
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Guge&#39;sBlog</title>
      <link>https://gugesay.com/blog</link>
      <description>骨哥说事公众号首发地</description>
      <language>zh-CN</language>
      <managingEditor>undefined (Guge)</managingEditor>
      <webMaster>undefined (Guge)</webMaster>
      <lastBuildDate>Tue, 07 May 2024 01:38:25 GMT</lastBuildDate>
      <atom:link href="https://gugesay.com/tags/bugbounty/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://gugesay.com/blog/10秒以内窃取你的telegram帐户</guid>
    <title>10秒以内窃取你的Telegram帐户</title>
    <link>https://gugesay.com/blog/10秒以内窃取你的telegram帐户</link>
    undefined
    <pubDate>Tue, 07 May 2024 01:38:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>telegram</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2023 Microsoft Office XSS</guid>
    <title>2023 Microsoft Office XSS</title>
    <link>https://gugesay.com/blog/2023 Microsoft Office XSS</link>
    undefined
    <pubDate>Sat, 07 Oct 2023 01:38:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>MSRC</category><category>Office</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2023 年十佳 Web 黑客技术</guid>
    <title>2023 年十佳 Web 黑客技术</title>
    <link>https://gugesay.com/blog/2023 年十佳 Web 黑客技术</link>
    undefined
    <pubDate>Wed, 28 Feb 2024 08:38:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2026年重点关注的3类高价值漏洞</guid>
    <title>2026年重点关注的3类高价值漏洞</title>
    <link>https://gugesay.com/blog/2026年重点关注的3类高价值漏洞</link>
    undefined
    <pubDate>Sat, 10 Jan 2026 02:27:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>漏洞</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/2222bypass-waf</guid>
    <title>[$2222]Bypass WAF</title>
    <link>https://gugesay.com/blog/2222bypass-waf</link>
    undefined
    <pubDate>Mon, 02 May 2022 05:25:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>WAF</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/23k：验证绕过文件上传任意文件覆盖</guid>
    <title>$23K：验证绕过+文件上传+任意文件覆盖</title>
    <link>https://gugesay.com/blog/23k：验证绕过文件上传任意文件覆盖</link>
    undefined
    <pubDate>Thu, 03 Nov 2022 22:25:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/30000美元赏金事件</guid>
    <title>30000美元赏金事件</title>
    <link>https://gugesay.com/blog/30000美元赏金事件</link>
    undefined
    <pubDate>Tue, 06 Jun 2023 07:47:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/40000！如何从路径遍历升级rce！</guid>
    <title>$40,000！如何将路径遍历升级为RCE！</title>
    <link>https://gugesay.com/blog/40000！如何从路径遍历升级rce！</link>
    undefined
    <pubDate>Fri, 17 Jan 2025 06:34:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category><category>路径遍历</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai黑客：chatgpt中的高级api攻击</guid>
    <title>AI黑客：ChatGPT中的高级API攻击</title>
    <link>https://gugesay.com/blog/ai黑客：chatgpt中的高级api攻击</link>
    undefined
    <pubDate>Sun, 26 May 2024 04:24:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>chatgpt</category><category>http请求走私</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/ai黑客：使用-chatgpt-在浏览器中挖掘-xxe</guid>
    <title>AI黑客：使用 ChatGPT 在浏览器中挖掘 XXE</title>
    <link>https://gugesay.com/blog/ai黑客：使用-chatgpt-在浏览器中挖掘-xxe</link>
    undefined
    <pubDate>Tue, 28 May 2024 01:27:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>Safari</category><category>xxe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/api-黑客</guid>
    <title>API 攻击与防御</title>
    <link>https://gugesay.com/blog/api-黑客</link>
    undefined
    <pubDate>Wed, 30 Aug 2023 07:13:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</guid>
    <title>BurpSuite Intruder 自动化测试反射型 XSS</title>
    <link>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</link>
    undefined
    <pubDate>Sat, 18 Jun 2022 07:36:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>burpsuite</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</guid>
    <title>Chrome 最新XSS攻击向量：CVE-2023-5480</title>
    <link>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</link>
    undefined
    <pubDate>Tue, 30 Jan 2024 01:51:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>CVE</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/citrix滴血：cve-2023-4966-泄漏citrix会话token</guid>
    <title>Citrix滴血：CVE-2023-4966 泄漏Citrix会话Token</title>
    <link>https://gugesay.com/blog/citrix滴血：cve-2023-4966-泄漏citrix会话token</link>
    undefined
    <pubDate>Wed, 01 Nov 2023 03:18:10 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Citrix</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/csgo-从0到0day！</guid>
    <title>CS:GO 从0到0day！</title>
    <link>https://gugesay.com/blog/csgo-从0到0day！</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 06:53:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CS:GO</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2022-38627：通过sqlite注入破坏整个企业大楼之旅</guid>
    <title>CVE-2022-38627：通过SQLite注入破坏整个企业大楼之旅</title>
    <link>https://gugesay.com/blog/cve-2022-38627：通过sqlite注入破坏整个企业大楼之旅</link>
    undefined
    <pubDate>Tue, 07 Feb 2023 01:50:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2022-4908：使用导航-api-绕过-chrome-sop</guid>
    <title>CVE-2022-4908：使用导航 API 绕过 Chrome SOP</title>
    <link>https://gugesay.com/blog/cve-2022-4908：使用导航-api-绕过-chrome-sop</link>
    undefined
    <pubDate>Tue, 17 Oct 2023 08:30:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>SOP</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/cve-2023-36934：moveit-transfer-sql注入分析</guid>
    <title>CVE-2023-36934：MOVEit Transfer SQL注入分析</title>
    <link>https://gugesay.com/blog/cve-2023-36934：moveit-transfer-sql注入分析</link>
    undefined
    <pubDate>Tue, 18 Jul 2023 02:20:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/git泄露搜索语法</guid>
    <title>Git泄露搜索语法</title>
    <link>https://gugesay.com/blog/git泄露搜索语法</link>
    undefined
    <pubDate>Tue, 31 Aug 2021 04:06:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/gmail-中的-html-表单注入漏洞</guid>
    <title>Gmail 中的 HTML 表单注入漏洞</title>
    <link>https://gugesay.com/blog/gmail-中的-html-表单注入漏洞</link>
    undefined
    <pubDate>Wed, 18 Sep 2024 14:18:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Gmail</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/graphql黑客：如何使用简单的探测查询找到1000漏洞</guid>
    <title>&quot;GraphQL黑客：如何使用简单的探测获得$1000赏金&quot;</title>
    <link>https://gugesay.com/blog/graphql黑客：如何使用简单的探测查询找到1000漏洞</link>
    undefined
    <pubDate>Mon, 16 Oct 2023 07:01:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>GraphQL</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</guid>
    <title>hackerone上TOP5的开放重定向漏洞</title>
    <link>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</link>
    undefined
    <pubDate>Fri, 16 Aug 2024 06:50:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>XSS</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/hello-lucee-让我们再次黑掉apple～</guid>
    <title>Hello Lucee! 让我们再次黑掉Apple～</title>
    <link>https://gugesay.com/blog/hello-lucee-让我们再次黑掉apple～</link>
    undefined
    <pubDate>Wed, 21 Feb 2024 07:24:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>Lucee</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/idor之如何打破订阅限制</guid>
    <title>IDOR之如何打破订阅限制</title>
    <link>https://gugesay.com/blog/idor之如何打破订阅限制</link>
    undefined
    <pubDate>Wed, 21 Aug 2024 01:48:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/iis欢迎页的安全隐患：从源代码到lfi的攻防之道</guid>
    <title>IIS欢迎页的安全隐患：从源代码到LFI的攻防之道</title>
    <link>https://gugesay.com/blog/iis欢迎页的安全隐患：从源代码到lfi的攻防之道</link>
    undefined
    <pubDate>Mon, 02 Sep 2024 01:25:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IIS</category><category>LFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/lfi-从高危升级为严重</guid>
    <title>LFI -从高危升级为严重</title>
    <link>https://gugesay.com/blog/lfi-从高危升级为严重</link>
    undefined
    <pubDate>Fri, 22 Sep 2023 09:29:40 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/odt文件漏洞利用</guid>
    <title>ODT文件漏洞利用</title>
    <link>https://gugesay.com/blog/odt文件漏洞利用</link>
    undefined
    <pubDate>Thu, 01 Aug 2024 02:37:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/svg对pdf转换时的ssrf攻击</guid>
    <title>SVG对PDF转换时的SSRF攻击</title>
    <link>https://gugesay.com/blog/svg对pdf转换时的ssrf攻击</link>
    undefined
    <pubDate>Fri, 28 May 2021 08:32:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/swagger-ui-从xss到账户接管</guid>
    <title>Swagger-UI 从XSS到账户接管</title>
    <link>https://gugesay.com/blog/swagger-ui-从xss到账户接管</link>
    undefined
    <pubDate>Tue, 24 May 2022 07:27:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>SwaggerUI</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/web-缓存欺骗：在意想不到的地方发现漏洞</guid>
    <title>Web 缓存欺骗：在意想不到的地方发现漏洞</title>
    <link>https://gugesay.com/blog/web-缓存欺骗：在意想不到的地方发现漏洞</link>
    undefined
    <pubDate>Wed, 13 Sep 2023 01:42:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Web缓存</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/wps-office攻击细节披露</guid>
    <title>WPS Office攻击细节披露</title>
    <link>https://gugesay.com/blog/wps-office攻击细节披露</link>
    undefined
    <pubDate>Fri, 27 Sep 2024 01:08:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>WPS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss-waf绕过的一些基本思考</guid>
    <title>XSS WAF绕过的一些基本思考</title>
    <link>https://gugesay.com/blog/xss-waf绕过的一些基本思考</link>
    undefined
    <pubDate>Fri, 14 Jun 2024 11:55:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</guid>
    <title>XSS！一次对抗Akamai WAF的经历</title>
    <link>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</link>
    undefined
    <pubDate>Mon, 30 Oct 2023 03:27:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>akamai</category><category>bugbounty</category><category>bypass</category><category>XSS</category><category>未分类</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【$20000】通过发送消息黑掉任意公司-cve-2021-34506</guid>
    <title>【$ 20,000】通过发送消息黑掉任意公司-CVE-2021–34506</title>
    <link>https://gugesay.com/blog/【$20000】通过发送消息黑掉任意公司-cve-2021-34506</link>
    undefined
    <pubDate>Sat, 28 Jan 2023 02:54:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>CVE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</guid>
    <title>【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</title>
    <link>https://gugesay.com/blog/【$40,000】AAD配置错误导致必应结果篡改与微软帐户接管</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 03:03:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AAD</category><category>bugbounty</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【10000】绕过github-html标签过滤</guid>
    <title>【$10,000】绕过GitHub HTML标签过滤</title>
    <link>https://gugesay.com/blog/【10000】绕过github-html标签过滤</link>
    undefined
    <pubDate>Fri, 28 Oct 2022 01:41:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【1060】gitlab-html-注入漏洞</guid>
    <title>【$1,060】GitLab HTML 注入漏洞</title>
    <link>https://gugesay.com/blog/【1060】gitlab-html-注入漏洞</link>
    undefined
    <pubDate>Tue, 15 Oct 2024 09:20:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Gitlab</category><category>hackerone</category><category>html注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【20000】通过-devtools-实现-chrome-浏览器沙箱逃逸</guid>
    <title>【$20,000】通过 DevTools 实现 Chrome 浏览器沙箱逃逸</title>
    <link>https://gugesay.com/blog/【20000】通过-devtools-实现-chrome-浏览器沙箱逃逸</link>
    undefined
    <pubDate>Tue, 22 Oct 2024 04:01:04 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>Google</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</guid>
    <title>【$2000】利用重置密码实现帐户接管</title>
    <link>https://gugesay.com/blog/【2000】利用重置密码实现帐户接管</link>
    undefined
    <pubDate>Thu, 26 Sep 2024 07:58:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category><category>重置密码</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【25300】绕过-facebook-双因素身份验证</guid>
    <title>【$25,300】绕过 Facebook 双因素身份验证</title>
    <link>https://gugesay.com/blog/【25300】绕过-facebook-双因素身份验证</link>
    undefined
    <pubDate>Wed, 23 Aug 2023 08:50:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>2FA</category><category>bugbounty</category><category>facebook</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【3400】一次点击，攻击者轻松窃取用户余额！</guid>
    <title>【$3400】一次点击，攻击者轻松窃取用户余额！</title>
    <link>https://gugesay.com/blog/【3400】一次点击，攻击者轻松窃取用户余额！</link>
    undefined
    <pubDate>Thu, 17 Aug 2023 08:27:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>paypal</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【50000】发现0day漏洞，渗透apple</guid>
    <title>【$50,000】发现0day漏洞，渗透Apple</title>
    <link>https://gugesay.com/blog/【50000】发现0day漏洞，渗透apple</link>
    undefined
    <pubDate>Mon, 09 Jan 2023 16:00:02 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>Apple</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</guid>
    <title>【$500】如何将DOM XSS升级为存储型XSS</title>
    <link>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</link>
    undefined
    <pubDate>Mon, 25 Dec 2023 08:20:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【6000】绕过apple-sso</guid>
    <title>【$6000】绕过Apple SSO</title>
    <link>https://gugesay.com/blog/【6000】绕过apple-sso</link>
    undefined
    <pubDate>Tue, 19 Apr 2022 06:40:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2024-31747】microsoft-teams-电话锁定绕过利用</guid>
    <title>【CVE-2024–31747】Microsoft Teams 电话锁定绕过利用</title>
    <link>https://gugesay.com/blog/【cve-2024-31747】microsoft-teams-电话锁定绕过利用</link>
    undefined
    <pubDate>Wed, 15 May 2024 01:59:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>Yealink</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【e300】打破逻辑：不安全的参数</guid>
    <title>【€300】打破逻辑：不安全的参数</title>
    <link>https://gugesay.com/blog/【e300】打破逻辑：不安全的参数</link>
    undefined
    <pubDate>Tue, 30 Aug 2022 01:57:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</guid>
    <title>【奖金$5000】将任意无主手机号码添加到我的Facebook账户</title>
    <link>https://gugesay.com/blog/【奖金5000】将任意无主手机号码添加到我的facebook账户</link>
    undefined
    <pubDate>Fri, 11 Feb 2022 02:19:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽故事】10000奖励：安卓平台adobe-acrobat-reader-rce漏洞</guid>
    <title>【白帽故事】$10,000奖励：安卓平台A​dobe Acrobat Reader RCE漏洞</title>
    <link>https://gugesay.com/blog/【白帽故事】10000奖励：安卓平台adobe-acrobat-reader-rce漏洞</link>
    undefined
    <pubDate>Mon, 14 Feb 2022 02:06:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>A​dobe</category><category>Android</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</guid>
    <title>【白帽故事】$8000赏金奖励：Opera浏览器从XSS 到 RCE</title>
    <link>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</link>
    undefined
    <pubDate>Tue, 18 Jan 2022 08:03:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Opera</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【赏金15000美元】通过监控调试模式实现-rce</guid>
    <title>【赏金15000美元】通过监控调试模式实现 RCE</title>
    <link>https://gugesay.com/blog/【赏金15000美元】通过监控调试模式实现-rce</link>
    undefined
    <pubDate>Sat, 14 Sep 2024 08:35:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>rce</category><category>白帽故事</category><category>调试模式</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一则ssrf漏洞的故事</guid>
    <title>一则SSRF漏洞的故事</title>
    <link>https://gugesay.com/blog/一则ssrf漏洞的故事</link>
    undefined
    <pubDate>Wed, 10 Jul 2024 07:55:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>aws</category><category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一周三步曲：从开放重定向到远程代码执行！</guid>
    <title>一周三步曲：从开放重定向到远程代码执行！</title>
    <link>https://gugesay.com/blog/一周三步曲：从开放重定向到远程代码执行！</link>
    undefined
    <pubDate>Tue, 19 Mar 2024 14:28:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一次有意思的otp绕过</guid>
    <title>一次有意思的OTP绕过</title>
    <link>https://gugesay.com/blog/一次有意思的otp绕过</link>
    undefined
    <pubDate>Wed, 22 Jun 2022 00:54:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>otp</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一次通过fuzz-api发现漏洞的旅程</guid>
    <title>一次通过Fuzz API发现漏洞的旅程</title>
    <link>https://gugesay.com/blog/一次通过fuzz-api发现漏洞的旅程</link>
    undefined
    <pubDate>Tue, 07 Nov 2023 04:22:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一款公共交通票务移动app的xxe漏洞</guid>
    <title>一款公共交通票务移动APP的XXE漏洞</title>
    <link>https://gugesay.com/blog/一款公共交通票务移动app的xxe漏洞</link>
    undefined
    <pubDate>Tue, 10 Aug 2021 06:28:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>xxe</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一起全账户接管漏洞案例</guid>
    <title>一起全帐户接管漏洞案例</title>
    <link>https://gugesay.com/blog/一起全账户接管漏洞案例</link>
    undefined
    <pubDate>Fri, 03 Nov 2023 02:07:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/三角测量行动：最后的（硬件）谜团</guid>
    <title>三角测量行动：最后的（硬件）谜团</title>
    <link>https://gugesay.com/blog/三角测量行动：最后的（硬件）谜团</link>
    undefined
    <pubDate>Wed, 03 Jan 2024 05:32:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>0day</category><category>Apple</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/五种用来挖掘API端点的方法</guid>
    <title>五种用来挖掘API端点的方法</title>
    <link>https://gugesay.com/blog/五种用来挖掘API端点的方法</link>
    undefined
    <pubDate>Sun, 14 Apr 2024 02:44:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API endpoint</category><category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-wayback-machine-到-aws-元数据：5-分钟内发现生产系统中的-ssrf</guid>
    <title>从 Wayback Machine 到 AWS 元数据：5 分钟内发现生产系统中的 SSRF</title>
    <link>https://gugesay.com/blog/从-wayback-machine-到-aws-元数据：5-分钟内发现生产系统中的-ssrf</link>
    undefined
    <pubDate>Wed, 18 Dec 2024 01:05:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从LFI到RCE</guid>
    <title>从LFI到RCE</title>
    <link>https://gugesay.com/blog/从LFI到RCE</link>
    undefined
    <pubDate>Mon, 20 Nov 2023 02:38:43 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</guid>
    <title>从Adobe的VIP赏金计划中获得近50,000美元奖励的故事</title>
    <link>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</link>
    undefined
    <pubDate>Tue, 02 Jan 2024 09:52:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从js代码审计到graphql利用的管理账户接管</guid>
    <title>从JS代码审计到GraphQL利用的管理账户接管</title>
    <link>https://gugesay.com/blog/从js代码审计到graphql利用的管理账户接管</link>
    undefined
    <pubDate>Thu, 05 Dec 2024 04:11:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>GraphQL</category><category>JS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从self-xss-到账户接管</guid>
    <title>从Self XSS 到账户接管</title>
    <link>https://gugesay.com/blog/从self-xss-到账户接管</link>
    undefined
    <pubDate>Fri, 22 Dec 2023 06:54:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从youtube演示视频获得启发，通过sql注入成功拿下4324漏洞</guid>
    <title>从Youtube演示视频获得启发，通过SQL注入成功拿下$4324漏洞赏金奖励</title>
    <link>https://gugesay.com/blog/从youtube演示视频获得启发，通过sql注入成功拿下4324漏洞</link>
    undefined
    <pubDate>Tue, 03 Jan 2023 07:25:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值-1000-美元的账户接管</guid>
    <title>价值 1000 美元的账户接管</title>
    <link>https://gugesay.com/blog/价值-1000-美元的账户接管</link>
    undefined
    <pubDate>Wed, 24 Aug 2022 02:58:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/价值-3500-美元的管理面板绕过漏洞</guid>
    <title>价值 3500 美元的管理面板绕过漏洞</title>
    <link>https://gugesay.com/blog/价值-3500-美元的管理面板绕过漏洞</link>
    undefined
    <pubDate>Tue, 20 Aug 2024 08:23:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/任意chatgpt-帐户接管-利用通配符进行网络缓存欺骗</guid>
    <title>任意ChatGPT 帐户接管 - 利用通配符进行网络缓存欺骗</title>
    <link>https://gugesay.com/blog/任意chatgpt-帐户接管-利用通配符进行网络缓存欺骗</link>
    undefined
    <pubDate>Sun, 18 Feb 2024 01:28:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>chatgpt</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用-aquatone-配合狩猎</guid>
    <title>使用 Aquatone 配合&#39;狩猎&#39;</title>
    <link>https://gugesay.com/blog/使用-aquatone-配合狩猎</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 05:45:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Aquatone</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</guid>
    <title>使用 Google 脚本资源绕过 PortSwigger上的 CSP</title>
    <link>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</link>
    undefined
    <pubDate>Tue, 27 Feb 2024 07:46:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>csp</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用ai大模型打造模糊测试工具</guid>
    <title>使用AI大模型打造模糊测试工具</title>
    <link>https://gugesay.com/blog/使用ai大模型打造模糊测试工具</link>
    undefined
    <pubDate>Sun, 07 Apr 2024 01:37:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>fuzz</category><category>LLMs</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</guid>
    <title>使用工具快速发现 SSRF、LFI、XSS</title>
    <link>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</link>
    undefined
    <pubDate>Tue, 29 Aug 2023 03:15:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>ssrf</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/入侵高露洁智能牙刷</guid>
    <title>入侵高露洁智能牙刷</title>
    <link>https://gugesay.com/blog/入侵高露洁智能牙刷</link>
    undefined
    <pubDate>Fri, 26 Apr 2024 01:54:22 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IoT</category><category>智能牙刷</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/具有邀请功能的账户劫持思路</guid>
    <title>具有邀请功能的账户劫持思路</title>
    <link>https://gugesay.com/blog/具有邀请功能的账户劫持思路</link>
    undefined
    <pubDate>Thu, 30 Nov 2023 02:14:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</guid>
    <title>凭借一手Apple 存储XSS赚取5000美元的故事</title>
    <link>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 16:00:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/创新拳法：漏洞链的艺术</guid>
    <title>组合拳法：漏洞利用链的艺术</title>
    <link>https://gugesay.com/blog/创新拳法：漏洞链的艺术</link>
    undefined
    <pubDate>Wed, 10 Jan 2024 04:23:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-github-最大化你的漏洞数量-2</guid>
    <title>利用 GitHub 最大化你的漏洞数量</title>
    <link>https://gugesay.com/blog/利用-github-最大化你的漏洞数量-2</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 07:38:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>github</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用-youtube-窃取文件</guid>
    <title>【$4133.70】利用 YouTube 窃取文件</title>
    <link>https://gugesay.com/blog/利用-youtube-窃取文件</link>
    undefined
    <pubDate>Tue, 24 Sep 2024 09:53:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</guid>
    <title>利用Param Miner挖掘基于缓存中毒的XSS漏洞</title>
    <link>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</link>
    undefined
    <pubDate>Fri, 10 Feb 2023 02:46:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用关键-0day-xxe-漏洞实现全面-ssrf-攻击</guid>
    <title>利用关键 0day XXE 漏洞实现 SSRF 攻击</title>
    <link>https://gugesay.com/blog/利用关键-0day-xxe-漏洞实现全面-ssrf-攻击</link>
    undefined
    <pubDate>Wed, 13 Dec 2023 01:27:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用出色的侦察能力获得-2000-美元赏金</guid>
    <title>利用出色的侦察能力获得 2000 美元赏金</title>
    <link>https://gugesay.com/blog/利用出色的侦察能力获得-2000-美元赏金</link>
    undefined
    <pubDate>Tue, 30 Jul 2024 01:12:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用工具从cloudflare中发现源ip</guid>
    <title>利用工具从Cloudflare中发现源IP</title>
    <link>https://gugesay.com/blog/利用工具从cloudflare中发现源ip</link>
    undefined
    <pubDate>Thu, 25 Jan 2024 08:29:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用开放式重定向、2fa-绕过等漏洞获取1600赏金奖励</guid>
    <title>利用开放式重定向、2FA 绕过等漏洞获取$1600赏金奖励</title>
    <link>https://gugesay.com/blog/利用开放式重定向、2fa-绕过等漏洞获取1600赏金奖励</link>
    undefined
    <pubDate>Tue, 27 Aug 2024 01:21:42 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>2FA bypass</category><category>bugbounty</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用非云-ssrf-获得更多乐趣和赏金</guid>
    <title>利用非云 SSRF 获得更多乐趣和赏金</title>
    <link>https://gugesay.com/blog/利用非云-ssrf-获得更多乐趣和赏金</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 00:48:20 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事</guid>
    <title>发现Facebook SSRF，收获31500美元赏金的故事【1】</title>
    <link>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事</link>
    undefined
    <pubDate>Thu, 17 Oct 2024 13:32:35 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事【2】</guid>
    <title>发现Facebook SSRF，收获31500美元赏金的故事【2】</title>
    <link>https://gugesay.com/blog/发现facebook-ssrf，收获31500美元赏金的故事【2】</link>
    undefined
    <pubDate>Fri, 18 Oct 2024 01:21:03 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>facebook</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</guid>
    <title>发现关键漏洞获得 $4,000 赏金奖励</title>
    <link>https://gugesay.com/blog/发现关键漏洞获得-4000-赏金奖励</link>
    undefined
    <pubDate>Wed, 11 Dec 2024 01:17:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>subdomain</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</guid>
    <title>另一处XSS！荣登微软MSRC 2022 Q3排行榜</title>
    <link>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</link>
    undefined
    <pubDate>Wed, 15 Feb 2023 16:00:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</guid>
    <title>另一枚价值$3133.7的Google IDOR漏洞</title>
    <link>https://gugesay.com/blog/另一枚价值3133-7的google-idor漏洞</link>
    undefined
    <pubDate>Wed, 29 Sep 2021 02:11:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/各大云-accesskey-特征整理</guid>
    <title>各大云 AccessKey 特征整理</title>
    <link>https://gugesay.com/blog/各大云-accesskey-特征整理</link>
    undefined
    <pubDate>Thu, 07 Nov 2024 01:37:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>AccessKey</category><category>bugbounty</category><category>HaE</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外4大众测平台优缺点对比</guid>
    <title>国外4大众测平台优缺点对比</title>
    <link>https://gugesay.com/blog/国外4大众测平台优缺点对比</link>
    undefined
    <pubDate>Tue, 14 May 2024 01:45:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bugcrowd</category><category>hackerone</category><category>Intigriti</category><category>Yeswehack</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/国外一位白帽子2年来总结的10条经验</guid>
    <title>国外一位白帽子2年来总结的10条经验</title>
    <link>https://gugesay.com/blog/国外一位白帽子2年来总结的10条经验</link>
    undefined
    <pubDate>Mon, 27 Sep 2021 05:46:08 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category><category>经验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在-instagram-上查看任何人的私人电子邮件和生日</guid>
    <title>在 Instagram 上查看任何人的私人电子邮件和生日信息</title>
    <link>https://gugesay.com/blog/在-instagram-上查看任何人的私人电子邮件和生日</link>
    undefined
    <pubDate>Tue, 06 Aug 2024 01:24:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Instagram</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</guid>
    <title>在ChatGPT中挖掘XSS漏洞实现任意账户接管</title>
    <link>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</link>
    undefined
    <pubDate>Fri, 23 Feb 2024 03:19:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>chatgpt</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在outlook上寻找远程代码执行漏洞【部分】</guid>
    <title>在Outlook上寻找远程代码执行漏洞【部分】</title>
    <link>https://gugesay.com/blog/在outlook上寻找远程代码执行漏洞【部分】</link>
    undefined
    <pubDate>Fri, 22 Mar 2024 16:00:48 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>outlook</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</guid>
    <title>在一个Web网站中获得$7000赏金奖励</title>
    <link>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</link>
    undefined
    <pubDate>Wed, 27 Mar 2024 01:32:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>rce</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在侦察阶段如何快速找到-rce</guid>
    <title>在侦察阶段如何快速找到 RCE</title>
    <link>https://gugesay.com/blog/在侦察阶段如何快速找到-rce</link>
    undefined
    <pubDate>Wed, 22 May 2024 01:27:38 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apache</category><category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在家用摄像头中利用-n-day</guid>
    <title>在家用摄像头中利用 N-Day</title>
    <link>https://gugesay.com/blog/在家用摄像头中利用-n-day</link>
    undefined
    <pubDate>Fri, 07 Jun 2024 02:26:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</guid>
    <title>在阅读了220份IDOR漏洞报告后的心得体会</title>
    <link>https://gugesay.com/blog/在阅读了220份idor漏洞报告后的心得体会</link>
    undefined
    <pubDate>Fri, 25 Feb 2022 06:20:41 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何为任意-youtube-频道提供验证徽章</guid>
    <title>如何为任意 YouTube 频道提供验证徽章</title>
    <link>https://gugesay.com/blog/如何为任意-youtube-频道提供验证徽章</link>
    undefined
    <pubDate>Fri, 20 Sep 2024 06:30:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>youtube</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何从iis欢迎页面中快速挖掘漏洞</guid>
    <title>如何从IIS欢迎页面中快速挖掘漏洞</title>
    <link>https://gugesay.com/blog/如何从iis欢迎页面中快速挖掘漏洞</link>
    undefined
    <pubDate>Thu, 31 Oct 2024 14:44:46 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>IIS</category><category>shortscan</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</guid>
    <title>已修复漏洞？如何绕过并再次利用！</title>
    <link>https://gugesay.com/blog/如何从已披露的漏洞报告中重新发现新的漏洞</link>
    undefined
    <pubDate>Thu, 14 Nov 2024 07:22:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何利用js进行进一步漏洞挖掘【2024至尊版】</guid>
    <title>JS利用-2024至尊版</title>
    <link>https://gugesay.com/blog/如何利用js进行进一步漏洞挖掘【2024至尊版】</link>
    undefined
    <pubDate>Mon, 28 Oct 2024 12:30:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>JS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</guid>
    <title>如何在Bugcrowd公共项目中找到50多个XSS漏洞</title>
    <link>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</link>
    undefined
    <pubDate>Wed, 20 Apr 2022 07:48:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bugcrowd</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在epic-games上赚到7000赏金</guid>
    <title>如何在Epic Games上赚到$7,000赏金</title>
    <link>https://gugesay.com/blog/如何在epic-games上赚到7000赏金</link>
    undefined
    <pubDate>Thu, 04 Jan 2024 12:07:12 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在两个不同的网站中发现sql注入</guid>
    <title>如何在两个不同的网站中发现SQL注入</title>
    <link>https://gugesay.com/blog/如何在两个不同的网站中发现sql注入</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 01:37:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在侦查阶段快速发现ssrf</guid>
    <title>如何在侦察阶段快速发现SSRF</title>
    <link>https://gugesay.com/blog/如何在侦查阶段快速发现ssrf</link>
    undefined
    <pubDate>Tue, 27 Dec 2022 04:23:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何大规模搜寻泄露的敏感文件</guid>
    <title>如何大规模搜寻泄露的敏感文件</title>
    <link>https://gugesay.com/blog/如何大规模搜寻泄露的敏感文件</link>
    undefined
    <pubDate>Tue, 25 Jun 2024 01:58:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>泄露</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</guid>
    <title>如何将 DOM XSS升级为一键帐户接管（下集）</title>
    <link>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 02:21:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</guid>
    <title>如何将DOM XSS升级为一键帐户接管（上集）</title>
    <link>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</link>
    undefined
    <pubDate>Wed, 17 Apr 2024 16:00:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将低危的-ssrf-盲注升级为严重漏洞</guid>
    <title>如何将低危的 SSRF 盲注升级为严重漏洞</title>
    <link>https://gugesay.com/blog/如何将低危的-ssrf-盲注升级为严重漏洞</link>
    undefined
    <pubDate>Sun, 17 Nov 2024 08:58:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>aws</category><category>bugbounty</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</guid>
    <title>一次白嫖LinkedIn Premium会员资格的经历</title>
    <link>https://gugesay.com/blog/如何获得免费的linkedin-premium会员资格</link>
    undefined
    <pubDate>Thu, 07 Sep 2023 08:15:25 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Linkedln</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何远程控制起亚汽车</guid>
    <title>如何远程控制起亚汽车</title>
    <link>https://gugesay.com/blog/如何远程控制起亚汽车</link>
    undefined
    <pubDate>Tue, 01 Oct 2024 04:00:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>kia</category><category>白帽故事</category><category>起亚汽车</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将selfxss升级为存储xss</guid>
    <title>将SelfXSS升级为存储XSS</title>
    <link>https://gugesay.com/blog/将selfxss升级为存储xss</link>
    undefined
    <pubDate>Mon, 01 Apr 2024 01:38:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</guid>
    <title>将赏金从$50变为$1000的帐户接管漏洞</title>
    <link>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 05:59:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</guid>
    <title>巧妙利用业务逻辑漏洞，实现Google帐户接管</title>
    <link>https://gugesay.com/blog/巧妙利用业务逻辑漏洞，实现google帐户接管</link>
    undefined
    <pubDate>Thu, 08 Aug 2024 01:41:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>idor</category><category>otp</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</guid>
    <title>巧妙利用本地存储漏洞，轻松登录他人直播 App 账户</title>
    <link>https://gugesay.com/blog/巧妙利用本地存储漏洞，轻松登录他人直播-app-账户</link>
    undefined
    <pubDate>Wed, 29 May 2024 03:25:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>Local Storage</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/开箱即用-payloads</guid>
    <title>开箱即用的Payloads</title>
    <link>https://gugesay.com/blog/开箱即用-payloads</link>
    undefined
    <pubDate>Tue, 20 Feb 2024 01:22:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Payload</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/彻底弄懂-http-request-smuggling（http-请求走私）攻击以及实战演示</guid>
    <title>HTTP Request Smuggling（HTTP 请求走私）攻击及案例说明</title>
    <link>https://gugesay.com/blog/彻底弄懂-http-request-smuggling（http-请求走私）攻击以及实战演示</link>
    undefined
    <pubDate>Tue, 12 Sep 2023 09:13:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>HTTP Request Smuggler</category><category>白帽故事</category><category>请求走私</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/必备收藏！国外整理收集的网络安全资源</guid>
    <title>必备收藏！国外整理收集的网络安全资源</title>
    <link>https://gugesay.com/blog/必备收藏！国外整理收集的网络安全资源</link>
    undefined
    <pubDate>Fri, 19 Jan 2024 06:56:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/快速发现未授权页面及sql注入漏洞，获得1500奖励</guid>
    <title>快速发现未授权页面及SQL注入漏洞，获得$1500奖励</title>
    <link>https://gugesay.com/blog/快速发现未授权页面及sql注入漏洞，获得1500奖励</link>
    undefined
    <pubDate>Thu, 19 Oct 2023 08:26:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/意外发现dos攻击并获得25000美元奖励的故事</guid>
    <title>意外发现DoS攻击斩获$25,000赏金的故事</title>
    <link>https://gugesay.com/blog/意外发现dos攻击并获得25000美元奖励的故事</link>
    undefined
    <pubDate>Tue, 16 Apr 2024 01:44:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>dos</category><category>rce</category><category>区块链</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/打造自己专属的漏洞赏金搜索引擎</guid>
    <title>打造自己专属的漏洞赏金搜索引擎</title>
    <link>https://gugesay.com/blog/打造自己专属的漏洞赏金搜索引擎</link>
    undefined
    <pubDate>Mon, 17 Jun 2024 02:10:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>搜索引擎</category><category>随记体验</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/挖掘p1漏洞最受欢迎的8款猎杀工具</guid>
    <title>挖掘P1漏洞最受欢迎的8款&#39;猎杀&#39;工具</title>
    <link>https://gugesay.com/blog/挖掘p1漏洞最受欢迎的8款猎杀工具</link>
    undefined
    <pubDate>Wed, 01 Feb 2023 07:55:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/挖掘开发环境隐藏的秘密：一次-oauth-凭证从泄露到利</guid>
    <title>挖掘开发环境隐藏的秘密：一次 OAuth 凭证从泄露到利用的旅程</title>
    <link>https://gugesay.com/blog/挖掘开发环境隐藏的秘密：一次-oauth-凭证从泄露到利</link>
    undefined
    <pubDate>Tue, 12 Dec 2023 10:12:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>API</category><category>bugbounty</category><category>OAuth</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/攻击google-bard-从实时注入到数据外泄</guid>
    <title>攻击Google Bard-从实时注入到数据外泄</title>
    <link>https://gugesay.com/blog/攻击google-bard-从实时注入到数据外泄</link>
    undefined
    <pubDate>Mon, 04 Dec 2023 01:39:32 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Bard</category><category>bugbounty</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新h1漏洞披露通过作用域标签绕过-csp-的存储-xss，获</guid>
    <title>通过作用域标签绕过 CSP 的存储 XSS，获得$13,950赏金奖励</title>
    <link>https://gugesay.com/blog/最新h1漏洞披露通过作用域标签绕过-csp-的存储-xss，获</link>
    undefined
    <pubDate>Tue, 21 Feb 2023 08:25:27 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</guid>
    <title>最新H1越权漏洞披露，获得15000美元奖励</title>
    <link>https://gugesay.com/blog/最新h1越权漏洞披露，获得15000美元奖励</link>
    undefined
    <pubDate>Mon, 29 Apr 2024 11:25:21 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</guid>
    <title>最新Twitter XSS + CSRF 漏洞完整披露</title>
    <link>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</link>
    undefined
    <pubDate>Wed, 20 Dec 2023 02:03:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最适合渗透人员的15款浏览器插件推荐</guid>
    <title>适合渗透人员的15款浏览器插件推荐</title>
    <link>https://gugesay.com/blog/最适合渗透人员的15款浏览器插件推荐</link>
    undefined
    <pubDate>Thu, 10 Aug 2023 07:13:54 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/服务器端原型污染检测插件</guid>
    <title>【工具推荐】服务器端原型污染检测插件</title>
    <link>https://gugesay.com/blog/服务器端原型污染检测插件</link>
    undefined
    <pubDate>Wed, 06 Mar 2024 04:48:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Prototype Pollution</category><category>原型污染</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/某android-app中一处有趣的bug</guid>
    <title>某Android APP中一处国内不认国外认的有趣Bug</title>
    <link>https://gugesay.com/blog/某android-app中一处有趣的bug</link>
    undefined
    <pubDate>Wed, 12 Jun 2024 06:17:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>APP</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/查询背后：通过sql注入挖掘ntlm哈希</guid>
    <title>查询背后：通过SQL注入挖掘NTLM哈希</title>
    <link>https://gugesay.com/blog/查询背后：通过sql注入挖掘ntlm哈希</link>
    undefined
    <pubDate>Thu, 02 Nov 2023 07:48:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>NTLM</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/每个白帽都不应错过的酷炫侦察技巧！总有一</guid>
    <title>每个白帽都不应错过的酷炫‘侦察’技巧！总有一个你不知道～</title>
    <link>https://gugesay.com/blog/每个白帽都不应错过的酷炫侦察技巧！总有一</link>
    undefined
    <pubDate>Sun, 20 Aug 2023 02:46:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>侦察</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/没有swaggerui的swag怎么破</guid>
    <title>没有SwaggerUI的Swag怎么破？</title>
    <link>https://gugesay.com/blog/没有swaggerui的swag怎么破</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 06:15:55 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>SwaggerUI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/独家揭秘：巧妙利用akamai，透过f5窃取用户内部数据！</guid>
    <title>&quot;独家揭秘：请求走私高级利用，利用组合链获取用户内部敏感数据！&quot;</title>
    <link>https://gugesay.com/blog/独家揭秘：巧妙利用akamai，透过f5窃取用户内部数据！</link>
    undefined
    <pubDate>Wed, 31 Jan 2024 08:22:00 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽故事</category><category>请求走私</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/白帽应如何避免攻击性扫描行为</guid>
    <title>白帽应如何避免攻击性扫描行为</title>
    <link>https://gugesay.com/blog/白帽应如何避免攻击性扫描行为</link>
    undefined
    <pubDate>Tue, 02 Apr 2024 01:26:01 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>白帽</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/空穴来宝：如何从一个空文件中找到登录凭据</guid>
    <title>空穴来&#39;宝&#39;：如何从一个空文件中找到登录凭据</title>
