Code auditing Overview
0x00 Introduction
I have read all the PHP code auditing books written by seay. as a little bit of code auditing, I hope to provide my gains to some people who are just like me, as well as an overall framework and common
Hackers have quietly moved the attack direction to the mobile platform.
Unlike computers, mobile phones store various types of user information, including email addresses, personal sensitive information, and bank information. Based on this,
Last part of Windows shellcode Development (3)I. Introduction
In the last part of the "Windows shellcode development getting started" series, we will write a simple "wapMouseButton" shellcode, which swaps the left and right mouse buttons. The basic
Be alert for attacks with CVE-2015-2545 VulnerabilitiesPreface
Recently, APT Warning Platform captured an attack sample, after analysis, the sample seems to use CVE-2015-2545 for attacks, and has a high level of attacks.Analysis
This sample is
Prohibit computer sharing files, group policies prohibit shared folders, and disable network sharingTo disable file sharing on a computer: Method 1: Cancel file sharing through the sharing settings of the operating system. The specific method is as
Penetration testing practices
In fact, I personally feel that a complete penetration (from the perspective of hackers to think about problems) should be to do everything possible to obtain the highest permissions of the target system or server,
JasPer jpc_pi_nextcprolactin Denial of Service Vulnerability (CVE-2016-1867)JasPer jpc_pi_nextcprolactin Denial of Service Vulnerability (CVE-2016-1867)
Release date:Updated on:Affected Systems:
University of Victoria JasPer 1.900.1
Description:
A document is leaked, resulting in 12306 direct access to the background of a system
Some documents should not be leaked.
http://www.sheny.12306.cn/Dzsw/downLoad/Dzsw201311doc.doc
The Manual of the Railway Freight electronic commerce system
A station of prudential Trust has command execution (involving millions of users/involving massive amounts of capital data/involving multiple bank agents)
RT
**. **: 7002/etrading/command execution exists. a large amount of information is found by
An interface for password verification in Meituan can be cracked (affecting Meituan merchants and Meituan take-out merchants)
An interface for password verification in Meituan can be cracked (hundreds of merchant accounts can be successfully logged
A storage-type XSS of Sina SAE can be targeted at applications (Browser User-Agent)
Reference wooyun-2010-066189, not strict repair
Sina sae log center real-time log function storage XSSIn the wooyun-2010-066189, xss is placed on the link to the
A command execution vulnerability exists in an important system of skyworth. You need to delete the shell and upgrade it.
No one submitted it, which is very dangerous.
Vulnerability addresses: http://skyhome.skyworthbox.com/Skyworth smart Router
A critical vulnerability that can steal passwords of Baidu accounts on a large scale (trigger a full-line attack)
Xss rookit, Baidu basically exists in all core businesses (Baidu Post Bar, Baidu news, Baidu know, Baidu encyclopedia, Baidu music, etc.
Huatu education has a vulnerability that kills 21 database servers in the intranet and involves millions of users.
Seckilling 21 database servers on the Intranet. The affected sites include but are not limited to: face-to-face, online schools, books,
Full SQL Injection caused by a log leakage on the KFC Main Site
A log is leaked to a complete SQL injection process.
First, the artifact is scanned
http://www.kfc.com.cn/service/log.txt
---------- Begin ----------- 1/19/2016 12:49:04 PMSystem.
A substation of founder broadband has a vulnerability. You can use Getshell.
A sub-station of founder broadband
Http://traffic.founderbn.com/
Cacti installed the weathermap plug-in to write arbitrary files./Plugins/weathermap/editor. php? Plug = 0
Thoughts and Countermeasures on Database theft and credential stuffing
Database theft refers to the theft of the website database by hackers. Credential stuffing refers to the attempts by hackers to log on to other websites in batches using the
Floating HOME hotel chain stores Multiple SQL injections on a station (DBA permission/nearly orders)
Floating HOME hotel chain
Http://www.piaohomeinn.com injection point:
Http://www.piaohomeinn.com/hotelList? Shard id = 43
Sunshine insurance group's java deserialization command executes two packages (write shell tutorial Linux)
Celebrate the achievement of 1000rank and share some experience in shell writing.This is a Linux server and has the default jboss
Okai airline Password Reset Vulnerability (required)
Http://bk.travelsky.com/bkair/page/users/front/userLogin.jspPassword retrieval process1. Enter the user name and submit it (brute-force)
2. Enter the password retrieval question (the page
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service