当前位置:网站首页>Vulfocus entry target
Vulfocus entry target
2022-06-30 07:53:00 【sec0nd_】
List of articles
Command Execution Vulnerability
Vulnerability description :
Command execution (Command Execution) Vulnerability means that hackers can directly Web Execute system commands in the application , To get sensitive information or win shell jurisdiction
The possible causes of command execution vulnerability are Web Insufficient security detection of user input commands by the server , Cause malicious code to be executed
Open the vulnerability address , Directly write out the parameters of the command execution 
Visit the address , return flag

Directory traversal vulnerability
Vulnerability description :
Directory browsing vulnerability is a kind of directory traversal vulnerability , The directory browsing vulnerability is due to a configuration defect in the website , There is a directory browsable vulnerability , This will lead to the disclosure of many private files and directories on the website , For example, database backup files 、 Configuration files, etc , Using this information, an attacker can get the website permission more easily , Cause the website to be hacked .
risk : When an attacker accesses a directory of a website , The directory does not have a default home page file or the default home page file is not set correctly , The entire directory structure will be listed , Completely expose the website structure to the attacker ;
The attacker may browse the directory structure , Access to some secret files ( Such as PHPINFO file 、 Server probe file 、 Website administrator background access address 、 Database connection files, etc ).
Open the vulnerability address , Is similar to ftp Pages of the site 
Came to tmp Under the table of contents , There is one flag( I thought it might be a fake flag, The submission was successful , A little insulting to IQ )
边栏推荐
- Cross compile opencv3.4 download cross compile tool chain and compile (3)
- min_ max_ Gray operator understanding
- 深度学习——LSTM
- 2021 private equity fund market report (62 pages)
- At the end of June, you can start to make preparations, otherwise you won't have a share in such a profitable industry
- December 4, 2021 [metagenome] - sorting out the progress of metagenome process construction
- National technology n32g45x series about timer timing cycle calculation
- 深度学习——卷积的滑动窗口实现
- Permutation and combination of probability
- Deep learning -- language model and sequence generation
猜你喜欢

深度学习——使用词嵌入and词嵌入特征

At the age of 25, I started to work in the Tiankeng industry with buckets. After going through a lot of hardships to become a programmer, my spring finally came

Simple application of generating function -- integer splitting 2

Multi whale capital: report on China's education intelligent hardware industry in 2022

Final review -php learning notes 5-php array

Deloitte: investment management industry outlook in 2022

想转行,却又不知道干什么?此文写给正在迷茫的你
![2021-10-27 [WGS] pacbio third generation methylation modification process](/img/a3/39d05e0daf4ea7eba95337b7a936b1.jpg)
2021-10-27 [WGS] pacbio third generation methylation modification process

Deep learning -- feature point detection and target detection
![July 30, 2021 [wgs/gwas] - whole genome analysis process (Part I)](/img/37/ae0f7ca03ef564b029c9c709779231.jpg)
July 30, 2021 [wgs/gwas] - whole genome analysis process (Part I)
随机推荐
【花雕体验】12 搭建ESP32C3之Arduino开发环境
Tencent and Fudan University "2021-2022 yuan universe report" with 102 yuan universe collections
C language operators
342 maps covering exquisite knowledge, one of which is classic and pasted on the wall
为什么大学毕业了还不知道干什么?
Acreems energy efficiency management platform escorts the power safety of high-rise residential areas
November 22, 2021 [reading notes] - bioinformatics and functional genomics (Chapter 5, section 4, hidden Markov model)
Shell command, how much do you know?
期末复习-PHP学习笔记4-PHP自定义函数
深度学习——卷积的滑动窗口实现
2021-10-29 [microbiology] qiime2 sample pretreatment form automation script
Multi whale capital: report on China's education intelligent hardware industry in 2022
Final review -php learning notes 7-php and web page interaction
December 4, 2021 [metagenome] - sorting out the progress of metagenome process construction
Deep learning - networks in networks and 1x1 convolution
全栈最全性能测试理论-总结
深度学习——BRNN和DRNN
ACM. HJ48 从单向链表中删除指定值的节点 ●●
December 13, 2021 [reading notes] | understanding of chain specific database building
深度学习——序列模型and数学符号