What you know:Creating autorun. inf files with various tricks prevents the virus from automatically playing on the USB flash drive.
What you don't know:You can create and delete files in Windows.
I have been looking for ways to enhance the security
In many cases, anti-virus software can kill our payload. In many cases, we use ENCODE to directly escape the software. However, as more and more people use it, this method is gradually not enough. Some people have said that 0x00 in shellcode is not
BKJIA ziming Series
In the previous course, I mainly introduced what pe is. In this course, we mainly talk about shells. This is also a required course for cracking software and a required course for reverse analysis.
In some computer software,
Tool: OllyDBG1.1 Chinese version; LordPEOperating System: WIN2KTarget Program: Armadillo.exe (3.6 Main Program)Recently, researchers have heated up on Armadillo 3.6 detachment, including standard shelling and CopyMemII + Debug shelling. So I am also
Some time ago, I was very interested in the Armadillo shell, So I collected a lot of information and wanted to study it,
These articles come from many sites. Thanks: Reading forums, cabbage parks, exploring magazines ......
Recently, we have seen a
Author: bad customersInformation Source: Alibaba Cloud Security Team (http://bbs.x-xox-x.com)
Today I have nothing to do, so I thought of the major forums to slide and see if there is any new 0-day missing. I did not intend to enter a Shadow
Author: Monster [E.S. T]Original Source:Www.hackerm.com.cnInformation Source: Technical Discussion Group of the Information Security Team of evil baboonsYou are welcome to repost, but please ensure the integrity of the article
I was looking for
System: Huawei data Decision Making System address: http: // 221.194.146.18: 8081/WebReport7/ReportServer? Op = fs_load & cmd = fs_signin & _ = 1347302374226 seems to be a general software-finereport report system official website:
I. IntroductionCSRF (Cross-site Request Forgery), Chinese name: Cross-site Forgery. Attackers can steal your identity and send malicious requests in your name. For example, you can steal your account, send emails as you, and purchase items.Ii.
Compared with Oauth1.0, Oauth2.0 simplifies the process, and improves security through HTTPS and restricted callback addresses. However, the implementation of Oauth2.0 by Internet companies does not fully comply with Oauth2.0 standards. So there
1. when you get the linux root shell, you can use the following statement to add the Administrator account to write "useradd icefish // Add the icefish user passwd icefish // set the password awk-F: '{print $1}'/etc/passwd can be used to check the
Netease youdao a substation blind note, resulting in user information leakage address: http://campus.youdao.com/campus/job_list.php? T1 = campus & positionId = 1 the vulnerability parameter is positionId. Use the and statement to determine the
Webshell has the SYSTEM permission, but cannot successfully Add the administrators user. Therefore, it cannot connect to 3389.
The reasons are as follows:I. Killing Software1,360 anti-virus software2. Coffee antivirus software3. Kaspersky Antivirus
Some time ago, dedecms and so on broke out a variety of 0-day cases, so I found a small php open-source program to open the knife.Tool used in the process: phpxref: a useful php code audit auxiliary tool in Windows Grep: linux to find the key
While a traditional cross-site scripting vulnerability occurs on the server-side code, document object model based cross-site scripting is a type of vulnerability which affects the script code in the client's browser.DOM or the document object model
Windows Management Specification (WMI) provides three methods to compile the file into the managed object format (MOF) of the WMI Repository: Method 1: run the MOF file to specify the Mofcomp.exe file as the command line parameter. Method2: Use the
Blind play, X to the background found that all apps of the company can push messages to the background (many apps of the company, various platforms, and all the feedback are sent to the background ), if the PUSH message is used for illegal purposes,
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service