<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Ricky</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/categories/security/</link><description>Recent content in Security on Ricky</description><generator>Hugo -- gohugo.io</generator><language>zh-tw</language><lastBuildDate>Mon, 20 Jul 2026 09:19:00 +0800</lastBuildDate><atom:link href="https://59d713fc.rickylin.pages.dev/zh-tw/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Articles</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2026/20260720-articles/</link><pubDate>Mon, 20 Jul 2026 09:19:00 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2026/20260720-articles/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://www.submission.directory/" target="_blank" rel="noopener">A website submission directory to submit your business, startup, or website&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://www.cloudflare.com/drop/" target="_blank" rel="noopener">Summon your site - HTML, CSS, JS. See it live instantly.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://metawilo.com/" target="_blank" rel="noopener">台灣罪犯圖鑑&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://clocks.dev/" target="_blank" rel="noopener">Collection of digital clock designs&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://clig.dev/" target="_blank" rel="noopener">Command Line Interface Guidelines&lt;/a>&lt;/li>
&lt;li>&lt;strong>Github&lt;/strong>
&lt;ul>
&lt;li>&lt;a href="https://github.com/searxng/searxng" target="_blank" rel="noopener">SearXNG is a free internet metasearch engine which aggregates results from various search services and databases. Users are neither tracked nor profiled.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/HelixDB/helix-db" target="_blank" rel="noopener">HelixDB is an OLTP graph-vector database built in Rust on Object Storage.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/VSCodium/vscodium" target="_blank" rel="noopener">vscodium: binary releases of VS Code without MS branding/telemetry/licensing&lt;/a> - &lt;code>VSCodium&lt;/code> 使用 &lt;code>Open VSX Registry&lt;/code> 替換 &lt;code>Visual Studio Marketplace&lt;/code>，相容大多數 extension。&lt;/li>
&lt;li>&lt;a href="https://github.com/EpicGames/lore" target="_blank" rel="noopener">Lore is a next-generation, open source version control system&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/paytonjjones/bsharp" target="_blank" rel="noopener">bsharp: A tool to teach children perfect pitch&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/stamparm/maltrail" target="_blank" rel="noopener">maltrail: Malicious traffic detection system&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/schollz/croc" target="_blank" rel="noopener">croc: Easily and securely send things from one computer to another&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/StarTrail-org/PixelRAG" target="_blank" rel="noopener">PixelRAG: The end of web parsing. The beginning of scalable pixel-native search. link: https://pixelrag.ai/&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/azukaar/Cosmos-Server" target="_blank" rel="noopener">Cosmos is the most secure and easy way to self-host a Home Server. It acts as a secure gateway to your application, as well as a server manager. It aims to solve the increasingly worrying problem of vulnerable self-hosted applications and personal servers.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/jhaals/yopass" target="_blank" rel="noopener">yopass: Secure sharing of secrets, passwords and files&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/OpenHub-Store/GitHub-Store" target="_blank" rel="noopener">GitHub-Store: A free, open-source app store for developers&amp;rsquo; releases on GitHub, Codeberg &amp;amp; Forgejo — browse, discover, and install apps with one click.