Microsoft Outlook vulnerability: Allows Remote Code Execution
Recently, Microsoft released a series of patches to fix some of the most influential and critical bugs in its products, including updating the Microsoft Office suite and solving some of
Android ARM 32-bit
The full name of drop is Return-oriented programming, which is an advanced memory attack technology, it can be used to bypass various universal defenses of modern operating systems (such as memory unexecutable and code signature ).
Analysis of CVE-2015-6974 Vulnerability
0x00: After iOS9.1 was released, pangu previously issued a topic about the vulnerabilities and exploitation methods they used to jailbreak. So I followed in for a little analysis.0x01: The problem lies in
Emlog automatic backup plug-in leakage full-Site Database Backup Vulnerability
This is the third time I found a critical vulnerability in my blog. The first time is a third-party storage, the solution is deleted. The second is "EMLOG album", that is,
Yun Da express information leakage (bidding plan + applicant information + administrative vehicle)
Huluwa, huluwa, one vine with Seven hangs ..Detailed description:
Standing on the shoulders of elders ~WooYun: internal information leakage caused by
Malware can delete all third-party apps not jailbroken iPhone
Malware can delete all third-party apps not jailbroken iPhoneA malicious iOS application can delete any non-system application on the device. Specifically, if A malicious application
General automatic shelling Method for Android applications
0x00 background and significance
Compared with traditional PC applications, Android applications are more likely to be reversed, because after being reversed, Java code or smali
Quick and efficient cracking of MySQL local and remote passwords
Quick MySQL local and remote password cracking! The first thing we need to explain to the database maintenance personnel is that you don't have to worry about it. You don't have to fix
Insurance security-Anhua insurance's JAVA deserialization vulnerability on an important website can penetrate multiple systems
Anwar Insurance
Http: // 221.8.57.106: 7006/Http: // 221.8.57.106: 7009/Weblogic deserialization VulnerabilityReverse
SQL Injection/unauthorized access/xss (demo successful) in p2p online lending system)
Only one home page is required.There are still safe dogs. But it is useless.
Inject 1 (test failed)See the code core \ deayou. core. php 65-86.
elseif ($_G['query_
Kingsoft ciba website MySQL blind note (bypassing GPC escape)
After reading this hole, WooYun: the SQL injection in the Kingsoft node has been fixed.But wide characters can be used to bypass GPC addslashes
sqlmap.py -u
Improper configuration of a substation in Baidu (the whole site source code can be downloaded to leak some sensitive information)
Baidu, you will know
Because the website is almost static and has no interaction, so...
Code Region
http://efe.baidu.
Part of the current target OA file can be traversed and downloaded
Entry level ~
Address: http://web.jingoal.com/#worklog (login required), may be shared with the microblogging attachment interface, part of the log attachments can be modified
Information Leakage from China Life Official Website
The website can freely refresh registered user information, and violently query user information to leak user information. The user information covers the real name, email address, and mobile
Unauthorized access to the Redis server of a financial investment company can cause a large amount of user information leakage.
Unauthorized access to the Redis server of a financial investment company can cause a large amount of user information
Use location to deform our XSS Payload
This article is a gesture I learned from a group some time ago. I will share it with you ~
In XSS, sometimes some filters are abnormal and filter many special symbols and keywords, such as &, (,), #, ', and ",
Use Shodan and Censys for Information Investigation
In the initial stage of penetration testing, online resources such as Shodan and Censys can be used as a starting point to identify technical traces of the target organization. This article
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service