Article list

2026

Twenty Years of Java Security: Reading the Trend Through Two Decades of Black Hat Talks When Security Research Enters the AI Era

2025

React2Shell Analysis

2024

Behind the Design of ByteCTF's Guess Cookie Challenge Common Tricks for Auditing Spring Applications

2023

MyBatis: From SQL Injection to OGNL Injection

2022

Analyzing Spring Framework RCE from the Ground Up From SSRF to RCE: Analyzing the Spring Cloud Gateway RCE Vulnerability Vulnerability Analysis of fastjson 1.2.68 and Earlier

2021

A Discussion of Configuration-File RCE A Discussion of Limited RCE in log4j 1.x and Logback Analysis of the log4j2 JNDI Injection Vulnerability Analyzing Thymeleaf SSTI and Bypassing the Latest Fix Java Code Auditing for Beginners 06: File Inclusion Vulnerabilities and Real-World Cases JVM Bytecode Notes: The Class File Structure My New Book: Java Code Auditing for Beginners Understanding the Native JDK 8u20 Deserialization Vulnerability Through a Case Study The Fundamentals of JEP 290 A Study of the Deserialization Process Follow My WeChat Official Account A Study of the Serialization Process Notes on the Object Serialization Stream Protocol Notes on the JDK 7u21 Deserialization Vulnerability WeEngine CMS: From SQL Injection to RCE

2020

Analyzing Remote Code Execution in Qishi CMS Notes on PHP's register_argc_argv Configuration Getting a Shell from a Low-Privilege FastAdmin Admin Account Analyzing a Front-End Shell Upload Vulnerability in the Latest FastAdmin Java Code Auditing for Beginners 05: RCE Vulnerabilities and Real-World Cases T-Star University Challenge Writeup Front-End Injection Vulnerability in the Latest SeaCMS Java Code Auditing Fundamentals: The Java Reflection Mechanism Security Issues Caused by Delimiters Java Code Auditing for Beginners 04: SSRF Vulnerabilities and Real-World Cases CVE-2019-2729 Exploit Script Analyzing the 800,000-Character RCE in maccms v8

2019

First Impressions of the XRAY Vulnerability Scanner Research on SQL Injection in phpMyAdmin's Designer Feature (CVE-2019-18622) Java Code Auditing for Beginners 03: XSS Vulnerabilities and Real-World Cases Java Code Auditing for Beginners 02: SQL Injection and Real-World Cases Getting Started with Industrial Control System Security A Brief Look at Prepared Statements in Java Java Code Auditing for Beginners 01: Preparing for an Audit Spring Study Notes: IoC Understanding PHP Session Deserialization Vulnerabilities Understanding the S7COMM and Modbus Industrial Protocols 2019 Industrial Information Security Competition Recap Running a Discourse Community Locally SUCTF Web Challenge Reproduction Notes Notes on Problems Installing a Cracked AWVS for Linux on CentOS 7 Selected Writeups from NISC CTF 2019 Solving a Covert-Channel Data Analysis Challenge from an ICS CTF Writeup for a CTF Challenge Based on the MMS Industrial Protocol A Technical Discussion Prompted by PHP's filter_var() Reflections on PHP Security Calendar 2017 Fixing Problems After Migrating Typecho Paper Notes: REDQUEEN — Fuzzing with Input-to-State Correspondence Paper Notes: CollAFL — Path-Sensitive Fuzzing Paper Notes: Coverage-Based Greybox Fuzzing as a Markov Chain Code Auditing in Theory and Practice: SQL, Part 1 Finding a CSRF Vulnerability in a CMS

2018

Fixing Microsoft VBScript Runtime Error '800a0009': Subscript Out of Range '[number: 1]' Study Notes on Support Vector Machines

2017

Selected WEB Solutions from Shiyanbar A Form-Based PoC for Posting JSON Data in a CSRF Attack Testing Slow HTTP Denial-of-Service Attacks with slowhttptest Auditing ZZCMS v8.1 Selected Web Writeups from the 10th National Information Security Competition Selected GCTF Web Writeups Analyzing and Fixing a Basic-Authentication Phishing Vulnerability in Discuz! 3.2 CVE-2017-9603 Analysis A Comprehensive Audit of AppCms