Skip to content
Panda's Blog
Home
Search
Menu
Home
Search
中
Article list
2026
Twenty Years of Java Security: Reading the Trend Through Two Decades of Black Hat Talks
August 2026
When Security Research Enters the AI Era
August 2026
2025
React2Shell Analysis
December 2025
2024
Behind the Design of ByteCTF's Guess Cookie Challenge
October 2024
Common Tricks for Auditing Spring Applications
October 2024
2023
MyBatis: From SQL Injection to OGNL Injection
March 2023
2022
Analyzing Spring Framework RCE from the Ground Up
April 2022
From SSRF to RCE: Analyzing the Spring Cloud Gateway RCE Vulnerability
March 2022
Vulnerability Analysis of fastjson 1.2.68 and Earlier
March 2022
2021
A Discussion of Configuration-File RCE
December 2021
A Discussion of Limited RCE in log4j 1.x and Logback
December 2021
Analysis of the log4j2 JNDI Injection Vulnerability
December 2021
Analyzing Thymeleaf SSTI and Bypassing the Latest Fix
November 2021
Java Code Auditing for Beginners 06: File Inclusion Vulnerabilities and Real-World Cases
November 2021
JVM Bytecode Notes: The Class File Structure
September 2021
My New Book: Java Code Auditing for Beginners
July 2021
Understanding the Native JDK 8u20 Deserialization Vulnerability Through a Case Study
June 2021
The Fundamentals of JEP 290
June 2021
A Study of the Deserialization Process
June 2021
Follow My WeChat Official Account
June 2021
A Study of the Serialization Process
June 2021
Notes on the Object Serialization Stream Protocol
June 2021
Notes on the JDK 7u21 Deserialization Vulnerability
June 2021
WeEngine CMS: From SQL Injection to RCE
May 2021
2020
Analyzing Remote Code Execution in Qishi CMS
November 2020
Notes on PHP's register_argc_argv Configuration
October 2020
Getting a Shell from a Low-Privilege FastAdmin Admin Account
October 2020
Analyzing a Front-End Shell Upload Vulnerability in the Latest FastAdmin
September 2020
Java Code Auditing for Beginners 05: RCE Vulnerabilities and Real-World Cases
July 2020
T-Star University Challenge Writeup
July 2020
Front-End Injection Vulnerability in the Latest SeaCMS
June 2020
Java Code Auditing Fundamentals: The Java Reflection Mechanism
June 2020
Security Issues Caused by Delimiters
April 2020
Java Code Auditing for Beginners 04: SSRF Vulnerabilities and Real-World Cases
January 2020
CVE-2019-2729 Exploit Script
January 2020
Analyzing the 800,000-Character RCE in maccms v8
January 2020
2019
First Impressions of the XRAY Vulnerability Scanner
December 2019
Research on SQL Injection in phpMyAdmin's Designer Feature (CVE-2019-18622)
December 2019
Java Code Auditing for Beginners 03: XSS Vulnerabilities and Real-World Cases
December 2019
Java Code Auditing for Beginners 02: SQL Injection and Real-World Cases
December 2019
Getting Started with Industrial Control System Security
December 2019
A Brief Look at Prepared Statements in Java
November 2019
Java Code Auditing for Beginners 01: Preparing for an Audit
November 2019
Spring Study Notes: IoC
November 2019
Understanding PHP Session Deserialization Vulnerabilities
November 2019
Understanding the S7COMM and Modbus Industrial Protocols
October 2019
2019 Industrial Information Security Competition Recap
October 2019
Running a Discourse Community Locally
August 2019
SUCTF Web Challenge Reproduction Notes
August 2019
Notes on Problems Installing a Cracked AWVS for Linux on CentOS 7
August 2019
Selected Writeups from NISC CTF 2019
August 2019
Solving a Covert-Channel Data Analysis Challenge from an ICS CTF
August 2019
Writeup for a CTF Challenge Based on the MMS Industrial Protocol
July 2019
A Technical Discussion Prompted by PHP's filter_var()
June 2019
Reflections on PHP Security Calendar 2017
June 2019
Fixing Problems After Migrating Typecho
June 2019
Paper Notes: REDQUEEN — Fuzzing with Input-to-State Correspondence
June 2019
Paper Notes: CollAFL — Path-Sensitive Fuzzing
May 2019
Paper Notes: Coverage-Based Greybox Fuzzing as a Markov Chain
May 2019
Code Auditing in Theory and Practice: SQL, Part 1
April 2019
Finding a CSRF Vulnerability in a CMS
April 2019
2018
Fixing Microsoft VBScript Runtime Error '800a0009': Subscript Out of Range '[number: 1]'
July 2018
Study Notes on Support Vector Machines
January 2018
2017
Selected WEB Solutions from Shiyanbar
December 2017
A Form-Based PoC for Posting JSON Data in a CSRF Attack
December 2017
Testing Slow HTTP Denial-of-Service Attacks with slowhttptest
December 2017
Auditing ZZCMS v8.1
December 2017
Selected Web Writeups from the 10th National Information Security Competition
December 2017
Selected GCTF Web Writeups
December 2017
Analyzing and Fixing a Basic-Authentication Phishing Vulnerability in Discuz! 3.2
December 2017
CVE-2017-9603 Analysis
December 2017
A Comprehensive Audit of AppCms
December 2017