跳至主要內容
>_ITDITD網站資安平台
資安整備,指揮中心般的從容

從真實事件學習,守護你自己的網站。

不是教你如何攻擊,而是教你如何防禦——取材自真實發生過的入侵事件。即使沒有資安背景,也有今天就能著手的實用防禦做法。

itd@defense:~ — site-health.shLIVE
$  
  • >.env exposure[ 已防護 ]
  • >TLS / cert expiry[ 留意 ]
  • >Dependency CVEs[ 危急 ]
  • >Security headers[ 已防護 ]
  • >Secret in repo[ 已防護 ]
02 — Field notes

重大資安事件與漏洞

Capital One、Log4Shell、MOVEit 等——公開的入侵事件與漏洞,轉化為你的防禦之道。

03 — Our stance

本站堅持的原則

資安產品必須先把自家的事做好。

We don't hold secrets

We never store your real API keys — only metadata. The safest secret is the one we can't leak.

Scan only what you own

Diagnostics run on verified domains only. Internal IPs and metadata endpoints are blocked — SSRF defense is built in.

Minimal blast radius

Isolation so one breach can't cascade. This site itself runs on a dedicated, isolated host.

We test on ourselves

This site watches its own dependencies for CVEs. The incident that started this never gets missed by a human again.