当前位置:网站首页>(3) Web security | penetration testing | basic knowledge of network security construction, IIS website construction, EXE backdoor generation tool quasar, basic use of
(3) Web security | penetration testing | basic knowledge of network security construction, IIS website construction, EXE backdoor generation tool quasar, basic use of
2022-07-06 19:42:00 【Black zone (rise)】
First, learn to use IIS Build a website
Common build platform scripts are enabled
ASP,PHP,ASPX,JSP,PY,JAVAWEB Such as the environment
domain name IP Directory resolution security issues
① adopt IP Address access can find more information , Sometimes you can find program source code backup files and sensitive information
② Domain name access can only find all files in one folder ,ip Access is the upper level of domain name access .
③ Support when building the website IP Access and domain name access , Domain name access points to a directory ,IP Access points to the root directory .
Common file suffix resolution corresponds to security
Specifies that the suffix corresponds to a file , If you encounter a file that cannot be parsed when accessing the website, the middleware may default or add some settings, resulting in problems in parsing .
Set print processing specific program requests
Safety protection in common safety tests
Internal websites of schools and enterprises , Will restrict external access to internal websites , Limit IP Address , Regulate the permissions of visitors . Authentication and access control , User based restrictions , Limit IP Address access , Authorized access - Only specified IP The address can be accessed . Access denied - Appoint IP Address denied access .
WEB Back door and user and file permissions
exe Back door generation tool Quasar
link :https://pan.baidu.com/s/15XpECQY8SKJwIBxsTy_F3Q
Extraction code :hj12
Usage method :
Folder settings related permissions , Disable guest user permissions , Cause the connected back door to see nothing , It's a protective skill , It is also a common problem in security testing
Brief identification based on middleware
The data packet returned by fetching , Query the platform information
service:nginx/1.8.0
web Summary of common middleware vulnerabilities
link :https://pan.baidu.com/s/1NKejdCI_UY8syRIDfVZwEg
Extraction code :hj12
边栏推荐
- 谷粒商城--分布式高级篇P129~P339(完结)
- Mathematical knowledge -- code implementation of Gaussian elimination (elementary line transformation to solve equations)
- Systematic and detailed explanation of redis operation hash type data (with source code analysis and test results)
- Application of clock wheel in RPC
- [translation] linkerd's adoption rate in Europe and North America exceeded istio, with an increase of 118% in 2021.
- CF960G - Bandit Blues(第一类斯特林数+OGF)
- 力扣101题:对称二叉树
- Blue Bridge Cup microbial proliferation C language
- How can my Haskell program or library find its version number- How can my Haskell program or library find its version number?
- PMP practice once a day | don't get lost in the exam -7.6
猜你喜欢
Zero foundation entry polardb-x: build a highly available system and link the big data screen
【翻译】Linkerd在欧洲和北美的采用率超过了Istio,2021年增长118%。
Mysql Information Schema 學習(一)--通用錶
spark基础-scala
社招面试心得,2022最新Android高频精选面试题分享
MySQL information schema learning (II) -- InnoDB table
The "white paper on the panorama of the digital economy" has been released with great emphasis on the digitalization of insurance
信息系统项目管理师---第八章 项目质量管理
深度剖析原理,看完这一篇就够了
An error occurs when installing MySQL: could not create or access the registry key needed for the
随机推荐
Translation D28 (with AC code POJ 26:the nearest number)
Microservice architecture debate between radical technologists vs Project conservatives
Classic 100 questions of algorithm interview, the latest career planning of Android programmers
zabbix 代理服务器 与 zabbix-snmp 监控
LeetCode_ Gray code_ Medium_ 89. Gray code
In simple terms, interview surprise Edition
深入浅出,面试突击版
Understand yolov1 Part II non maximum suppression (NMS) in prediction stage
In depth analysis, Android interview real problem analysis is popular all over the network
spark基础-scala
Hudi vs Delta vs Iceberg
USB host driver - UVC swap
The "white paper on the panorama of the digital economy" has been released with great emphasis on the digitalization of insurance
Vmware虚拟机无法打开内核设备“\\.\Global\vmx86“的解决方法
[玩转Linux] [Docker] MySQL安装和配置
深度剖析原理,看完这一篇就够了
C # - realize serialization with Marshall class
[pytorch] yolov5 train your own data set
DaGAN论文解读
《数字经济全景白皮书》保险数字化篇 重磅发布