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/n0-computer/iroh" target="_blank" rel="noopener">iroh: IP addresses break, dial keys instead. A library that adds QUIC + NAT Traversal to your apps.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/Crosstalk-Solutions/project-nomad" target="_blank" rel="noopener">Project N.O.M.A.D, is a self-contained, offline survival computer packed with critical tools, knowledge, and AI to keep you informed and empowered—anytime, anywhere.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/sw33tLie/macshot" target="_blank" rel="noopener">macshot: Feature-packed native macOS screenshot &amp;amp; recording tool: annotate, auto-redact PII, record GIFs, OCR + translate, scroll capture, beautify, and more. No Electron, no subscription.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/iOfficeAI/OfficeCLI" target="_blank" rel="noopener">OfficeCLI is the first and best Office suite purpose-built for AI agents to read, edit, and automate Word, Excel, and PowerPoint files. Free, open-source, single binary, no Office installation required.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/Diolinux/Photogimp" target="_blank" rel="noopener">A Patch for GIMP 3+(https://www.gimp.org/) for Photoshop Users&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/chattocorp/chatto" target="_blank" rel="noopener">chatto: A fully-featured team and group chat application that you can easily selfhost.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/nextest-rs/nextest" target="_blank" rel="noopener">nextest: A next-generation test runner for Rust.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/peetzweg/opendisplay" target="_blank" rel="noopener">OpenDisplay：Sidecar 与 Duet Display 的开源替代品，把闲置的 iPhone / iPad 变成 Mac 第二显示屏&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/pavlobu/deskreen" target="_blank" rel="noopener">Deskreen：将局域网设备变为电脑的第二块屏幕&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>&lt;strong>Skill&lt;/strong>
&lt;ul>
&lt;li>&lt;a href="https://github.com/DietrichGebert/ponytail" target="_blank" rel="noopener">ponytail: Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/nvidia/skillspector" target="_blank" rel="noopener">skillspector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/cloudflare/security-audit-skill" target="_blank" rel="noopener">security-audit: A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>&lt;strong>Article&lt;/strong>
&lt;ul>
&lt;li>&lt;a href="https://www.rfc-editor.org/info/rfc10008/" target="_blank" rel="noopener">RFC 10008: The HTTP QUERY Method&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://mareksuppa.com/til/bash-dev-tcp-http-without-curl/" target="_blank" rel="noopener">Making HTTP requests from a container that has no curl, using bash &lt;code>/dev/tcp&lt;/code>&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://t.me/TheB1ackParade/1076" target="_blank" rel="noopener">rr-debugger(https://github.com/rr-debugger/rr)&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://docs.deno.com/runtime/desktop/" target="_blank" rel="noopener">Deno Desktop&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://www.fosslinux.com/158206/linux-on-older-hardware-revival-guide.htm" target="_blank" rel="noopener">Linux on Older Hardware: The Complete Revival Guide (2026)&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://news.ycombinator.com/item?id=48842459" target="_blank" rel="noopener">Show HN: Getting GLM 5.2 running on my slow computer&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://mrmad.com.tw/how-to-turn-on-iphone-guided-access" target="_blank" rel="noopener">iPhone引導模式怎麼開？借手機人不怕隱私外洩和一鍵鎖定App&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ikrima.dev/dev-notes/linux/linux-modern-tools/" target="_blank" rel="noopener">Modern Linux Tools&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="iphone引導模式怎麼開借手機人不怕隱私外洩和一鍵鎖定app">iPhone引導模式怎麼開？借手機人不怕隱私外洩和一鍵鎖定App&lt;/h2>
