阿里云安全专家,主要负责阿里云云产品安全。
RealNetworks Helix Server URI Traversal Arbitrary File Access Vendor: RealNetworks (http://www.
http://www.informit.com/store/product.aspx?isbn=0321591801
http://engineeringforfun.com/wiki/index.php/Durzosploit_Introduction ...
The popular website WHOIS.com used to check the availability of domain names and the current own...
GuestStealer allows for the stealing of VMware guests from vulnerable hosts based on the Directo...
http://www.openbsd.org/faq/zh/faq4.html http://v.
http://wirelessdefence.org/Contents/WirelessDistros.
http://itboba.com/taxonomy/term/959
Standards compliance There are a number of good standards and guidelines in relation to informat...
Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers1.
(to get the scripts mentioned by this advisory please get the fullversion at http://www.
WinScanX Pro is only $10.00 for the month of February (normally $250.
Developed as part of G-SEC's investigation for the"Secure SSL/TLS configuration Report 2010" (to...
Hey all,Since there seems to be a fair bit of disinformation, and utter nonsense, floating aroun...
Introduction============keimpx is an open source tool, released under a modified version ofApache License 1.
[ PHP 5.2.12/5.3.1 session.save_path safe_mode and open_basedir bypass ]Credit: Grzegorz StachowiakProvided by: SecurityReason.
[ Cpanel Image Manager Local File Include Exploit ][~] Author : AnTi SeCuRe[~] TeaM : SauDi ViRuS TeaM[~] Site : WwW.
Yesterday, I received a post in the Pen-Test mailing list requesting for tips/resources on penetration testing of flash applications.
http://packetstormsecurity.org/1002-exploits/sapone_fc.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -- Product JDownloader[1] is an open source do...
[+] Vurnerebility: LDAP Injection [+] Category : Implemented Web exploit [+] Category : At...
Trustwave's SpiderLabs Security Advisory TWSL2010-001: Multiplatform View State Tampering Vulnerabilities Published: 2010-02-08 Version: 1.
http://packetstormsecurity.org/1002-exploits/rpc_cmsd_opcode21.
http://java.sun.com/products/servlet/download.html
分布式(Distributed)数据访问层(Data Access Layer)(以下简称DAL)是综合MySQL Proxy、Memcached、集群等等技术优点而构建的一个软件系统。
http://owasp.blip.tv/ http://irongeek.blip.tv/
http://wiki.hak5.org/wiki//USB_Switchblade
http://www.irongeek.com/i.php?page=maemo/nokia-770-800-hacking-pen-testing ...
http://www.securitytube.net/Using-Database-Caches-to-Detect-SQL-injection-(SecTor-2009)-video.
www.livecdlist.com
http://www.blackhat.com/html/bh-dc-10/bh-dc-10-archives.
A vulnerability was found in Web Administration Interface of device HP StorageWorks 1/8 G2 Tape Autoloader.
http://www.vsecurity.com/download/papers/WeaningTheWebOffOfSessionCookies.
https://www.honeynet.org/node/507 http://www.honeypots.net/
http://www.mytty.org/wafp/ Next generation web scanner.
Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order.
We have pushed a new major release of Dradis (an open source frameworkto enable effective inform...
################################################################# # Securitylab.
This trick is mostly useful but can also be used for wrong purposes.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.
A commercial exploit is available through the Immunity Partners program: https://www.
http://www.securityfocus.com/data/vulnerabilities/exploits/38109.
At the recent Black Hat DC 2010 conference , British security expert David Litchfield demonstrat...
http://www.youtube.com/watch?v=NN50RtZ2N74 http://www.
http://www.securityfocus.com/data/vulnerabilities/exploits/35929.
http://www.securityfocus.com/data/vulnerabilities/exploits/37806.
http://www.securityfocus.com/data/vulnerabilities/exploits/36901.
http://intevydis.blogspot.com/2010/01/oracle-weblogic-1032-node-manager-fun.
|------------------------------------------------------------------|| __ __ || _________ _______...
http://www.youtube.com/watch?v=NN50RtZ2N74 Samba Remote Directory Traversallogic fuckup discover...