当前位置:网站首页>Zhongke panyun-d module analysis and scoring standard
Zhongke panyun-d module analysis and scoring standard
2022-07-04 04:55:00 【Beluga】
Windows Target reinforcement (5 Two points )( common 100 branch )
need D Module environment private
1. Back door user
(1) The process or idea of vulnerability discovery (5 branch )
(2) Delete backdoor users , If the operation is correct on the command line (10 branch )
or
or
or
2. Administrator user password reinforcement
(1) The process or idea of vulnerability discovery (5 branch )
(2) Set complex passwords for administrator users , If the operation is correct on the command line (10 branch
3.HTTP.SYS Loophole (MS15_034)
(1) The process or idea of vulnerability discovery (5 branch )
(2) Ban IIS Kernel cache , Avoid using ms15_034 Vulnerability in progress DOS attack ,
Get rid of 【 Enable kernel caching 】 Hook in front of check box (10 branch )
(3) Vulnerability verification process (10 branch )
4. Blue hole of eternity (MS17_010)
(1) The process or idea of vulnerability discovery (5 branch )
(2) To guard against ms17_010 And so on , stop it Server service .(10 branch )
or
or
(3) Vulnerability verification process (10 branch )
5. Remote Desktop Protocol RDP Remote code execution vulnerability (MS12_020)
(1) The process or idea of vulnerability discovery (5 branch )
(2) Avoid using ms12_020 Vulnerability in progress DOS Attack and appear blue screen phenomenon , Turn off Remote Desktop Services .(5 branch )
or
(3) Vulnerability verification process (10 branch )
Linux Target reinforcement (7 Two points )( common 100 branch )
1. Back door user
(1) The process or idea of vulnerability discovery (3 branch )
(2) Abnormal user found , Use command “userdel” Delete the user , You can also change the passwords of these two users (2 branch )
or
2. Administrator user password reinforcement
(1) The process or idea of vulnerability discovery (3 branch )
(2) modify root User's password (3 branch )
3. prohibit root User pass SSH Sign in
(1) The process or idea of vulnerability discovery (3 branch )
(2) prohibit root User pass SSH Service login server (4 branch )
4.SAMBA Service vulnerabilities ( Remote code execution )
(1) The process or idea of vulnerability discovery (8 branch )
(2) modify /etc/samba/smb.conf Profile reinforcement .(17 branch )
5. Database user weak password reinforcement
(1) The process or idea of vulnerability discovery (5 branch )
(2) Modify database users root Password , Prevent the other party from logging into the database by brute force cracking with too weak password ,(13 branch )
6. Prohibit database users from logging in from any place
(1) The process or idea of vulnerability discovery (7 branch )
(2) Prohibit database users root Log in from anywhere (10 branch )
or
etc. ,( As long as it is forbidden root It is correct for users to log in from any place )
7. Backdoor deletion
(1) The process or idea of vulnerability discovery (8 branch )
(2) Backdoor deletion (14 branch )
边栏推荐
- Annex 4: scoring criteria of the attacker docx
- Balloon punching and Boolean operation problems (extremely difficult)
- NTFS 安全权限
- Beipiao programmer, 20K monthly salary, 15W a year, normal?
- 【MATLAB】MATLAB 仿真 — 低通高斯白噪声
- Intersection traffic priority, illustration of intersection traffic rules
- ADB tools
- 【MATLAB】MATLAB 仿真数字基带传输系统 — 双极性基带信号(第 I 类部分响应波形)的眼图
- 附件三:防守方评分标准.docx
- appliedzkp zkevm(13)中的Public Inputs
猜你喜欢
Utiliser des unités de mesure dans votre code pour une vie meilleure
Maui introductory tutorial series (5.xaml and page introduction)
如何构建属于自己的知识引擎?社群开放申请
Use units of measure in your code for a better life
GUI 应用:socket 网络聊天室
附件五:攻击过程简报.docx
STM32F1与STM32CubeIDE编程实例-74HC595驱动4位7段数码管
Yolov6 practice: teach you to use yolov6 for object detection (with data set)
RPC - gRPC简单的demo - 学习/实践
Definition of DCDC power supply current
随机推荐
【MATLAB】MATLAB 仿真数字基带传输系统 — 双极性基带信号(第 I 类部分响应波形)的眼图
20000 words will take you to master multithreading
【无标题】
Change the background color of Kivy tutorial (tutorial includes source code)
QT qtableview data column width adaptation
[wechat applet] good looking carousel map component
Correct the classpath of your application so that it contains a single, compatible version of com.go
Kivy教程之 07 组件和属性绑定实现按钮button点击修改label组件(教程含源码)
Share some of my telecommuting experience
Technology Management - learning / practice
qt下开发mqtt的访问程序
Balloon punching and Boolean operation problems (extremely difficult)
LeetCode136+128+152+148
附件三:防守方评分标准.docx
Kivy tutorial 07 component and attribute binding implementation button button click to modify the label component (tutorial includes source code)
附件二:攻防演练保密协议.docx
Kivy教程之 更改背景颜色(教程含源码)
【MATLAB】MATLAB 仿真数字基带传输系统 — 双极性基带信号(余弦滚降成形脉冲)的眼图
Dp83848+ network cable hot plug
YoloV6实战:手把手教你使用Yolov6进行物体检测(附数据集)