一个人的闲言碎语

dr0v

blog.drov.com.cn
一个人碎碎念。
About Me
A lazy security employee.

2020年3月11日星期三

1. 官网下载最新的安装包 XMind For Mac,断网安装(安装软件需在断网情况下进行!!!).
    
    双击打开安装包xmind.dmg,直接拖动安装.
    
    ![](https://img2018.cnblogs.com/blog/1364389/201902/1364389-20190214192256574-986768458.png)

    安装完成之后,打开 偏好设置-->常规-->启动,将如图所示的两个标签的对勾取消掉,然后点击确定,关闭软件.

    ![](https://img2018.cnblogs.com/blog/1364389/201902/1364389-20190214192704068-1601692584.png)



2. 下载破解包 XMindCrack.jar,链接: https://pan.baidu.com/s/1sCbCQHTI24CgyaVrwGW_kQ  提取码: dejw

3. 激活xmind:
    
    a. 将下载的破解补丁复制到安装好的软件包下的Eclipse这个目录中:安装好的XMind-->鼠标右键显示包内容-->Contents-->Eclipse。
    
    ![](https://img2018.cnblogs.com/blog/1364389/201902/1364389-20190214194340329-2109792670.png)

    b. 打开安装目录Eclipse中的 XMind.ini  (我下面使用的软件是Visual Studio Code,需要的自行Google吧)
    
    c. 在 XMind.ini 最后追加一行XMindCrack.jar的绝对路径,并保存。(绝对路径如下可复制)
    
    -javaagent:/Applications/XMind.app/Contents/Eclipse/XMindCrack.jar

    ![](https://img2018.cnblogs.com/blog/1364389/201902/1364389-20190214194546705-631969993.png)

    d. 重新打开 XMind, 点击 帮助-->序列号-->输入序列号,进入XMind激活页面,然后输入以下序列号 ,邮箱可以随便填,可以填自己的,提示激活成功之后点击'关闭'即可。

    序列号:

    >XAka34A2rVRYJ4XBIU35UZMUEEF64CMMIYZCK2FZZUQNODEKUHGJLFMSLIQMQUCUBXRENLK6NZL37JXP4PZXQFILMQ2RG5R7G4QNDO3PSOEUBOCDRYSSXZGRARV6MGA33TN2AMUBHEL4FXMWYTTJDEINJXUAV4BAYKBDCZQWVF3LWYXSDCXY546U3NBGOI3ZPAP2SO3CSQFNB7VVIY123456789012345
Categories: ,

2020年1月17日星期五


2019年12月31日星期二

- 12.26 [由HTTPS抓包引发的一系列思考](https://www.freebuf.com/articles/web/222564.html)
- 12.25 [Gafgyt家族物联网僵尸网络家族分析](https://www.freebuf.com/articles/others-articles/222677.html)
- 12.24 [2019年移动应用安全十件影响力事件](https://www.anquanke.com/post/id/195635)
- 12.24 [全新 Mozi P2P 僵尸网络入侵 Netgear、D-Link、Huawei 路由器](http://hackernews.cc/archives/29000)
- 12.25 [Twitter Android app 漏洞被用于匹配 1700 万用户手机号码](https://www.solidot.org/story?sid=63050)
- 12.26 [隐私政策保护中第三方sdk问题](https://blog.trustlook.com/yin-si-zheng-ce-bao-hu-zhong-di-san-fang-sdkwen-ti/)
- 12.25 [ATT&CK 之防御逃逸](https://paper.seebug.org/1103/)
- 12.26 [2019年勒索软件:针对市政部门的全面攻击](https://www.freebuf.com/articles/network/223202.html)
- 12.26 [揭露电信诈骗之悄无声息的转走银行卡资金](https://www.anquanke.com/post/id/195840)
- 12.30 [关于印发《App违法违规收集使用个人信息行为认定方法》的通知](https://www.anquanke.com/post/id/196074)
- 12.31 [非法支付之恶:涉案540多亿的非法网络支付连环案告破](https://www.anquanke.com/post/id/196164)
- 12.31 [警惕伪装成“Synaptics触摸板驱动程序”的新型蠕虫病毒](https://www.freebuf.com/articles/terminal/222991.html)
- 12.30 [穷源溯流:KONNI APT组织伪装韩国Android聊天应用的攻击活动剖析](https://www.freebuf.com/articles/terminal/223567.html)
- 12.30 [伸向中亚地区的触手——DustSquad APT组织针对乌兹别克斯坦的活动分析](https://www.anquanke.com/post/id/196067)
- 12.29 [404 Keylogger最新木马,盗取受害者浏览器网站帐号和密码](https://www.freebuf.com/articles/system/222808.html)

