Windows shellcode Development (2)
In the first part of this series, we learned the definition of Shellcode and its working principle. To correctly compile the Shellcode for Windows, the author will describe the required information in this article:
How can I view shared files on the LAN, prohibit file sharing, and protect the security of computer files?Setting up shared files in the LAN facilitates file sharing and transmission, and brings security risks to the network. How can I view shared
Android Application Security Development to prevent unintentional data leakage
4th of the Top 10 OWASP mobile security vulnerabilities are unintentional data leaks. When an application stores data in a vulnerable location, it may cause unintentional
Analysis of assembly code debugging under X86-64
This article should be the most basic thing for some big guys who often use gdb, but here I just want to share some basic tools or other useful things I have found.
If you are converting from gdb to
Construct a BER file without a public key to cause the system to crash.
In January 25, 2016, Wade Mealing sent an email to the OSS Security and CVE certification departments. The electronic topic is: constructing a special key file to cause DoS on
Apple fixed a critical iOS vulnerability where hackers could steal cookies from devices (CVE-2016-1730)
Recently, Apple fixed a serious vulnerability in iOS. This vulnerability allows hackers to disguise themselves as end users and obtain the
Qidian education background universal password/SQL injection vulnerability involving more than 3717 million user data
Qidian education background universal password/SQL Injection Vulnerability
Http://account2.gongfubb.com/home/admin? ACT = AC
Dict.cn domain name transfer Vulnerability
The domain name transfer vulnerability exists in the sea words. It should have been fixed, but the vulnerability still exists.
Nothing can be seen hereLet's continue to look at the subdomain name.I did
Reset any User Password
Password retrieval in the wooden ant user center-reset the User PasswordThe password reset link encryption method received by the mailbox is too simple. You can perform the on-chip connection to reset any user password.
I
Sohu mail persistent xss
Trigger an email
Use your own smtp tool (Link: http://pan.baidu.com/s/1jHiOhZS password: xqbp) send the following content as body
test
Log on to the mailbox and click the email to trigger alert.
User Password leakage due to improper p2p configuration (plaintext)
The user's account and password (in plaintext) can be seen directly)
I was shocked to see this. p2p is really unreliable.
The company is affiliated with the Financial Management
Cookie injection packaging and arbitrary User Password Reading Vulnerability (1.3 million student data)
Cookie injection packaging and arbitrary User Password Reading Vulnerability (1.3 million student data)
Http://www.17xuexi.com/reg/reg3.asp? Jz_
A system at Guangdong Airport found that shell could threaten the Intranet.
Discover shell, which can threaten the Intranet
The system was so long that it did not know what operations caused it to report an error.
One-sentence address: **.
Weak passwords in a backend packaging and Configuration System of Netease cause leakage of a large number of app key payment keys
The group said that they could not enter the community without logging in for a month, and scared the baby to death.
Analysis of PayPal Remote Command Execution Vulnerability
In December 2015, the authorA SubstationJava deserialization vulnerability that can remotely execute arbitrary shell commands is found, and the product database of PayPal can be affected. I
An injection of a Chinese civil aviation product found in the official APP of okai Aviation
SQL Injection for APP security
Objective: To launch okai official APPCheck that SQL Injection exists in the following places: (userName in POST)
POST https:/
The JAVA deserialization Command executed by the Chinese enterprise has been Getshell
RT
Http: // 121.14.65.32: 8080/building.htmlEnterprise-centric!Jboss middleware, which has the latest JAVA deserialization command execution
Pseudo static SQL injection (bypassing filtering) on a bus stop)
Pseudo static SQL injection (bypassing filtering) on a bus stop)
URL: http://speed.tgbus.com/tgdb/car/202.shtmlPOC http://speed.tgbus.com/tgdb/car/202 xor sleep(52.16.shtml because of
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service