Counterfeit mobile base station Method
Let's talk about the working principle of the mobile base station:
To work with a mobile base station, we must first use a dedicated channel to say, "lalala, I am a mobile base station. Come and connect to me
1.Symptom
A resort hotel in Jiangxia experienced a slow connection and failed to access the Internet.
2.Initial Diagnosis
Figure 1]
We can see that 192.168.1.1 and 192.168.1.88 are the same mac addresses, and we suspect arp spoofing.
If arp-d is
Affected Versions:MolyX Board 2.81
Vulnerability description:MolyX Board is one of the Magic Series of Web application software products. MolyX Studios, after years of market technology research and research, based on the advantages of many Forum
ECMall community e-commerce system (ECMall) is another e-commerce sister product launched by Shanghai shangpi Network Technology Co., Ltd. following ECShop.
Appgroupbuy. app. php: 26:Function index (){$ Id = empty ($ _ GET [id])? 0: $ _ GET [id]; //
Affected Systems:
MyPHP. ws MyPHP Forum v3.0 (Final)
Description:
Bugtraq id: 27118
MyPHP Forum is a Forum that is easy to set up and easy to use based on MySQL and PHP.
The input authentication vulnerability exists when MyPHP Forum processes user
When I recently studied PIL, I studied the verification code by the way.
The verification code is generally used in registration, speech, modification of information, and other places. Its role is to prevent malicious submission of users from
Attackers can use the application's dynamic data display function to embed malicious code into html pages. When a user browses this page, the malicious code embedded in html will be executed, and the user's browser will be controlled by attackers to
Persistent xss (with limited words), design defects, and several serious Unauthorized User Permissions
1. The "Modify style" function of the personal space only makes js judgment before saving, and does not filter the substantive content, resulting
Expression can be used for DIY personal space. IE6 and IE7 are tested and passed.
Http://blog.19lou.com /? 18202069 (use IE6 and IE7 to view details)Http://blog.19lou.com/user/69/diy_css_18202069.cache.css
In DIY, when SQL processing is too slow,
Baigo CMS is a website content management system developed using ASP + Access. You can install and deploy Windows servers or servers that support ASP + Access (including virtual hosts ). Baigo CMS is also an open-source and free website content
Security of cookies generated by asp.net forms authentication
I did this experiment because of http://community.csdn.net/expert/topic/3927/3927012.xml? Temp =. 3752405.
At first, I thought that. net authentication should be relatively safe, and the
Currently, ecshop has reflected XSS, which can be used. If secondary development has XSS or other CSRF problems, more can be used. (I was slightly affected by this problem)
Use XSS to construct post to submit personal data modification, change it to
Author: marsAffected Versions: xyxcms v1.3Official Address: www.xyxcms.comVulnerability Description: The Search Page code is not strictly filtered, resulting in string SEARCH injection.Code Analysis: s. asp from this code, we can see that string
I saw this clear and clear code execution with the front-end code execution at the beginning of the year. I guess there are quite a few people who have seen it. Fortunately, no one has published it for so long, it has been used many times in the
The following is the code for the conversion. asp page, and there are many other pages with the same situation.
The username in the Code is the registered user name. If it is not filtered, It is substituted into the query. The Administrator table
From: E-Industry Press authorizes the red and black Union www.2cto.com to publish
The User Name of the current database is admin, the database server address is 10.10.82.159, the database version is Mysql 5.0.27, and the current database name is
Affected Versions:MetInfo 2.0
Vulnerability description:MetInfo is a fully functional marketing-type enterprise website management platform, with a PHP + MYSQL architecture.
MetInfo 2.0/include/common. inc. php file 132nd rows:Eval (base64_decode ($
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.