当前位置:网站首页>HW is around the corner. Can't you read the danger message?

HW is around the corner. Can't you read the danger message?

2022-06-22 13:40:00 zkzq

 Zero basic hacker , Search official account : White hat left 

Eight recent mainstream vulnerability attack packets are collected , From multiple threat aware platforms , Small white can see

Information disclosure

This is the most common case , It is also the most difficult to capture , Because it may be easily accessible without attacking data , Especially the error report or probe page , Improper configuration can reveal a lot of things

 Insert picture description here

Although it does little harm , But often a humble information can become a breakthrough point

 Insert picture description here

Command execution class

Such attacks are mostly echo、curl、wget、cd、ping、cat、ls Wait for the command to appear , It's still easy to identify

stay GET Execute the command in the parameter

 picture

stay POST Execute the command in the parameter

 Insert picture description here

Execute the command in the request header

 Insert picture description here

In addition to ordinary system commands , There are specially constructed command execution statements , For example, this kind of utilization thinkphp Vulnerability for command execution

 picture

Code execution class

URL There is encoded data in

 picture

This is what happens after decoding

 picture

Baidu knows this is a loophole cve-2012-1823 Attack code , Online exp

 picture

File read class

stay GET Parameter

 Insert picture description here

sql Injection class

stay GET Parameter sql sentence

 picture

Inject... Into the request header sql sentence

 picture

File upload class

A test Trojan disguised as a compressed file

 picture

A sentence disguised as a picture

 picture

URL Jump class

use @ Bypass domain names or ip White list detection

 picture

xml External entity injection class

stay POST Attack command in request ,xxe The vulnerability can also read arbitrary files

 picture
 Insert picture description here
 Insert picture description here

原网站

版权声明
本文为[zkzq]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/173/202206221236539102.html