当前位置:网站首页>Web foundation of network security note 02
Web foundation of network security note 02
2022-07-01 11:05:00 【I'm not zzy1231a】
About web Source code
web Source code is an important information breakthrough of code audit vulnerability , The main knowledge points include contents 、 Script 、 Application etc. .
web Directory structure :
It is divided into background directories 、 The template directory 、 Database directory 、 Database configuration file .
The script type :
It mainly includes ASP、PHP、ASPX、JSP、JAVAWEB、Python.
Application classification :
Portal corresponds to comprehensive vulnerabilities , E-commerce corresponds to business logic vulnerabilities , Forum correspondence XSS Logical loopholes 、 Blog vulnerability is less 、 The third party mainly depends on the function .
Supplementary contents include framework and non framework 、CMS distinguish 、 Open source or internal vulnerability audit and testing .
web Key files in the source code
Backstage path , Database configuration file , Backup file
backstage : It usually refers to those program methods that bypass security control and obtain access to programs or systems . In the software development phase , Programmers often create backdoors in software so that they can modify defects in programming .
In security testing , Back door open source makes it easier to connect to the host , When obtaining host permission , Backdoor open source acts as a command console .
What we need to pay attention to is whether the back door gives permission , Whether to give permission to operate directories or files , Whether to give other users permission .
Reference material :
official account 0x00 laboratory , If you are interested, please go to twitter
边栏推荐
- Harbor webhook从原理到构建
- Huawei equipment is configured with large network WLAN basic services
- Database experiment report (I)
- [.net6] use ml.net+onnx pre training model to liven the classic "Huaqiang buys melons" in station B
- The project bar on the left side of CodeBlocks disappears, workspace automatically saves the project, default workspace, open the last workspace, workspace (Graphic tutorial, solved)
- NC | intestinal cells and lactic acid bacteria work together to prevent Candida infection
- "Target detection" + "visual understanding" to realize the understanding and translation of the input image (with source code)
- 力扣(LeetCode)181. 超过经理收入的员工(2022.06.29)
- Sqlachemy common operations
- sdp 协议中的packetization-mode方式和三种流传输模式
猜你喜欢

y48.第三章 Kubernetes从入门到精通 -- Pod的状态和探针(二一)

CVPR 2022 | Virtual Correspondence: Humans as a Cue for Extreme-View Geometry

YoDA统一数据应用——融合计算在蚂蚁风险场景下的探索与实践

关于Keil编译程序出现“File has been changed outside the editor,reload?”的解决方法

Oracle和JSON的结合

技术分享 | Linkis参数介绍

“目标检测”+“视觉理解”实现对输入图像的理解及翻译(附源代码)

Value 1000 graduation project campus information publishing platform website source code

12款大家都在用的产品管理平台

The project bar on the left side of CodeBlocks disappears, workspace automatically saves the project, default workspace, open the last workspace, workspace (Graphic tutorial, solved)
随机推荐
力扣(LeetCode)181. 超过经理收入的员工(2022.06.29)
CPI教程-异步接口创建及使用
[MPC] ② quadprog solves positive definite, semi positive definite and negative definite quadratic programming
The exclusive collection of China lunar exploration project is limited to sale!
Mobile hard drive reads but does not display drive letter
JS foundation -- data type
. Net 5.0+ does not need to rely on third-party native implementation of scheduled tasks
The list of winners of the digital collection of "century master" was announced
Exposure:A White-Box Photo Post-Processing Framework阅读札记
Huawei equipment is configured with large network WLAN basic services
Face detection and recognition system based on mtcnn+facenet
爬虫(2) - Requests(1) | Requests模块的深度解析
flutter Uint8List格式的图片和File格式图片的互相转换
Ask everyone in the group about the fact that the logminer scheme of flick Oracle CDC has been used to run stably in production
Uncover the secrets of new products! Yadi Guanneng 3 multi product matrix to meet the travel needs of global users
NC | 肠道细胞和乳酸菌共同作用来防止念珠菌感染
想开个户,在网上开华泰证券的户安全吗?
英特爾實驗室公布集成光子學研究新進展
12 product management platforms that everyone is using
Website source code whole site download website template source code download