当前位置:网站首页>Information security - security professional name | CVE | rce | POC | Vul | 0day
Information security - security professional name | CVE | rce | POC | Vul | 0day
2022-07-06 15:48:00 【Empty one by one】
CVE
CVE Our English full name is “Common Vulnerabilities & Exposures” Universal Loophole Disclosure .CVE It's like a dictionary table , For widely recognized Information security Vulnerabilities or weaknesses that have been exposed give a public name . Use a common name , It can help users evaluate vulnerabilities in their independent vulnerability databases Tools Data sharing in , Although these tools are difficult to integrate . So that makes CVE It has become the of security information sharing “ keyword ”. If in a vulnerability report To specify A loophole in , If there is CVE name , You can do it quickly in any other CVE Find the corresponding patching information in the compatible database , Solve security problem .
RCE
Full name :remote command/code execute
Remote code execution (RCE) It is a kind of software security defect / Loophole .RCE The vulnerability will allow malicious actors to pass LAN、WAN or Internet Execute any code of your choice on the remote computer .RCE Belongs to the broader arbitrary code execution (ACE) Vulnerability categories . However , With the popularization of the Internet ,RCE The impact of the vulnerability has expanded rapidly . therefore ,RCEs Now it could be ACE The most important type of vulnerability .
POC
Full name :Proof of Concept, It means to provide evidence for opinions
Just evidence , Prove that the vulnerability exists , But not by means , Can't be used directly .
POC In the hacker world, it refers to the verification program ;
VUL
VUL,Vulnerability Abbreviation , A loophole .
EXP
EXP,Exploit, in ⽂ intend “ Loopholes benefit ⽤”.
intend ⼀ How to benefit from loopholes ⽤ Or ⼀ Individual performance ⽰ Vulnerability attack code , It can make readers fully understand the mechanism and benefits of vulnerabilities ⽤ Of ⽅ Law .
0DAY Loopholes and 0DAY attack
In the field of computer
zero ⽇ Vulnerability or zero time difference vulnerability ( English :Zero-dayexploit) This usually refers to a security hole that has not been patched ;
⽽ zero ⽇ Attack or zero time difference attack ( English :Zero-dayattack) It means profit ⽤ This loophole goes into ⾏ The attack of .
Provide details of the vulnerability or benefit ⽤ programmatic ⼈ It is usually the discoverer of the vulnerability .
zero ⽇ The benefit of loopholes ⽤ Program pair ⽹ Network security has great ⼤ threat , So zero ⽇ Loopholes are not only ⿊ My favorite , Master how many zeros ⽇ Vulnerabilities also become evaluation ⿊ Guest technology ⽔ Flat ⼀ An important parameter .
zero ⽇ Loopholes and their benefits ⽤ Code is not only for crime ⿊ customer ⽽⾔, Have pole ⾼ Benefits of ⽤ value ,⼀ Some state spies and ⽹ The army , For example, the national security agency and the United States ⽹ War command also ⾮ Always pay attention to this information .
According to Reuters report, the US government is zero ⽇ Loophole ⿊ The most ⼤ buyers .
边栏推荐
- MySQL授予用户指定内容的操作权限
- mysql导入数据库报错 [Err] 1273 – Unknown collation: ‘utf8mb4_0900_ai_ci’
- 【练习-6】(PTA)分而治之
- Learning record: STM32F103 clock system overview working principle
- Gartner:关于零信任网络访问最佳实践的五个建议
- Research Report of cylindrical grinder industry - market status analysis and development prospect forecast
- 【练习-8】(Uva 246)10-20-30==模拟
- 洛谷P1102 A-B数对(二分,map,双指针)
- Cost accounting [13]
- 0-1 knapsack problem (I)
猜你喜欢

用C语言写网页游戏

D - Function(HDU - 6546)女生赛

渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus

数据在内存中的存储&载入内存,让程序运行起来

信息安全-威胁检测引擎-常见规则引擎底座性能比较
![[analysis of teacher Gao's software needs] collection of exercises and answers for level 20 cloud class](/img/3b/dc43564a36f82e73826b08f39c935e.png)
[analysis of teacher Gao's software needs] collection of exercises and answers for level 20 cloud class

STM32 learning record: play with keys to control buzzer and led

csapp shell lab

Matlab example: two expressions of step function

力扣刷题记录
随机推荐
程序员的你,有哪些炫技的代码写法?
0-1 knapsack problem (I)
ucorelab4
Cost accounting [21]
STM32 learning record: play with keys to control buzzer and led
Market trend report, technical innovation and market forecast of lip care products in China and Indonesia
HDU-6025-Coprime Sequence(女生赛)
STM32 learning record: LED light flashes (register version)
Research Report on medical toilet industry - market status analysis and development prospect forecast
7-1 懂的都懂 (20 分)
Research Report of exterior wall insulation system (ewis) industry - market status analysis and development prospect prediction
Cost accounting [13]
学习记录:串口通信和遇到的错误解决方法
D - Function(HDU - 6546)女生赛
STM32学习记录:LED灯闪烁(寄存器版)
Cost accounting [20]
学习记录:TIM—基本定时器
0-1背包问题(一)
China's earthwork tire market trend report, technical dynamic innovation and market forecast
力扣刷题记录