阿里云安全专家,主要负责阿里云云产品安全。
http://gigaom.com/cloud/real-world-nosql-hbase-at-trend-micro/ http://www.
http://www.dataguru.cn/article-4037-1.html http://blog.
http://opentsdb.net/ http://www.searchtb.com/2012/07/opentsdb-monitoring-system.
我在 DBAnotes.net 上记录过不少比较大的网站架构分析(eg: eBay [1], eBay [2]) ,Amazon 一直找不到太多的资料。
http://www.amazon.com/s/ref=nb_sb_noss/184-1475344-8555167?url=search-alias%3Daps&field-keywor...
https://www.merchantriskcouncil.org/Pages/home.aspx
https://www.packetloop.com//#sign-up
http://blog.linezing.com/2013/01/storm%E5%85%A5%E9%97%A8%E6%95%99%E7%A8%8B-%E7%AC%AC%E4%BA%8C%E...
http://www.amazon.com/s/ref=lp_5_nr_n_16?rh=n%3A283155%2Cn%3A!1000%2Cn%3A5%2Cn%3A377560011&bbn=...
http://51studyit.com/
http://www.oschina.net/p/restsuperman
http://sishuok.com/product/561 http://sishuok.
http://cve.scap.org.cn/cve_list.php?action=recent
This is an example of how to get and set a bean property.
http://i.youku.com/u/UNTQwMzM4NDU2 http://v.youku.
Hi! The Eyou Mail System have a Remote Code Execution in \inc\fuction.
http://www.appinn.com/docfetcher/
1.概述 本文介绍了JAVA虚拟机一些安全基础,第四节介绍了两个非常著名的JAVA 0day,分析了cve-2012-0507 漏洞原理和jdk1.70day漏洞,这两个漏洞被广泛应用于浏览器挂马。
博文作者:雕哥 发布日期:2014-01-09 阅读次数:56 博文内容: CGI好比Web漏洞扫描器的眼睛,只有CGI更全更准,Web漏洞扫描器才能更好的“看到”漏洞,为业务的Web安全保驾护航。
http://contextis.com/research/blog/server-technologies-jboss-rmi-twiddling/ Context encount...
【Apache Kafka——一个不同的消息系统】Apache发布了Kafka 0.8,这是Kafka成为Apache软件基金会顶级项目后的第一个主版本。
amazon s3的用户验证方式是一种对称加密方式,下面介绍此加密方式。 请求的构造 请求元素: AWS Access Key Id:其实就是常见的用户名,用来区分用户的。
http://blogs.cisco.com/security/big-data-in-security-part-i-trac-tools/ ...
http://prestodb.io/ https://github.com/packetloop/packetpig https://github.
http://docs.aws.amazon.com/STS/latest/UsingSTS/CreatingSAML.
http://developer.baidu.com/map/ip-location-api.htm
http://information.rapid7.com/rs/rapid7/images/SAP%20Penetration%20Testing%20Using%20Metasploit%20Final.
http://www.faradaysec.com/buy.html#prettyPhoto
前段时间,在一位大牛的BLOG上看到其resume上撰写的开源项目列表琳琅满目,数不胜数。再跟自己对比一下,从来没有一个开源项目,没有成功的参加过一个开源项目,只是零星的贡献过几个所谓工具,脚本。
https://hyperiongray.atlassian.net/wiki/display/PUB/PunkSCAN+1.
http://www.junopen.com/memadmin/
http://punkspider.hyperiongray.com/
1、bitsadmin /rawreturn /transfer getfile http://download.
https://developers.google.com/maps/documentation/javascript/tutorial#api_key ...
http://ecomfe.github.io/echarts/doc/slide/whyEcharts.
RSoP(Result Strategy of Policy)----策略结果集 策略结果集有什么功能 Gpresult 显示用户或计算机的组策略设置和策略的结果集 (RSOP)。
http://bbs.pediy.com/showthread.php?t=101217 by WinsOn@Cybersword 在经典的栈溢出模型中,通过覆盖函数的返回地址来达到控制程序执行流程(EIP寄存器),通常将返回地址覆盖为0x7FFA4512,这个地址是一条JMP ESP指令,在函数返回时就会跳转到这个地址去执行,也就是执行JMP ESP,而此时ESP刚好指向我们在栈上布置的Shellcode,于是就执行了Shellcode。
Exploiting vulnerabilities on Windows 7 is not as easy as it used to be on Windows XP.
http://nodexl.codeplex.com/ http://exchangespigot.
1. 有多少真实的攻击被阻断(TP) 2. 有多少有效的请求允许通过(TN) 3. 有多少有效的流量被不恰当的阻断(FP) 4.
http://www.youtube.com/playlist?list=PLpr-xdpM8wG8ODR2zWs06JkMmlRiLyBXU https://www.
What is NoSQLMap?NoSQLMap is an open source Python tool designed to audit for as well as automa...
https://www.youtube.com/user/HackersOnBoard
线上幽灵 http://product.china-pub.com/3768955#ml hadoop 2.
https://archive.farsightsecurity.com/Passive_DNS_Sensor/ https://archive.
# Exploit Title : Zend-Framework Full Info Disclosure # Google Dork : inurl:/application/configs/application.
# Exploit Title: Zimbra 0day exploit / Privilegie escalation via LFI # Date: 06 Dec 2013 # E...
http://www.paulekman.com/
http://bigsnarf.wordpress.com/
https://github.com/packetloop/packetpig