Telegram RegisterThe public register of Telegram
Telegram profile photo for Bc渗透劫持|数据入侵提取

Channel

Bc渗透劫持|数据入侵提取

@heikesentou0

On this record: Growth · Engagement · Reactions · Posts · Citations · Cite this entry

8,001subscribers

+426 since we began measuring on 7 August 2026

Risers and fallers across the register · movement among entries of 3,162–10,000.

Register entry

Telegram ID-1002252800474
TypeChannel
Username@heikesentou0
CreatedBetween 1 October 2024 and 31 March 2025— estimated from Telegram’s id allocation, not measured. How this range is calculated.
First recorded7 August 2026
Last confirmed live30 August 2026
Measurements held10
Confirmed unchanged1 time, most recently 30 August 2026
On Telegramt.me/heikesentou0

Growth

6,4028,2187,3107 August 2026 — 7,575 subscribers7 August 2026 — 7,575 subscribers7 August 2026 — 7,556 subscribers10 August 2026 — 7,298 subscribers14 August 2026 — 7,073 subscribers17 August 2026 — 6,861 subscribers20 August 2026 — 6,657 subscribers24 August 2026 — 6,402 subscribers27 August 2026 — 8,218 subscribers30 August 2026 — 8,001 subscribers8,0017 August 202630 August 2026
10 measurements spanning 23 days, net +426. Dots are measurements; the straight line between them is drawn to join them, not to claim we know the path taken in between — snapshots are recorded only when a count changes, so gaps mean “no change observed”, never “interpolated”. The vertical axis spans 6,130–8,490 and does not start at zero.
Measurement log — every subscribers count we have recorded
Measured (UTC)SubscribersChange
30 Aug 2026, 14:458,001-217
27 Aug 2026, 11:338,218+1,816
24 Aug 2026, 01:466,402-255
20 Aug 2026, 18:526,657-204
17 Aug 2026, 15:056,861-212
14 Aug 2026, 01:487,073-225
10 Aug 2026, 23:077,298-258
7 Aug 2026, 21:367,556-19
7 Aug 2026, 18:317,575no change
7 Aug 2026, 18:237,575first reading

Engagement

22 posts held, back to 17 July 2026the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 13 pagesof Telegram’s post history, 20 posts per page.

ERR · 30 days
0.564%
avg views ÷ 8,001 subscribers
Avg views / post
45.2
13 posts measured
Reaction rate
this channel exposes no reaction counts
Posts in window
13
of 22 held

ERR is average views per post over the last 30 days divided by subscribers, the definition TGStat uses, so this figure is comparable with the one you will see elsewhere. It falls structurally as a channel grows: a high ERR on a small channel and a low one on a large channel describe reach mathematics, not quality. We publish the figure and the sample it came from and pass no verdict on it.

ER is defined industry-wide as (forwards + reactions + comments) ÷ views— note the denominator is views, not subscribers. Telegram’s public web preview carries views and reactions but not forward or comment counts, so the reaction rate above is the reactions term only and is therefore a floor: the true ER for this channel is higher by an amount we have not measured and will not estimate.

What these figures were computed from
WindowRolling 30 days · latest post in window 28 August 2026
Posts held22 (17 July 202628 August 2026)
Views total587
Reactions total
Forwards / commentsnot exposed by the public surface — not measured, not estimated
Readings taken28 Aug 2026, 18:18 UTC

Views are a single reading per post, taken at the time above. A post published in the last day or two is still accumulating views, which pulls the 30-day average down slightly. That is a property of the standard definition rather than a fault in it, so we keep the definition rather than “correcting” the number into something nobody can reproduce.

Precision. Telegram publishes view counts on its public widget in short form — 8.12K, 3.7M — so any reading at or above 1,000 reaches us rounded to three significant figures, and only counts below 1,000 are exact. Averages and rates derived from them are shown to the same precision rather than to the unit: a figure like 3,701,250 would assert digits nobody measured.

