文章列表
 
2011-12-31 15:20

Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)


Bug has been reported/NoScript users are safe

First of all, this vulnerability and the related techniques have already been reported to Mozilla on 21st Nov 2011, without having any specific result till the date of this report (issue ID 704354 – works on all the latest versions which support HT

 
2011-10-06 11:17

 
2011-07-14 16:11

From:http://blog.anantshri.info/chrome-extensions-for-security-professionals/

During Recent days we have seen a phenomenal increase in usage of Google Chrome Browser, however Security Professionals are still looking at Firefox for there day to day life usage, the basic reason behind it is large set of

 
2011-06-30 16:04

 

很多人在挂0day时一不小心就被安全公司截获了样本,有些时候,如果你实在bypass不了某款安全软件的检测的话,那么就绕着它走吧。

虽然可能打不中目标,但也比0day被抓了去要好。

比如下面的POC:

 

<html><body>

<div id=sH style='display:none'><img src="symres:sb_nortoncertified.png" onerror="alert('Norton not Installed.')" onload="alert('Norton Installed!')"></img></div>

</body></html>

 
2011-05-22 14:57

老早的东西了,忘记以前谁给我的了,比较简单,单纯的trace而已,当然不如DOMinator好用。

 

 

 

DownlLoad:

https://rapidshare.com/files/3687281109/domtracer.xpi

 

 
2011-04-02 17:23

While strolling through mysql.com I came across this page.

There you can view the possibility of the bitwise function right shift.

A bitwise right shift will shift the bits 1 location to the right and add a 0 to the front.

Here is an example:

mysql> select ascii(b'00000010'); +--------------------+| ascii(b'00000010') |+--------------------+ | 2 |+--

 
2011-02-06 15:40

黑哥果然够猥琐

 

话说开始我还以为BOM是BrowserObjectModel(浏览器对象模型)的缩写,google了一圈之后才发现原来还有这么个东西,以前还真没注意过。

 
2010-12-05 12:15
 
2010-11-07 13:34

 
2010-10-23 14:29
# cd /var/lib/mysql/dbname_
# myisamchk -r -q tablename_
 
   
 
 
文章分类
 
   
 
文章存档
 
     
 
最新文章评论
  

加下我哦
 

[表情]
 
 

自己用anehta这个平台挂马,应该很好
 

回复zrxc:360
   
帮助中心 | 空间客服 | 投诉中心 | 空间协议
©2012 Baidu