Ultra-simple Overflow Vulnerability Mining Technology Fuzzing

The origin of Fuzzing Just as Watt invented the steam machine to free us from human hands and increase productivity, some or an outstanding hacker invented the Fuzzing technology when studying vulnerability mining technology. It can be said that

Starting from vro for network protection -- talking about CISCO Router Security Configuration

As the number of vrouters increases, the security of vrouters has gradually become a hot topic for discussion. Today, Alibaba Cloud also talks about the security configurations of vrouters in network security. the following articles are my study

Are you sure you are ready to crack WPA? (1)

I caught a handshake packet, and spent a lot of effort to run the password out of the dictionary, but I couldn't connect to the wireless router at the end ...... Come on, and create an experiment together! Step 1: Set up a wireless router for the

Brute-force cracking of wireless route users' clever defense against Network Attacks

Reaver cracking Wireless Router password basics Currently, the Wi-Fi router on the market has enabled WPS encryption protection before leaving the factory, and such a "good intention" is actually quite safe. However, Stefan Viehbock, an information

Detect man-in-the-middle attacks

Today, John Nagle (the one who invented the TCP Nagle algorithm) mentioned in the mail list that he wanted OpenSSL to provide some methods to automatically detect man-in-the-middle attacks. Simply put, the man-in-the-middle attack will change the

D-Link DSL-2740B (ADSL Router) Authentication Bypass

Title: D-Link DSL-2740B (ADSL Router) Authentication Bypass Author: Ivano Binetti ( http://ivanobinetti.com ) Official Website: http://www.d-link.com Affected Version: DSL-2740B test: Firmware Version: EU_1.0 (other models/firmware cocould be also

Seven mistakes in DDoS cleaning solution Selection

As DDoS attacks become increasingly fierce, the scale of attacks is also growing. How Should users choose DDoS cleaning solutions and products to avoid unnecessary equipment procurement? Finally, they can choose their own products to control costs

Summary of the work of an information security practitioner

After training in the development of Phoenix and the perfect world, I have a good understanding of security development. Next I will summarize my past experiences and lessons.For security development, there must be a set of maturity models. For

APT continuous integrated penetration experience: 1. from Web to PC 1

This post uses a small and medium-sized company as an example to describe a simple method for APT to perform "step-by-step". In this post, the step-by-step method is relatively simple, but it is the first step for sustained penetration. The target

3389 method for establishing a VPN connection on a terminal

We often encounter an Internet IP address and terminal failure when the server is powered on 3389. Today, we can see that a method that is loose is to use a permission escalation tool to execute a vpn batch process, then access the server through

Google Hacking-For fun and profit-I

Google has been used ever since its beginning to find answers for most if not all of our questions from the beginning of the universe to even finding cure for common ailments. a bbc expert was found commenting that Google has the capability of

Bo-Blog XSS cross-site Vulnerability

Long Ying Today, over built a new blog to deploy vulnerabilities. In the evening, I went to check out the bo-blog program. When I saw the above message board, I remembered the xss Cross-Site vulnerability. Go to the message board page and select

Kiccom v6.5 CMS Oday

Background: Write the website's kesion directory, as shown in figureHttp: // localhostCookies: COOKIS of the USER captured after loginAccount Password: the user name and password for normal login after registrationVerification Code: The verification

Export the system registry to capture the Hash

I saw an article about exporting the Registry to break the password forever. This is a good news for a lot of hash-grabbing tools that have been killed and won't be killed by yourself, in fact, this was a long time ago. It seems that it was proposed

Use vbs to read index. dat

From vbs small shop s blog + ---------------------------------------------------------------------------- +| Contact Info |+ ---------------------------------------------------------------------------- +Author: VengyModiy: lcxEmail:

Multiple Vulnerabilities in EASY Enterprise DMS

Test method: The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! ------------------------------------------------ Multiple Vulnerabilities in EASY Enterprise

Dedecms.com brute-force path

From Minghackers Vulnerability description:The dedecms 5.5 program exposes the website path information. : Parse error: syntax error, unexpected T_ELSE in I: dedecms. compublic_htmlpluspaycenteralipayeturn_url.php on line 13 Warning: require_once

Bird CMS injection vulnerability!

From H4ckx7s Blog When observing a large station, you can see the Bird CMS management system in the background of a station, and remember what the omnipotent Password Vulnerability exceeded 1.1! I don't know what's wrong with the latest version! I

Mi bar Article management system cross-site 0-Day Vulnerability

# Exploit Title: Mihao8 CMS Multiple XSS Vulnerabilities# Date: 2010-4-23# Author: riusksk (quange)# Tested on: [Windows 7] ========================================================== ========================================================== ========

Factor online store system GShop SQL Injection Vulnerability

Google: inurl: showhelp. asp? Title = about us Showhelp. asp file   Id = request ("id ")Thetitle = request ("title ")If id = "" and thetitle = "\" thenResponse. redirect "tip. asp? Tipstr = No parameter. Please return"Response. endEnd ifIf id <> ""

Total Pages: 1330 1 .... 787 788 789 790 791 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.