Reaction counts are published per emoji and rounded the same way, so a total below 1,000 is exact and a larger one is a sum that may carry a rounded component from each emoji above 1,000. Because it is a sum, it does not look rounded — read a large reaction total as three significant figures per contributing emoji rather than as the figure it prints.

Reaction mix

2 reactions across 2 posts, in 1 kind.

Every reaction kind recorded on the sample, most used first
ReactionCountShareShare, drawn
2100.0%

No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.

Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.

Coverage. Reactions were read on 3 of the 22 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 2reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.

Measured over the 22 most recent posts we hold, published 17 July 2026 to 28 August 2026, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.

Recent posts

28 Aug 2026, 16:19 UTC3 viewsread 28 August 2026
Photo

在handle_connect和authentic相关的时候,会执行mosquitto_security_auth_start,通过返回值rc确定数据流 其中mosquitto_security_auth_start 调用auth_start_v4相关 由此可知这个方法恒定返回MOSQ_ERR_SUCCESS,之后会调用到connect__on_authorised,里面的connection_check_acl再调用mosquitto_acl_check函数对权限进行检测 之后的mosquitto_acl_check函数会去配置信息,再根据策略去执行相关的认证函数。 渗透站点 密码爆破 数据劫持 数据库脱库 劫持/渗透业务:@Aboutthi9vv

26 Aug 2026, 16:18 UTC23 viewsread 28 August 2026
Photo

INITPARSE()是一个在 中定义的函数PEFILE.cpp。 它的唯一作用是验证给定的文件是否为 PE 文件,然后确定该文件是PE32还是PE32+。 它读取文件的 DOS 标头并检查 DOS MZ 标头,如果未找到则返回错误。 验证 PE 文件后,它将文件位置设置为(DOS_HEADER.e_lfanew+ PE 签名大小DWORD+ 文件头大小),即可选头起始位置的精确偏移量。 然后,它读取一个值WORD,我们知道WORD可选头的第一个字符是一个指示文件类型的“魔数”,接着它将该值与“IMAGE_NT_OPTIONAL_HDR32_MAGIC或”进行比较IMAGE_NT_OPTIONAL_HDR64_MAGIC,并根据比较结果返回“32或”64表示PE32“或” PE32+,或者返回错误。 渗透站点 密码爆破 数据劫持 数据库脱库 劫持/渗透业务:@Aboutthi9vv

24 Aug 2026, 16:23 UTC30 viewsread 28 August 2026
Photo

Apache httpd对CVE-2022-26377的描述中指出, “Apache HTTP Server的mod_proxy_ajp存在不一致的HTTP请求解释('HTTP Request Smuggling')漏洞,允许攻击者将请求走私到其转发请求的 AJP 服务器。此问题影响 Apache HTTP Server 2.4 版本 2.4.53 及之前的版本。” 我们希望在F5 httpd服务上发现一个请求走私问题,以提供所需的绕过身份验证来完全妥协设备。 从 httpd 服务发送到后端 AJP 侦听器的二进制 AJP 消息以字节“0x12”“0x34”开头,后跟两字节消息长度,最后是“数据”。消息的第 5 个字节包含“Code”,该值确定 AJP 请求的类型。HTTP 转发请求的代码是值“0x2”。HTTP 转发请求的第 6 个字节对请求的 HTTP进行编码。GET请求是 0x2,POST 请求是 0x4,依此类推。其余消

22 Aug 2026, 16:19 UTC34 viewsread 28 August 2026
Photo

当对 Apache httpd 服务的原始请求包含值为“chunked, chunked”的“Transfer-Encoding”标头时,会出现 CVE-2022-26377。值“chunked, chunked”是有效的“Transfer-Encoding”标头。当Apache接收到同时包含"Transfer-Encoding"和"Content-Length"标头的请求时,它会从发送给后端AJP服务器的请求中移除"Content-Length"头 因此,转发到Apache mod_proxy_ajp的请求不包含“Content-Length”标头。首先,httpd AJP 处理器将请求及其标头发送到后端。然后mod_proxy_ajp检查检查是否存在"Transfer-Encoding"头,以及它是否完全匹配"chunked"。由于它正在处理的标头的“chunked, chunked”值不匹配,因此会继续执行else分支的剩

