![个人头像照片](https://ucc.alicdn.com/avatar/avatar3.jpg)
阿里云安全专家,主要负责阿里云云产品安全。
http://www.youtube.com/watch?v=rrjSEkSwwOQ
https://www.owasp.org/index.php/OWASP_Testing_Guide_v4_Table_of_Contents ...
https://www.owasp.org/index.php/Category:OWASP_Video https://owasp.
https://code.google.com/p/malicious-domain-profiling/ https://www.
https://www.veil-framework.com/
有很多不错的议题: http://2014.appsecusa.org/2014/ http://owaspappsecusa2014.
http://www.youtube.com/watch?v=fV5kED7nryw&list=PLpr-xdpM8wG_KHsxepT9o6trkqDELhr3_&index=12 ...
https://code.google.com/p/corkami/ https://github.
http://security.ctocio.com.cn/41/12654541.shtml
http://suchalin.blog.163.com/blog/static/55304677201010221235907/ ...
Semanticnet library https://github.com/ThibaultReuille/semanticnet ...
http://code.google.com/p/grr/ https://github.
http://www.opengraphiti.com/
SYNC:sqoop,odbc,rest script:pig SQL:hive,tez,hcatalog nosql:hbase,accumulo stream:storm search:...
https://www.loggly.com/ 日志的分析和监控在系统开发中占非常重要的地位,系统越复杂,日志的分析和监控就越重要,常见的需求有: 根据关键字查询日志详情 监控系统的运...
FullStroy(https://www.fullstory.com) Trak.io http://mouseflow.
A while back I was testing a CMS that had a curious feature, all uploaded files were placed in their own directory.
http://2013.zeronights.org/materials
http://2012.zeronights.org/includes/docs/Firstov%20-%20Attacking%20MongoDB.
The web.config file plays an important role in storing IIS7 (and higher) settings.
http://www.harmj0y.net/blog/penetesting/pass-the-hash-is-dead-long-live-pass-the-hash/ You ma...
http://rvasec.com/rvasec-2014-videos/
# Exploit Title: IBM Sametime Meet Server 8.
https://media.defcon.org/DEF%20CON%2021/
http://man7.org/linux/man-pages/man7/capabilities.
这种利用xmlrpc.php的攻击可以绕过这些限制。攻击的方式直接POST以下数据到xmlrpc.
http://lib.liquidmatrix.org/2013/blackhat-2013-video/ http://www.
https://github.com/dpnishant/jsprime
https://github.com/quentinhardy/odat
http://www.mafengwo.cn/i/2978248.html http://chinese.
https://github.com/cloudflare/bpftools
fedramp nist sp 53
https://launchpad.net/openjdk http://bazaar.launchpad.
https://www.netspi.com/blog/
Introduction Migrating to Domain Admin processes is a common way penetration testers are ab...
In this blog I'll share a new PowerShell script that uses Service Principal Name (SPN) recor...
Watching the industry respond to the Heartbleed vulnerability has been fascinating.
https://github.com/rapid7/metasploit-framework/tree/master/external/source/exploits/cve-2013-1...
If the "pw_type" is crypt-based and the password field returned by the query is null, user is able to authenticate with any password.
When using a GRUB bootloader password, the md5 hash of said password was collected and stored i...
It was found that the ovirt-engine-reports setup script logged the reportsdatabase password in plain text to a world-readable file.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 === LSE Leading Security Experts GmbH - Securit...
http://xxx.com:9200/_search?source={%22size%22:1,%22query%22:{%22filtered%22:{%22query%22:{%22m...
ID:GENXOR TEAM:360网站卫士 [转载请注明出处自 : 360网站卫士博客-blog.wangzhan.360.cn] 0×01 原理分析 最近爆出关于利用社工库爆破Discuz论坛用户名密码的工具,造成很多大的论坛用户信息泄露,分析原理如下。
1. 检查帐户 ? 1 2 3 4 5 # less /etc/passwd # grep :0...
http://www.secniu.com/blog/page/2/ https://media.
http://wenku.baidu.com/link?url=awoYxUopvjR9miMvaVQvgtpGDUMmjilVlaHfOuUBEliyFC7SJl-F0Pc05E_6vnB...
http://product.china-pub.com/3803691
http://blog.silentsignal.eu/2014/02/09/jdb-tricks-hacking-java-debug-wire/ http://pki.
http://sishuok.com/forum/blogPost/list/4201.html http://blog.