JAVA serialization and deserialization and vulnerability remediation
Last week, cyber security staff suffered a further setback in front of the black market. Joomla exposed high-risk 0-day vulnerabilities, which can be triggered without user login.
Reverse trip to the Android APP of the anonymous social APP Yik Yak
This article mainly performs Reverse Analysis on the anonymous social media application Yik Yak on the Android platform. During the analysis, it is found that the APP uses code
Lobotomy: Android Reverse Engineering Framework (Part1)
If you have followed the previous articles on Android security, you should be familiar with rotlogix. He is keen on the mobile security business and plays a binary role. This series of
How to Use snapshots to reinforce security and strengthen Privacy Protection
I haven't talked about technical topics for two consecutive months. Today I will post an article about the use of the "snapshot function" and fill in the "Literacy Virtual
How to Use the netcat [nc] command to scan ports in Linux and Unix
How can I find out which ports are open on my server? How can I use the nc command for port scanning to replace the nmap command in Linux or Unix?
Nmap ("Network Mapper") is an
This malicious program can turn your computer into a Proxy Server
Security CompaniesPalo Alto NetworksResearchers have discovered a new malicious program family ProxyBack, which can turn infected computers into proxy servers.
Malware targets
How to Use machine learning to detect malware
Comprehensive research on malware is not a simple task. Before performing reverse engineering and building a timeline, researchers need to obtain a large number of samples from multiple stages of malware
Tomcat security protection for normal usersThreat: Generally, When configuring the Tomcat production environment, Tomcat is usually configured to run as a specific identity (non-root), which is conducive to improving security, this prevents further
Exploitation of File Inclusion vulnerabilities in the DVWA Series
After understanding the principles of file inclusion, we will go to DVWA and select low-level file inclusion. A prompt is displayed on the page. You can edit the page parameter in
File Inclusion Vulnerability Analysis for DVWA Series 14
Program developers usually write reusable functions into a single file. When using some functions, they call this file directly without writing it again, this process of calling a file is
Netease subsite SQL Injection Vulnerability
SQL injection vulnerability in a website on Netease
Http://op.campus.163.com/adm/selectcate.do? Flags = 1, 2The above link has the SQL injection vulnerability to obtain database data.
$ ./sqlmap.py -u
Weak Password in Shanghai Volkswagen mail + svn + xss
The access is too slow and it hurts .. No.
No verification, can be cracked. Employees have insufficient security awareness and weak passwords. Example:
Returns 482 characters in
Elsearch sensitive information leakage may cause all its domain names to be hijacked
Easou.com Sensitive Information Leakage
Email Address: [email protected]
Whois lookup its domain nameDomain names are registered on www.net.cn, and
Unauthorized access to a background in Phoenix & SQL Injection
Phoenixnet
Http://online.3g.ifeng.com/live/manager/ifeng_match_live.php? & Amp; match = 7192Unauthorized operation. You can directly modify or delete an article.Injection packet capture:
Writeup of 32C3 CTF two Web questions
0x00 Introduction
As a dog for sales, I am very happy to be able to do Web problems. I have two questions: TinyHosting and Kummerkasten.0x01 TingHosting
A new file hosting service for very small files. could
Espcms latest V6.4.15.08.25 arbitrary User Login
Definitely the latest version!Version: V6.4.15.08.25 UTF8 official versionUpdated on: 12:29:04 Software size: 7.67 MBUpdated on the 25 th
Appears at User Logon/Interface/memebermain. php
function
Media services on meizu mobile phones can produce SQL Injection
Media services on meizu mobile phones can generate SQL injection.
When the file name is enclosed in quotation marks, the Media Service may have the risk of SQL injection. The direct
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service