20 Aug 2026, 16:24 UTC42 viewsread 28 August 2026
Photo

WebSudo 是 Atlassian Confluence 的一项安全功能,在此发挥着至关重要的作用。它要求用户在执行关键操作之前,必须使用提升的权限(通常是密码)重新进行身份验证。 具体来说,WebSudoInterceptor 执行以下检查: 如果请求路径为空/authenticate.action,则跳过该请求。 如果请求路径为空/admin,则检查该WebSudoNotRequired属性是否不为空。 对于其他任何请求路径(例如/json命名空间中的请求路径),它会确保该WebSudoRequired属性为空。此条件表明该WebSudoRequired注解在类、包或方法级别均不存在。如果满足此条件,则会跳过负责启动安全管理会话的 WebSudo 检查。 现在的目标是找出在 HTTP 处理程序方法级别缺少任何授权或身份验证检查的操作(类)。 /admin/后续阶段是对命名空间内的所有端点/操作进行暴力破解/json/。目

18 Aug 2026, 16:26 UTC48 viewsread 28 August 2026
Photo

写完Broker的利用后,又开始思考是否能对Consumer进行攻击,因为漏洞是出现在反序列化阶段的,按理来说Consumer也会存在该漏洞的。且通常来说,Consumer才是部署业务的机器会比起Broker更加核心,通常一个Broker中会接入多个Consumer,如果能控制Consumer那么很可能一次性能控制大量业务机器。但是Consumer在实际使用中,并不会监听端口,那么怎么来给消费者发送恶意数据呢。 ActiveMQ有两种常用的消息模型,点对点、发布/订阅模式。无论是哪种模式,在实际业务中为了持续消费,通常会设置一个监听器,同时让消费者和Broker保持长链接。那么思路就有了,在控制了Broker后,获取到Broker和消费已建立的Socket链接,给消费推恶意数据进行反序列化按理是可以实现利用的。 所以首先要找到已经ESTABLISH的Socket链接 org.apache.activemq.broker.Brok

16 Aug 2026, 16:26 UTC37 viewsread 28 August 2026
Photo

U8cloud 在 web.xml 文件中配置 ServiceDispatcher 的 servlet 映射,URL路由为 /ServiceDispatcherServlet,servlet 命名为 CommonServletDispatcher 。 跟进名为 CommonServletDispatcher 的 servlet ,发现该 servlet 映射到了 nc.bs.framework.comn.serv.CommonServletDispatcher 类中,并在初始化中定义了一个 service 参数 [5] ,该参数映射到了 nc.bs.framework.comn.serv.ServiceDispatcher 类[6]中。 渗透站点 密码爆破 数据劫持 数据库脱库 劫持/渗透业务:@Aboutthi9vv

14 Aug 2026, 16:26 UTC42 viewsread 28 August 2026
Photo

在doGet方法中定义了 label118 的循环体,循环中通过 this.serviceHandler.execCall(request, response); 调用了上文中已经实例化后的 nc.bs.framework.comn.serv.ServiceDispatcher 类的 execCall 方法并传入 request 和 response 。 跟进 ServiceDispatcher 类的 readObject() 方法,该方法首先使用 BufferedInputStream 读取流数据,通过 NetObjectInputStream 类的 readInt 方法对流数据进行移位运算解析得到流的字节长度,对比 BufferedInputStream 类中读取的长度来判断是否为一个正常的可以被 NetObjectInputStream 解析的反序列化流数据。 如果判断是一个可以被 NetObjectInputStream

