OpenSSL DROWN death Vulnerability Detection and repair methods
I. Vulnerability Description: popular servers and clients use TLS encryption. SSL and TLS protocols ensure that users surf the Internet, shop, and instant messaging without being read by
Getshell can be used on the official website of UUCall. (root permission + main site + client shell + large amount of sensitive information leakage)
Can I use the previous homepage?
Target: http ://**.**.**.**/Start with the next station, http: // **
A certain design defect in zhenkung fu can be used to order any take-out with one cent of money (the order is verified before the order is generated in the background)
Generating orders does not validate front-end data
Go to the official website,
Can I send a "red envelope" to control others' QQ accounts? (Demonstration using QQ mail/xss not required)
How do I send a "red packet" to control others' QQ messages (using QQ mail as a demonstration/xss is not
A vulnerability in shundian online store may leak a large number of member and order information (various payment keys)
In November 12, 2014, Shenzhen shundian Chain Co., Ltd. was successfully listed on the New Three board, known as "Chinese Nasdaq.
Improper command execution vulnerability repair and bypass on a Baidu website
A command execution vulnerability on a Baidu site, which can be used to fix improper Bypass
#1 vulnerability referenceWooYun: Execute the st2 command on a Baidu site
Web vulnerabilities on major automatic card issuance platforms allow you to view card passwords and transaction information
You can use the Web vulnerabilities of the automatic card issuance platform to obtain transaction information such as card
Ruff. io is not properly configured. (Nan Chao: Li Ge's embedded smart hardware development company)
NanchaoCompany ProfileWe are an Internet company dedicated to simplifying smart hardware development. We welcome people who are willing to learn and
The full-network user password of Apsara stack can be reset.
The full-network user password of Apsara stack can be reset.Simple
It is not a brute-force SMS verification code, but a logic reset vulnerability.1. First, go to the forgot password
2
An interesting instance makes NoSQL injection no longer mysterious
This article focuses on the security issues brought about by mongodb, and then introduces the injection of NoSQL by an interesting CTF instance.MongoDB can adapt to open-source
An incorrect location in laiyi (involving 561858 orders containing detailed user information)
On such a cold day, there are still mosquitoes. In the morning, my brother got up and squatted, and mosquitoes were biting Chrysanthemums! It's so cool to
Immediately protect two SQL vulnerabilities on the master site (hundreds of thousands of insurance order information leaks)
Immediately protect two SQL vulnerabilities on the master site (hundreds of thousands of insurance order information
Ocai aviation design defects can cause (sensitive information leakage + unconditional 1 second admin reset)
Kill admin directlyRetrieve the homepage
Site:
Http://bk.travelsky.com/when the main site is open, it will jump to this station. This is how
Oz sandbox technical details
0 × 01 Introduction
The OZ system protects the program security by running the Linux desktop program in an isolated security sandbox, so that attackers can easily exploit the vulnerabilities of the application to further
A system vulnerability package in gionee may leak the IMEI serial number of 3.69 million users (unauthorized access/SQL injection)
Export the IMEI serial number file of the 3.69 million user in one click, and calculate 20 rank
Http: // 218.16.100.212
Chinacache new posture arbitrary Password Reset
Before the white hat submitted the Chinese talent through any password reset wooyun-2015-0117458, because the number of digits of the verification code is short and do not limit the number of times.
Database hit caused by improper design of the primary site of Ruili Network
Database hit caused by improper design of the primary site of Ruili Network
Http://www.rayli.com.cn/No verification code, no limit on the number of timesPOST/apsaradb for
Browser DoS Attack and Defense Analysis of 12 lines of code
There is a 12-line JavaScript code that can crash firefox, chrome, and safari browsers, as well as restart the iphone and crash android, the author of this article analyzes and interprets
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service