[Detailed analysis] X Windows's 22-year Vulnerability

X WindowsThe system, as a Linux Desktop around the world, has existed for more than 20 years and still has bugs. A few days ago, Sysadmins provided patches for the libXfont library to address the newly discovered 22-year Privilege Escalation

Professional attacks: Linux basics of excellent hackers, part 4 (search for files)

The reason why I wrote these columns is that many people are puzzled when using Linux. As a hacker, Linux skills are irreplaceable attack tools. Because Linux has a file directory structure different from Mac OS and Windows, many new users will have

Typical Android bootloader Analysis

1. What is bootloader?   In short, bootloader is a small program that runs before the operating system kernel runs. Through this small program, we can initialize hardware devices and build a map of memory space to bring the system's hardware and

ASLR/DEP bypass technology Overview

By WinsOn @ Cybersword In the classic stack overflow model, the return address of the function is overwritten to control the program execution flow (EIP register). Generally, the return address is overwritten with 0x7FFA4512, this address is a jmp

Web browser development-related website security vulnerability packaging (source code leakage, code packaging, command execution, and online backdoor files)

Http://kernel-c.maxthon.cn/www/init.php server not resolved can download the database configuration file http://build.maxthon.com/code packaging http://partner.maxthon.com/login.action struts2 vulnerability, found has been intruded (dark clouds have

Detailed description on exploitation of the CSRF vulnerability in D-link Routers

1, IntroductionThe purpose of this article is to show the harm of CSRF vulnerability, take D-link DIR-600 router (hardware version: BX, firmware version: 2.16) CSRF vulnerability as an example.The CSRF vulnerability of D-link is already public. This

Use Google Authenticator to enhance SSH login security

Environment: CentOS 6.3 minimal i386 Basic component installation: yum -y install wget gcc make pam-devel libpng-devel  1. Install qrencodeOn Linux, a command line tool named QrenCode can easily generate a QR code. The google authenticator command

How to back up databases and files remotely

Author: Mickey and Anthr @ XWindows1.Determine which port is availableSometimes there is a firewall, and you don't know which port can come out. You only have SHELL. How can you determine which port can come out? If you are using a version earlier

Learn how to perform penetration test VPN and Vlun VPN

The author of VulnVPN has created http://www.rebootuser.com/, which is a very good tool. Our goal is to obtain root access to the VPN Server. This article will take you through every step of the entire process. Set VulnVPNAnd Backtrack VulnVPN

Depth: An Exploration of social engineering attacks (II)

Depth: An Exploration of social engineering attacks (I) http://www.bkjia.com/Article/201312/262946.htmlIn other words, we have not only learned the basic information of the target but also obtained the target IP address. This certainly cannot

Application of open-source tools to monitor enterprise LAN security: configuration and use

Enable Cacti round robinDelete the hash tag from the left end of the/etc/cron. d/cacti crontab file to enable Cacti polling. */5 entries in this file cause crond to execute the script once every five minutes. $ Cat/etc/cron. d/cacti*/5 *

Ossim system principles and practices

650) this. width = 650; "title =" 2014-02014-02014-02014-01-20 20.11.04.54.png "style =" float: none; "alt =" wKioL1LdPBmz67w7ABa2h3aqyMU143.jpg "src =" http://www.bkjia.com/uploads/allimg/140207/2205253045-0.jpg "/> 650) this. width = 650; "title ="

How to hide your Email address on the webpage

You have a website where you want to put your email address on it so that others can easily contact you. However, you are worried that spam may flow in like a flood once the email address is published. You are right. Currently, crawlers crawling

Detailed description of JBoss remote method call vulnerability Exploitation

In the morning, I got up and opened my microblog and saw an article about the Jboss vulnerability. It seems very difficult for me to wait for the cainiao article, so I checked the information at home and abroad, the translation has written this

Arbitrary user order traversal of changtu Network (a large amount of sensitive information)

The problem lies in the changtu app. After logging on to the mobile phone, the mobile phone finds that there is almost no verification for the query request. The only parameter "pkTicketOrderId and userId" does not check each other. The following is

Logic problems of a substation on Renren

Still all evil wordpress, although the core code security factor is very high, but the logical defects lead to brute force cracking problem domain name: http://fed.renren.com OK, can automation fuzz 1, http://ued.aili.com /? Author = * (1, 2, 3 ,...)

360 change the password of any user

360 any user password modification (critical 360 mobile guard, 360 cloud disk, 360 browser cloud synchronization, leakage of Address Book, SMS, call records, etc.) and a female star account Oh! Ps: I tested the mailboxes of several 360 executives.

Pulse network parallel permissions + CSRF allow the instructor to help you send Weibo posts

Pulse network parallel permission + CSRF. Ask Kaifu to send Weibo posts for you. The problem occurred in the http://www.vmaibo.com/timer timed occurrence function set a timed sending microblogging due to the modification function has parallel

An attempt to change the write permission to immediate execution failed

Ps: I think it is necessary to record the process of this exploration. If you have a better idea, please remind me...Scenario:Web-Internet, apache, PHPDb-Intranet, mysql, win 6.1x64A get union Select MySQLi is the Root permission. How can this

Security risks and solutions for business processing caused by concurrent requests

0x00 background A simple purchase procedure looks like there is no problem. The remaining balance, goods inventory, purchase permissions, and other judgments are all-encompassing, from the beginning to the end of the packaging strictly. But why do

Total Pages: 1330 1 .... 571 572 573 574 575 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.