Remote code execution in the cheetah Browser
1. download the latest version of the cheetah Browser: KSbrowser_5.2.85.9616.exe
2. Through analysis and observation of some User-Defined Function interfaces implemented by the cheetah (Some APIs under
Sogou browser extension can cause Remote Denial of Service
Sogou browser extension can cause remote denial of service. Version: 5.2.5.15900
This is a little prank. The advantage is to search for the extension idea API of the dog browser, which can
Quanyou home Terminal Management System Remote Command Execution
Logon addressHttp://tcm.iquanyou.com.cn/tcm/userLogin.actionVulnerability exists, but the system will jump automaticallyHttp://tcm.iquanyou.com.cn/tcm/frameLogin.jspSo upload a file
Baidu COM control BaiduSetupAx Remote Stack Overflow Vulnerability
The length verification of the COM control BaiduSetupAx parameter is incomplete. Malformed parameters can cause stack overflow.
This control will install and run the download program
Rising posture! How to crack the graphic lock of Android phones
The graphic lock of the Android phone is a 3 × 3 dot matrix. The number of connections in order reaches the lock/unlock function. At least four points must be connected, and up to nine
Defend against attacks
0 × 01. Preface
I am a cainiao security engineer. I had the honor to have participated in two security competitions, and some people had some personal experience, so I had this article.0 × 02. What will attackers do?
I
Commonly used iptables scripts
#! /Bin/bashexport PATH =/sbin:/usr/sbin:/bin:/usr/biniptables-Fiptables-Xiptables-Z # remote SSH Login, we need to enable port 22 iptables-a input-p tcp -- dport 22-j ACCEPT # WEB server, enable port 80 iptables-a
Grub Password and user permissions for CentOS System Security
1. Add the grub Password in linux
. Use the grub-md5-crypt command to generate the encrypted MD5 code
Grub-md5-crypt>/boot/grub. conf
Enter the password twice in the blank space and
Install Fail2ban in CentOS to prevent brute-force FTP/SSH cracking
If we do not need VPS for a variety of demanding purposes, we should try to avoid using VPS for website construction, because in many cases, we will be subject to various active and
One-click pptp vpn installation script under centos 6.x
A very practical script. All previously shared scripts are invalid... This script is useful in centos6.x.
1. Download the one-click installation package for vpn (dedicated to CentOS6)Wget http:/
Anti-Virus Defense Research: monitoring the replication and auto-deletion of malicious programsI. Preface monitors the changes of directories in computer systems and files in directories in real time to effectively detect changes to files. In
Php user-defined function for generating random passwords
Generate a random password function. The generated password is a random string of lowercase letters and numbers. The length can be customized.
/*
* Php automatically generates a
Attackers can exploit some design defects of Renren to attack internal network applications.
Attackers can exploit some design defects of Renren to attack internal network
A wonderful file upload on ZTE bypasses GetShell
After a long time, I finally uploaded it. Come to the homepage ~
http://www.appstar.com.cn
On the ZTE application star website, we saw a Common File Upload Bypass Vulnerability.
Next let's take a look
XML security-Web Services0x01 Introduction
Some time ago, I encountered related technologies related to ws in the trs system. Not long ago, when I was playing a xx Hotel, I went to its database through ws, later, I met or saw XML-related
Mining and Analysis of JiaThis Flash XSS
According to WeChat Weibo, the website www.jiathis.com has an XSS vulnerability, which can cause vulnerabilities on any website that uses JiaThis. With this clue, we will start to analyze the XSS principles
False or false: Use the Instagram API to create malicious sharing links
Security researchers recently discovered a malicious sharing link using the Instagram API, which is easily believed and downloaded by users because it points to the Instagram
Zabbix security: Execute the command to obtain the shell after cracking the weak password.
If your Zabbix Admin password is too weak or you use the default password (Admin/zabbix) and the password is cracked by a hacker, The Zabbix server is no
Attackers can exploit the ElasticSearch vulnerability to obtain webshell permissions of a website.
ElasticSearch is usually deployed in many large enterprises. Therefore, further penetration makes sense after obtaining an intranet permission. In the
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service