First Article: It turns out that changing MDB to ASP can prevent download. Download the data. asp file using flashget and save it as the data. MDB file. You can find that the file is intact with access!
1. Use your imagination to modify the
What is an mdb database? All network administrators who have experience creating websites know that the combination of IIS, ASP, and ACCESS is the most popular. Most small and medium Internet websites use this package, however, security issues are
If you do not directly change the suffix, you can directly download it using tools such as quickshield. In fact, you have opened the door for intruders. Intruders can use a database suffixed with ASP/ASA to directly obtain webshells.
I. IdeasAs
1. Use your imagination to modify the database file name
However, If attackers obtain the database path through a third-party channel, they can download the database. Therefore, the confidentiality is the lowest.
2. Change the database name
Article first language: Originally changed MDB for ASP can prevent download is nonsense. Use the FlashGet test to download the data.asp file and save it as a Data.mdb file, which is found to be intact with access.
1. Play your imagination modify
1. Play your imagination modify the database file name
However, if an attacker obtains a database path through a third-party approach, the database can be downloaded. So confidentiality is the lowest.
2. Database name suffix to ASA, ASP, etc.This
What is an mdb database? Any experience in website creationNetworkManagementMembers know that currentlyUseThis combination of "IIS + ASP + Access" is the most popular way to build websites. Most small and medium Internet websites use this "package",
What is an mdb database? All network administrators who have some experience in website creation know that the combination of "IIS + ASP + ACCESS" is the most popular in website creation. Most small and medium Internet websites use this "package ",
Do not say directly to change the suffix, directly can use the net fast and other tools to download directly, in fact, so you have opened the door for intruders. Intruders can use Asp/asa as a suffix database to get Webshell directly.
one.
What is an mdb database? All network administrators who have some experience in website creation know that the combination of "IIS + ASP + ACCESS" is the most popular in website creation. Most small and medium Internet websites use this "package ",
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.