10 Aug 2026, 16:24 UTC62 viewsread 28 August 2026
Photo

查看“/usr/share/tomcat/conf/server.xml”确认了 Tomcat 上使用了 AJP 连接器,这是请求走私漏洞的先决条件。 我们还观察到Apache httpd配置(/etc/httpd/conf.d/proxy_ajp.conf)使用AJP将请求路由到运行Apache Tomcat应用程序的后端应用程序(参见图2)。 渗透站点 密码爆破 数据劫持 数据库脱库 劫持/渗透业务:@Aboutthi9vv

8 Aug 2026, 16:24 UTC65 viewsread 20 August 2026
Photo

当我们第一次发送此有效负载时,服务器返回登录页面,这是正常且预期的响应。然后,我们利用先进的渗透测试技能多次重新运行curl命令,因为有时漏洞研究会多次执行相同的操作,但会以某种方式得到不同的结果。 在几次curl 请求之后,会偶尔收到 404 Not Found 响应。因此我们反编译了相关的 Apache .so 模块,并将其实现与修补后的 httpd 源代码进行了比较。 在这篇博文中,将进一步深入探讨AJP数据包的工作原理,但上面的示例基本与从Tomcat的ROOTwebapp( 2020 年的默认 PoCGhostCat 漏洞)])读取 /WEB-INF/web.xml 的内容相同)。默认情况下,F5-BIGIP 不运行 ROOT Web 应用程序,因此系统返回 404。通过在 /usr/share/tomcat/webapps/ROOT/WEB-INF/web.xml 显式创建文件,触发GhostCat的本地文件包含漏洞

6 Aug 2026, 16:17 UTC72 viewsread 20 August 2026
Photo

在处理 HTTP 请求时,如果出现任何错误,PVE 服务器会将错误消息写入响应的状态行。 对应的代码位于perl5/PVE/APIServer/AnyEvent.pm: # line 294 my $code = $resp->code; my $msg = $resp->message || HTTP::Status::status_message($code); ($msg) = $msg =~m/^(.*)$/m; # [1] # ... # line 308 my $proto = $reqstate->{proto} ? $reqstate->{proto}->{str} : 'HTTP/1.0'; my $res = "$proto $code $msg\015\012"; # [2] 服务器端[1]使用正则表达式匹配错误消息的第一行,试图避免后续行导致 HTTP 响应中断[2]。然而,这种方法只能阻止换行

4 Aug 2026, 16:17 UTC65 viewsread 20 August 2026
Photo

测试时,使用 CR(%0d) 注入响应头仅适用于基于 Chromium 内核的浏览器(Chrome、Microsoft Edge、Opera 等),且无法仅使用 CR(%0d) 将其注入到响应体中。Firefox 无法将 CR(%0d) 识别为有效的换行符,必须使用 LF(%0a) 才能生效。 PVE 中的这个漏洞乍一看似乎完全无害。但实际上,在AnyEvent.pm第 1327 行,有一个针对传入 HTTP 请求的长度限制检查。如果请求头超过 8192 字节,服务器将拒绝处理该 HTTP 请求。 # line 55 my $limit_max_header_size = 8*1024; # ... # line 1327 die "http header too large\n" if ($state->{size} += length($line)) >= $limit_max_header_size; 因此,攻击者可以精心

Showing the 12 most recent of 22 posts we hold for @heikesentou0. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.

Mentions

Names

Channels on the register whose handles appear in this channel's posts.

A mention is a weaker signal than a forward and is counted separately for that reason — naming a channel is not republishing it, and a handle in a post body is easy to place deliberately. The post counts beside each row below are distinct posts in which the handle appeared, from posts we have read on both sides — the “Named by N registered channels” figure above is a different count, of distinct NAMING CHANNELS rather than posts, and is not the sum of the rows under it.

Cite this entry

A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 30 August 2026 — this entry's latest reading, not the date you are reading this.

“Bc渗透劫持|数据入侵提取” (@heikesentou0), 8,001 subscribers as measured 30 August 2026. Telegram Register, tgregister.com/channel/heikesentou0.

Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.