自我介绍
Hey,我是Hilda(a.k.a. 希尔达),一个“不仅不会修电脑,但还能打游戏”的网络安全研0硕士,2024上岸东南大学。
在南京信息工程大学本科阶段,我学习还可以。我不仅熟悉计算机网络、数据结构算法,还对各种WEB漏洞如SQL注入、XSS、CSRF等了如指掌。而且,我还有个超长的技能列表,xxxxxx,“几乎”是一站式服务!
说到项目经验,我曾自己开发了一个“安全态势感知系统安全态势感知系统”,就是那种能让你看到网络活动和安全事件的直观界面罢了。用这个系统,你就可以轻松地防御各种攻击,而我也能悠哉地坐在云端进行值守(对于我自己本地搭建的靶场,好了,大佬别嘲笑了)。其他项目几乎都是java为主。
工作经验?没错,我曾短暂地为国家税务总局扬州市税务局的安全部门当渗透测试工程师。就在那短短的一个月里,我不仅完成了一系列的渗透测试和漏洞扫描,还优化了应急响应流程。说到这里,我突然觉得自己有点像那种“一日国家护网,终身国家护网”的感觉(???)。
证书/技能
CET4(615分) CET6(534分) CISP-PTE(国家注册信息安全渗透测试工程师认证)
安全
- 熟悉常见WEB漏洞原理,如:SQL注入、文件上传、XSS、CSRF、文件包含、SSRF、XXE、RCE、反序列化漏洞、未授权访问、逻辑漏洞、验证码绕过等
- 熟悉Metasploit+Cobalt Strike、AWVS、AppScan、Nessus、Burpsuite、sqlmap、哥斯拉、binwalk、foremost等工具
- 熟悉中间件和一些主流框架的漏洞复现及理解原理,有复现漏洞和阅读源码、及时收集指纹的习惯,了解bypass的技巧。
- 熟悉计算机网络等计算机基础知识,对CTF-MISC有兴趣,熟悉密码学、隐写、文件分离及合并,熟悉流量分析,能书写python脚本进行隐写的破解。
其他
- 熟悉HTML,CSS,Javascript,VUE,Ajax,Node,Java SE、Java EE、Git、MySQL、PHP、Python、Maven,Spring,Spring Boot,Redis,RabbitMQ,Dubbo等,熟悉多线程和高并发,熟练使用Git以及Github进行团队协作开发
- 熟悉Mongodb、Oracle、Redis、kotlin,了解JVM和Java设计模式,热爱在leetcode算法刷题(??)
- 了解Linux系统安全,致力于GitHub,stackoverflow等开源社区的贡献,对攻防安全技术拥有浓厚的兴趣,有创新精神、良好的学习心态,热爱阅读技术书籍和框架源码,勤于书写博客自我总结,能够积极主动学习最新技术。
兴趣爱好
- 除了技术,我还是个政治军事新闻的忠实粉丝,特别是对俄乌战争这种大事件总是津津乐道。
- 徒步旅行
github
如果你对我的技术或者项目感兴趣,可以去我的GitHub地址GitHub地址,或者关注我的个人公众号:“小东方不败”(别骂了,别骂了)。
关于我爱看的剧
- 斯皮尔伯格 《兄弟连》(2001)
- 《我的天才女友》 2024期待第四季
- 《This is us》
Introduce myself
Hey, I am Hilda (a.k.a. Hilda), a “not only can not repair the computer, but also can play games” network security research 0 master, 2024 shore Southeast University (examination comprehensive performance professional master rank 6/174).
When I was an undergraduate in Nanjing University of Information Science and Technology (GPA: 3.72, weighted average score of required courses: 87, rank of undergraduate major: 3/69), I was able to study well. I am not only familiar with computer networks, data structure algorithms, but also familiar with various WEB vulnerabilities such as SQL injection, XSS, CSRF, etc. Also, I have a long list of skills, xxxxxx, which is “almost” a one-stop shop!
When it comes to project experience, I was involved in developing a “security situational awareness system [the] security situation awareness system (https://github.com/kirsten-1/situationAwareness)”, is that can let you see the network activities and security incident intuitive interface. With this system, you can easily defend against all kinds of attacks, and I can sit in the cloud and watch (for my locally built shooting range, okay, big guys don’t laugh). The other projects are almost always Java-focused.
Work experience? Yes, I briefly worked as a penetration testing engineer for the security department of the Yangzhou Tax Bureau of the State Administration of Taxation. In that short month, I not only completed a series of penetration tests and vulnerability scans, but also optimized my emergency response process. Speaking OF THIS, I suddenly feel a bit like THE “ONE day national network, lifetime national network” feeling (???). .
Credentials/Skills
CET4(615 points) CET6(534 points) CISP-PTE(National Certified Information Security Penetration Testing Engineer)
Security
- Familiar with common WEB vulnerabilities such as: SQL injection, file upload, XSS, CSRF, file inclusion, SSRF, XXE, RCE, deserialization vulnerabilities, unauthorized access, logic vulnerabilities, CAPTcode bypass, etc
-Familiar with Metasploit+Cobalt Strike, AWVS, AppScan, Nessus, Burpsuite, sqlmap, Godzilla, binwalk, foremost and other tools
- Familiar with the vulnerability reproduction and understanding principles of middleware and some mainstream frameworks, have the habit of reproducing vulnerabilities and reading source code, collecting fingerprints in time, and understand the skills of bypass.
- Familiar with computer network and other basic computer knowledge, interested in CTF-MISC, familiar with cryptography, steganography, file separation and merging, familiar with traffic analysis, able to write python scripts to crack steganography.
Other
- Familiar with HTML, CSS, Javascript, VUE, Ajax, Node, Java SE, Java EE, Git, MySQL, PHP, Python, Maven, Spring, Spring Boot, Redis, RabbitMQ, Dubbo et al., familiar with multi-threading and high concurrency, skilled in using Git and Github for team collaboration development
- Familiar with Mongodb, Oracle, Redis, kotlin, JVM and Java design patterns, love to practice algorithms in leetcode
- Understand Linux system security, devote to GitHub, stackoverflow and other open source community contribution, have a strong interest in attack and defense security technology, have innovative spirit, good learning attitude, love to read technical books and framework source code, diligent in writing blog self-summary, can actively learn the latest technology.
Hobbies
- Aside from technology, I’m also a big fan of political and military news, especially about big events like the war between Russia and Ukraine.
- Hiking
github
If you are interested in my technical or project, you can go to my lot address [making address] (https://github.com/kirsten-1), or on my personal public number: “small east don’t hurt” (don’t scold, don’t scold the).
About my favorite shows
- Steven Spielberg, Band of Brothers (2001)
- My Brilliant Girlfriend (2024 is looking forward to Season 4)
- “This is us”