- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
目前分類:一般文章分享 (185)
- Oct 08 Mon 2007 10:40
MSSQL cookie注入工具[web版]
- Oct 08 Mon 2007 10:35
ASP.NET木馬及Webshell安全解決方案
- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
- Oct 08 Mon 2007 10:05
根據Web服務器記錄來追擊黑客
Web服務是Internet所提供最多,最豐富的服務,各種Web服務器自然也是受到攻擊最多的,我們採用了很多措施來防止遭受攻擊和入侵,其中查看Web服務器的記錄是最直接,最常用,又比較有效的一種方法,但logging記錄很龐大,查看logging記錄是很繁瑣的事情,如果抓不住重點,攻擊線索就容易被忽略。下面就對最流行的兩類Web服務器:Apache和IIS做攻擊的實驗,然後在眾多的記錄中查到攻擊的蛛絲馬跡,從而採取適當的措施加強防範。
- Oct 08 Mon 2007 10:01
增強防御DDOS的能力
- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
- Oct 08 Mon 2007 09:59
用Windows的ipsec 防DDos
- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
- Oct 05 Fri 2007 14:48
[轉貼]黑客常用入侵Windows XP的方法
在Windows中啟用了屏幕保護之後,只要我們離開計算機(或者不操作計算機)的時間達到預設的時間,系統就會自動啟動屏幕保護程序,而當用戶移動鼠標或敲擊鍵盤想返回正常工作狀態時,系統就會打開一個密碼確認框,只有輸入正確的密碼之後才能返回系統,不知道密碼的用戶將無法進入工作狀態,從而保護了數據的安全。
- Oct 05 Fri 2007 14:41
[轉貼]告訴你如何查出自己電腦的木馬,大家都學學.....(10招)
- Oct 05 Fri 2007 14:25
[轉貼]安全隱患依然 三種系統漏洞至今無法解決
Web安全應用公司Watchire的安全研究總監Danny Allan總結到:這是幾年來第一次,人們走出黑客大會的主會場,搖頭聳肩表示無奈,因為有一些漏洞之今仍沒有解決方案。
- Sep 26 Wed 2007 12:08
Sophos Blocks Unauthorized Remote Connection Tools
Remote connection tools like RealVNC and Radmin that allow employees to access remote-based PCs or laptops from any other computer via the Internet, though often unendorsed by IT management, are common tools used by staff and represent an end-run around corporate computer usage policies, Sophos contends.
- Sep 26 Wed 2007 11:41
Linux系統安全隱患及安全管理的方法
下面,我具體從兩個方面來闡述Linux存在的不足之處,並介紹如何加強Linux系統在安全方面的管理。
- Sep 17 Mon 2007 15:10
Microsoft Patches Tackle Evil Clippy
The security advisory for Microsoft Agent, MS07-051, is the only critical release out of four security advisories the company put out on Sept. 11. It addresses a vulnerability whereby Clippy can get hoodwinked by a malicious URL and can then be used to take over a targeted system without ever appearing to the user.
Clippy—officially known as Clippit—met its demise in Office 2007, but this vulnerability still affects the agent as it exists in Microsoft Windows 2000 SP4.
- Sep 11 Tue 2007 23:35
如何防止網頁篡改系統技術的比較
- Sep 11 Tue 2007 23:32
轉貼-【2007.08.31】關於中國網頁防篡改技術分析
- Sep 10 Mon 2007 12:10
Microsoft to Spackle Holes in Windows, Messenger, Visual Studio
While only one—a vulnerability in Windows—is deemed critical, three of the advisories address vulnerabilities that can lead to system takeover: the Windows flaw, flaws in MSN Messenger and Windows Live Messenger, and holes in Visual Studio.
"If the Windows Messenger vulnerability lends itself to a chat-based attack vector, then organizations and users of the ubiquitous Microsoft Messenger should pay attention, because this would be a prime candidate for spreading malware and viruses," said Paul Zimski, senior director of market and product strategy for PatchLink, in a statement.
- Sep 10 Mon 2007 11:38
Analysts Predict Death of Traditional Network Security
According to them, in the next five years the Internet will be the primary connectivity method for businesses, replacing their private network infrastructure as the number of mobile workers, contractors and other third-party users continues to grow. In this new world, which Whiteley and Lambert called "Internet Everywhere," corporations will have to redefine network security and focus on data encryption, managing risk at the endpoint and having strict data access controls, they said.
Some corporations, such as the energy giant BP, have already taken big steps towards deperimeterization—a term created by the Jericho Forum to describe a strategy that focuses on protecting data with tactics such as encryption rather than traditional efforts aimed at fending off attacks from intruders at the network's boundary. BP has taken some 18,000 of its 85,000 laptops off its LAN and allowed them to connect directly to the Internet, the two said.
- Sep 10 Mon 2007 09:49
More .Gov Sites Boobytrapped
I had just finished writing up this story of a European country with a defense agency site that's got its database dangling out for all the world to play with, when Exploit Prevention Labs Chief Technology Officer Roger Thompson pointed to about a dozen poisoned government sites that are hosting pages serving malware and porn.
Thompson says that he expects there are many more, which wouldn't surprise me—a quick Google search yesterday turned up plenty.
EPL reports that the hacked .gov sites are dishing out malware via drive-by download and social engineering. The front pages give off no clues of having been compromised, but they're hosting pages that serve junk. EPL has identified city governments such as lasalle, il and frenchsettlement-la as being compromised.
- Aug 30 Thu 2007 10:48
安全知識:從註冊表下手 切斷一切黑客入侵的路徑
1.清理訪問「網絡鄰居」後留下的字句信息
在HEKY_CURRENT_USER\Network\Recent下,刪除下面的主鍵。
2.取消登陸時自動撥號在HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Network\RealModeNet下修改右邊窗口中的「autologon」為「01 00 00 00 00」。
- Aug 28 Tue 2007 14:35
入侵oracle資料庫的一些心得
- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
- Aug 28 Tue 2007 14:32
php代碼不開源下的一種漏洞檢測思路
- 這篇文章限定好友觀看。
若您是好友,登入後即可閱讀。
- Aug 28 Tue 2007 14:14
Targets of the day
Last Updated: 2007-08-26 22:13:44 UTC
by Pedro Bueno (Version: 1)