&lt;h3 id="開啟與設定功能">開啟與設定功能&lt;/h3>
&lt;ol>
&lt;li>打開 iPhone 上的 &lt;strong>「設定」&lt;/strong> App。&lt;/li>
&lt;li>點選 &lt;strong>「輔助使用」&lt;/strong>。&lt;/li>
&lt;li>往下找到並點選 &lt;strong>「引導使用模式」&lt;/strong>，然後將其&lt;strong>開啟&lt;/strong>。&lt;/li>
&lt;li>建議順便進行以下設定：&lt;/li>
&lt;/ol>
&lt;ul>
&lt;li>&lt;strong>密碼設定&lt;/strong>：點一下「密碼設定」&amp;gt;「設定引導使用模式密碼」，輸入一組解鎖密碼，並可同時開啟 &lt;strong>Face ID&lt;/strong> 或 &lt;strong>Touch ID&lt;/strong> 作為快速解鎖/結束的方式。&lt;/li>
&lt;li>&lt;strong>輔助使用快速鍵&lt;/strong>：建議將其開啟，之後只要連按三下側邊按鈕就能快速叫出或退出此模式。&lt;/li>
&lt;/ul>
&lt;h3 id="開始使用將-iphone-鎖定在單一-app">開始使用（將 iPhone 鎖定在單一 App）&lt;/h3>
&lt;ol>
&lt;li>打開你想要讓別人（或自己專注）使用的 &lt;strong>App&lt;/strong>。&lt;/li>
&lt;li>&lt;strong>啟動引導使用模式&lt;/strong>：&lt;/li>
&lt;/ol>
&lt;ul>
&lt;li>&lt;strong>具備 Face ID 的 iPhone&lt;/strong>（全螢幕機型）：&lt;strong>連按三下側邊按鈕&lt;/strong>（電源鍵）。&lt;/li>
&lt;li>&lt;strong>具備主畫面按鈕的舊款 iPhone&lt;/strong>：&lt;strong>連按三下主畫面按鈕&lt;/strong>（Home 鍵）。&lt;/li>
&lt;li>或者也可以呼叫 Siri：「打開引導使用模式」。&lt;/li>
&lt;/ul>
&lt;ol start="3">
&lt;li>如果跳出輔助使用快速鍵面板，請點選 &lt;strong>「引導使用模式」&lt;/strong>。&lt;/li>
&lt;li>&lt;strong>自訂限制區域（選用）&lt;/strong>：&lt;/li>
&lt;/ol>
&lt;ul>
&lt;li>如果想讓螢幕上的特定區域&lt;strong>無法被觸控點擊&lt;/strong>（例如遊戲內的廣告區塊），直接用手指在該區域&lt;strong>畫一個圓圈&lt;/strong>，之後可以拖曳邊框來調整大小。&lt;/li>
&lt;/ul>
&lt;ol start="5">
&lt;li>&lt;strong>點一下右下角的「階段設定」&lt;/strong>（或選項），可以自由決定是否停用以下功能：&lt;/li>
&lt;/ol>
&lt;ul>
&lt;li>側邊按鈕 / 頂端按鈕&lt;/li>
&lt;li>音量按鈕&lt;/li>
&lt;li>動作（防止螢幕自動旋轉或因晃動而有反應）&lt;/li>
&lt;li>軟體鍵盤&lt;/li>
&lt;li>觸控（若想完全讓整個螢幕無法觸控可關閉此項）&lt;/li>
&lt;li>時間限制&lt;/li>
&lt;/ul>
&lt;ol start="6">
&lt;li>設定完成後，點一下右上角的 &lt;strong>「完成」&lt;/strong>，再點一下 &lt;strong>「開始」&lt;/strong> 即可正式鎖定。&lt;/li>
&lt;/ol>
&lt;h3 id="如何結束引導使用模式">如何結束引導使用模式&lt;/h3>
&lt;ol>
&lt;li>&lt;strong>連按三下&lt;/strong>側邊按鈕（或主畫面按鈕）。&lt;/li>
&lt;li>輸入你剛剛設定的&lt;strong>引導使用模式密碼&lt;/strong>（或直接使用 Face ID / Touch ID 驗證）。&lt;/li>
&lt;li>畫面左上角會出現 &lt;strong>「結束」&lt;/strong> 按鈕，點下去即可退出此模式。&lt;/li>
&lt;/ol></description></item><item><title>Articles</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2026/20260610-articles/</link><pubDate>Wed, 10 Jun 2026 10:59:53 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2026/20260610-articles/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://pokeemerald.com/" target="_blank" rel="noopener">Pokemon Emerald in WebAssembly(https://github.com/tripplyons/pokeemerald-wasm)&lt;/a>&lt;/li>
&lt;li>&lt;strong>Github&lt;/strong>
&lt;ul>
&lt;li>&lt;a href="https://github.com/wxt-dev/wxt" target="_blank" rel="noopener">wxt: Next-gen Web Extension Framework&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/anthropics/defending-code-reference-harness" target="_blank" rel="noopener">Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can &lt;code>/customize&lt;/code>&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/ad-si/awesome-3d-printing" target="_blank" rel="noopener">A curated list of awesome 3D printing resources&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/NousResearch/hermes-agent" target="_blank" rel="noopener">hermes-agent: It&amp;rsquo;s the only agent with a built-in learning loop - it creates skills from experience, improves them during use, nudges itself to persist knowledge, searches its own past conversations, and builds a deepening model of who you are across sessions. Run it on a $5 VPS, a GPU cluster, or serverless infrastructure that costs nearly nothing when idle. It&amp;rsquo;s not tied to your laptop - talk to it from Telegram while it works on a cloud VM.