1x00 background
If a website is found to have a vulnerability, perform the test:
Is this a cgi script http://xxx.com/cgi-bin/printfile.cgi that gets web source code? File = http://www.baidu.com compiler is habitually tested after file .. /.. /.. /..
0x00 background
Feye recently detected a highly spoofed phishing email (fork phishing email) attack targeting financial institutions in the United States. The malicious code used in the attack is generated by a spy and monitoring tool sold by the
First, apply for a free domain name from the peanut shell or other dynamic domain names.
1. Write the rules on the server to prevent SSH connection failure.
-A input DROP-A INPUT-p tcp -- dport 80-j ACCEPT-A INPUT-p tcp -- dport 22-s finy. hhks.
Vswitch Port Security: vswitch port security allows only a specific mac address to send frames to the vswitch interface by configuring the switch interface. If the switch receives a frame from the mac address, the frames from the device are
A Hollywood hacker empire once made new humans "hackers" a perfect savior, but is it true in the real world? Recently, Southern Metropolis Daily disclosed an international professional hacker: Alexander Jones (Alexander Jones). What he is best at is
Enterprise Network Security Model EvaluationWhich security mode should we choose? Depends on the situation. Because it depends on which method is most suitable for your organization, the following problems are summarized:· How is your organizational
0x00 Wedge
Recently, James had a headache. It turned out that an Android phone of Goddess had a strange problem, and the text message could not be received by others. What's more, the money the goddess used to prepare for online shopping was
Today, China Telecom's broadband network has started to enter the home. As a home terminal, China Telecom provides a ZTE F460 optical cat. This device integrates all the Internet, TV, and phone. However, the All-in-One device that provides four
IPtables is a packet-based firewall software that runs well on low-configuration servers. All Linux distributions contain it.
Security rules on network devices are usually sequential matching, such as the ACL of a Cisco device. The core of IPTables
Main Ossim Functions
By integrating open-source products, OSSIM provides a basic platform that can implement security monitoring, including Nagiso, Ntop, Snort, nmap and other open-source tools are integrated to provide comprehensive security
I learned these things in dvwa (Damn Vulnerable Web App). I installed dvwa in my free space. If you are interested, please check it out. DVWA
If you want a user name and password, you can contact me: sq371426@163.com
Dvwa is provided by google for
If the user in the game life page to share the content of others can find the game life user's QQ number such as game life home page: http://igame.qq.com/qdrlennz with Google browser open after review elements, ctrl + F search and forwarding before
Unauthorized downloading of plug-ins with "read permission" and downloading of plug-ins without chargeReproduction steps:
1. Use the Administrator account to upload an attachment with a high read permission. 2. Use a low-Permission user account
The 0-day elevation method of 03 system under Aspx has a high success rate. However, the following conditions must be met:1. webshell supports aspx2. Execute the cmd command3. The system disk has a writable and readable directory.The tools to be
Qibo cms won qibo cms with the power of combining three 0day backend getshells with the front-end storage-type xss + background CSRF + with little threat and negligible impact, although it is not a serious vulnerability, the problems and
I haven't played XSS for a long time. In the vulnerability reply, the dispatch Administrator said that many of my friends are scanning their websites. (It seems that this is not good. Can you get a test, do not scan other servers). After seeing the
SQL bypasses double insurance and then injects + does not need to solve MD5 background Authentication Bypass (and bypasses the verification code written in the config file during installation) + background GETSHELL no matter the technical
I have recently studied PHP vulnerability mining, summarized some of the vulnerabilities I have discovered, sorted out some ideas, and asked various gods to supplement, criticize, and guide them ~
All examples in this article are from
The method of penetration testing for the target site,Objective: To obtain the target operating system control permission(Windows: administrator,Linux: root) Let's add other frequently used methods! By the way, correct the errors in this article.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service