阿里云安全专家,主要负责阿里云云产品安全。
http://www.ethicalhacker.net/content/view/227/24/
Technical explanation of The MySpace WormAlso called the "Samy worm" or "JS.
http://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents The following resources may be of interest:http://www.
http://ucsniff.sourceforge.net/ UCSniff is a VoIP/UC Sniffer / Assessment / Pentest tool with some useful new features, such as IP Video Sniffing.
http://hba.by.ru/localroot/
Ok basically what this exploit does, it uses an active XSS vuln to automaticly post a buddy bulletin from whomever views your site.
Its very easy to fool Rapid Share server if your IP address is assigned by your ISP.
Ajax Worm - Proof of Concept http://myappsecurity.
http://forum.darkc0de.com/index.php?action=vthread&forum=19&topic=5178 ...
http://sourceforge.net/projects/xss-proxy
http://www.codepub.com/software/view-software-8932.html
https://developer.mozilla.org/En/HTTP_access_control https://forum.
http://www.slax.org/
http://www.youku.com/playlist_show/id_281293.html
http://blog.s135.com/post/360/ http://www.sphinxsearch.
http://blog.s135.com/post/360/ http://www.sphinxsearch.
1. Add N Edit Cookies 查看和修改本地的Cookie,Cookie欺骗必备。
Burp Proxy is an interactive HTTP/S proxy server for attacking and testing web applications.
http://www.itlearner.com/code/js_ref/contents.htm DOM组件 http://www.
ext2hide allows users and administrators to utilize the reserved space of the ext2/3 superblocks...
The following proof-of-concept PHP code is available:var_dump(curl_exec(curl_init("file://safe_mode_bypass/x00".
利用是PHP5,是因为_SERVER的变量不受'引号的限制,即便是开启了转义漏洞出在User-Agent 第二:insert into的多个数据插入文中构造的地方就是insert INTO {...
http://www.jb51.net/article/8676.htm 请问下那此句语句的作用。
http://v.youku.com/v_show/id_XNzUxMTk0OTY=.html http://www.
http://huaidan.org/archives/1897.html http://www.
http://netsecurity.51cto.com/art/200902/111734.htm 1) Dshield Web Honeypot:SQL注入、XSS、密码拆解等攻击手段是互联网网站经常面临的威胁,然而因为传统的IDS和防火墙并不能检查来自Web上的攻击数据,网站管理员很难及时发现攻击行动的存在,往往在黑客攻击成功乃至很长时间之后,才发现已经遭受攻击。
http://hack.77169.com/HTML/20080627112722.html
Tools:Ettercapnano1. For SSL Dissection support (hotmail,gmail), you need to do this:Open a shell, type: "nano /usr/local/etc/etter.
最近,Citrix 宣布将推出的 XenServer 新版本免费提供给用户。据 Citrix 发布的新闻稿称,该 XenServer 新版本为“经过云验证”的企业级虚拟化平台,任何用户都可免费无限制地进行应用部署。
http://www.howtoforge.com/suhosin_php_debian_etch_ubuntu
vmstat详解 http://hi.baidu.com/wanqiai/blog/item/05d90d2d66df3535359bf713.
http://www.securityfocus.com/infocus/1679 http://blog.
http://linux.chinaunix.net/bbs/thread-722462-1-1.html
Recommended UNIX/Linux Links: Linux Ftp Watcher, Linux Links by Goob, KMFMS, Linux Web Watcher, ...
http://linas.org/linux/secure.html
原贴:http://turbolinux.com.cn/turbo/wiki/doku.php?id=arp:arp%E5%B7%A5%E5%85%B7%E7%AE%80%E4%BB%8B_arptables_arpwatch 一.
http://www.lupaworld.com/441/viewspace-1762.html http://staff.
http://os.51cto.com/art/200802/65589.htm
文章作者:solariz7@yahoo.com 信息来源:中国Linux论坛 http://www.
pssh http://www.theether.org/pssh/docs/0.2.3/pssh-HOWTO.
Sphinx+memcached+ttserver+tokyocabinet+tokyotyrant-1.
http://securitytube.net/Defeating-SSL-using-SSLStrip-(Marlinspike-Blackhat)-video.
#!/bin/sh # socket queue# sysctl -w net.ipv4.tcp_max_syn_backlog=4096sysctl -w net.
An attacker may exploit this issue using readily available commands.
Description Dear lighty community, I am using lighty to serve a wiki; to have nice urls, i use the following in my lighttpd.
Description Hi, I run lighttpd 1.4.19 on Linux on top of a case-insensitive filesystem (JFS with OS/2 compatibility enabled).
[ SecurityReason.com PHP 5.2.6 (error_log) safe_mode bypass ]Author: Maksymilian Arciemowicz (cXIb8O3)securityreason.
PHP is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input.
http://www.kachakil.com/papers/SFX-SQLi-en.htm
http://huaidan.org/archives/2810.html