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/mysk-research/loupe" target="_blank" rel="noopener">loupe: A privacy-focused iOS app that raises awareness about what native apps can see(https://apps.apple.com/cn/app/loupe-app%E8%83%BD%E7%9C%8B%E5%88%B0%E4%BB%80%E4%B9%88/id6766152470)&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/RoversX/LaunchNext" target="_blank" rel="noopener">LaunchNext: Bring your Launchpad back in MacOS26+ ,highly customizable, powerful, free.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/skeeto/endlessh" target="_blank" rel="noopener">endlessh: SSH tarpit that slowly sends an endless banner&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/akerouanton/iptables-tracer" target="_blank" rel="noopener">iptables-tracer: Trace packets as they go through iptables chains&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/serverless-dns/serverless-dns" target="_blank" rel="noopener">serverless-dns: The RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/ouch-org/ouch" target="_blank" rel="noopener">ouch: stands for Obvious Unified Compression Helper. It&amp;rsquo;s a CLI tool for compressing and decompressing various formats.(https://github.com/ouch-org/ouch#supported-formats)&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/shell-pool/shpool" target="_blank" rel="noopener">shpool: shpool is a service that enables session persistence by allowing the creation of named shell sessions owned by shpool so that the session is not lost if the connection drops. shpool can be thought of as a lighter weight alternative to tmux or GNU screen. While tmux and screen take over the whole terminal and provide window splitting and tiling features, shpool only provides persistent sessions. The biggest advantage of this approach is that shpool does not break native scrollback or copy-paste.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/google/capslock" target="_blank" rel="noopener">capslock: is a capability analysis CLI for Go packages that informs users of which privileged operations a given package can access. This works by classifying the capabilities of Go packages by following transitive calls to privileged standard library operations.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/psviderski/unregistry" target="_blank" rel="noopener">unregistry: Push docker images directly to remote servers without an external registry&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/Ranchero-Software/NetNewsWire" target="_blank" rel="noopener">NetNewsWire is a free and open-source feed reader for macOS and iOS. It supports RSS, Atom, JSON Feed, and RSS-in-JSON formats.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/k4yt3x/sysctl" target="_blank" rel="noopener">K4YT3X&amp;rsquo;s Hardened &amp;amp; Optimized Linux Kernel Parameters&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/tursodatabase/turso" target="_blank" rel="noopener">Turso is an in-process SQL database, compatible with SQLite.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/zizmorcore/zizmor" target="_blank" rel="noopener">zizmor is a static analysis tool for GitHub Actions.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/rustfs/rustfs" target="_blank" rel="noopener">RustFS is a high-performance, distributed object storage system built in Rust.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/jdx/usage" target="_blank" rel="noopener">Usage: is a spec and CLI for defining CLI tools. Arguments, flags, environment variables, and config files can all be defined in a Usage spec. It can be thought of like OpenAPI (swagger) for CLIs.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/MODSetter/SurfSense" target="_blank" rel="noopener">SurfSense: An open source, privacy focused alternative to NotebookLM for teams with no data limits.&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/icann/icann-rdap" target="_blank" rel="noopener">ICANN implementation of the Registry Data Access Protocol (RDAP)&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/openrdap/rdap" target="_blank" rel="noopener">OpenRDAP is a command line RDAP client implementation in Go.&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>&lt;strong>Article&lt;/strong>
