function is_ShadowHider(){return true}_百度空间
 
文章列表
 
2011-12-31 15:20

Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)


Bug has been reported/NoScript users are safe

First of all, this vulnerability and the related techniques have already been reported to Mozilla on 21st Nov 2011, without having any specific result till the date of this report (issue ID 704354 – works on all the latest versions which support HT

 
2011-10-06 11:17

 
2011-07-14 16:11

From:http://blog.anantshri.info/chrome-extensions-for-security-professionals/

During Recent days we have seen a phenomenal increase in usage of Google Chrome Browser, however Security Professionals are still looking at Firefox for there day to day life usage, the basic reason behind it is large set of

 
2011-06-30 16:04

 

很多人在挂0day时一不小心就被安全公司截获了样本,有些时候,如果你实在bypass不了某款安全软件的检测的话,那么就绕着它走吧。

虽然可能打不中目标,但也比0day被抓了去要好。

比如下面的POC:

 

<html><body>

<div id=sH style='display:none'><img src="symres:sb_nortoncertified.png" onerror="alert('Norton not Installed.')" onload="alert('Norton Installed!')"></img></div>

</body></html>

 
2011-05-22 14:57

老早的东西了,忘记以前谁给我的了,比较简单,单纯的trace而已,当然不如DOMinator好用。

 

 

 

DownlLoad:

https://rapidshare.com/files/3687281109/domtracer.xpi

 

 
2011-04-02 17:23

While strolling through mysql.com I came across this page.

There you can view the possibility of the bitwise function right shift.

A bitwise right shift will shift the bits 1 location to the right and add a 0 to the front.

Here is an example:

mysql> select ascii(b'00000010'); +--------------------+| ascii(b'00000010') |+--------------------+ | 2 |+--

 
2011-02-06 15:40

黑哥果然够猥琐

 

话说开始我还以为BOM是BrowserObjectModel(浏览器对象模型)的缩写,google了一圈之后才发现原来还有这么个东西,以前还真没注意过。

 
2010-12-05 12:15
 
2010-11-07 13:34

 
2010-10-23 14:29
# cd /var/lib/mysql/dbname_
# myisamchk -r -q tablename_
 
     
 
 
个人档案
 
zrxc
女, 
北京 宣武区 
 
   
 
文章分类
 
 
 
0day(33)
 
 
 
 
闲扯(23)
 
 
Xss(16)
 
     
 
最新评论
 
     
 
留言板
 
     
 
最新照片
 
   
 
最近访客
 
 

頌伊雪

jvilyux

Swearos

mango1104

majinxin2003

西安贷款_公司

antilop

micropoor
     
 
背景音乐
 
     
 
订阅我的空间
 
已有人次访问本空间
 
订阅RSS  什么是RSS?

您也想拥有这样的空间?请点此申请。
     

帮助中心  |  空间客服  |  投诉中心  |  空间协议
©2012 Baidu