Fri, 16 Dec 2022 03:19:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>shellcode</category><category>浏览器</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/life-is-short</guid>
    <title>Life is Short</title>
    <link>https://gugesay.com/blog/life-is-short</link>
    undefined
    <pubDate>Thu, 10 Nov 2022 02:46:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>随记体验</category><category>鸡汤</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/23k：验证绕过文件上传任意文件覆盖</guid>
    <title>$23K：验证绕过+文件上传+任意文件覆盖</title>
    <link>https://gugesay.com/blog/23k：验证绕过文件上传任意文件覆盖</link>
    undefined
    <pubDate>Thu, 03 Nov 2022 22:25:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【10000】绕过github-html标签过滤</guid>
    <title>【$10,000】绕过GitHub HTML标签过滤</title>
    <link>https://gugesay.com/blog/【10000】绕过github-html标签过滤</link>
    undefined
    <pubDate>Fri, 28 Oct 2022 01:41:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【e300】打破逻辑：不安全的参数</guid>
    <title>【€300】打破逻辑：不安全的参数</title>
    <link>https://gugesay.com/blog/【e300】打破逻辑：不安全的参数</link>
    undefined
    <pubDate>Tue, 30 Aug 2022 01:57:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值-1000-美元的账户接管</guid>
    <title>价值 1000 美元的账户接管</title>
    <link>https://gugesay.com/blog/价值-1000-美元的账户接管</link>
    undefined
    <pubDate>Wed, 24 Aug 2022 02:58:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用python配置tor</guid>
    <title>使用Python配置Tor</title>
    <link>https://gugesay.com/blog/使用python配置tor</link>
    undefined
    <pubDate>Wed, 17 Aug 2022 02:28:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>python</category><category>tor</category><category>代理</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一次有意思的otp绕过</guid>
    <title>一次有意思的OTP绕过</title>
    <link>https://gugesay.com/blog/一次有意思的otp绕过</link>
    undefined
    <pubDate>Wed, 22 Jun 2022 00:54:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>otp</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</guid>
    <title>BurpSuite Intruder 自动化测试反射型 XSS</title>
    <link>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</link>
    undefined
    <pubDate>Sat, 18 Jun 2022 07:36:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>burpsuite</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/swagger-ui-从xss到账户接管</guid>
    <title>Swagger-UI 从XSS到账户接管</title>
    <link>https://gugesay.com/blog/swagger-ui-从xss到账户接管</link>
    undefined
    <pubDate>Tue, 24 May 2022 07:27:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>SwaggerUI</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-js-文件实现bypass管理面板</guid>
    <title>通过 JS 文件实现Bypass管理面板</title>
    <link>https://gugesay.com/blog/通过-js-文件实现bypass管理面板</link>
    undefined
    <pubDate>Tue, 10 May 2022 01:48:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ubuntuwineida7-6激活插件</guid>
    <title>Ubuntu+Wine+IDA7.6+激活插件</title>
    <link>https://gugesay.com/blog/ubuntuwineida7-6激活插件</link>
    undefined
    <pubDate>Thu, 05 May 2022 03:22:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ida</category><category>ubuntu</category><category>wine</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2222bypass-waf</guid>
    <title>[$2222]Bypass WAF</title>
    <link>https://gugesay.com/blog/2222bypass-waf</link>
    undefined
    <pubDate>Mon, 02 May 2022 05:25:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>WAF</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</guid>
    <title>如何在Bugcrowd公共项目中找到50多个XSS漏洞</title>
    <link>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</link>
    undefined
    <pubDate>Wed, 20 Apr 2022 07:48:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bugcrowd</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【6000】绕过apple-sso</guid>
    <title>【$6000】绕过Apple SSO</title>
    <link>https://gugesay.com/blog/【6000】绕过apple-sso</link>
    undefined
    <pubDate>Tue, 19 Apr 2022 06:40:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/spring4shell</guid>
    <title>Spring4Shell？</title>
    <link>https://gugesay.com/blog/spring4shell</link>
    undefined
    <pubDate>Sat, 02 Apr 2022 07:29:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【随记】vm虚机通过宿主机实现代理跳板</guid>
    <title>VM虚机通过宿主机实现代理跳板</title>
    <link>https://gugesay.com/blog/【随记】vm虚机通过宿主机实现代理跳板</link>
    undefined
