Analysis of Different Types of DTD/XXE attacks

Analysis of Different Types of DTD/XXE attacks     When evaluating the security of XML-based services, you cannot forget the DTD-based attacks, such as XML external entity injection attacks (XXE ). In this article, we will provide a comprehensive

Technology sharing: Build poc for malware by using python and PyInstaller

Technology sharing: Build poc for malware by using python and PyInstaller Disclaimer: This article is intended to be shared and never used maliciously!This article mainly shows how to use python and PyInstaller to build some poc of malware.As we all

Google Chrome Security Restriction Bypass Vulnerability (CVE-2016-1629)

cve

Google Chrome Security Restriction Bypass Vulnerability (CVE-2016-1629)Google Chrome Security Restriction Bypass Vulnerability (CVE-2016-1629) Release date:Updated on:Affected Systems: Google Chrome Description: CVE (CAN) ID:

Detect Android simulators using the specific system value of the cache

Detect Android simulators using the specific system value of the cache0x00 Currently, Android simulators are detected based on specific system values. For example, getDeviceId (), getLine1Number (), and a series of values recorded by the android.

Patch does not work: Mac platform security vulnerabilities still exist

Patch does not work: Mac platform security vulnerabilities still exist Synack, a security research organization, revealed in a report in May that the keeper in the Mac platform has a serious system vulnerability that they can exploit to bypass the

Proface GP-Pro EX cross-border read information leakage Vulnerability

Proface GP-Pro EX cross-border read information leakage VulnerabilityProface GP-Pro EX cross-border read information leakage Vulnerability Release date:Updated on:Affected Systems: Proface GP-Pro EX Description: Proface GP-Pro EX is a

Startup attack analysis for Linux system full encryption

Startup attack analysis for Linux system full encryption Recently, our tan digital technology (GDS) researchers have discussed the cold start attack on Linux system full encryption. Everyone thinks this attack is feasible, but how hard is it to

Analysis of Drag and Drop security policies in IE sandbox

Analysis of Drag and Drop security policies in IE sandbox 0x00 Preface Internet Explorer sandbox escape is an important topic in Internet Explorer security research. One type of vulnerability uses the defects of the white list program in

Autodesk Design Review buffer overflow vulnerability in CVE-2015-8572)

cve

Autodesk Design Review buffer overflow vulnerability in CVE-2015-8572)Autodesk Design Review buffer overflow vulnerability in CVE-2015-8572) Release date:Updated on:Affected Systems: Autodesk Design Review Description: CVE (CAN) ID: CVE-2015-8

Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)

Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317) Release date:Updated on:Affected Systems: Libxml libxml2 Description: CVE

Usage of windows Security Log Analysis Tool logparser

Usage of windows Security Log Analysis Tool logparser Introduction to logparser First, let's take a look at the Logparser architecture diagram and familiarize ourselves with this diagram, which is of great benefit for us to understand and use

Windows Name resolution mechanism and defect Utilization

Windows Name resolution mechanism and defect Utilization As a popular science article, this article describes the name resolution mechanism in Windows systems, and also mentions several ways of using the name resolution mechanism defects for

The latest Android vulnerability can be hacked into any mobile phone in simple steps

The latest Android vulnerability can be hacked into any mobile phone in simple steps At a PacSec hacking conference in Tokyo, researchers from Qihoo 360 demonstrated the use of a vulnerability in the Android Chrome browser targeting JavaScript v8.

APP Security douyu live broadcast arbitrary user login (it is a broadcaster with a gun)

APP Security douyu live broadcast arbitrary user login (it is a broadcaster with a gun) I watched douyu live broadcast last night and saw a wave of ads for this APP. Then let's test the logic.Attackers can log on to major broadcasters (mainly LOL

Logging of APP security is tiring for any user login (major broadcasters lay down their guns)

Logging of APP security is tiring for any user login (major broadcasters lay down their guns) I watched douyu live broadcast last night and saw a wave of ads for this APP. Then let's test the logic.Attackers can log on to major broadcasters (mainly

Sina Integrated Management backend has high-risk design defects and can obtain management permissions (permission control required)

Sina Integrated Management backend has high-risk design defects and can obtain management permissions (permission control required) RTThe permission of the sensitive word library. Why did weibo spread the advertisement? Source:Http://admin.iask.sina.

SQL Injection exists in the official APP of Shanda game (injection parameter v/type, Boolean blind injection)

SQL Injection exists in the official APP of Shanda game (injection parameter v/type, Boolean blind injection) SQL Injection for APP security Target: Shanda game assistant Butler APPSQL Injection exists in the following areas: (injection parameter

From crash to vulnerability exploits: bypass aslr Vulnerability Analysis)

From crash to vulnerability exploits: bypass aslr Vulnerability Analysis) 0 × 01 Introduction This is an out-of-bounds read bug that exists in Internet Explorer 9-11. The vulnerability exists for nearly five years and was not found until April 2015.

Xiangpeng aviation's system SQL injection (you can run the SQL-shell command)

Xiangpeng aviation's system SQL injection (you can run the SQL-shell command) Xiangpeng aviation's system SQL Injection Http: // **. **/web/Help. aspx? Code = Private injection parameter: code    sqlmap identified the following injection points

More than 1000 weak passwords of the O & M system of China tower company leak a large number of base stations, O & M monitoring, data centers, maintenance teams, contracts, and other information throughout the country.

More than 1000 weak passwords of the O & M system of China tower company leak a large number of base stations, O & M monitoring, data centers, maintenance teams, contracts, and other information throughout the country. Too many weak passwords.Find

Total Pages: 1330 1 .... 154 155 156 157 158 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.