当前位置:网站首页>(3) Web security | penetration testing | basic knowledge of network security construction, IIS website construction, EXE backdoor generation tool quasar, basic use of
(3) Web security | penetration testing | basic knowledge of network security construction, IIS website construction, EXE backdoor generation tool quasar, basic use of
2022-07-06 19:42:00 【Black zone (rise)】
First, learn to use IIS Build a website
Common build platform scripts are enabled
ASP,PHP,ASPX,JSP,PY,JAVAWEB Such as the environment
domain name IP Directory resolution security issues
① adopt IP Address access can find more information , Sometimes you can find program source code backup files and sensitive information
② Domain name access can only find all files in one folder ,ip Access is the upper level of domain name access .
③ Support when building the website IP Access and domain name access , Domain name access points to a directory ,IP Access points to the root directory .
Common file suffix resolution corresponds to security
Specifies that the suffix corresponds to a file , If you encounter a file that cannot be parsed when accessing the website, the middleware may default or add some settings, resulting in problems in parsing .
Set print processing specific program requests
Safety protection in common safety tests
Internal websites of schools and enterprises , Will restrict external access to internal websites , Limit IP Address , Regulate the permissions of visitors . Authentication and access control , User based restrictions , Limit IP Address access , Authorized access - Only specified IP The address can be accessed . Access denied - Appoint IP Address denied access .
WEB Back door and user and file permissions
exe Back door generation tool Quasar
link :https://pan.baidu.com/s/15XpECQY8SKJwIBxsTy_F3Q
Extraction code :hj12
Usage method :
Folder settings related permissions , Disable guest user permissions , Cause the connected back door to see nothing , It's a protective skill , It is also a common problem in security testing
Brief identification based on middleware
The data packet returned by fetching , Query the platform information
service:nginx/1.8.0
web Summary of common middleware vulnerabilities
link :https://pan.baidu.com/s/1NKejdCI_UY8syRIDfVZwEg
Extraction code :hj12
边栏推荐
- A5000 vGPU显示模式切换
- MySQL must know and learn
- DaGAN论文解读
- 部门树递归实现
- LeetCode_格雷编码_中等_89.格雷编码
- zabbix 代理服务器 与 zabbix-snmp 监控
- How to access localhost:8000 by mobile phone
- [translation] Digital insider. Selection process of kubecon + cloudnativecon in Europe in 2022
- Use of map (the data of the list is assigned to the form, and the JSON comma separated display assignment)
- Lick the dog until the last one has nothing (simple DP)
猜你喜欢
Blue Bridge Cup microbial proliferation C language
Application of clock wheel in RPC
[infrastructure] deployment and configuration of Flink / Flink CDC (MySQL / es)
Looting iii[post sequence traversal and backtracking + dynamic planning]
Detailed idea and code implementation of infix expression to suffix expression
如何自定义动漫头像?这6个免费精品在线卡通头像生成器,看一眼就怦然心动!
凤凰架构3——事务处理
Fast power template for inverse element, the role of inverse element and example [the 20th summer competition of Shanghai University Programming League] permutation counting
Druid database connection pool details
谷粒商城--分布式高级篇P129~P339(完结)
随机推荐
How can my Haskell program or library find its version number- How can my Haskell program or library find its version number?
Alibaba数据源Druid可视化监控配置
map的使用(列表的数据赋值到表单,json逗号隔开显示赋值)
利用 clip-path 绘制不规则的图形
CF960G - Bandit Blues(第一类斯特林数+OGF)
In depth analysis, Android interview real problem analysis is popular all over the network
【pytorch】yolov5 训练自己的数据集
算法面试经典100题,Android程序员最新职业规划
The "white paper on the panorama of the digital economy" has been released with great emphasis on the digitalization of insurance
C # - realize serialization with Marshall class
黑馬--Redis篇
腾讯T3手把手教你,真的太香了
学习探索-使用伪元素清除浮动元素造成的高度坍塌
LeetCode_双指针_中等_61. 旋转链表
Leetcode 30. Concatenate substrings of all words
谷粒商城--分布式高级篇P129~P339(完结)
350. 两个数组的交集 II
MATLAB中deg2rad和rad2deg函数的使用
121. The best time to buy and sell stocks
通俗的讲解,带你入门协程