<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>DuckDB | baozongwi's blog</title><link>https://baozongwi.xyz/tags/duckdb/</link><description>Currently exploring Java security and internal network penetration, with CTFs as a hobby.</description><generator>Hugo</generator><language>zh-cn</language><item><title>HKCERTCTF 2025</title><link>https://baozongwi.xyz/p/hkcertctf-2025/</link><pubDate>Mon, 22 Dec 2025 01:16:06 +0800</pubDate><guid>https://baozongwi.xyz/p/hkcertctf-2025/</guid><description>renderme thinkphp 的模板注入，测试了一下，参数带外可以放恶意函数，解析的话，ThinkPHP 模板引擎支持 {$var|function}的语法，语法结构为{$待处理变量|函数名}，发现 choom 进行 suid 提权 …</description></item></channel></rss>