2019年5月7日星期二

- 4.23 [Adware Plagues Google Play Store | Avast](https://blog.avast.com/adware-plagues-google-play)
- 4.24 [恶意SDK无感刷百度广告,数千款APP植入影响千万用户](https://www.freebuf.com/articles/terminal/201714.html)
- 4.24 [“天鼠”系列盗号木马分析报告](https://www.anquanke.com/post/id/177066)
- 4.24 [真假文件夹?FakeFolder病毒再次捣乱企业内网](https://www.secpulse.com/archives/104540.html)
- 4.25 [赛门铁克2019年互联网安全威胁报告:数据篇](https://www.freebuf.com/news/201265.html)
- 4.25 [新型赌博黑产攻击肆虐网吧:LOL博彩引流&棋牌盗号](https://www.freebuf.com/articles/system/201459.html)
- 4.25 [从源码层面看一款精致的病毒软件应具备哪些特质](https://www.freebuf.com/articles/system/200923.html)
- 4.25 [正则表达式所引发的DoS攻击(Redos)](https://www.anquanke.com/post/id/177100)
- 4.25 [卡巴斯基:除华硕外至少还有6家公司受到“影锤”行动攻击](http://hackernews.cc/archives/25333)
- 4.25 [外国骗子装成中国黑客造假0day骗钱删号走人](https://www.anquanke.com/post/id/177212)
- 4.26 [威胁情报在态势感知系统中的一种落地尝试](https://www.freebuf.com/articles/security-management/200882.html)
- 4.26 [海莲花APT组织2019年第一季度针对中国的攻击活动技术揭秘](https://www.freebuf.com/articles/network/201940.html)
- 4.27 [IoT-Home-Guard:一款可检测物联网设备中恶意行为的工具](https://www.freebuf.com/articles/terminal/198163.html)
- 4.28 [号称“十分在意用户隐私”的恶意软件罗宾汉是个啥?](https://www.freebuf.com/news/201080.html)
- 4.28 [APT34泄密武器分析报告](https://www.freebuf.com/articles/database/202303.html)
- 4.28 [因广告欺诈及滥用权限,百度子公司数十款应用被Google Play封杀](https://www.freebuf.com/news/202248.html)
- 4.29 [2019年Q1 Android Native病毒疫情报告](https://www.anquanke.com/post/id/177478)
- 4.30 [浅析某针对乌克兰国防和经济部门的大规模钓鱼事件](https://www.freebuf.com/articles/network/201788.html)
- 4.30 [AWS安全笔记|扯淡与权限](https://www.secpulse.com/archives/105062.html)
- 4.30 [The inception bar:一种新型网络钓鱼手段](https://www.anquanke.com/post/id/177488)
- 4.30 [DDoS攻击新趋势:海量移动设备成为新一代肉鸡](https://www.secpulse.com/archives/105045.html)
- 4.30 [防代码泄漏的监控系统架构与实践](https://www.freebuf.com/articles/es/201845.html)
- 5.2 [新型蠕虫病毒攻击服务器,政企电脑变矿机](https://www.freebuf.com/articles/database/201525.html)
- 5.3 [DDoS反射放大攻击全球探测分析](https://www.freebuf.com/articles/database/201804.html)
- 5.5 [聊聊安全测试中如何快速搞定Webshell](https://www.freebuf.com/articles/web/201421.html)
- 5.5 [ISPsystem漏洞分析](https://www.anquanke.com/post/id/177599)
- 5.5 [基于排序的SQL猜解问题](https://www.anquanke.com/post/id/177572)
- 5.5 [“盗梦空间栏”,Chrome 移动版上的新型网络钓鱼](http://hackernews.cc/archives/25369)

2019年4月23日星期二

- 4.16 [黑客 Gnosticplayers 兜售第五批数据:总涉44家企业近10亿用户记录](http://hackernews.cc/archives/25259)
- 4.16 [登录注册攻与防](https://www.secpulse.com/archives/104091.html)
- 4.17 [浅析基于人格特征的内部高风险用户识别方法](https://www.freebuf.com/articles/network/200564.html)
- 4.18 [CNCERT发布《2018年我国互联网网络安全态势报告》](https://www.freebuf.com/articles/network/201280.html)
- 4.18 [一些知名中國 app 因涉嫌大規模廣告詐騙而被 Google 下架](https://chinese.engadget.com/2019/04/18/google-pulls-android-apps-ad-fraud/)
- 4.19 [门罗币挖矿&远控木马样本分析](https://www.freebuf.com/articles/system/200875.html)
- 4.19 [新型Anatova恶意软件分析](https://www.freebuf.com/articles/database/199895.html)
- 4.19 [国家安全机关公布境外网络攻击窃密案件](https://www.anquanke.com/post/id/176944)
- 4.22 [Bilibili 源代码泄漏](https://www.solidot.org/story?sid=60351)
- 4.22 [APT34攻击全本分析](http://www.ijiandao.com/2b/baijia/245780.html)

