Source: www.hackbase.com
On the NT server that has not been patched with Services Pack6, there are at least 6 ways to see the source code of the ASP program. They are:
1, http://www.someserver.com/msadc/Samples/SELECTOR/showcode.asp? Source
/*************************
Note:
Determines whether the passed variable contains invalid characters.
Such as $ _ POST and $ _ GET
Function:
Anti-Injection
**************************/
// Invalid characters to be filtered
$ ArrFiltrate = array ("", ";
Foreign --Http://md5.rednoize.com/This site is in the form of a search engine and supports bidirectional conversion, that is, MD5 hash-> string-> MD5 HashThis usage is relatively simple. Enter the MD5 hash or string in the text box above to get the
I would like to give this document to my beloved pig, Xuan.Currently, web-based attacks are generally injected. Generally, the cause of injection is that the variables are not completely filtered, so that intruders can illegally execute programs or
When I wrote code today, I suddenly thought that I could not use a single file to process all possible injection points on the entire website for defense? In this way, you do not need to filter every variable in each program, saving time and code.
First, analyze what intruders have done!
I remember that for the convenience of installing RADMIN on his machine, I logged on and the password was incorrect. It seems that someone went up and the intruders also got the system administrator
Some time ago, Microsoft released an IE update Patch, causing the Flash control to fail to be automatically activated. As a result, many websites that use the src code to embed flash files are not properly displayed, A dialog box is always displayed
Speaking of url encoding, you may think of the url Encoding Vulnerability N years ago. Unfortunately, when I got in touch with the Internet, the vulnerability had long been extinct.
What is URL encoding? Let's take a look at the definition I copied
This vulnerability exists in both component upload and non-component upload. You need to read the following code carefully and understand the code.
The following uses the ASPUPLOAD component as an example.
The following three key functions:
Function
I saw a piece of code on the Internet: (I will explain the key part later)Id1 = replace (request ("id"), "", "") 'the replace function does not work in simple filtering.If id1 <> "" then': determines whether id1 is null.Set rs = server. createobject
Source: Network
This is a method for exporting log files to the web directory to obtain shell backups.Condition1. You must know the Web directory.2. The Web and database are not separated.Backup method:(1); alter database name set recovery full --(2
Method 1: brute-force cracking.
The most prominent one is the user name and password. The key is how to break the password? I found a specialized tool for breaking the serv-upassword (serv-upasscrack1.0a.rar) on the Internet. It's too slow. What
Involved procedures:ASP. Net
Description:ASP. Net processing XSS protection Defects
Details:To allow application developers to write secure code, Microsoft adds a new feature named "request confirmation" to ASP. Net 1.1 framework. Protects against
Table guessing process --------------------------------------------->Username range:Http://www.target.com/class.asp? Typeid = comedy film 'and 1 = (select id from password where len (name) = number of digits to guess) and '1Guess the User Password
Original launch: hacker alert lineAuthor: hackIEA friend said, I bought a 10 Gb space and I want to build a large website... I want to go all over China, I want ....= 660) window. open (http://www.bkjia.com/uploads/allimg/131128/140Q02191-0.jpg);
Caozhe blogHow to enable xp_cmdshell in SQL server 2005
EXEC sp_configure show advanced options, 1; RECONFIGURE; EXEC sp_configure xp_cmdshell, 1; RECONFIGURE;
How to enable OPENROWSET in SQL2005:
Exec sp_configure show advanced options, 1;
In today's world, Internet (Internet) has become a very important basic platform. Many enterprises have deployed applications on this platform to provide customers with more convenient and fast service support. These applications are constantly
Earlier versions are also possibly vulnerable. Information: Affected program: Network Weathermap 0.97a Remote-exploit: yes program address: http://www.network-weathermap.com/ Abstract Network Weathermap 0.97a is vulnerable to a persistent XSS when
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service