<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://fewftybet.github.io/</id><title>DIger's Blog</title><subtitle>A personal blog built with Jekyll and the Chirpy theme, hosted on GitHub Pages.</subtitle> <updated>2026-07-24T21:53:35+08:00</updated> <author> <name>DIger</name> <uri>https://fewftybet.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://fewftybet.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="zh-CN" href="https://fewftybet.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 DIger </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>MSF内网渗透与横向移动</title><link href="https://fewftybet.github.io/posts/msf-lateral-movement/" rel="alternate" type="text/html" title="MSF内网渗透与横向移动" /><published>2026-07-23T14:00:00+08:00</published> <updated>2026-07-23T18:03:53+08:00</updated> <id>https://fewftybet.github.io/posts/msf-lateral-movement/</id> <content type="text/html" src="https://fewftybet.github.io/posts/msf-lateral-movement/" /> <author> <name>DIger</name> </author> <category term="工具速查" /> <category term="MSF利用" /> <summary>MSF 内网渗透全流程，涵盖路由转发、内网扫描、SOCKS代理、凭证提取、哈希传递攻击等横向移动核心技术。</summary> </entry> <entry><title>MSF提权与权限维持（含Docker逃逸）</title><link href="https://fewftybet.github.io/posts/msf-privilege-escalation/" rel="alternate" type="text/html" title="MSF提权与权限维持（含Docker逃逸）" /><published>2026-07-23T13:00:00+08:00</published> <updated>2026-07-23T18:03:53+08:00</updated> <id>https://fewftybet.github.io/posts/msf-privilege-escalation/</id> <content type="text/html" src="https://fewftybet.github.io/posts/msf-privilege-escalation/" /> <author> <name>DIger</name> </author> <category term="工具速查" /> <category term="MSF利用" /> <summary>MSF 后渗透实战，涵盖Windows/Linux自动化提权、凭证窃取、持久化后门、Docker容器逃逸等核心技术。</summary> </entry> <entry><title>MSF Payload生成与监听配置</title><link href="https://fewftybet.github.io/posts/msf-exploitation/" rel="alternate" type="text/html" title="MSF Payload生成与监听配置" /><published>2026-07-23T12:00:00+08:00</published> <updated>2026-07-23T18:03:53+08:00</updated> <id>https://fewftybet.github.io/posts/msf-exploitation/</id> <content type="text/html" src="https://fewftybet.github.io/posts/msf-exploitation/" /> <author> <name>DIger</name> </author> <category term="工具速查" /> <category term="MSF利用" /> <summary>msfvenom 实战指南，涵盖Windows/Linux/WebShell/正向反向Payload生成、编码器免杀、以及multi/handler监听配置全流程。</summary> </entry> <entry><title>Web中间件安全基线与加固指南（安服视角）</title><link href="https://fewftybet.github.io/posts/web-middleware-security-hardening/" rel="alternate" type="text/html" title="Web中间件安全基线与加固指南（安服视角）" /><published>2026-07-23T09:00:00+08:00</published> <updated>2026-07-24T21:53:01+08:00</updated> <id>https://fewftybet.github.io/posts/web-middleware-security-hardening/</id> <content type="text/html" src="https://fewftybet.github.io/posts/web-middleware-security-hardening/" /> <author> <name>DIger</name> </author> <category term="经验分享" /> <category term="安全基线与加固" /> <summary>从安服视角出发，系统梳理Nginx、Tomcat、Apache、IIS、Redis、RabbitMQ等常见Web中间件的安全基线与加固方案，涵盖配置规范、访问控制、日志审计等核心维度。</summary> </entry> <entry><title>数据库安全基线检查与加固指南（安服视角）</title><link href="https://fewftybet.github.io/posts/database-security-baseline-hardening/" rel="alternate" type="text/html" title="数据库安全基线检查与加固指南（安服视角）" /><published>2026-07-16T12:20:00+08:00</published> <updated>2026-07-24T21:11:36+08:00</updated> <id>https://fewftybet.github.io/posts/database-security-baseline-hardening/</id> <content type="text/html" src="https://fewftybet.github.io/posts/database-security-baseline-hardening/" /> <author> <name>DIger</name> </author> <category term="经验分享" /> <category term="安全基线与加固" /> <summary>本文档从安全服务（安服）专业视角出发，依据等级保护2.0三级标准与CIS Benchmark数据库基线，围绕身份鉴别、访问控制、安全审计、资源控制、剩余信息保护、入侵防范、恶意代码防范七大维度，系统性梳理MySQL、Microsoft SQL Server（MSSQL）、Oracle三大主流数据库的安全基线检查与加固方案。</summary> </entry> </feed>
