GNU glibc Denial of Service Vulnerability (CVE-2014-8121)
Release date:Updated on:
Affected Systems:GNU glibcDescription:Bugtraq id: 73038CVE (CAN) ID: CVE-2014-8121
Glibc is the libc library released by GNU, that is, the c Runtime Library. Glibc
PCRE Denial of Service Vulnerability (CVE-2015-2327)
Release date:Updated on:
Affected Systems:PCRE pcreDescription:CVE (CAN) ID: CVE-2015-2327
PCRE (Perl Compatible Regular Expressions) is a Perl library, including a perl-Compatible Regular
Alictf linux exploit Solution
1. Load modulesSudo insmod moduledmesg can see the hook. It is suggested that the module hijacked the system call, or the system call may be added.Then I wrote a program to traverse the system call, confirmed that no
Local Denial-of-Service for Huawei P7 mobile phones
Component exposure, improper Intent Filtering
For Huawei P7 telecommunications version 4G mobile phone, firmware version P7-L09V100R001C92B609, EMUI 3.0Malicious apps without any permissions can
How to deal with anti-buffer overflow Technology in Android1. What is ASLR?
ASLR (Address space layout randomization) is a security protection technology for buffer overflow. It randomizes linear zone la S such as heap, stack, and shared library ing,
Unauthenticated remote control of computer shutdown and screen lock under cheetah wifi
Enable the cheetah WiFi hotspot on the computer. One function is to remotely control the shutdown and lock screen of the computer. It is found that authentication
Mobile phone Control for Intranet penetration
I have been studying the methods from wifi cracking to pc and mobile phone Control recently. I want to share with you how to download and replace apk on a mobile phone!
(1) Environment:Target machine: 192
One-click rsync server shell script configuration in CentOS
1. Save the following code as a file and upload it to the server named rsync. sh.
#! /Bin/bash
# Rsync Written by zhumaohai
# For more information please visit http://www.centos.bz
Simple shell script for Security Log statistics in CentOS
Every time you sort out security logs, it is very troublesome. You can simply edit a script to count the total number of attacks per month, the total number of each attack type, and the top 10
Analysis of HTTP-channel worm attacks occupied by BT downloadsFault description
A recent customer reported that their network was slow, the webpage was slow, and sometimes emails could not be sent and received normally. They want to know why the
The user information leaked by unauthorized access exists on a site of Home Inn.
Rujia's website has unauthorized disclosure of user information that can be traversed #2
The problem still lies in home optimization.Http://youxuan.homeinns.com/After
Formatting String Vulnerability Experiment
1. Experiment descriptionThe formatting string vulnerability is caused by Code such as printf (user_input). user_input is the data input by the user, and such programs with the Set-UID root permission are
Test the XXE vulnerability in SpringMVCThe SpringMVC framework supports XML-to-Object ing. Internally, it uses two global interfaces Marshaller and Unmarshaller. One implementation is implemented using the Jaxb2Marshaller class, which naturally
BCTF 2015 WEB Question clearance strategy (Writeup)
About bctf:
BCTF is a network security challenge held by the Blue Lotus team. It was only available in China last year and will be open to the whole world from this year. We welcome our partners
How to apply the authentication module and. htaccess file to ensure Web Security
To restrict access to a webpage, you can use the Authentication Modules and methods provided by Apache and a third party to verify the user's creden (such as the user
YOHO! In-stock CSRF, You Can batch Delete others' shopping cart content and modify the shipping address.
YOHO! It's nice to have the goods, but it's a pity that the year-end prize will not be issued in March.Here, a csrf is submitted to delete items
Create a permanent backdoor using NTFS data streams
NTFS exchange data stream (ADS) is a feature of the NTFS disk format. In the NTFS file system, each file can have multiple data streams, in other words, in addition to the main file stream, many
Optimistic about your portal-data transmission from the client-insecure fixed EncryptionFirst of all, we need to declare that this article is purely the ignorant opinion of a little developer who has no foresight or practical knowledge. It is only
Optimistic about your website-common WEB security terms-CSRF attacks1. A brief description of CSRF (Cross-site request forgery, also known as "one click attack" or session riding, usually abbreviated as CSRF or XSRF, is a type of malicious use of
Cmseasy full-site user cookie enumeration counterfeit Login
This problem is tricky because of the openid.
We have analyzed a case before:Cmseasy logical defects can be upgraded common users as administrators (shell will be difficult):
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service