<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>PCAP | baozongwi's blog</title><link>https://baozongwi.xyz/tags/pcap/</link><description>Currently exploring Java security and internal network penetration, with CTFs as a hobby.</description><generator>Hugo</generator><language>zh-cn</language><item><title>玄机第六章</title><link>https://baozongwi.xyz/p/xuanji-chapter-6/</link><pubDate>Wed, 09 Apr 2025 16:11:44 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-6/</guid><description>第六章 流量特征分析-蚁剑流量分析 直接拿到一个流量包，去peterpan博客偷点知识 1. 基本过滤器 过滤HTTP状态码200： http.response.code == 200 过滤HTTP GET请求： http.request.method == "GET" 2. IP 地址过滤 过滤特定源IP地址的流量： …</description></item><item><title>铁三2024</title><link>https://baozongwi.xyz/p/iron-three-2024/</link><pubDate>Sun, 15 Dec 2024 21:24:24 +0000</pubDate><guid>https://baozongwi.xyz/p/iron-three-2024/</guid><description>怎么什么都是我一个人在干</description></item><item><title>记一次文件上传</title><link>https://baozongwi.xyz/p/file-upload-case-study/</link><pubDate>Tue, 17 Sep 2024 21:36:55 +0000</pubDate><guid>https://baozongwi.xyz/p/file-upload-case-study/</guid><description>0x01 前言 之前一般遇到的文件上传，仅仅考虑header等操作就可以了，但是前几天却遇到了一个与流量包相关联的，那么，让我想起了墨者杯，顺便也来记录一下 0x02 question 这道题目，是和一个师傅交流之后(由于没有电脑)，由那位师傅打通 whereisfilepath 既然是文件上传而且给了流量包，我们先看 …</description></item><item><title>bsidescf2020</title><link>https://baozongwi.xyz/p/bsidescf2020/</link><pubDate>Wed, 21 Aug 2024 15:56:14 +0000</pubDate><guid>https://baozongwi.xyz/p/bsidescf2020/</guid><description>[BSidesCF 2020]Bulls23 先搞下来，解压发现是个html 本地搞个html网页来加载发现可以登录 发现第一个链接就是 http://bash.org/?random 找到是websocket流量 发现第二个链接 http://n-gate.com 中途发现端口是8888 但还是不懂，说的要追踪TCP …</description></item></channel></rss>