&lt;ul>
&lt;li>&lt;a href="https://blog.ammaraskar.com/github-token-stealing/" target="_blank" rel="noopener">1-Click GitHub Token Stealing via a VSCode Bug&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://www.zhihu.com/question/590661860" target="_blank" rel="noopener">Linux 系统误将 chmod 权限改成 了 000，如何恢复?&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ahelwer.ca/post/2026-05-08-builtin-u2f/" target="_blank" rel="noopener">Laptops all have built-in security tokens these days&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://tailscale.com/blog/tailscale-rustdesk-remote-desktop-access" target="_blank" rel="noopener">Tailscale and RustDesk: Secure remote access to all your desktops&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/" target="_blank" rel="noopener">Unexpected security footguns in Go&amp;rsquo;s parsers&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://marvin.yabi.me/misc/junzishendoo.htm" target="_blank" rel="noopener">君子慎讀&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://marvin.yabi.me/misc/wenbai.htm" target="_blank" rel="noopener">辭典中標注的「讀音」和「語音」是什麼？&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://marvin.yabi.me/misc/AND.htm" target="_blank" rel="noopener">拜託別再「我汗你」了！&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="linux-系统误将-chmod-权限改成-了-000如何恢复">Linux 系统误将 chmod 权限改成 了 000，如何恢复?&lt;/h2>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-c" data-lang="c">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">#include&lt;/span> &lt;span style="color:#75715e">&amp;lt;sys/stat.h&amp;gt;&lt;/span>&lt;span style="color:#75715e">
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">int&lt;/span> &lt;span style="color:#a6e22e">main&lt;/span>() {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">chmod&lt;/span>(&lt;span style="color:#e6db74">&amp;#34;/usr/bin/chmod&amp;#34;&lt;/span>, &lt;span style="color:#ae81ff">0755&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">return&lt;/span> &lt;span style="color:#ae81ff">0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-shell" data-lang="shell">&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ which chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>/usr/bin/chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lrwxrwxrwx &lt;span style="color:#ae81ff">1&lt;/span> root root &lt;span style="color:#ae81ff">8&lt;/span> Sep &lt;span style="color:#ae81ff">27&lt;/span> &lt;span style="color:#ae81ff">2025&lt;/span> /usr/bin/chmod -&amp;gt; gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-rwxr-xr-x &lt;span style="color:#ae81ff">1&lt;/span> root root 67K Jan &lt;span style="color:#ae81ff">23&lt;/span> 21:34 /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ sudo chmod &lt;span style="color:#ae81ff">000&lt;/span> /usr/bin/chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lrwxrwxrwx &lt;span style="color:#ae81ff">1&lt;/span> root root &lt;span style="color:#ae81ff">8&lt;/span> Sep &lt;span style="color:#ae81ff">27&lt;/span> &lt;span style="color:#ae81ff">2025&lt;/span> /usr/bin/chmod -&amp;gt; gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>---------- &lt;span style="color:#ae81ff">1&lt;/span> root root 67K Jan &lt;span style="color:#ae81ff">23&lt;/span> 21:34 /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ cat main.c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">#include &amp;lt;sys/stat.h&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>int main&lt;span style="color:#f92672">()&lt;/span> &lt;span style="color:#f92672">{&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> chmod&lt;span style="color:#f92672">(&lt;/span>&lt;span style="color:#e6db74">&amp;#34;/usr/bin/chmod&amp;#34;&lt;/span>, 0755&lt;span style="color:#f92672">)&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">return&lt;/span> 0;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">}&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ gcc ./main.c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ sudo ./a.out
