阿里云安全专家,主要负责阿里云云产品安全。
设置邮件系统管理密码 密 码: 重输密码: Copyright © 2002 Beijing Anymacro Investment Ltd.
# Exploit Title: Huawei HG866 Authentication Bypass # Date: Jun 14 2012 # Exploit Author: hkm # Vendor Homepage: http://www.
We have recently implemented data retrieval over DNS in sqlmap.
最近国外安全人员发现了一个PostgreSQL(所有版本)基于错误XML外部实体执行的高危漏洞。
http://www.sparxsystems.com/products/ea/index.html
http://www.drupalexploit.com/
The current module does not allow you to download exe's, in fact these are specifically blacklisted.
http://www.unshadow.com/?p=309
http://v.youku.com/v_show/id_XMzIzMzEzODgw.html
http://www.juzhiwn.com/
http://wenku.baidu.com/view/b59d13e8856a561252d36fb9.
When penetration-testing you get to see lots of seemingly unbelievable security failures, but...
"Trace.axd is an Http Handler for .Net that can be used to view the trace details for an application.
Web服务器文件监控平台-Falcon 如何安装并且开始监控: 第一步,解压并检查程序编译环境 tar -zxvf falcon.
#!/bin/bash #description: check files shell #author:coralzd powered by www.
boblog任意变量覆盖漏洞(二) by Ryat[puretot] mail: puretot at gmail dot com team: http://www.
原文地址:http://hi.baidu.com/netxfly/blog/item/a2c7bb0ea8f764ed37d1227a.html 前言 Php 是一种功能强大且应用非常广泛的脚本语言,Internet 中很多的网站都 是通过 php 架构的。
Open NFS mounts/shares are awesome. talk about sometimes finding "The Goods".
#!/usr/bin/python # Symantec Web Gateway 5.
在Linux服务器的web应用中,经常需要上传文件到服务器上。不管是php的也好,jsp的也好,如果web程序对于上传检查不严格,可导致黑客上传webshell,对服务器安全威胁自不用说了。
又是转载的,没啥含量,呵呵。 aka Why an exposed LM/NTLM Hash is comparable to a clear-text password aka...
Hello everybody!I just released the slides of a course about anti-fingerprintingtechniques.
This Report focuses on vulnerability assessment tools, which this Report defines as: automated ...
Microsoft update release http://technet.microsoft.
Just found some interesting and useful extensions that can help many of us when we are doing an penetration test.
文章来自 http://hi.baidu.com/kerving/blog/item/de133cd27263633a970a16fd.
http://blog.spiderlabs.com/2012/05/hulk-vs-thor-application-dos-smackdown.
通过Oracle数据库的触发器实现,例如:TEST为测试账号、绑定的IP为:10.142.244.
Post [6] SharePoint Misconfigured SharePoint can be *really* useful.
So this didn't make it into the talk, but was in the hidden slides.
FCKeditor is bundled with seems-like everything (ColdFusion, Drupal plugins, WordPress plugins,...
Back in April I presented my Securing Development with PMD (Teaching an Old Dog New Tricks) presentation at OWASP AppSec DC.
Preventing SQL Injection The following functions and methods provide a way for SQL to be submit...
http://www.wooyun.org/bugs/wooyun-2010-05526 Joomla! 1.
wget -q -O - http://www.atomicorp.com/installers/atomic | sh yum install -y openvas* https://wiki.
OpenVAS (Open Vulnerability Assessment System)是一个包含集成安全工具和服务的系统,为漏洞管理提供了强大的平台,其开发基于C/S架构,通过客户端向服务端请求对目标的具体网络漏洞执行测试集。
http://site.com/index.php/module/action/param1/${@phpinfo()} 直接拿SHELL index.
http://www.cert.org/vuls/discovery/triage.html
########## Blueliv Advisory 2012-004 ##########- Discovered by: Jesus Olmos Gonzalez at Blueliv...
=======Summary=======Name: Websense (Triton 7.
=======Summary=======Name: Websense (Triton 7.
今天尝试了一下,在Linux下删除一个数据文件,然后进行回复。 环境:数据库在Open的状态,然后rm -rf users.dbf (删除users表空间),最后找回users.dbf文件。
一、为什么选择了iperf 之前做了一个项目,说要测试两台服务器之间的带宽,本想通过拷贝来进行测试,后来客户觉得得出的数据没有说服性,于是改拿工具来进行测试。
Basic authentication doesn’t work Using HTTP basic authentication to protect backends or adminitrative panels is a bad idea.
http://carnal0wnage.attackresearch.com/2012/04/from-low-to-pwned-3-jbosstomcat-server.
http://www.ibm.com/developerworks/web/library/wa-vulnerabilities/index.
BananaStand learned from last time (to see last time, go here).
http://www.dbappsecurity.com/dbscan.html http://www.
https://www14.software.ibm.com/webapp/iwm/web/reg/pick.
https://store.tenable.com/ https://store.tenable.