Let's talk about Wordpress security today ..WORDPRESS has been very insecure recently. 0-day vulnerabilities often exist ~ Therefore, you need to set the security of the program.========================================================== =============
From: www.0855. TVBy: Mr. DzYDate: 2011/08/25
The enterprise website system is a small-sized enterprise website source code customized for small and medium-sized enterprises. The code is made public for free and can be modified and learned on its
Now I want to talk about the 40-bit Decryption Method to everyone about the 40-bit encrypted data. In fact, it is still MD5 encryption, but some changes have been made:Take admin as an example,Admin's 16-bit and 32-bit ciphertext:7a57a5a743894a0e2123
Author mog
Brief description:Cross-site scripting (XSS) attacks exist in ET voice software. The account password can be obtained through simulated login.Detailed description:When a custom video is played in a channel, the webpage is
Recently, we used a template for the zhirui enterprise website. (This template is downloaded from all major websites and marked as free use and free software.) I feel that the framework architecture is clear and simple, the most important version is
Title: Cotonti CMS v0.9.4 Multiple Remote Vulnerabilities
Author: Cotonti Team www.2cto.com
Developer: http://www.cotonti.com
Affected Versions: 0.9.4 (Siena)
Summary: Cotonti is a powerful open-source web development
Framework and content
Abstract:This is a classic example of random function cracking. In java programs, there are multiple methods to obtain random numbers. However, when we implement a random token and use it for authentication, we usually think of using "System.
1. directly access default. aspx after the directory is guessed (you may need to modify the uploadid parameter. You can see the specific packet capture, but undefined is not allowed)
2. Upload and test, capture packets
3. Modify the
Author: nerd does not speak
Brief description:
It's very funny, but I can give you an xss after using your computer.
Detailed description:
Know the id of the target user. Execute js www.2cto.com in the current domain.
LocalStorage. setItem ("
It is mainly because a system is authorized to access the database, resulting in the execution of arbitrary commands, the permission is still root, the database is not subject to access restrictions, and the data volume is quite large ..Details:
User center friend group location:
X "x =" x
There is a length check on the page, but it doesn't matter. packet capture structure:
Name = addGroup & groupName = x "onmouseover =" var h = document. getElementsByTagName ('head') [0]; var s =
A long time ago I found that I have been researching and trying to release it. It is also good for the manufacturer to fix it early. When I first discovered it, I could only use it to play a box, and I could not even write a jump. Go directly to the
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service