|
Never Trust the Output: Data Pollution in AI Agents and MCP
|
https://blog.slonser.info/posts/smugglle...
|
mcp
agent
|
使用不可回显字符,<ERROR>等欺骗AI输出,导致信息泄露
|
|
Chrome Browser Exploitation, Part 3: Analyzing and Exploiting CVE-2018-17463
|
https://jhalon.github.io/chrome-browser-...
|
v8
|
chrome v8 漏洞学习 part 3
|
|
Chrome Browser Exploitation, Part 2: Introduction to Ignition, Sparkplug and JIT Compilation via TurboFan
|
https://jhalon.github.io/chrome-browser-...
|
v8
|
chrome v8 漏洞学习 part 2
|
|
Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals
|
https://jhalon.github.io/chrome-browser-...
|
v8
|
chrome v8 漏洞学习 part 1
|
|
We Hacked Apple for 3 Months: Here’s What We Found
|
https://samcurry.net/hacking-apple
|
案例
|
apple漏洞案例
|
|
XSS深度解析
|
https://aszx87410.github.io/beyond-xss/
|
xss
|
xss全系列讲解
|
|
Make Self-XSS Great Again
|
https://blog.slonser.info/posts/make-sel...
|
self-xss
|
self-xss的利用
|