About vsftpd Security

FTP is the first thing INTERNET enthusiasts are familiar with. It facilitates file sharing (cross-platform access), but the security of ftp transmitted in plain text has become a big problem. This article focuses on the security of ftp from four

MYSQL security-delete historical Operating Files

It was discovered today that ~ /. Mysql_history stores all commands executed after the user accesses mysql. Example: [xxx @ localhost ~] $ Cat ~ /. Mysql_historyuse mysqlselect * from user; update user set host = '%' where user = 'root'; update user

Intrude into linux-change normal permissions to root

1. Use root to create a normal user mary and switch to mary. 2. Test the permissions of the current user. 3. Go to/tmp and create the directory abc. 4. Execute the following commands. Make sure that the two red parts after the last line are

Simple privilege escalation in linux

Get the shell and prepare to raise the privilege. Check the Linux kernel first. Uname- 2.6.18-194.11.3.el5 kernel 2010, which is good for CentOS release 5.5 Then Baidu or other paths are used to find EXP, 2.6.18-194. I have already added this

Mimikatz grabs the management password on a remote terminal

In the remote terminal (338920.mstsc.exe) and virtual desktop, you can capture the password. Generally, when you run this program on a remote terminal, the following message is displayed: the storage space is insufficient and the command cannot be

Simple cleaning of window penetration traces

1. directly go to % systemroot % \ system32 \ logfiles \ xxx, select all, shift + del Delete Similarly, the same is true for httperr, which cannot be deleted today. 2.In this case, the host uploads an unlocker1.9.1.exe with only over 700 KB, which

Some optimizations made after the WEB Service is attacked

The environment is windows + apache + php + tomcat + jk recently found that my WEB server was under attack and tampered with my homepage information. Did I find the cup first, my colleague found this information. After opening the homepage, I found

Flash memory becomes a Windows door god

Whether you are using Windows XP or the trendy Windows 7/8, the login password is the first line of defense to protect system security. In order to protect system security, we often try our best to increase the complexity of the password and think

Safari location pollution vulnerability and repair

Location is contaminated due to browser parsing of some protocol errors. when safari opens an http url with username/password, it will keep the account password in the address, because safari will decode the username part of the url when obtaining

Replacing Windows notepad and task manager with image hijacking

In Windows, image hijacking can redirect specific programs to custom programs without replacing or setting file associations. Use NotePad2 to replace the built-in notepad and import the following registry: for Windows Registry Editor Version 5.00

MS13-005 HWND_BROADCAST PoC

/* Ms13-005-funz-poc.cpp-Drive a Medium IL cmd.exe via a Low ILprocess and message broadcasted Copyright (C) 2013 Axel "0vercl0k" Souchet- http://www.twitter.com/0vercl0k This program is free software: you can redistribute it and/or modify it under

Windows NC bounce CMD Elevation of Privilege

Server-U and so on are not available. generally, you can think about using this method. However, if the other party has installed a firewall or shielded all ports except the commonly used ports... This method also becomes invalid .... 1: Upload the

Denial of Service (DoS) attacks caused by su privilege broadcast hijacking

The su request used by CyanogenMod 10. x can be hijacked. As a result, the normal request cannot be responded, and the app fails to escalate the permission. Although the writing vendor is CyanogenMod, this version of su may be used by many other ROM.

Kangji automatic water vending machine storage card arbitrary modification of balance

A design vulnerability exists in the stored-value card of the kangji water vending machine. The encrypted sector is simple, and the stored-value amount is clearly indicated. It is easy to tamper with without a reconciliation mechanism.According to

1433 image hijacking backdoor Elevation of Privilege

First: 1. the server has enabled the terminal port (the terminal port may not be 3389 and can be queried by itself. the sticky key function of the server is lossless, as long as it can be popped up normally. the server has not disabled registry

The most basic security policy in Linux

1. Linux SSH Security Policy 1: Shut down the majority of hosts attacked on the unrelated port network, which are targeted by hackers who use scanning tools for a wide range of scanning. Therefore, in order to avoid being scanned, all ports, such as

Introduction to using the registry to add a Service Startup Program

There are many tools to add system services. The most typical tool is netservice. However, we are talking about manually adding system services, so the use of tools is not covered in this article.Nowadays, many Trojans, backdoors, and worms are

Use shell to prevent brute-force email cracking

The mailbox Server is a company IP address mapped to the Intranet. After the port is opened, it is constantly cracked and depressed. There is an IP address that has been used for more than times. In this way, IP address access is blocked by scripts.

Nginx 1.3.9/1.4.0 Buffer Overflow

# encoding: ASCIIabort("#{$0} host port") if ARGV.length  

VBScript-compares the Registry to find hidden services

System services may be hidden by rootkit, but sometimes we can still find relevant information from the registry. We recommend that you run the command as administrator. Otherwise, some services cannot be listed or an error message is

Total Pages: 1330 1 .... 1326 1327 1328 1329 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.