阿里云安全专家,主要负责阿里云云产品安全。
http://www.niiconsulting.com/services/security_assessment/NII_Sample_PT_Report.
Features handles as many connections as you want simultaneously (configurable, default is 10...
KrbGuess is a small and simple tool which can be used during security testing to guess valid usernames against a Kerberos environment.
http://www.sans.org/reading_room/whitepapers/testing/rss/a_fuzzing_approach_to_credentials_disco...
DMA[2005-0614a] - 'Global Hauri ViRobot Server cookie overflow' Author: Kevin Finisterre Vendor: http://www.
We all know what username enumeration vulnerabilities are about.
http://www.governmentsecurity.org/articles/default-logins-and-passwords-for-networked-devices.
http://netloony.sourceforge.net/
很多,非常多。 Test sites / testing grounds SPI Dynamics (live) – http://zero.
http://hi.baidu.com/%BF%D5%C6%F8%C8%CB%B6%F9/blog/item/dedb06b1c26adc52092302e0.
Yokoso! is a project focused on creating fingerprinting code that is deliverable through some form of client attack.
postal是一个不错的SMTP压力测试工具,作者还写了Bonnie++,他是一个测试磁盘IO的东西,也很不错。
共享文件系统文件传输,是网络侦控项目中的一个实际操作。它是为了抵制入侵者进入内网而提出的一种安全解决方案。
http://portswigger.net/suite/help.html
简单说说跨域访问 http://farthinker.cn/2007/12/22/cross-domain-visit/ 使用 window.
/etc/sysconfig/network-scripts/route-ethX 也能定义单个网卡的静态路由呀,我之前只知道/etc/sysconfig/static-route ...
下载地址 http://www.verycd.com/topics/241533/
debian:~# uname -a Linux debian 2.6.18-6-686 #1 SMP Thu Aug 20 21:56:59 UTC 2009 i686 GNU/Linux debian:~# cat /etc/issue Debian GNU/Linux 4.
Hi! This is forward from lkml, so no, I did not invent this hole.
http://www.securitytube.net/FastTrack-Autopwn-video.aspx
一、添加swap空间: 1、扩展一个现有的swap空间: 、首先禁止正在使用的swap空间: [root@server4 ~]# swapoff /dev/mapper/tools-sw...
http://trac.thepentest.com/wiki/FasttrackOverview http://trac.
http://book.51cto.com/art/200710/58933.htm php5与mysql5 web开发技术详解 http://book.
http://www.hacktoolrepository.com/tool/59/Oracle%20Auditing%20Tools http://www.
host monitor
AutoNessus automates regular Nessus scans and provides delta reporting.
昨天出来的一份传输层保护的Cheat Sheet实际上主要是 TLS 的正确部署指导原则,我仔细阅读了一遍,非常不错。
MSCS,SAFEKIT,AUOTOSTART,LIFEKEEPER,ROSE
Computerworld reports that according to Gartner's research, client virtualization, more data, le...
首先作为我,gxm,很荣幸的与咔咔在23号的早上凌晨2点多共同研究了流数据这个课题。感谢咔咔的无私奉献。
http://sourceforge.net/projects/wapiti/
http://pentestit.com/2009/10/18/bitmeter-2-bandwidth-meter-calculate-total-internet/ ...
systrace ttyrpld
Longcat Flooder is a multi-protocol flooding tool written during the Subeta raids, by the same c...
Z (Z [at] wechall [dot] net) submitted this cool video to us.
http://www.oissg.org/wiki/index.php?title=ISAAF-PENETRATION_TESTING_FRAMEWORK ...
It's final time to stop procrastinating: Nikto 2.
http://blog.csdn.net/sunchaohuang/archive/2007/07/01/1674731.
http://www.bitmover.com/lmbench/ http://sysbench.
在debian Linux服务器的日志中,dmesg出现类似的信息:TCP: Treason uncloaked! Peer 202.
http://www.tudou.com/programs/view/xFqhBEYcgu0/ http://linux.
1. 目录遍历漏洞绕过 1.1URL编码 . %2e / %2f / %5c 1.
CGI(Perl)的漏洞及防范措施(1) 一般来说,编程语言本身并不是导致安全隐患的主要因素,事实上,软件的整体安全性仍然大部分取决于软件制造者的知识面、理解能力和安全意识。
http://www.gogoqq.com/photos.htm?uin=550669&bumid=0
http://bbs.linuxteam.com.cn/viewthread.php?tid=471
http://www.cnxhacker.com/Article/hacker/study/200808/11281.
http://www.cnxhacker.com/Article/hacker/tools/200904/11345.
http://www.owasp.org/index.php/Category:OWASP_Joomla_Vulnerability_Scanner_Project ...
ServerMask 这个程序通过移走你开的标志使 Windows 网服务器的特性变暗 IIS。