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/chmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>lrwxrwxrwx &lt;span style="color:#ae81ff">1&lt;/span> root root &lt;span style="color:#ae81ff">8&lt;/span> Sep &lt;span style="color:#ae81ff">27&lt;/span> &lt;span style="color:#ae81ff">2025&lt;/span> /usr/bin/chmod -&amp;gt; gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ubuntu@ubuntu:~$ ls -lh /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>-rwxr-xr-x &lt;span style="color:#ae81ff">1&lt;/span> root root 67K Jan &lt;span style="color:#ae81ff">23&lt;/span> 21:34 /usr/bin/gnuchmod
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;hr>
&lt;h2 id="laptops-all-have-built-in-security-tokens-these-days">Laptops all have built-in security tokens these days&lt;/h2>
&lt;h3 id="macos">macOS&lt;/h3>
&lt;blockquote>
&lt;p>&lt;a href="https://github.com/yubico/libfido2" target="_blank" rel="noopener">https://github.com/yubico/libfido2&lt;/a>&lt;/p></description></item><item><title>我用 Zip Bomb 來保護我的伺服器</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2025/20250503-zipbomb-protection/</link><pubDate>Sat, 03 May 2025 11:24:00 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2025/20250503-zipbomb-protection/</guid><description>&lt;ul>
&lt;li>
&lt;p>&lt;a href="https://idiallo.com/blog/zipbomb-protection" target="_blank" rel="noopener">我用 Zip Bomb 來保護我的伺服器&lt;/a>&lt;/p>
&lt;/li>
&lt;li>
&lt;p>發生的情況是：對方收到檔案後，讀取標頭得知這是壓縮檔，因此嘗試解壓那個 1MB 的檔案來找他們要的內容。但檔案會不斷膨脹，直到耗盡記憶體、伺服器崩潰。1MB 的檔案會解壓成 1GB，這已足以讓多數機器人失敗。不過對於那些死纏爛打的腳本，我就給它 10MB 的檔案，解壓後會變成 10GB，立刻把腳本搞掛。&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;code>dd if=/dev/zero bs=1G count=10 | gzip -c &amp;gt; 10GB.gz&lt;/code>&lt;/p>
&lt;ul>
&lt;li>&lt;code>dd&lt;/code>：用於複製或轉換資料的指令。&lt;/li>
&lt;li>&lt;code>if&lt;/code>：輸入檔案，這裡指定 &lt;code>/dev/zero&lt;/code>，它會產生無限的零位元組串流。&lt;/li>
&lt;li>&lt;code>bs&lt;/code>：區塊大小，設為 1GB（1G），代表 dd 會以 1GB 為單位讀寫。&lt;/li>
&lt;li>&lt;code>count=10&lt;/code>：代表處理 10 個區塊、每個 1GB，因此會產生 10GB 的零資料。&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>
&lt;p>middleware&lt;/p>
&lt;/li>
&lt;/ul>
&lt;pre tabindex="0">&lt;code>if (ipIsBlackListed() || isMalicious()) {
header(&amp;#34;Content-Encoding: gzip&amp;#34;);
header(&amp;#34;Content-Length: &amp;#34;. filesize(ZIP_BOMB_FILE_10G)); // 10 MB
readfile(ZIP_BOMB_FILE_10G);
exit;
}
&lt;/code>&lt;/pre></description></item><item><title>Objective-See：一個關於 Apple 裝置隱私與安全的開源專案組織</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2024/20241113-objective-see/</link><pubDate>Wed, 13 Nov 2024 09:44:00 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2024/20241113-objective-see/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://t.me/misakatech/1349" target="_blank" rel="noopener">Objective-See：一個關於 Apple 裝置隱私與安全的開源專案組織&lt;/a>&lt;/li>
&lt;/ul>
&lt;p>今天在找小工具時發現他們做了一堆 macOS 上的開源軟體，基本都是和隱私與安全相關。&lt;/p>
&lt;ul>
&lt;li>
&lt;p>&lt;a href="https://objective-see.org/products/knockknock.html" target="_blank" rel="noopener">KnockKnock&lt;/a>：查看你的 Mac 上有哪些背景行程、守護行程、啟動項、核心擴充、登入項、瀏覽器外掛等等。能看到的比「Login Items」詳細得多（有的軟體會用其他方式自啟）。&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;a href="https://objective-see.org/products/lulu.html" target="_blank" rel="noopener">LuLu&lt;/a>：一個開源的 macOS 網路防火牆，可以讓你詳細控制每個軟體的網路連線（類似 Hands Off!）。&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;a href="https://objective-see.org/products/taskexplorer.html" target="_blank" rel="noopener">TaskExplorer&lt;/a>：增強版的工作管理員，可以看到應用的簽名、開啟的檔案、網路連線等等，還可以根據 sha256 自動幫你搜尋 VirusTotal 的結果。&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;a href="https://objective-see.org/products/dnd.html" target="_blank" rel="noopener">Do Not Disturb&lt;/a>：可以阻止你的 Mac 被打擾（沒錯），當你的 Mac 被別人打開上蓋時可以發送警告、執行腳本、偵測裝置變化之類的。&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;a href="https://objective-see.org/products/blockblock.html" target="_blank" rel="noopener">BlockBlock&lt;/a>：可以阻止背景的持久化安裝，RansomWhere 可以偵測檔案被加密的行為，還有一些雜七雜八的獨立工具。&lt;/p>
