当前位置:网站首页>Information security - security professional name | CVE | rce | POC | Vul | 0day
Information security - security professional name | CVE | rce | POC | Vul | 0day
2022-07-06 15:48:00 【Empty one by one】
CVE
CVE Our English full name is “Common Vulnerabilities & Exposures” Universal Loophole Disclosure .CVE It's like a dictionary table , For widely recognized Information security Vulnerabilities or weaknesses that have been exposed give a public name . Use a common name , It can help users evaluate vulnerabilities in their independent vulnerability databases Tools Data sharing in , Although these tools are difficult to integrate . So that makes CVE It has become the of security information sharing “ keyword ”. If in a vulnerability report To specify A loophole in , If there is CVE name , You can do it quickly in any other CVE Find the corresponding patching information in the compatible database , Solve security problem .
RCE
Full name :remote command/code execute
Remote code execution (RCE) It is a kind of software security defect / Loophole .RCE The vulnerability will allow malicious actors to pass LAN、WAN or Internet Execute any code of your choice on the remote computer .RCE Belongs to the broader arbitrary code execution (ACE) Vulnerability categories . However , With the popularization of the Internet ,RCE The impact of the vulnerability has expanded rapidly . therefore ,RCEs Now it could be ACE The most important type of vulnerability .
POC
Full name :Proof of Concept, It means to provide evidence for opinions
Just evidence , Prove that the vulnerability exists , But not by means , Can't be used directly .
POC In the hacker world, it refers to the verification program ;
VUL
VUL,Vulnerability Abbreviation , A loophole .
EXP
EXP,Exploit, in ⽂ intend “ Loopholes benefit ⽤”.
intend ⼀ How to benefit from loopholes ⽤ Or ⼀ Individual performance ⽰ Vulnerability attack code , It can make readers fully understand the mechanism and benefits of vulnerabilities ⽤ Of ⽅ Law .
0DAY Loopholes and 0DAY attack
In the field of computer
zero ⽇ Vulnerability or zero time difference vulnerability ( English :Zero-dayexploit) This usually refers to a security hole that has not been patched ;
⽽ zero ⽇ Attack or zero time difference attack ( English :Zero-dayattack) It means profit ⽤ This loophole goes into ⾏ The attack of .
Provide details of the vulnerability or benefit ⽤ programmatic ⼈ It is usually the discoverer of the vulnerability .
zero ⽇ The benefit of loopholes ⽤ Program pair ⽹ Network security has great ⼤ threat , So zero ⽇ Loopholes are not only ⿊ My favorite , Master how many zeros ⽇ Vulnerabilities also become evaluation ⿊ Guest technology ⽔ Flat ⼀ An important parameter .
zero ⽇ Loopholes and their benefits ⽤ Code is not only for crime ⿊ customer ⽽⾔, Have pole ⾼ Benefits of ⽤ value ,⼀ Some state spies and ⽹ The army , For example, the national security agency and the United States ⽹ War command also ⾮ Always pay attention to this information .
According to Reuters report, the US government is zero ⽇ Loophole ⿊ The most ⼤ buyers .
边栏推荐
- JS调用摄像头
- Research Report of pharmaceutical solvent industry - market status analysis and development prospect prediction
- SSM框架常用配置文件
- Cost accounting [13]
- Research Report on printed circuit board (PCB) connector industry - market status analysis and development prospect forecast
- CS zero foundation introductory learning record
- ucore lab5
- 信息安全-威胁检测-NAT日志接入威胁检测平台详细设计
- ucorelab4
- 动态规划前路径问题
猜你喜欢
随机推荐
区间和------离散化
C语言必背代码大全
China medical check valve market trend report, technical dynamic innovation and market forecast
Cost accounting [20]
Interesting drink
Learning record: Tim - Basic timer
学习记录:如何进行PWM 输出
Hospital privacy screen Industry Research Report - market status analysis and development prospect forecast
Learning record: use STM32 external input interrupt
B - 代码派对(女生赛)
【练习-6】(Uva 725)Division(除法)== 暴力
Cost accounting [18]
Shell脚本编程
Matlab comprehensive exercise: application in signal and system
China potato slicer market trend report, technical dynamic innovation and market forecast
Market trend report, technical innovation and market forecast of Chinese hospital respiratory humidification equipment
Path problem before dynamic planning
【练习-3】(Uva 442)Matrix Chain Multiplication(矩阵链乘)
Cost accounting [22]
ucore lab5








