Security risks of Edge browsers may be exploited by hackers.
Users who use Edge browsers should pay attention to the fact that this browser is considered to have some security risks recently and may be exploited by hackers to endanger computer
Linux kernel sound/core/hrtimer. c DoS Vulnerability (CVE-2016-2549)Linux kernel sound/core/hrtimer. c DoS Vulnerability (CVE-2016-2549)
Release date:Updated on:Affected Systems:
Linux kernel
Description:
CVE (CAN) ID: CVE-2016-2549Linux Kernel is
Detailed description of AceDeceiver Technology0x00 Preface
Security company palo alto networks published "AceDeceiver: The first iOS Trojan to infect any iOS device with DRM design defects" in March 17, and spread malicious programs using Apple's
Android app security risks of loading DEX files externally1. Risks of loading DEX files externally
The Android system provides the DexClassLoader, which can dynamically load and interpret and execute DEX files contained in JAR or APK files at
Analysis of SlemBunk Trojan Samples
Reading: 584
SlemBunk was first discovered by FireEye. Later, some other security companies also found that the author had the honor to get the sample and analyzed the Trojan horse to find that its design was
Special Condition Data Transmission Analysis
0x00 ask the restaurant
Is there anything you can't get? Open a brain hole.
The reason is that at the end of 2014, we saw Kingsoft's online malicious code analysis system "Fire eye"
Search for a website SQL Injection Vulnerability (DBA permission)
Search for a website SQL Injection Vulnerability (DBA permission)
Vulnerability addresses: http://oa.xywy.com/We will capture packets and modify the user nameAnd then drop the ing
SQL Injection exists in the official medical drug search APP (involving more than 1 million user data)
SQL Injection (including 116 million + User Data) exists in the official medical drug search APP
Objective: To detect the Android APP of a
Due to a product vulnerability in Iot era, Getshell needs to carefully check the source code (discover webshells)
Found the predecessor shell.
Source git information leakage:
http://vip.now.net.cn/.git
Download the source code found that there is a
Cool music main site SQL injection vulnerability requires parameter filtering (ROOT injection/Intranet ip leakage)
Cool music main site SQL Injection Vulnerability (ROOT injection/Intranet ip leakage)
Different from WooYun: The domain name of a
Hainan Airlines deserialization command execution (Intranet)
~~~~
202.100.226.94 corresponds to srm.hnair.comWeblogic deserializationHttp: // 202.100.226.94: 7001
## Configured using SAM by root on Thu Oct 29 17:18:19 2009## Configured using
IORegistryIterator competitive condition vulnerability can cause arbitrary code execution0x00 Introduction
CVE-2015-7084 is because IORegistryIterator does not consider the user State of multi-threaded simultaneous calls, causing Race Condition,
Getshell can be used for weak passwords in a substation of Huaxia mingwang (strong and weak passwords and patches are required)
Huaxia mingwang's weak password for a substation can be getshell (case study of cloud lock waf)
Directly go to the
HTTPS-related contentWhy https?
HTTP is transmitted in plaintext, which means that any node between the sender and acceptor can know what the content you transmit is. These nodes may be routers and proxies.
The most common example is user login. If
Case study of a rare MSSQL Injection Vulnerability
The author is going to share a fairly rare vulnerability found in last year's Google rewards program, the only one that the author has encountered throughout his penetration testing career.
The
Min An Property Insurance Company Limited multiple core system middleware weak password Getshell (many vulnerabilities are not fixed)
RT.
1. Core Business System of Min 'an Property Insurance Co., Ltd.
Http: // 218.17.200.230: 9004/casserver/login?
Analysis of security problems caused by releasing files to temporary folders
Recently, McAfee's advanced Vulnerability Detection System (AEDS) has detected some interesting RTF files that execute "additional" content in the document. In general,
Process Analysis of wireless penetration + social engineering acquisition of Wi-Fi + QQ + vro by neighbors
It's a useless blind game. Try a new dictionary...Finally, I got my sister's wi-fi password, sister's QQ number, sister's name, and Router
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service