阿里云安全专家,主要负责阿里云云产品安全。
http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.
#!/bin/sh for i in `seq -f "172.16.40.%g" 3 26` do echo $i done
lib/ThinkPHP/Vendor//Vendor/module/action/param1/$%7B@print(phpinfo())%7D ...
http://www.dell800.com/thread-56276-1-1.html
CVE ID: CVE-2012-1823 PHP是一种HTML内嵌式的语言,PHP与微软的ASP颇有几分相似,都是一种在服务器端执行的嵌入HTML文档的脚本语言,语言的风格有类似于C语言,现在被很多的网站编程人员广泛的运用。
export SSH_AUTH_SOCK=/tmp/ssh-tqiEl28473/agent.
FCKeditor助手 by jacks function BuildBaseUrl( sUrl,command ) { if(sUrl.indexOf("http://")
How to Do Application Logging Right is the best guidance I have come across to date.
http://hi.baidu.com/p3rlish/blog/item/51c448399f4c02d33a87cee0.
In the course of a recent assessment of a web application, I ran into an interesting problem.
SpiderLabs is the corporate sponsor of the WASC Distributed Web Honeypots Project which is an ...
http://www.darknet.org.uk/2012/04/nfspy-id-spoofing-nfs-client-tool-mount-nfs-shares-without-account/ https://github.
http://packetstormsecurity.org/files/111842/McAfee-Web-Gateway-And-Squid-Proxy-3.
http://www.sourceconference.com/archive/ http://www.
http://code.google.com/p/ra2-dom-xss-scanner/downloads/detail?name=ra.
http://security.ctocio.com.cn/39/12311539.shtml http://tech.
http://www.ibm.com/developerworks/cn/java/j-lo-spring25-ioc/ ...
During the past week I spent some time documenting O2's support for Spring MVC apps.
http://www.darkreading.com/galleries/security/news/232900180/slide-show-10-sql-injection-tools-for-database-pwnage.
#xxx# 代表xxx是属性值,map里面的key或者是你的pojo对象里面的属性, ibatis会自动在它的外面加上引号,表现在sql语句是这样的where xxx = 'xxx' ; ...
http://blog.csdn.net/daryl715/article/details/1760793 首先简历数据库demo(本文选mysql) 数据库脚本: CREATE...
http://www.blogjava.net/freeman1984/archive/2007/12/07/166112.
第一种采用预编译语句集,它内置了处理SQL注入的能力,只要使用它的setString方法传值即可: String sql= "select * from users where usern...
http://space.itpub.net/3704/viewspace-559855 http://www.
select top 1 oid,name from(select top 1 oid,name from [active].
http://www.cqsec.com/read/SQL2005_2008_Injection_By_Hand_For_XML_Path ...
http://packetstormsecurity.org/files/111157/Drupal-FCKEditor-CKEditor-PHP-Execution.
http://xhe.myxwiki.org/xwiki/bin/view/XSLT/Application_Liferay http://www.
http://www.exploit-db.com/exploits/18723/
http://www.slideshare.net/wearefractal/fusker-a-nodejs-security-framework-8850586 http://bishankochher.
http://resources.infosecinstitute.com/sql-injection-http-headers/ ...
https://github.com/carnal0wnage/carnal0wnage-code/tree/master/oraclemodules_public ...
Its been a while since i posted. I've been bogged down with code reviews and training but even...
1. construction CWE,CAPEC,CCR 2.verification CWE,CWRAF,CWSS,CAPES,CCR 3.
http://www.wisec.it/sectou.php?id=4e6e1cae16dc7 https://www.
Web渗透技术及实战案例解析 http://www.phei.com.cn/module/goods/wssd_content.
HTML5 is an emerging stack for next generation applications.
This is a awesome sqlmap python gui made by xcedz.
http://code.google.com/p/sqlifuzzer/downloads/detail?name=sqlifuzzer-0.
http://resources.infosecinstitute.com/owasp-top-10-tools-and-tactics/ http://www.
http://code.google.com/p/websploit/
http://www.redteam-pentesting.de/en/publications/jboss/-bridging-the-gap-between-the-enterprise...
http://web.cs.sunyit.edu/network/downloads/OperatingSystems/Solaris/x86/Solaris_9_0904/sol-9-u7-install-x86.
1.IT治理 http://product.china-pub.com/198862&ref=browse 2.
the file: http://svn.apache.org/repos/asf/struts/struts2/trunk/core/src/main/java/org/apache/struts2/views/xslt/XSLTResult.
https://buildsecurityin.us-cert.gov/bsi/articles/knowledge/principles.
List of SAP HTTP Resources to hack at… /rep/build_info.
Vulnerability assessors and code auditors are often faced with situations where a large volume ...
https://www.owasp.org/index.php/OWASP_AppSec_Research_2010_-_Stockholm,_Sweden https://www.
Recently I needed to setup a fake access point for a presentation, I fired up my Backtrack5 ...