	- 4.19 [黑客在 Telegram 上出售伊朗间谍部队 APT34 的黑客工具源代码](http://hackernews.cc/archives/25286)
	
	- 4.19 [黑客泄露APT 34组织工具、成员信息,扬言更多秘密将持续曝光](https://www.freebuf.com/news/201501.html)

- 4.22 [DNS劫持欺骗病毒“自杀”](https://www.freebuf.com/articles/system/201032.html)
- 4.23 [Targeted Attacks hit multiple embassies with Trojanized TeamViewer](https://securityaffairs.co/wordpress/84367/hacking/trojanized-teamviewer-hit-embassies.html)
- 4.23 [起底童星培训骗局:千亿级的“黑金”产业链,到底有多赚?](http://www.ijiandao.com/2b/baijia/246470.html)

2019年4月15日星期一

- 4.8 [GandCrab5.2勒索病毒伪装国家机关发送钓鱼邮件进行攻击](https://www.freebuf.com/articles/system/200070.html)
- 4.9 [苹果企业证书再爆丑闻 间谍软件窃取用户隐私信息](http://hackernews.cc/archives/25210)
- 4.10 [“银行提款机”变种病毒分析报告](https://www.freebuf.com/articles/paper/200284.html)
- 4.10 [火眼推出 Windows 免费渗透测试套件,包含140多款工具](https://www.freebuf.com/sectool/200524.html)
- 4.10 [流行开发工具 bootstrap-sass 被修改植入后门](https://www.solidot.org/story?sid=60184)
- 4.15 [FuzzScanner:信息搜集开源小工具](https://www.freebuf.com/sectool/200344.html)
- 4.15 [使用HTML注入进行信息泄露](https://www.anquanke.com/post/id/176565)
- 4.15 [数据分析与可视化:谁是安全圈的吃鸡第一人](https://www.freebuf.com/articles/web/199925.html)

2019年4月8日星期一

- 4.2 [学习手册:窥探Web前端黑客技术](http://blog.nsfocus.net/spying-web-front-end-hacking-techniques/)
- 4.2 [“铝”巨人遭勒索病毒攻击,工业互联时代如何保障网络安全](http://blog.nsfocus.net/how-to-guarantee-network-security-in-the-age-of-industrial-interconnecti/)
- 4.3 [KBuster:以伪造韩国银行APP的韩国黑产活动披露](https://www.freebuf.com/articles/terminal/199175.html)
- 4.3 [伊拉克电信公司遭到MuddyWater组织定向攻击](https://www.freebuf.com/articles/network/199008.html)
- 4.3 [换瓶不换酒,盗号木马还在钻搜索引擎广告的空子](https://www.anquanke.com/post/id/175954)
- 4.4 [Xiaomi Vulnerability: When Security Is Not What it Seems](http://blog.checkpoint.com/2019/04/04/xiaomi-vulnerability-when-security-is-not-what-it-seems/)
- 4.5 [友讯路由器 DNS 流量遭黑客劫持](https://www.solidot.org/story?sid=60138)
- 4.5 [Chashell:基于DNS的反向Shell](https://www.freebuf.com/sectool/199406.html)
- 4.5 [2018全球网络安全图鉴](https://www.freebuf.com/articles/network/199133.html)
- 4.6 [如何使用SQLMap脚本绕过Web应用防火墙](https://www.freebuf.com/sectool/198403.html)
- 4.6 [“商贸信”病毒装成商品图片,双击就被安装商业间谍软件](https://www.freebuf.com/articles/network/199906.html)
- 4.7 [奇思妙想之用JS给图片加口令](https://www.freebuf.com/articles/web/199559.html)
- 4.7 [4月7日每日安全热点 - 湖北一公职人员泄露公民信息5万余条](https://www.anquanke.com/post/id/176043)
- 4.8 [CISO的闪电战——2年甲方安全的自我修炼](https://www.anquanke.com/post/id/176075)
- 4.8 [谁劫持了我的DNS:全球域名解析路径劫持测量与分析](https://www.inforsec.org/wp/?p=3161)