<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>渗透测试 on 7anX 的博客</title><link>https://7anX.github.io/tags/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/</link><description>Recent content in 渗透测试 on 7anX 的博客</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Tue, 30 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://7anX.github.io/tags/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95/index.xml" rel="self" type="application/rss+xml"/><item><title>A2A 资产渗透测试：Agent Card 侦察与 JSON-RPC 利用实战</title><link>https://7anX.github.io/security-research/a2a-pentest/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://7anX.github.io/security-research/a2a-pentest/</guid><description>A2A 渗透的傻瓜式完整链路：FOFA搜资产、Agent Card 发现与字段解读、私网地址泄露识别、JSON-RPC 端点无认证探测与直接利用。一看就懂的实战宝典。</description></item><item><title>MCP 资产渗透测试：无认证端点发现与工具调用指南</title><link>https://7anX.github.io/security-research/mcp-pentest/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://7anX.github.io/security-research/mcp-pentest/</guid><description>从资产发现到工具调用的完整 MCP 渗透攻略。教你如何用 FOFA 找目标、探测路径、无脑发 initialize 请求、拿 shell 和读敏感文件。已覆盖 2026-07-28 无状态新版协议（server/discover 探活与枚举）。小白也能轻松看懂的实战教程。</description></item></channel></rss>