<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web漏洞 :: 标签 :: x7peeps</title><link>https://x7peeps.com/tags/Web%E6%BC%8F%E6%B4%9E/index.html</link><description/><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Sat, 13 Jun 2026 13:40:32 +0800</lastBuildDate><atom:link href="https://x7peeps.com/tags/Web%E6%BC%8F%E6%B4%9E/index.xml" rel="self" type="application/rss+xml"/><item><title>SQL注入漏洞利用与盲注技术分析</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E4%B8%8E%E7%9B%B2%E6%B3%A8%E6%8A%80%E6%9C%AF%E5%88%86%E6%9E%90/index.html</link><pubDate>Fri, 12 Jun 2026 11:16:51 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E4%B8%8E%E7%9B%B2%E6%B3%A8%E6%8A%80%E6%9C%AF%E5%88%86%E6%9E%90/index.html</guid><description>围绕SQL注入漏洞利用与盲注相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>SSRF漏洞利用与内网服务劫持</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/SSRF%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E4%B8%8E%E5%86%85%E7%BD%91%E6%9C%8D%E5%8A%A1%E5%8A%AB%E6%8C%81/index.html</link><pubDate>Fri, 12 Jun 2026 11:16:51 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/SSRF%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E4%B8%8E%E5%86%85%E7%BD%91%E6%9C%8D%E5%8A%A1%E5%8A%AB%E6%8C%81/index.html</guid><description>围绕SSRF漏洞利用与内网服务劫持相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>XSS漏洞深度利用与CSRF攻击链构造</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/XSS%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8%E4%B8%8ECSRF%E6%94%BB%E5%87%BB%E9%93%BE%E6%9E%84%E9%80%A0/index.html</link><pubDate>Fri, 12 Jun 2026 11:16:51 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/XSS%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8%E4%B8%8ECSRF%E6%94%BB%E5%87%BB%E9%93%BE%E6%9E%84%E9%80%A0/index.html</guid><description>围绕XSS漏洞深度利用与CSRF攻击链构造相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>文件上传与解析机制漏洞利用技术</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E4%B8%8E%E8%A7%A3%E6%9E%90%E6%9C%BA%E5%88%B6%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E6%8A%80%E6%9C%AF/index.html</link><pubDate>Fri, 12 Jun 2026 13:21:38 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E4%B8%8E%E8%A7%A3%E6%9E%90%E6%9C%BA%E5%88%B6%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E6%8A%80%E6%9C%AF/index.html</guid><description>围绕文件上传与解析机制漏洞相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>命令执行与代码注入实战突破</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E4%B8%8E%E4%BB%A3%E7%A0%81%E6%B3%A8%E5%85%A5%E5%AE%9E%E6%88%98%E7%AA%81%E7%A0%B4/index.html</link><pubDate>Fri, 12 Jun 2026 12:44:31 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E4%B8%8E%E4%BB%A3%E7%A0%81%E6%B3%A8%E5%85%A5%E5%AE%9E%E6%88%98%E7%AA%81%E7%A0%B4/index.html</guid><description>围绕命令执行与代码注入相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>反序列化漏洞利用链与内存马注入</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E9%93%BE%E4%B8%8E%E5%86%85%E5%AD%98%E9%A9%AC%E6%B3%A8%E5%85%A5/index.html</link><pubDate>Fri, 12 Jun 2026 12:45:11 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E9%93%BE%E4%B8%8E%E5%86%85%E5%AD%98%E9%A9%AC%E6%B3%A8%E5%85%A5/index.html</guid><description>围绕反序列化漏洞利用链与内存马注入相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>Spring Boot Actuator与Jolokia未授权访问打点利用技术</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/Spring_Boot_Actuator%E4%B8%8EJolokia%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%89%93%E7%82%B9%E5%88%A9%E7%94%A8%E6%8A%80%E6%9C%AF/index.html</link><pubDate>Sat, 13 Jun 2026 13:40:32 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/Spring_Boot_Actuator%E4%B8%8EJolokia%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%89%93%E7%82%B9%E5%88%A9%E7%94%A8%E6%8A%80%E6%9C%AF/index.html</guid><description>围绕Spring Boot Actuator与Jolokia相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>XXE与文件包含漏洞深度利用</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/XXE%E4%B8%8E%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8/index.html</link><pubDate>Fri, 12 Jun 2026 12:45:41 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/XXE%E4%B8%8E%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8/index.html</guid><description>围绕XXE与文件包含漏洞相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>身份认证绕过与越权访问漏洞深度利用</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E4%B8%8E%E8%B6%8A%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8/index.html</link><pubDate>Fri, 12 Jun 2026 13:22:26 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E4%B8%8E%E8%B6%8A%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%E6%B7%B1%E5%BA%A6%E5%88%A9%E7%94%A8/index.html</guid><description>围绕身份认证绕过与越权访问漏洞相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>服务端模板注入(SSTI)沙箱逃逸技术</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%9C%8D%E5%8A%A1%E7%AB%AF%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5SSTI%E6%B2%99%E7%AE%B1%E9%80%83%E9%80%B8%E6%8A%80%E6%9C%AF/index.html</link><pubDate>Fri, 12 Jun 2026 13:22:57 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%9C%8D%E5%8A%A1%E7%AB%AF%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5SSTI%E6%B2%99%E7%AE%B1%E9%80%83%E9%80%B8%E6%8A%80%E6%9C%AF/index.html</guid><description>围绕服务端模板注入(SSTI)沙箱逃逸技术相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>HTTP请求走私与Web缓存投毒攻击</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/HTTP%E8%AF%B7%E6%B1%82%E8%B5%B0%E7%A7%81%E4%B8%8EWeb%E7%BC%93%E5%AD%98%E6%8A%95%E6%AF%92%E6%94%BB%E5%87%BB/index.html</link><pubDate>Fri, 12 Jun 2026 13:23:28 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/HTTP%E8%AF%B7%E6%B1%82%E8%B5%B0%E7%A7%81%E4%B8%8EWeb%E7%BC%93%E5%AD%98%E6%8A%95%E6%AF%92%E6%94%BB%E5%87%BB/index.html</guid><description>围绕HTTP请求走私与Web缓存投毒攻击相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item><item><title>新型API架构与云原生Web攻防实战</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%96%B0%E5%9E%8BAPI%E6%9E%B6%E6%9E%84%E4%B8%8E%E4%BA%91%E5%8E%9F%E7%94%9FWeb%E6%94%BB%E9%98%B2%E5%AE%9E%E6%88%98/index.html</link><pubDate>Fri, 12 Jun 2026 13:24:08 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/04-%E6%B8%97%E9%80%8F%E6%94%BB%E5%87%BB/%E6%96%B0%E5%9E%8BAPI%E6%9E%B6%E6%9E%84%E4%B8%8E%E4%BA%91%E5%8E%9F%E7%94%9FWeb%E6%94%BB%E9%98%B2%E5%AE%9E%E6%88%98/index.html</guid><description>围绕新型API架构与云原生Web相关攻击面与利用路径，分析打点识别、接口枚举、风险链条、日志痕迹与防守处置思路。</description></item></channel></rss>