当前位置:网站首页>Web foundation of network security note 02
Web foundation of network security note 02
2022-07-01 11:05:00 【I'm not zzy1231a】
About web Source code
web Source code is an important information breakthrough of code audit vulnerability , The main knowledge points include contents 、 Script 、 Application etc. .
web Directory structure :
It is divided into background directories 、 The template directory 、 Database directory 、 Database configuration file .
The script type :
It mainly includes ASP、PHP、ASPX、JSP、JAVAWEB、Python.
Application classification :
Portal corresponds to comprehensive vulnerabilities , E-commerce corresponds to business logic vulnerabilities , Forum correspondence XSS Logical loopholes 、 Blog vulnerability is less 、 The third party mainly depends on the function .
Supplementary contents include framework and non framework 、CMS distinguish 、 Open source or internal vulnerability audit and testing .
web Key files in the source code
Backstage path , Database configuration file , Backup file
backstage : It usually refers to those program methods that bypass security control and obtain access to programs or systems . In the software development phase , Programmers often create backdoors in software so that they can modify defects in programming .
In security testing , Back door open source makes it easier to connect to the host , When obtaining host permission , Backdoor open source acts as a command console .
What we need to pay attention to is whether the back door gives permission , Whether to give permission to operate directories or files , Whether to give other users permission .
Reference material :
official account 0x00 laboratory , If you are interested, please go to twitter
边栏推荐
- [MPC] ② quadprog solves positive definite, semi positive definite and negative definite quadratic programming
- Dotnet console uses microsoft Maui. Getting started with graphics and skia
- Half of 2022 has passed, isn't it sudden?
- 云上“视界” 创新无限 | 2022阿里云直播峰会正式上线
- 使用强大的DBPack处理分布式事务(PHP使用教程)
- 金融壹账通拟7月4日香港上市:2年亏近30亿 市值蒸发超90%
- The exclusive collection of China lunar exploration project is limited to sale!
- 想开个户,在网上开华泰证券的户安全吗?
- Uncover the secrets of new products! Yadi Guanneng 3 multi product matrix to meet the travel needs of global users
- Huawei Equipment configure les services de base du réseau WLAN à grande échelle
猜你喜欢

mysql如何把 一个数据库中的表数据 复制到 另一个数据库中(两个数据库不在同一个数据库链接下)

Suggest collecting | what to do when encountering slow SQL on opengauss?

Oracle和JSON的结合

全局过滤器(处理时间格式)

. Net 5.0+ does not need to rely on third-party native implementation of scheduled tasks

Exposure:A White-Box Photo Post-Processing Framework阅读札记

田溯宁投的天润云上市:市值22亿港元 年利润下降75%

Applymiddleware principle

Website source code whole site download website template source code download

Mall applet source code open source version - two open
随机推荐
《数据安全法》出台一周年,看哪四大变化来袭?
Cvpr22 | CMT: efficient combination of CNN and transformer (open source)
Technology sharing | introduction to linkis parameters
价值1000毕业设计校园信息发布平台网站源码
12款大家都在用的產品管理平臺
Mall applet source code open source version - two open
技术分享 | Linkis参数介绍
金鱼哥RHCA回忆录:DO447使用Ansible与API通信--使用Ansible Tower API启动作业
“目标检测”+“视觉理解”实现对输入图像的理解及翻译(附源代码)
dotnet 控制台 使用 Microsoft.Maui.Graphics 配合 Skia 进行绘图入门
达梦数据冲刺科创板:拟募资24亿 冯裕才曾为华科教授
flutter path_provider: ^2.0.10可以获取临时目录
The list of winners of the digital collection of "century master" was announced
LeetCode. 515. Find the maximum value in each tree row___ BFS + DFS + BFS by layer
获取键代码
I'd like to know where I can open an account in Guangzhou? Is it safe to open an account online now?
bash: ln: command not found
Valgrind usage of memory leak locating tool
Uncover the secrets of new products! Yadi Guanneng 3 multi product matrix to meet the travel needs of global users
Huawei equipment is configured with large network WLAN basic services