当前位置:网站首页>Information security - security professional name | CVE | rce | POC | Vul | 0day
Information security - security professional name | CVE | rce | POC | Vul | 0day
2022-07-06 15:48:00 【Empty one by one】
CVE
CVE Our English full name is “Common Vulnerabilities & Exposures” Universal Loophole Disclosure .CVE It's like a dictionary table , For widely recognized Information security Vulnerabilities or weaknesses that have been exposed give a public name . Use a common name , It can help users evaluate vulnerabilities in their independent vulnerability databases Tools Data sharing in , Although these tools are difficult to integrate . So that makes CVE It has become the of security information sharing “ keyword ”. If in a vulnerability report To specify A loophole in , If there is CVE name , You can do it quickly in any other CVE Find the corresponding patching information in the compatible database , Solve security problem .
RCE
Full name :remote command/code execute
Remote code execution (RCE) It is a kind of software security defect / Loophole .RCE The vulnerability will allow malicious actors to pass LAN、WAN or Internet Execute any code of your choice on the remote computer .RCE Belongs to the broader arbitrary code execution (ACE) Vulnerability categories . However , With the popularization of the Internet ,RCE The impact of the vulnerability has expanded rapidly . therefore ,RCEs Now it could be ACE The most important type of vulnerability .
POC
Full name :Proof of Concept, It means to provide evidence for opinions
Just evidence , Prove that the vulnerability exists , But not by means , Can't be used directly .
POC In the hacker world, it refers to the verification program ;
VUL
VUL,Vulnerability Abbreviation , A loophole .
EXP
EXP,Exploit, in ⽂ intend “ Loopholes benefit ⽤”.
intend ⼀ How to benefit from loopholes ⽤ Or ⼀ Individual performance ⽰ Vulnerability attack code , It can make readers fully understand the mechanism and benefits of vulnerabilities ⽤ Of ⽅ Law .
0DAY Loopholes and 0DAY attack
In the field of computer
zero ⽇ Vulnerability or zero time difference vulnerability ( English :Zero-dayexploit) This usually refers to a security hole that has not been patched ;
⽽ zero ⽇ Attack or zero time difference attack ( English :Zero-dayattack) It means profit ⽤ This loophole goes into ⾏ The attack of .
Provide details of the vulnerability or benefit ⽤ programmatic ⼈ It is usually the discoverer of the vulnerability .
zero ⽇ The benefit of loopholes ⽤ Program pair ⽹ Network security has great ⼤ threat , So zero ⽇ Loopholes are not only ⿊ My favorite , Master how many zeros ⽇ Vulnerabilities also become evaluation ⿊ Guest technology ⽔ Flat ⼀ An important parameter .
zero ⽇ Loopholes and their benefits ⽤ Code is not only for crime ⿊ customer ⽽⾔, Have pole ⾼ Benefits of ⽤ value ,⼀ Some state spies and ⽹ The army , For example, the national security agency and the United States ⽹ War command also ⾮ Always pay attention to this information .
According to Reuters report, the US government is zero ⽇ Loophole ⿊ The most ⼤ buyers .
边栏推荐
- 洛谷P1102 A-B数对(二分,map,双指针)
- Alice and Bob (2021牛客暑期多校训练营1)
- 渗透测试 ( 5 ) --- 扫描之王 nmap、渗透测试工具实战技巧合集
- 渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus
- China's salt water membrane market trend report, technological innovation and market forecast
- 学习记录:使用STM32F1看门狗
- Learning record: STM32F103 clock system overview working principle
- 程序员的你,有哪些炫技的代码写法?
- Research Report of cylindrical grinder industry - market status analysis and development prospect forecast
- 学习记录:串口通信和遇到的错误解决方法
猜你喜欢
随机推荐
动态规划前路径问题
Truck History
STM32 learning record: play with keys to control buzzer and led
B - 代码派对(女生赛)
CS zero foundation introductory learning record
Opencv learning log 14 - count the number of coins in the picture (regardless of overlap)
差分(一维,二维,三维) 蓝桥杯三体攻击
信息安全-安全编排自动化与响应 (SOAR) 技术解析
学习记录:STM32F103 时钟系统概述工作原理
【高老师UML软件建模基础】20级云班课习题答案合集
Accounting regulations and professional ethics [1]
Opencv learning log 13 corrosion, expansion, opening and closing operations
Accounting regulations and professional ethics [4]
C语言是低级和高级的分水岭
Nodejs+vue网上鲜花店销售信息系统express+mysql
ucore lab7
Accounting regulations and professional ethics [2]
D - Function(HDU - 6546)女生赛
入门C语言基础问答
渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus