DiceCTF 2024 Quals Write-Up
Write-up forDiceCTF 2024 Quals (dicedicegoose, funnylogin, gpwaf, calculator, dicequest, three, C(OOO)RCPU).
Computer Organization and Design 第二章学习笔记
《Computer Organization and Design RISC-V Edition: The Hardware/Software Interface (2nd Edition)》第二章“Instructions: Language of the Computer” 的学习笔记。
CNATDA 第七章学习笔记
《Computer Networking: A Top-Down Approach (8th Edition)》第七章“Wireless and Mobile Networks” 的学习笔记。
CVE-2023-41054 漏洞分析
LibreX/Y 对 URL host 的错误解析导致了 SSRF 漏洞,攻击者可以绕过对 host 的检查向任意 URL 发送 GET request 并获取 response body,从而访问内网资源或进行 DoS 攻击。