    <pubDate>Tue, 29 Mar 2022 08:19:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>VM</category><category>代理跳板</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</guid>
    <title>在阅读了220份IDOR漏洞报告后的心得体会</title>
    <link>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</link>
    undefined
    <pubDate>Fri, 25 Feb 2022 06:20:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽故事】10000奖励：安卓平台adobe-acrobat-reader-rce漏洞</guid>
    <title>【白帽故事】$10,000奖励：安卓平台A​dobe Acrobat Reader RCE漏洞</title>
    <link>https://gugesay.com/blog/【白帽故事】10000奖励：安卓平台adobe-acrobat-reader-rce漏洞</link>
    undefined
    <pubDate>Mon, 14 Feb 2022 02:06:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>A​dobe</category><category>Android</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</guid>
    <title>【奖金$5000】将任意无主手机号码添加到我的Facebook账户</title>
    <link>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</link>
    undefined
    <pubDate>Fri, 11 Feb 2022 02:19:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</guid>
    <title>【白帽故事】$8000赏金奖励：Opera浏览器从XSS 到 RCE</title>
    <link>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</link>
    undefined
    <pubDate>Tue, 18 Jan 2022 08:03:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Opera</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</guid>
    <title>另一枚价值$3133.7的Google IDOR漏洞</title>
    <link>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</link>
    undefined
    <pubDate>Wed, 29 Sep 2021 02:11:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外一位白帽子2年来总结的10条经验</guid>
    <title>国外一位白帽子2年来总结的10条经验</title>
    <link>https://gugesay.com/blog/国外一位白帽子2年来总结的10条经验</link>
    undefined
    <pubDate>Mon, 27 Sep 2021 05:46:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category><category>经验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/推荐4本模糊测试fuzz-testing的相关书籍</guid>
    <title>推荐4本模糊测试(Fuzz Testing)的相关书籍</title>
    <link>https://gugesay.com/blog/推荐4本模糊测试fuzz-testing的相关书籍</link>
    undefined
    <pubDate>Wed, 15 Sep 2021 01:40:01 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>fuzz</category><category>模糊测试</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/深入理解计算机系统</guid>
    <title>深入理解计算机系统</title>
    <link>https://gugesay.com/blog/深入理解计算机系统</link>
    undefined
    <pubDate>Mon, 06 Sep 2021 08:37:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>学习</category><category>操作系统</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/git泄露搜索语法</guid>
    <title>Git泄露搜索语法</title>
    <link>https://gugesay.com/blog/git泄露搜索语法</link>
    undefined
    <pubDate>Tue, 31 Aug 2021 04:06:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/notion，它的强大之处远超我的想象！</guid>
    <title>Notion，它的强大之处远超我的想象！</title>
    <link>https://gugesay.com/blog/notion，它的强大之处远超我的想象！</link>
    undefined
    <pubDate>Wed, 18 Aug 2021 04:28:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>notion</category><category>工具</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一款公共交通票务移动app的xxe漏洞</guid>
    <title>一款公共交通票务移动APP的XXE漏洞</title>
    <link>https://gugesay.com/blog/一款公共交通票务移动app的xxe漏洞</link>
    undefined
    <pubDate>Tue, 10 Aug 2021 06:28:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>xxe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/不忘初心，方得始终！</guid>
    <title>不忘初心，方得始终！</title>
    <link>https://gugesay.com/blog/不忘初心，方得始终！</link>
    undefined
    <pubDate>Thu, 05 Aug 2021 02:56:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/伊卡洛斯</guid>
    <title>伊卡洛斯</title>
    <link>https://gugesay.com/blog/伊卡洛斯</link>
    undefined
    <pubDate>Wed, 28 Jul 2021 05:55:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>伊卡洛斯</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/svg对pdf转换时的ssrf攻击</guid>
    <title>SVG对PDF转换时的SSRF攻击</title>
    <link>https://gugesay.com/blog/svg对pdf转换时的ssrf攻击</link>
    undefined
    <pubDate>Fri, 28 May 2021 08:32:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【动手】captcha-killer配合深度学习实现burpsuite验证码一条龙爆</guid>
    <title>【动手】Captcha-Killer配合深度学习实现BurpSuite验证码一条龙爆破攻击</title>
    <link>https://gugesay.com/blog/【动手】captcha-killer配合深度学习实现burpsuite验证码一条龙爆</link>
    undefined
    <pubDate>Thu, 25 Feb 2021 10:16:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>burpsuite</category><category>Captcha-Killer</category><category>随记体验</category>
  </item>

    </channel>
  </rss>
