How to perform security analysis on unknown apps on mobile phones
Mobile Anti-Virus Software mostly uses signatures to determine the virus. It cannot be prevented before the virus is intercepted. However, the anti-virus software on the PC end has a
Prohibit computer sharing of files, prohibit LAN sharing of files, and prevent copying shared filesSometimes to protect the security of computer files, we need to disable computer sharing and block LAN shared file access. The specific settings are
FFmpeg 0-day vulnerability allows attackers to remotely steal local files
FFmpegg, a widely used open-source multimedia framework, discovers a 0-day vulnerability that allows attackers to remotely steal local files. Popular FFmpeg applications
Research on Android system call hook (I)
When talking about Xposed, everyone should be very familiar with it. It mainly hooks the target function at the Java layer, and is powerless to call the underlying system. Since the hook system calls need to
Java deserialization vulnerability batch Detection
PrefaceJava deserialization vulnerabilities have appeared in people's field of view for a while. The Rubik's Cube security team has reproduced this vulnerability and developed a highly accurate
Vulnerability Management e-stream
0x01 PrefaceThis article mainly aims to share and record some of your own growth. If something is not well written, I hope you can still make an ax. In the early days of Vulnerability Management, I personally felt
Principle of HTTP Evasions: Block Transmission bypasses the Firewall
This is the third article in the HTTP Evasions series. The Transfer-Encoding field is used to block request packets to bypass the firewall. For example, you can bypass malicious
Solutions to XSS attacks
In my previous article "XSS attacks of front-end security", I did not provide a complete solution to XSS attacks, and XSS attacks were so varied, are there any tricks that can be used to compete? After all, developers cannot
Jingbo petrochemical mall Vulnerability (leakage of a large amount of oil purchase information/leakage of a large number of car owner's personal details/ROOT permissions can be tampered with to buy oil)
Jingbo petrochemical mall Vulnerability
Deserialization of PERL 5.80x00 simple article Translation
During the penetration test, I found that an application contains a form with a base64 encoded hidden attribute parameter named "state ", contains some strings and binary data.
#!bash$ echo
BYD remote command execution can roam 44 hosts in the Intranet
High rank
219.134.188.42
A byd siteJAVA deserialization command execution vulnerability exists!
The host name can also be seen as byd.Ipconfig
Intranet IP address, which can
Weak passwords in a CSDN system leak vulnerability information of all projects (including more than usernames/email addresses)
Weak Password in http://git.csdn.net/JIRA system, password 1234568148 cuixiang 302 false 45816867 guochao 302 false 458182
The Getshell of a Project System of Beijing Telecom has been added to the Intranet (you can view the information about the entire company's devices/project information leakage)
--
Defect address: http: // 59.41.46.167: 8122 -- this is Sichuan
Multiple internal systems of the central control group can be infiltrated, resulting in a large amount of information leakage.
Founded in 1993, the central control group is China's leading provider of automation and information technology, products,
The Haier community XSS vulnerability allows you to directly log on to another user's account (and possibly log on to the APP to control users' smart devices)
1. register two accounts, one for xss and the other for victims. log on to the two
Attacks and defense against abuse of permissions in the IOT age
In addition to debugging on the android real machine, the permission Abuse Vulnerability has many other scenarios. It is particularly widely used in the IOT field. For example: A smart
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service