How to Develop Apache security best practices?

Apache HTTP Server software was first launched 18 years ago and has been the most popular Web Server software for more than 10 years. Apache accounts for more than 50% of the Web Server market, this also makes it the most popular attack

Tomcat vulnerability utilization and security reinforcement instance analysis

Tomcat is a free and open-source WEB application server of the Apache Software Foundation. It can run on Linux, Windows, and other platforms, thanks to its stable performance, good scalability, and free features, it is favored by many users.

Mobile app intrusion diary (on)

[0x00]-Overview [0x01]-application monitoring [0x01a]-insecure Data Storage [0x01b]-decompilation program installation package [0x02]-Man-in-the-middle attack [0x02a]-tool preparation [0x02b]-Man-in-the-middle attack [0x03]-server

Resolving disputes allows the IPsec and NAT technologies to coexist peacefully

Currently, network security and network address translation are widely used. For any of these technologies, it is very good. Many people are thinking about how to share two good technologies but make them safe. Network Security (IPsec) and Network

Clever use of port redirection to break through the gateway into the Intranet

From FoolishQiangblog Some people often ask me this question "how to enter the intranet" and how to answer it. In summary, it is a sentence "break through the gateway and use port redirection to enter the intranet ". The first choice is to break

In fact, it's easy to teach you how to set up a safer wireless network.

Set wireless encryption and change user name and password With the popularization of wireless networks in modern homes, people's security protection needs are constantly increasing. But how can we make the wireless networks in the home more secure?

Http Authentication Url and csrf = Router Hacking

First, let's briefly describe what is Http Authentication. The server returns a 401 status and a WWW-Authenticate header.   The WWW-Authenticate header contains descriptions of the Http Authentication box, such   Enter the user name and password

NBSI Injection Analysis and tracking report (MSSQL)

NBSI Injection Analysis and tracking report (MSSQL)Source: emotional network Author: SoftbugPreface:Writing a good tool is not easy, but writing an injection tool is not easy. This article systematically analyzes the testing ideas of Niu Ren by

Top 10 shopping website Security Assessment

Online shopping has increasingly become a lifestyle pursued by young people. But is online shopping safe enough? Is there enough "checkpoints" to prevent risks? This reporter recently conducted an online test on 10 popular shopping websites, and

How to Prevent database Injection

As ASP script systems are widely used on the Internet, script attacks against ASP systems are becoming increasingly popular. In these attacks, attackers use injection, cross-site, violent library, upload, Cookie spoofing, and bypass to control the

SQL blind injection attack technology Overview

1 SQL blind injection attack technology overview JavaphileSQL blind injection attack technology OverviewCoolswallow of Javaphile (coolswallow@shaolin.org.cn)Blind SQL Injection Techniques: A SurveyAbstract: This paper gives a survey of current Blind

Browser hijacking caused by Cross-Site Scripting

| = -------------------------------- = || = ------ = [Browser hijacking caused by cross-site scripting] = ------ = || = -------------------------------- = || = ------------- = [By rayh4c] = ------------ = || = ----------- = [Rayh4c@80sec.com] = -----

Some research on data obtained by union in mssql Injection

Extracted from bloodsword  During injection, in the access and mysql environments, we usually obtain data through union. However, in the mssql environment, union often does not work. If the page does not report an error and openrowset is unavailable,

A Better Member-Based ASP Photo Gallery SQL Injection patch Analysis

Riusksks blog Previously, an SQL injection vulnerability about A Better Member-Based ASP Photo Gallery was published on milw0rm:Http://www.milw0rm.org/exploits/8012And then it was officially repaired. If you open the following

Research on the alternative writing of a message book into a Trojan

Magic spring [B .S.N] Follow Script Security sites.google.com/site/bsnguanzhujiaobenanquan In the "Mining vulnerabilities in message books" article, I wrote a paragraph, that is, for the study of writing a sentence Trojan into the database, you can

Browser hijacking using the window reference vulnerability and XSS Vulnerability

= Ph4nt0m Security Team = Issue 0x03, Phile #0x05 of 0x07 | = --------------------------------------------------------------------------- = || = --------------- = [Browser hijacking using the window reference vulnerability and XSS vulnerability] = --

Who is watching my website? First: DOM sandbox vs cross-site scripting (XSS)

Source: External region of Alibaba Cloud On Sunday afternoon, it was raining heavily. I couldn't go out. I started Plurk and thought of the "XSS challenge" that was launched before Plurk. I only needed to find the vulnerability, if you confirm and

Methods and code for improving the anti-DDOS capability of Discuz

Because of the special nature of the admincp file. When a new connection is generated. It will occupy a lot of system resources. Therefore, when multiple IP addresses continuously access the admincp. php file, the server is vulnerable to DDOS

PHPWIND 7.5 usage Principle and Method

From kwang.cn If ($ route = "groups "){Require_once $ basePath./action/m_groups.php;} Elseif ($ route = "group "){Require_once $ basePath./action/m_group.php;} Elseif ($ route = "galbum "){Require_once $ basePath./action/m_galbum.php;}This is the

Joomla Component Multi-Venue Restaurant Menu Manager & amp

Test method:The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! # Exploit Title: Joomla Component Multi-Venue Restaurant Menu Manager SQL Injection Vulnerability#

Total Pages: 1330 1 .... 198 199 200 201 202 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.