    <link>https://gugesay.com/blog/空穴来宝：如何从一个空文件中找到登录凭据</link>
    undefined
    <pubDate>Wed, 29 May 2024 01:33:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Credentials</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/突破google的bug跟踪系统，获得15600美元赏金之旅</guid>
    <title>突破Google的Bug跟踪系统，获得15,600美元赏金之旅</title>
    <link>https://gugesay.com/blog/突破google的bug跟踪系统，获得15600美元赏金之旅</link>
    undefined
    <pubDate>Fri, 24 Nov 2023 15:41:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Google</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/绕过双因素认证至账户接管</guid>
    <title>绕过双因素认证至账户接管</title>
    <link>https://gugesay.com/blog/绕过双因素认证至账户接管</link>
    undefined
    <pubDate>Mon, 22 Jan 2024 08:56:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/继续citrix传奇：cve-2023-5914和cve-2023-6184</guid>
    <title>继续Citrix传奇：CVE-2023-5914和CVE-2023-6184</title>
    <link>https://gugesay.com/blog/继续citrix传奇：cve-2023-5914和cve-2023-6184</link>
    undefined
    <pubDate>Wed, 20 Mar 2024 01:41:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Citrix</category><category>rce</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</guid>
    <title>致命组合--利用IDOR实现CSRF攻击</title>
    <link>https://gugesay.com/blog/致命组合-利用idor实现csrf攻击</link>
    undefined
    <pubDate>Wed, 11 Jan 2023 02:03:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/越权拿下超级管理员权限</guid>
    <title>一个简单的越权漏洞成功拿下Admin权限</title>
    <link>https://gugesay.com/blog/越权拿下超级管理员权限</link>
    undefined
    <pubDate>Tue, 05 Sep 2023 03:17:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/远程文件包含（rfi）小技巧</guid>
    <title>远程文件包含（RFI）小技巧</title>
    <link>https://gugesay.com/blog/远程文件包含（rfi）小技巧</link>
    undefined
    <pubDate>Sun, 22 Oct 2023 13:10:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>RFI</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/逆向分析混淆-js-代码处理签名哈希并实现工具化</guid>
    <title>手把手逆向分析混淆 JS 代码&amp;amp;处理签名哈希并实现工具化</title>
    <link>https://gugesay.com/blog/逆向分析混淆-js-代码处理签名哈希并实现工具化</link>
    undefined
    <pubDate>Tue, 23 Jan 2024 01:37:29 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>工具</category><category>白帽故事</category><category>逆向分析</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-js-文件实现bypass管理面板</guid>
    <title>通过 JS 文件实现Bypass管理面板</title>
    <link>https://gugesay.com/blog/通过-js-文件实现bypass管理面板</link>
    undefined
    <pubDate>Tue, 10 May 2022 01:48:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-pdf-打印功能利用ssrf访问内部数据</guid>
    <title>通过 PDF 打印功能利用SSRF访问内部数据</title>
    <link>https://gugesay.com/blog/通过-pdf-打印功能利用ssrf访问内部数据</link>
    undefined
    <pubDate>Tue, 26 Nov 2024 01:02:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>pdf</category><category>ssrf</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过-url-解析器绕过-csp-混淆，实现-netlify-cdn-上的xss</guid>
    <title>绕过 CSP，实现 Netlify CDN 上XSS</title>
    <link>https://gugesay.com/blog/通过-url-解析器绕过-csp-混淆，实现-netlify-cdn-上的xss</link>
    undefined
    <pubDate>Thu, 19 Sep 2024 07:33:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csp bypass</category><category>Netlify</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过反向代理劫持oauth代码的账户接管之旅</guid>
    <title>通过反向代理劫持OAuth代码的帐户接管之旅</title>
    <link>https://gugesay.com/blog/通过反向代理劫持oauth代码的账户接管之旅</link>
    undefined
    <pubDate>Wed, 29 Nov 2023 12:57:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>OAuth</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过更改logo进行命令注入的故事</guid>
    <title>通过更改LOGO进行命令注入的故事</title>
    <link>https://gugesay.com/blog/通过更改logo进行命令注入的故事</link>
    undefined
    <pubDate>Mon, 06 Mar 2023 02:17:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>命令注入</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过重置密码token泄露收获e2500赏金</guid>
    <title>通过重置密码token泄露收获€2500赏金</title>
    <link>https://gugesay.com/blog/通过重置密码token泄露收获e2500赏金</link>
    undefined
    <pubDate>Wed, 03 Apr 2024 01:11:57 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>ATO</category><category>bugbounty</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/重置密码绕过的n种利用姿势</guid>
    <title>重置密码绕过的N种利用姿势</title>
    <link>https://gugesay.com/blog/重置密码绕过的n种利用姿势</link>
    undefined
    <pubDate>Tue, 09 Apr 2024 01:38:05 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>idor</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉-apple-系列-从-sql-注入到远程代码执行</guid>
    <title>黑掉 Apple 系列 - 从 SQL 注入到远程代码执行</title>
    <link>https://gugesay.com/blog/黑掉-apple-系列-从-sql-注入到远程代码执行</link>
    undefined
    <pubDate>Thu, 09 May 2024 03:13:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>rce</category><category>sqli</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa【1】：从发现漏洞到荣登名人堂之旅</guid>
    <title>‘黑掉NASA’【1】：从发现漏洞到荣登名人堂之旅</title>
    <link>https://gugesay.com/blog/黑掉nasa【1】：从发现漏洞到荣登名人堂之旅</link>
    undefined
    <pubDate>Fri, 30 Aug 2024 07:45:11 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa【2】：从发现漏洞到荣登名人堂之旅</guid>
    <title>‘黑掉NASA’【2】：从发现漏洞到荣登名人堂之旅</title>
    <link>https://gugesay.com/blog/黑掉nasa【2】：从发现漏洞到荣登名人堂之旅</link>
    undefined
    <pubDate>Fri, 30 Aug 2024 08:04:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/黑掉nasa：ssrf、子域接管以及xss</guid>
    <title>‘黑掉’NASA：SSRF、子域接管以及XSS</title>
    <link>https://gugesay.com/blog/黑掉nasa：ssrf、子域接管以及xss</link>
    undefined
    <pubDate>Sun, 02 Jun 2024 14:40:59 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Hacking NASA</category><category>白帽故事</category>
  </item>

    </channel>
  </rss>
