导航

Web安全手册

分享本身就是件快乐的事 我因别人得到帮助而感到幸福

[置顶] 悲剧啊

[置顶] 技术过关游戏

[置顶] 免责声明 & 文章投递

马克斯CMS2.0beta (maxcms)SQL注入漏洞

马克斯CMS2.0beta (maxcms)SQL注入漏洞

Jieqi cms v1.5 remote code execution exploit

杰奇 CMS 0DAY

WFTPD Explorer Pro 1.0 Remote Heap Overflow Exploit

WFTPD Explorer Pro 1.0 Remote Heap Overflow Exploit

Submit Your Top Web Hacking Techniques for 2008

Submit Your Top Web Hacking Techniques for 2008

Php168 v2008 权限提升漏洞

Php168 v2008 权限提升漏洞 by Ryat http://www.wolvez.org 2009-01-25

OWASP's XSS Prevention Cheat Sheet

The Open Web Application Security Project (OWASP) has recently released a XSS (Cross Site Scripting) Prevention Cheat Sheet. This cheat sheet helps developers identify how and when to output encode or escape untrusted user data when including it within a page. I am particularly excited about this resource because it not only discusses the case in which HTML encoding is necessary, but also helps layout rules or conditions for using JavaScript, CSS, Attribute, and other encoding schemes.
 

How to attack a windows domain

Trace注:文章中提到的Incognito可以到这里下载。

JBroFuzz 1.2 Released

Trace注:一款Fuzzer,功能比较全,需要JavaRuntime支持。

Version 1.2 (codename Athena) introduces the ability to open, load and save files on fuzzing sessions using the .jbrofuzz format. Graphing has been expanded to a tab and can be performed at any time. Also, a headers tab, including default headers of a number of operating system browsers has been included.

union select控制ewebeditor上传文件后缀

目前网上流传太多ewebeidtor的修改版 lite版 216版的ewebeditor 存在一个注入漏洞 之后一个版也存在这样的问题 前段时间拉至尊宝渗透一内网时发现这个东西 无后台 无法登陆 默认数据库 但用处也不大 所以就深刻研究了下这个注入 发现可以通过union 来控制允许上传类型的列表 随后时间成功利用此漏洞拿了不少东西 分享下

Videos from HITBSecConf2008 - Malaysia released!

The videos from HITBSecConf2008 - Malaysia are now available for download!

Vulnerabilities & proofs-of-concept

During this week, securityfocus, have reported a number of vulnerabilities in several applications where, as usual, one can not miss for Microsoft environments. Given that these "unsafe gaps" in planning the program allows to conduct attacks of various kinds, it's interesting to know the potential that can exploit a vulnerability through proofs-of-concept.

Fscan v1.0 : Fast HTTP Vulnerability Scanner v1.0 have been released

Trace注:tarasco出的http扫描软件,这次发行的版本带了fscan_gui。

sql_2005_inj[MSSQL2005注射工具]

Sql_2005_inj是专门用于注入mssql2005数据库的工具,是我
去年暑假7月份写的。由于功能很简单不完善一直没发布,由于要
写新版本所以把老的放出来晒晒。

Tutorial on how to test for Broken Authentication using Acunetix WVS tools

Broken authentication is the 7th in the OWASP top 10 web application vulnerabilities. It is a security problem that is prevalent in many web applications, especially custom ones or those written in-house.  Sandro just published a tutorial showing how to identify these security issues and attack vulnerable web applications for educational purposes. To automate much of the process, Sandro makes use of Acunetix WVS HTTP Sniffer and the HTTP Fuzzer instead of writing custom tools to do this.

Rainbow tables

Trace注:硬盘够大的朋友下吧
Two resources with a nice collection of rainbow tables available for download for free:

分页:«123»

Powered By Z-Blog .Theme from Google黑板报 By Washun

Copyright 2008-2009 Pcsec.org. Some Rights Reserved.苏ICP备08110306号