Aggregator
浏览器解析js - bamb00
6 years 7 months ago
网页加载js步骤1、浏览器一边下载html网页,一边开始解析(不等下载完就解析)2、遇到<script>标签,暂停解析,网页渲染的控制权交给javascript引擎3、如果<script>标签引用了外部脚本,先下载在执行,否则直接执行4、执行完毕,控制权交还渲染引擎,继续往下解析html网页注意:有
bamb00
The Hunt for IoT: So Easy To Compromise, Children Are Doing It
6 years 7 months ago
This episode in The Hunt for IoT Volume 6 series focuses on the threat actors building IoT botnets, how easy IoT devices are to exploit, recent thingbot discoveries, and the status of Mirai infections worldwide.
The Hunt for IoT: So Easy To Compromise, Children Are Doing It
6 years 7 months ago
This episode in The Hunt for IoT Volume 6 series focuses on the threat actors building IoT botnets, how easy IoT devices are to exploit, recent thingbot discoveries, and the status of Mirai infections worldwide.
The Hunt for IoT: So Easy To Compromise, Children Are Doing It
6 years 7 months ago
This episode in The Hunt for IoT Volume 6 series focuses on the threat actors building IoT botnets, how easy IoT devices are to exploit, recent thingbot discoveries, and the status of Mirai infections worldwide.
CVE-2019-11249
6 years 7 months ago
Incomplete fixes for CVE-2019-1002101 and CVE-2019-11246, kubectl cp potential directory traversal
CVE-2019-11247
6 years 7 months ago
API server allows access to custom resources via wrong scope
哈希长度拓展攻击之De1CTF - SSRF Me - PaperPen
6 years 7 months ago
第一次做哈希长度拓展攻击的题目,记录一下
PaperPen
让终端更好看--Ubuntu OhMyZsh配置指南 - luoyesiqiu
6 years 7 months ago
查看shell列表 如果发现没有zsh就安装 安装zsh 设置默认shell 重启主机 查看当前默认shell 确认zsh是否为默认shell 安装oh my zsh 安装zsh syntax highlighting插件 安装字体 oh my zsh会有许多符号来美化终端界面,所以安装一些支持多样
luoyesiqiu
IOMMU introduction
6 years 7 months ago
Terenceli
由一道工控路由器固件逆向题目看命令执行漏洞 - H4lo
6 years 7 months ago
前言 2019 工控安全比赛第一场的一道固件逆向的题目,好像也比较简单,好多人都做出来了。这里就分别从静态和动态调试分析复现一下这个命令执行的洞。 赛题说明 题目给的场景倒是挺真实的:路由器在处理 tddp 协议时出现了命令注入,导致了远程命令执行。就是后面做出来的这个答案的格式咋提交都不对...
H4lo
intent 参数的规范 - bamb00
6 years 7 months ago
对于采用 intent 参数的 Activity Manager 命令,您可以使用以下选项指定 intent:
bamb00
Kazakhstan Attempts to MITM Its Citizens
6 years 7 months ago
Kazakhstan is now asking its citizens to install digital certificates so that it can decrypt all online communications. Their methods, however, may leave the population vulnerable to cyber attacks for many years to come.
Kazakhstan Attempts to MITM Its Citizens
6 years 7 months ago
Kazakhstan is now asking its citizens to install digital certificates so that it can decrypt all online communications. Their methods, however, may leave the population vulnerable to cyber attacks for many years to come.
Kazakhstan Attempts to MITM Its Citizens
6 years 7 months ago
Kazakhstan is now asking its citizens to install digital certificates so that it can decrypt all online communications. Their methods, however, may leave the population vulnerable to cyber attacks for many years to come.
Xposed反射字段流程分析 - luoyesiqiu
6 years 7 months ago
在 "XposedBridge源码" 中,反射字段的方法封装在 类里面.下面来看看Xposed是如何获取和设置字段的值的 获取字段的值 获取字段的值有许多个方法,有获取基本类型字段的值的方法(getIntField,getLongField,getDoubleField...),也有获取对象类型字段
luoyesiqiu
MLSRC与你相约第四届SSC安全峰会
6 years 7 months ago
MLSRC与你相约第四届SSC安全峰会
MLSRC与你相约第四届SSC安全峰会
6 years 7 months ago
MLSRC与你相约第四届SSC安全峰会
MLSRC与你相约第四届SSC安全峰会
6 years 7 months ago
MLSRC与你相约第四届SSC安全峰会
Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in June 2019
6 years 7 months ago
Similar to April and May, threat actors in June continued targeting the deserialization vulnerabilities found in Oracle WebLogic to mine cryptocurrency.