Use network traffic analysis to improve network security visibility

Over the years, security experts have been arguing about whether external personnel or internal personnel bring greater risks. Today, this debate has no practical significance: As network boundaries are blurred, threats are everywhere.For example,

Security impact of traditional SLAAC addresses on IPv6 addressing

Editor's note: IPv6 automatic address configuration is increasingly concerned with the security and confidentiality of IPv6 addressing. The automatically configured IPv6 addresses have three security meanings: they narrow down the search scope for

Using SMS to hijack a Facebook account

This article demonstrates a simple vulnerability. This vulnerability allows you to gain full control of any Facebook account without any user interaction. See the following. Facebook allows you to associate your mobile phone number with your account.

Modify the NIC address and defend against ARP attacks in Mac OS X.

I have been using the Mac system for some time. Here I will record the problems that need to be solved by terminal commands. The network environment is bound to the MAC address of the original machine. for special reasons, change the NIC address of

Security risks of proxy servers

There seems to be a large number of people who like to find agents to hide themselves and use proxies to shield IP addresses on some servers, or because the system does not support Internet sharing, it is forced to use proxy software to enable

Database horse insertion vulnerability and Prevention Measures

The database plug-in has always been a blind spot in network security. Indeed, this vulnerability is hard to prevent. mdb is almost replaced with. asp to prevent database downloads.This attack is almost fatal. No matter how strict your website is,

Phplist version 2.8.11 SQL Injection Vulnerability

Test method:The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk![~] Bytes ---------------------------------------------------------------------------------------------

DEDECMS V5.6 File Deletion vulnerability details

Files of the jpg, gif, and png types can be deleted because they are not filtered./or can be traversed.Code Analysis: edit_face.phpElse if ($ dopost = delold) // 45 rows {if (empty ($ oldface) {ShowMsg ("No Avatar to be deleted! ","-1 "); exit () ;}$

PHP168 Arbitrary File Download Vulnerability Analysis

I flipped through the old file today and found an analysis report a long time ago. Then I went to the php168 test site to test whether the vulnerability still exists?Vulnerability-related file HASHB912249a22b630c04f7ad65f8ba5a2f6 download.

Douban Dom persistent cross-site scripting vulnerability and repair solution

A csrf cross-site submission and XSS cross-site scripting vulnerability exists in a Douban service. Some csrf vulnerabilities exist at Douban, most of which are caused by undetected ck values.If you create a page to submit the parameter name = &

Persistent xss of Youku, design defects, unauthorized user permissions, and repair

Persistent xss (with limited words), design defects, and several serious Unauthorized User Permissions 1. The "Modify style" function of the personal space only makes js judgment before saving, and does not filter the substantive content, resulting

XSS vulnerability and repair on a Sina Channel

The search characters are not effectively filtered, causing XSS vulnerability. & Service = cars> http://che.sina.com.cn/apps/index.php? Homo = off & mod = auto & act = sinaresult & type = search & query = "> & service = cars Copy to the browser

Cross-Site vulnerability repair at 20 blog bus sites

In the "homepage layout Settings" of the "template" and "Internal page layout Settings", the "article content editing" section and the modules in the secondary column are XSS vulnerabilities exist. By default, a total of 12 vulnerabilities exist,

Use Nessus for WEB Application Security Scanning

In the previous article, you Xia talked about [Free Network and host Vulnerability Assessment Program Nessus 4.2.0 installation trial], Some may have noticed that Nessus only scans for host, network device, and other vulnerabilities, but not for the

Parsing of cross-site scripting attacks and Cross-Site Request Forgery

The Cross-Site vulnerabilities mentioned here include cross-site scripting attacks, cross-site request forgery, and other same-source attacks. These attacks are currently very common attacks. This article can be viewed by Web developers or by

Eval principle of one-sentence Trojan

To explain its principles.The first is the start mark of the JavaScript script. The value of the RUNAT attribute SERVER indicates that the script will run on the SERVER side, and the eval is the essence of a Trojan, if the eval method is used, the

Guess the default database and The NASL script of the conn. asp brute-force database

The script language is also very powerful. :) Code:Include ("http_func.inc ");Include ("http_keepalive.inc ");Dir = make_list ("/data/database. mdb ","/data. mdb ","/data/date. mdb ","/data/bbs. mdb ","/data/dvbbs7.mdb ","/data. mdb ","/database.

Hacking Postgresql for fun!

Source: pentestmonkey.net Some useful syntax reminders for SQL Injection into PostgreSQL databases...This post is part of a series of SQL Injection Cheat Sheets. in this series, Ive enstmured to tabulate the data to make it easier to read

Xp_hello.dll (sa) Elevation of Privilege

Source: Freezing Point Forum February Main Code: Create a stored procedure project in VC6 and write the following code In proc. cpp: # Include # Include # Define XP_NOERROR 0 # Define XP_ERROR 1 # Define MAXCOLNAME 25 # Define MAXNAME 25 # Define

Some solutions to bypass MSSQL injection prevention

At work or other times, I often encounter some websites with anti-injection code, which is really a headache, however, on the other hand, I finally had a new topic that could be considered in depth. At the same time, I also saw many methods provided

Total Pages: 1330 1 .... 792 793 794 795 796 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.