教学频道 第110页
教学频道 – 华盟网

Discuz插件禾今微信投票权限和刷票漏洞(内含python脚本)

Discuz插件禾今微信投票权限和刷票漏洞(内含python脚本)-华盟网
文章详细分析了Discuz插件禾今微信投票系统的刷票漏洞,并提供了python脚本来模拟请求提交数据。同时揭示了插件未做权限设置的问题,以及如何通过抓包和源码分析来发现刷票行为。
AlexFrankly的头像-华盟网AlexFrankly9年前
05.7W+0

SQL注入之骚姿势小记

SQL注入之骚姿势小记-华盟网
了解SQL注入中的IN、BETWEEN、ORDER BY等技巧,提升网络安全防护能力。安全客分享实战经验,助你掌握更多注入姿势。
AlexFrankly的头像-华盟网AlexFrankly9年前
04.5W+0

以“催眠”绕过认证:一个影响Kerberos协议长达20年的漏洞

以“催眠”绕过认证:一个影响Kerberos协议长达20年的漏洞-华盟网
揭示了一个长达20年的Kerberos协议漏洞,名为‘奥菲斯的竖琴’。该漏洞影响Heimdal Kerberos和微软Kerberos实现版本,并可能导致权限提升和内网资源窃取。了解其原理与修复措施。
AlexFrankly的头像-华盟网AlexFrankly9年前
08.1W+0

BurpSuite 代理设置的小技巧

BurpSuite 代理设置的小技巧-华盟网
本文详细介绍了如何正确配置BurpSuite代理,包括HTTP和HTTPS网站、移动APP以及多重代理环境下的设置方法。
AlexFrankly的头像-华盟网AlexFrankly9年前
04.6W+0

重放攻击无线键盘实验,篡改你的输入信息

重放攻击无线键盘实验,篡改你的输入信息-华盟网
Discover the risks of wireless keyboards and mice with a replay attack experiment. Learn how to protect your inputs from unauthorized alterations in this detail
AlexFrankly的头像-华盟网AlexFrankly9年前
01.5W+0

安全运维之如何将Linux历史命令记录发往远程Rsyslog服务器

安全运维之如何将Linux历史命令记录发往远程Rsyslog服务器-华盟网
Learn how to send Linux history command records to a remote Rsyslog server using two methods. This guide covers modifying the bash source code and configuring r
AlexFrankly的头像-华盟网AlexFrankly9年前
01.3W+0

反入侵之发现后门利用mount-bind将进程和端口信息隐匿

反入侵之发现后门利用mount-bind将进程和端口信息隐匿-华盟网
This article discusses a case study on detecting and mitigating a sophisticated backdoor technique that uses mount-bind to hide processes and port information.
AlexFrankly的头像-华盟网AlexFrankly9年前
01.3W+0

通过gpg签名来防止伪造的github commits

通过gpg签名来防止伪造的github commits-华盟网
Explore how to use GPG signatures to prevent forged GitHub commits and protect your code from unauthorized modifications. Understand the security risks of unver
AlexFrankly的头像-华盟网AlexFrankly9年前
01.2W+0

如何利用密码学以及数论基础攻击一个“宣称安全”的密码系统

如何利用密码学以及数论基础攻击一个“宣称安全”的密码系统-华盟网
Explore how to exploit vulnerabilities in a claimed secure cryptographic system by targeting its protocol rather than the algorithm or key. Understand the role
AlexFrankly的头像-华盟网AlexFrankly9年前
01.1W+0

使用.NET汇编技术绕过Windows系统的Device Guard

使用.NET汇编技术绕过Windows系统的Device Guard-华盟网
了解如何利用微软Device Guard(设备保护)用户模式代码完整性(UMCI)中的漏洞,通过绕过csc.exe编译过程来执行任意代码。本文详细介绍了绕过技术的工作原理和实现方法,适合网络安全专业人士阅...
AlexFrankly的头像-华盟网AlexFrankly9年前
04.4W+0

10种常见的进程注入技术的总结

10种常见的进程注入技术的总结-华盟网
Explore 10 common process injection techniques used in malware and fileless attacks. Learn about the methods such as CreateRemoteThread and LoadLibrary, PE inje
AlexFrankly的头像-华盟网AlexFrankly9年前
04.6W+0

如何在未root的Android手机上安装漏洞利用框架RouterSploit

如何在未root的Android手机上安装漏洞利用框架RouterSploit-华盟网
Learn how to install the powerful RouterSploit framework on your unrooted Android device and use it for security testing and wireless network penetration. This
AlexFrankly的头像-华盟网AlexFrankly9年前
05.3W+0