Program trusted path Code Execution Vulnerability

Time: 2012-09-26   [Vulnerability description] When using the CreateProcess function, when the first parameter lpApplicationName is NULL and the second parameter lpCommandLine contains spaces without double quotation marks, the function will be

The most basic security policy for Linux servers

1. Linux SSH Security Policy 1: Shut down the majority of hosts attacked on the unrelated port network, which are targeted by hackers who use scanning tools for a wide range of scanning. Therefore, in order to avoid being scanned, all ports, such as

One ibl Log Analysis

In the past few attempts to get a honeypot, the hacker's method of hacking into the website is to collect 0-day data. This time I decided to come to a great god. I won't talk about the day. It's about dz. I guess I'm still analyzing it when I write

Linux root exp for 2.6.37-3. x. x x86_64

Foreign hackers discovered a Linux kernel 2.6.37-3.8.9 vulnerability. Successful exploitation of this vulnerability may lead to privileged users. It is still fresh. Let's take a look. Relatively easy to use ~Http://fucksheep.org /~ Sd/warez/semtex.

Cainiao terminal breakthrough Summary

I haven't written anything for a long time. The study class is boring. Let's sum up the method for breaking through the terminal. I am a newbie on the Internet and I am actually using it.The first is the online method. 1. Command: win + R, win + D,

How to locate file fields in File Vulnerability Analysis

 Today, I saw someone asking me how to compare the file format document and what structure is being parsed In the debugging analysis program? I have summarized several methods here. You are welcome to add them, but sometimes you still need to rely

Application Security Testing: Dual-sided Black Box

The biggest risk of software security is the opaque nature of testing tools and processes, and different testing technologies (such as automated Dynamic Testing) cannot cover the potential possibility of false negative errors. Although the security

Protection Method chapter 2 (Virtual Machine template environment settings)

After receiving the previous article (How to Protect Your VM proxy Transit server settingsFirst, create a virtual machine named Original. As the Original virtual machine, configure the Virtual Machine and clone other virtual machines. Install the

Browser security (I)

0x00 background Well, long short asked me to write an article on browser security, so I appeared, please don't speak out, this scum technology. This article draws on Kcon and hitcon PPT.  0x01 Introduction The question about browser security is the

Basic knowledge of exploit on linux

The shellcode on linux is slightly different from the shellcode on windows. The shellcode on linux is called by the system to execute the desired function. View the system call number cat/usr/src/linux-2.6.38.8/arch/x86/include/asm/unistd_32.h

Simply modify the basic header to make the server more secure

Today, we can see the Response header returned by the server with such information. Server: nginx/1.4.0X-Powered-By: PHP/5.5.1Content-Encoding: gzip: The first shows the webserver used by the server and the version number.Article 2 shows the script

Tomcat Security Mechanism

Tomcat security mechanism BASIC Authentication BASIC DIGEST authentication uses MD5 encryption DIGEST FORM authentication for basic Custom forms, you can specify the login verification FORM form /login.htm /error.html CLIENT-CERT A

Prevent hackers from entering the system to create hidden accounts

What Should users do if hackers create a hidden account on their own computers? Although the account hiding technology is the most concealed backdoor, it is difficult for users to find the hidden account in the system. In fact, as long as you

Linux Kernel module Security

Linux can dynamically load kernel modules. In many cases, you may need to ensure the security of kernel loading. If attackers load malicious kernel modules, the kernel will become extremely dangerous. Of course, the safe way is to sign the kernel

Trs wcm 6. X Arbitrary File writing

Files can be written directly to the server. The file name and content can be customized. The affected version is unknown, which is about 6. x, there is no one-to-one test for the billable guy. It is unknown whether to use it. There are several

PERL: multithreading + Chinese cracking SQL Injection

Note: replace all the records in the Code with $. #! /Usr/local/ActivePerl-5.8/bin/perl-w Use IO: Socket;Use threads;# Function list;Sub gethost{If (# url = ~ /(Http ://)? (. + ?) /(. + )/){# Host = #2;# Path =/. #3;If (# host = ~ /(.*):(.*)/){#

Foreign MYSQL injection tutorial

(From Projectmoose 4th)[]-[1-Simple SQL Security by Netjester.]-[] Contact: netjester@zoite.net/irc.zoite.net I dont know about you, oh most knowledgable of SQL users, but when I learned how to build a database driven website from varous tutorials

Standard injection statement

1. determine whether there are any injection points; And 1 = 1 and 1 = 22. Generally, the name of a table is admin adminuser user pass password ..And 0 <> (select count (*) from *)And 0 <> (select count (*) from admin) --- determine whether the

An idea of circular injection

Source: http://blog.csdn.net/brain _/ When I was writing an injection program, I occasionally encountered some bad things, such as hanging on the explorer and not running, but hanging on other processes is normal, in order to solve the problem as

Perform a simple injection using ice dance 2.5.

Chapter Author: fuerSource: evil gossip Security TeamPreface:For a long time, I want to mix it up here, because the ice blood is here :)I want to post a post, but I found that my permissions can only be posted here. It is depressing.I have seen

Total Pages: 1330 1 .... 601 602 603 604 605 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.