h4fan
blog about security, tech...
  • Index
  • Tags
  • Archive
  • Tech
  • HackerDefense
  • FabDefense
  • Tools

h4fan security

blog about security, tech

2026-07-22

interesting tagName xss payload

Gareth Heyes发了一个有意思的xss payload,<alert(1) onfocus="attributes[0].value=localName,new onfocus" autofocus tabindex=1>。试了一下,确实可以执行。
security xss
阅读全文 →
2026-06-08

学习Device Bound Session Credentials

Device Bound Session Credentials,通过使用设备端的Private Key来验证当前设备与Session Cookie的关系,削弱Cookie窃取的危害。
security cookie
阅读全文 →
2026-05-29

用AI重新发现CVE-2026-26980

出乎意料,一句话prompt,它真的重新发现了。
security ai
阅读全文 →
2026-05-28

用AI复现分析CVE-2026-32316

最近看到anthropic公布了claude mythos发现的漏洞列表,于是尝试用DeepSeek“复现”是否也能分析出来。
security ai
阅读全文 →
2026-05-16

修复被更新坏了的系统

打开一台Linux虚拟机,更新完系统之后,无法进行系统了。
linux
阅读全文 →
2026-05-16

AI将加速漏洞发现过程

最近关于Claude Mython Preview和GPT 5.5的文章变多了,从各篇评测文章来看,AI发现或者协助发现漏洞的过程正在加速。
security ai
阅读全文 →
← 上一页 下一页 →

© 2026 h4fan  ·  基于 Beautiful Jekyll 重新设计