阿里云安全专家,主要负责阿里云云产品安全。
MC pushed out a new exploit today (jboss_deploymentfilerrepository) so while it lists 4.
Metasploit has a nifty PHP Remote File Include module that allows you to get a command shell from a RFI.
Thanks to sites like the Sucuri Security blog, domain name administrators should be learning tha...
http://zh.wikipedia.org/zh/Kerberos OpenSSH on Linux using Windows/Kerberos for Authentication http://port25.
Please Check your server. http://www.80sec.com/nginx-securit.
http://www.computerperformance.co.uk/w2k3/W2K3_RIS.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_scedefaultpols.
http://technet.microsoft.com/zh-cn/library/cc787506(WS.
https://blogs.apache.org/infra/entry/apache_org_downtime_report ...
计算机审计案例 http://www.china-pub.com/14264#ml 计算机信息系统审计 http://www.
http://item.taobao.com/auction/item_detail.htm?item_num_id=5093912577 ...
http://articles.techrepublic.com.com/5100-10878_11-6081763.
http://www.microsoft.com/china/technet/security/guidance/secrisk/default.
对IT研发人员来说,有些秘密是不能说的。法律是战争爆发的底线。与其事后诉诸法律,不如防范于未然,通过制度和技术保障,让机密不大白于天下。
http://search.taobao.com/search?q=2010+itil&from=rs&navlog=rs-3-q-2010+itil CISA http://search.
http://pentestit.com/2010/04/04/list-free-firewalls-windows/ ...
http://www.csres.com/s.jsp?keyword=%D0%C5%CF%A2%B0%B2%C8%AB+GB&xx=on&wss=on&zf=on&fz=on&pageSize...
1.Building a Blind TCP IP Hijacking Tool http://www.
由于目前一种专门针对SSL、HTTPS的新型攻击工具在网上广泛传播,严重影响SSL/HTTPS所保护的用户身份等敏感信息数据的安全性。
http://www.google.com/support/webmasters/bin/answer.py?hl=cn&answer=96569 http://www.dmseo.com/seo/seo_18_893.html 摘要:Google联合Yahoo! MSN和主要Blog服务提供商:推出一个新的搜索引擎收录服务标准,超链的rel="nofollow"属性。
http://securitytube.net/Defeating-SSL-using-SSLStrip-(Marlinspike-Blackhat)-video.
http://www.mirrorservice.org/sites/ftp.isc.org/isc/IRRToolSet/ http://pwhois.
Hi,I've identified a couple of security flaws affecting the Varnish reverse proxy which may allow privilege escalation.
http://www.sans.org/reading_room/whitepapers/testing/scanning_windows_deeper_with_the_nmap_scann...
###author:hiphop### ###qq:70381908###为什么要关注 Oracle ?因为Oracle 被大量企业所使用,有许多目标可以选择来渗透许多企业都没有更新且有潜在的...
#!/bin/sh## root shell exploit for postfix + sudo# tested on debian powerpc unstable## by Charle...
在我们身边经常听到以下的话题和牢骚: “小王啊听说你的工资又涨了?你在单位干的一不定很不错。
#######################################################################/ ## ...
Lately I started to see a few web-based attacks with a php script inside the user agent.
If you think that your logs are only useful when something crashes or when you need to troublesh...
May 5th, 2000. It was almost ten years ago that news came out.
http://download.oracle.com/docs/cd/E12840_01/wls/docs103/sitemap.
This idea occurred to me a few weeks back when discussing the potential impact of ClickJacking attacks with Luca.
The other day I was performing some CITRIX poking, so I had a lot of fun with breaking GUIs, whi...
============================================ ncpfs, Multiple Vulnerabilities March 5, 2010 CV...
Jeremiah Grossman gave his “2010: A Web Hacking Odyssey – The Top Ten Hacks of the Year” talk he...
http://wordpress.org/extend/plugins/exploit-scanner/
With the sharp increase of hacking attacks over the last couple of years, and the introduction o...
这是因为AA是一个动态的内部类,创建这样的对象必须有实例与之对应,程序是在静态方法中直接调用动态内部类会报这样错误。
http://www.securitytube.net/SSH-Gymnastics-using-ProxyChains-video.
http://tech.it168.com/wec.shtml http://baike.baidu.
Description: The Spamassassin Milter plugin suffers from a remote root command execution vulnerability.
http://www.webspherechina.net/club/tag-WebSphere%E8%A7%86%E9%A2%91.
转自t00ls 关于Union偏移注射这个东西,最早貌似是lake2大黑客提出来的,以前一直当他是鸡肋,没去关注过,直到昨天遇到一个mysql 4.1的点。
http://www.56cto.com/html/Safe/4/34302.html http://www.
在menzhi007的blog里看到非常有意思的东西:http://hi.baidu.com/menzhi007/blog/item/c2e98551a18754848c54301c.
Security Ressources SitesOperating systems architecture http://www.
http://www.ringkee.com/note/opensource/openldap.
http://www.easysoft.com/applications/openldap/back-sql-odbc.