阿里云安全专家,主要负责阿里云云产品安全。
http://web.nvd.nist.gov/view/ncp/repository?page_num=1 http://nvd.
http://tech.it168.com/tu/1297158_6.shtml#show
For those who are learning web application security testing (or just trying to stay sharp) it'...
What is it and why should I care? X-XSS-Protection is a Microsoft IE technology used to help prevent reflected XSS attacks in IE.
Cloud providers and many federated IAM practitioners are excited about OAuth, a new(ish) security technology on the scene.
http://tv.ssw.com/1492/protecting-your-web-apps-from-the-tyranny-of-evil-with-owasp ...
At South by Southwest this year, during my talk Defense Against The Dark Arts - ESAPI I cover...
Up until this point we’ve focused on all the preparatory work before you finally turn on the switch and start using your DLP tool in production.
Veracode’s nomination for “Best Corporate Security Blog” at the 2012 Social Security Bloggers ...
http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/
http://en.wikipedia.org/wiki/Top_100_US_Federal_Contractors ...
This is a follow-up post of the first edition of Exploiting hard filtered SQL Injections an...
http://bbs2.99nets.com/forum.php?mod=forumdisplay&fid=113&page=1 ...
http://v.youku.com/v_show/id_XMzYxODc0OTQ4.html
There are different CMS (content management system) are available like wordpress, Joomla, light CMS and Drupal.
这天,新上任的邢县长到小吃摊吃早餐,刚找个板凳坐下,就听炸油条的胡老头一边忙活一边唠叨:“大家吃好喝好哦,城管要来撵摊儿了,起码三天你们捞不着吃咱炸的油条了!” 邢县长心里一惊:省卫生厅领导最近要来视察,昨天下午县里才决定明后两天开展突击整治,这老头儿怎么今天一早就知道了? 哪料这件事还没弄明白,另一件事儿让县长脑袋里的问号更大了。
http://detail.tmall.com/item.htm?id=14601884506&wwdialog=bbxxbbmc&prt=1331034541339&prc=1 ...
http://blog.xdite.net/posts/2012/03/05/github-hacked-rails-security/ ...
_,.
google dork: "YOUR QUERY GOES HERE" {site:codepad.
https://community.rapid7.com/community/metasploit/blog/2012/03/05/how-to-own-a-virtual-data-ce...
2010年04月01日 07:22 IT168网站原创 作者:IT168内存硬盘频道 编辑:林伟明 在普通的日子,我们是不会刻意强调内容的真伪,毕竟IT168平时的评测报告是建立在事实的基础上。
http://www.jtmelton.com/2012/01/02/year-of-security-for-java-week-1-session-fixation-preventio...
https://blog.whitehatsec.com/vote-now-top-ten-web-hacking-techniques-of-2011/ Every year the ...
http://www.pcworld.com/article/250950/google_privacy_checklist_what_to_do_before_googles_privacy_policy_changes_on_march_1.
http://www.acunetix.com/blog/web-security-zone/articles/web-vulnerabilities-path-fragments/?ut...
查看一下symfony CodeIgniter cakephp
http://www.cesclub.com/bw/jishuzhongxin/wangluokaifajishu/2012/0103/19238.
1. 子类的构造的方程中必须调用基类的构造方法 2.子类可以在自己的构造方法中使用super()调用基类的构造方法 3.
http://blog.buguroo.com/?p=2471
- Burp Suite
UPDATE: See http://pauldotcom.com/2011/12/safely-dumping-hashes-now-avai.
http://www.cnblogs.com/zijinguang/archive/2008/04/22/1165469.
http://www.pentest-standard.org/ https://www.owasp.
http://www.isecom.org/research/soma.html
http://www.exploit-db.com/papers/17073/ Faster Blind MySQL Injection Using Bit Shifting ### # http://h.
http://websec.ca/blog/view/Bypassing_WAFs_with_SQLMap Web Application Firewalls have become the new security solution for several businesses.
http://seclists.org/fulldisclosure/2012/Feb/409 Google V8 Server-Side JavaScript Injection joi...
1. http://www.amazon.com/Qualities-Highly-Secure-Software/dp/1439814465/ref=sr_1_111?s=books&ie=UTF8&qid=1330409500&sr=1-111 2.
http://www.tppayment.com/html/2011/strategy_0322/266.html
concat(0x7C, hex(cc_number), 0x7C) concat(0x7C, ord(substring('11',1,1)), 0x7C) concat(0x7...
http://www.oldjun.com/blog/index.php/archives/62/ # oldjun注:帮朋友打下广告,新书上市。
https://mylogin.exin.nl/Portal/polarserver.asp?Screen=FrameSet&SID=623C84F6A43AEABC&PageID=151...
SAP NetWeaver 7.0 Internet Sales (crm.b2b) has local file read vulnerability.
vsftpd cmds_allowed cmds_allowed=ABOR,CWD,LIST,MDTM,MKD,NLST, PASS,PASV,PORT,PWD,QUIT,RETR,RMD...
XHR level 2 calls embedded in HTML5 browser can open a cross domain socket and deliver HTTP request.
This document reflects my personal opinion on the state of application security.
https://www.owasp.org/index.php/Session_Management_Cheat_Sheet ...
http://blog.kotowicz.net/2012/02/intro-to-chrome-addons-hacking.
http://pnig0s1992.blog.51cto.com/393390/775440 exec master.