New Linux Trojan Ekocms appears, screenshots, recording
Dr. Web, a Russian software vendor, recently discovered the Linux platform's new Trojan Linux. Ekocms.1. Currently, from the Trojan samples intercepted, the Trojan can take screenshots and
Linux Kernel group_info UAF vulnerability exploitation (CVE-2014-2851)
This case studies CVE-2014-2851 vulnerabilities that affect Linux kernels until 3.14.1. First of all, I am very grateful to Thomas for his help. He gave his initial analysis and
Pack several security vulnerabilities on the Ticwear assistant APP interface, mall, and developer Platform
Pack several security vulnerabilities in the Ticwear assistant APP interface, mall, and developer platform (any user password reset/SMS
Google Chrome Document: open function Spoofing Vulnerability (CVE-2015-6782)Google Chrome Document: open function Spoofing Vulnerability (CVE-2015-6782)
Release date:Updated on:Affected Systems:
Google Chrome
Description:
CVE (CAN) ID: CVE-201
Honeywell 93gas Detector information leakage (CVE-2015-7908)Honeywell 93gas Detector information leakage (CVE-2015-7908)
Release date:Updated on:Affected Systems:
Honeywell Midas gas detectors Honeywell Midas Black gas detectors
Description:
A vulnerability in the GPS Positioning System of Ping An can leak a large amount of information (user information/order information/real-time vehicle location)
Detailed description:
Http://gps.lnwin.com/
Account: testPassword 123456
After
Do you believe this? The smartphone may disappear within five years.
1. Do you believe it? The smartphone may disappear within five years.
Five years later, Apple may no longer be able to make money by creating a new iPhone. Want to know why?
Arista EOS Remote Arbitrary Code Execution Vulnerability (CVE-2015-8236)Arista EOS Remote Arbitrary Code Execution Vulnerability (CVE-2015-8236)
Release date:Updated on:Affected Systems:
Arista EOS Arista EOS 4.15-4.15.0FX1.1Arista EOS
Restless chess and card gamesPreface
Games have gradually penetrated into our lives, and game Trojans have gradually penetrated into our lives. Various Trojans are waiting for us to click. Then we steal our data, our equipment, and our money.
Analysis Report: embedding malicious payload Word documents
A week ago, Mr. Xavier Mertens, sans isc management and freedom security consultant, analyzed a malicious Word document. The following is his analysis report.
Event background
Last week,
Magento storage xss detailed analysis
Affected Versions: Magento CE
0x00 Magento Introduction
Magento is a professional open-source e-commerce system. The legendary world's No. 1 e-commerce system. Magento is designed flexibly and has a modular
Embedded-WINKHUB edge channel attack (NAND Glitch)0x00 Preface
With the rapid development of IOT, research on the security of various embedded devices and routers is becoming increasingly popular. however, unlike previous software-only security
A System in Tianya has been added to the background management of the Forum for xss blind access.
Tianya customer service system has million xss user information, which can be managed in the background of the Forum (users with insufficient customer
Xss murder caused by "recent visitor"
Recently, a "recent visitor" function has been roughly implemented on the homepage.
Then there are various interesting guys on my homepage:
Also:
As a professional front-end, I was attacked by xss.In
China Telecom Jiangxi main site can be accessed by getshell over waf
Verify getshell
Address: http ://**. **. **. **/res/active/4G/upload. jsp (login required) Upload Vulnerability is also installed with security software, so I killed all my
Hong Kong Cloud technology main site SQL Injection Vulnerability (leakage of tens of millions of installed machine information)
RT
Main site address:
http://**.**.**.**/pc/index.aspx
Injection address:
Http: // **. **/pc/productlist. aspx? Productid
SQL Injection in a management system of Zhengzhou Nissan # a large amount of data information can be obtained
RT, a large amount of database information
0x01 vulnerability location
eip.zznissan.com.cn:2051
Or the electric vehicle management system.
SQL injection vulnerability in the APP on the official website of hailoan
SQL injection vulnerability in the APP on the official website of hailoan
Purpose: To detect the APP of good loan network and find SQL injection in the following places:
Air Security-Sichuan Airlines's alternative brute-force bypass Verification Code (resulting in leakage of internal information)
RTDetailed description:
High RANK; Sichuan Airlines's MAIL system uses IBM Lotus Domino MAIL Server with verification
One of Dropbox's Web Security Protection Policies: Content Security Policy (CSP)-based reporting and filtering mechanisms
One of Dropbox's Web security protection measures is to use content-based security policies (CSPs ). Devdatta Akhawe, a
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service