&lt;/li>
&lt;/ul>
&lt;p>&lt;a href="https://objective-see.org" target="_blank" rel="noopener">https://objective-see.org&lt;/a>&lt;/p></description></item><item><title>供應鏈攻擊</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2024/20240913-golang/</link><pubDate>Fri, 13 Sep 2024 09:41:00 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2024/20240913-golang/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://v2ex.com/t/1072079" target="_blank" rel="noopener">提高警惕，供應鏈攻擊就在你我身邊&lt;/a>&lt;/li>
&lt;/ul>
&lt;ul>
&lt;li>&lt;code>github.com/siruspen/logrus&lt;/code> 假&lt;/li>
&lt;li>&lt;code>github.com/sirupsen/logrus&lt;/code> 真&lt;/li>
&lt;/ul></description></item><item><title>Container security fundamentals</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2023/20231004-container/</link><pubDate>Wed, 04 Oct 2023 09:06:00 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2023/20231004-container/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-1/" target="_blank" rel="noopener">Container security fundamentals: Exploring containers as processes&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-2/" target="_blank" rel="noopener">Container security fundamentals part 2: Isolation &amp;amp; namespaces&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-3/" target="_blank" rel="noopener">Container security fundamentals part 3: Capabilities&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-4/" target="_blank" rel="noopener">Container security fundamentals part 4: Cgroups&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-5/" target="_blank" rel="noopener">Container security fundamentals part 5: AppArmor and SELinux&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://securitylabs.datadoghq.com/articles/container-security-fundamentals-part-6/" target="_blank" rel="noopener">Container security fundamentals part 6: seccomp
&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>冰山一角的駭客工具介紹</title><link>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2020/20201208-2536/</link><pubDate>Tue, 08 Dec 2020 21:50:47 +0800</pubDate><guid>https://59d713fc.rickylin.pages.dev/zh-tw/posts/2020/20201208-2536/</guid><description>&lt;ul>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/users/20114110/ironman/2536" target="_blank" rel="noopener">冰山一角的駭客工具介紹&lt;/a>
&lt;ul>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10214839" target="_blank" rel="noopener">[駭客工具 Day10] web 安全測試 - Burp Suite&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10215002" target="_blank" rel="noopener">[駭客工具 Day11] 網站路徑遍歷 - DirBuster&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10215072" target="_blank" rel="noopener">[駭客工具 Day12] 密碼暴力破解 - Hydra&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10215234" target="_blank" rel="noopener">[駭客工具 Day13] 密碼字典檔生成工具 - crunch&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10216722" target="_blank" rel="noopener">[駭客工具 Day16] 滲透神器 - Metasploit&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10217688" target="_blank" rel="noopener">[駭客工具 Day18] windows 密碼獲取神器 - mimikatz&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://ithelp.ithome.com.tw/articles/10221189" target="_blank" rel="noopener">[駭客工具 Day25] CTF Exploit 的 Python library - pwntools&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul></description></item></channel></rss>