JAVA serialization and deserialization and vulnerability remediation

JAVA serialization and deserialization and vulnerability remediation Last week, cyber security staff suffered a further setback in front of the black market. Joomla exposed high-risk 0-day vulnerabilities, which can be triggered without user login.

WinRAR file-execution Privilege Escalation Vulnerability (CVE-2015-5663)

cve

WinRAR file-execution Privilege Escalation Vulnerability (CVE-2015-5663)WinRAR file-execution Privilege Escalation Vulnerability (CVE-2015-5663) Release date:Updated on:Affected Systems: WinRar Description: CVE (CAN) ID: CVE-2015-5663WinRAR

Corega CG-WLBARAGM Denial of Service Vulnerability (CVE-2015-7793)

cve

Corega CG-WLBARAGM Denial of Service Vulnerability (CVE-2015-7793)Corega CG-WLBARAGM Denial of Service Vulnerability (CVE-2015-7793) Release date:Updated on:Affected Systems: Corega CG-WLNCM4G Description: CVE (CAN) ID: CVE-2015-7793The Corega

Samba smbd vfs. c access Restriction Bypass Vulnerability (CVE-2015-5252)

Samba smbd vfs. c access Restriction Bypass Vulnerability (CVE-2015-5252)Samba smbd vfs. c access Restriction Bypass Vulnerability (CVE-2015-5252) Release date:Updated on:Affected Systems: Samba Samba 4.x-4.1.22Samba Samba 4.3.x-4.3.3Samba Samba 4.2.

Reverse trip to the Android APP of the anonymous social APP Yik Yak

Reverse trip to the Android APP of the anonymous social APP Yik Yak This article mainly performs Reverse Analysis on the anonymous social media application Yik Yak on the Android platform. During the analysis, it is found that the APP uses code

Lobotomy: Android Reverse Engineering Framework (Part1)

Lobotomy: Android Reverse Engineering Framework (Part1) If you have followed the previous articles on Android security, you should be familiar with rotlogix. He is keen on the mobile security business and plays a binary role. This series of

How to Use snapshots to reinforce security and strengthen Privacy Protection

How to Use snapshots to reinforce security and strengthen Privacy Protection I haven't talked about technical topics for two consecutive months. Today I will post an article about the use of the "snapshot function" and fill in the "Literacy Virtual

How to Use the netcat [nc] command to scan ports in Linux and Unix

How to Use the netcat [nc] command to scan ports in Linux and Unix How can I find out which ports are open on my server? How can I use the nc command for port scanning to replace the nmap command in Linux or Unix? Nmap ("Network Mapper") is an

This malicious program can turn your computer into a Proxy Server

This malicious program can turn your computer into a Proxy Server Security CompaniesPalo Alto NetworksResearchers have discovered a new malicious program family ProxyBack, which can turn infected computers into proxy servers. Malware targets

How to Use machine learning to detect malware

How to Use machine learning to detect malware Comprehensive research on malware is not a simple task. Before performing reverse engineering and building a timeline, researchers need to obtain a large number of samples from multiple stages of malware

Tomcat security protection for normal users

Tomcat security protection for normal usersThreat: Generally, When configuring the Tomcat production environment, Tomcat is usually configured to run as a specific identity (non-root), which is conducive to improving security, this prevents further

Exploitation of File Inclusion vulnerabilities in the DVWA Series

Exploitation of File Inclusion vulnerabilities in the DVWA Series After understanding the principles of file inclusion, we will go to DVWA and select low-level file inclusion. A prompt is displayed on the page. You can edit the page parameter in

File Inclusion Vulnerability Analysis for DVWA Series 14

File Inclusion Vulnerability Analysis for DVWA Series 14 Program developers usually write reusable functions into a single file. When using some functions, they call this file directly without writing it again, this process of calling a file is

Netease subsite SQL Injection Vulnerability

Netease subsite SQL Injection Vulnerability SQL injection vulnerability in a website on Netease Http://op.campus.163.com/adm/selectcate.do? Flags = 1, 2The above link has the SQL injection vulnerability to obtain database data.  $ ./sqlmap.py -u

Weak Password in Shanghai Volkswagen mail + svn + xss

Weak Password in Shanghai Volkswagen mail + svn + xss The access is too slow and it hurts .. No. No verification, can be cracked. Employees have insufficient security awareness and weak passwords. Example:  Returns 482 characters in

Elsearch sensitive information leakage may cause all its domain names to be hijacked

Elsearch sensitive information leakage may cause all its domain names to be hijacked Easou.com Sensitive Information Leakage Email Address: [email protected]  Whois lookup its domain nameDomain names are registered on www.net.cn, and

An unauthorized website in phoenixnet Background & amp; SQL Injection

Unauthorized access to a background in Phoenix & SQL Injection Phoenixnet Http://online.3g.ifeng.com/live/manager/ifeng_match_live.php? & Amp; match = 7192Unauthorized operation. You can directly modify or delete an article.Injection packet capture:

Writeup of 32C3 CTF two Web questions

Writeup of 32C3 CTF two Web questions 0x00 Introduction As a dog for sales, I am very happy to be able to do Web problems. I have two questions: TinyHosting and Kummerkasten.0x01 TingHosting A new file hosting service for very small files. could

Espcms latest V6.4.15.08.25 arbitrary User Login

Espcms latest V6.4.15.08.25 arbitrary User Login Definitely the latest version!Version: V6.4.15.08.25 UTF8 official versionUpdated on: 12:29:04 Software size: 7.67 MBUpdated on the 25 th Appears at User Logon/Interface/memebermain. php function

Media services on meizu mobile phones can produce SQL Injection

Media services on meizu mobile phones can produce SQL Injection Media services on meizu mobile phones can generate SQL injection. When the file name is enclosed in quotation marks, the Media Service may have the risk of SQL injection. The direct

Total Pages: 1330 1 .... 872 873 874 875 876 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.