当前位置:网站首页>Xiaodi network security - Notes (3)
Xiaodi network security - Notes (3)
2022-07-19 06:55:00 【ha_ O】
1. Common build platform scripts are enabled
ASP PHP ASPX SP PY JAVAWEB Such as the environment
2. domain name IP Directory resolution security issues
IP Address access can find more information, and often find program source code backup files and sensitive information , Domain name access can only find
All files in one folder . Support when building the website IP Access and domain name access , When visiting a domain name, it usually only points to a
A catalog ,IP When accessing, it points to the root directory
3. Common file suffix resolution corresponds to security

Specifies that the suffix corresponds to a file , When you visit a website and encounter a file that cannot be parsed, the middleware may default or add some settings, resulting in
There was a problem parsing
4. Safety protection in common safety tests
(1). There will be... On the intranet of the school and inside and outside the enterprise , It will restrict external personnel from accessing the internal network , Limit IP Address , Regulate the permissions of visitors

(2). Authentication and access control , User based restrictions
3. Limit IP Address access , Authorized access - Only specified IP The address can be accessed . Access denied - Appoint IP Address denied access
Be careful : stay windows In the authority of , With permission, click reject , Rejection is greater than permission !!!
、
5.WEB Back door and user and file permissions
Folder settings related permissions , Disable guest user permissions , Cause the connected back door to see nothing , It's a protective skill , It is also a common problem in security testing

Set execution permission , No execution permission , The file is not executed , The code will not execute properly , The back door won't work properly
Bypassing ideas : Try putting the back door in another executable Directory , For example, there are scripts stored under the directory
Be careful : The back door cannot be placed in the root directory , If the back door is placed under the root directory, it cannot be executed
边栏推荐
- Application case of CS brand sdnand in color detector industry
- [ restartedMain] o.s.b.d.LoggingFailureAnalysisReporter :
- Release nohup Out disk space occupied
- Tower of Hanoi 2 (function)
- Xiaodi network security notes - Information Collection - architecture, construction, WAF (8)
- freebsd12 安装gnome3图形界面
- notepad++下划线以及大小写字母置换
- Homework
- Wu Enda machine learning chapter 1-2
- Generate audio and waveform in PWM and DAC exercises of stm32
猜你喜欢

Machine learning - classification prediction of logistic regression

文本三剑客之awk命令--截取

高并发day04(ZAB协议,观察者,nc,AVRO,RPC)

Commande awk du troisième épéiste - - interception

Programming learning based on ardunio ide software development

C language structure array pointer and function

Top command

聊聊中台:我对中台的一些理解与思考

Xiaodi network security - note encryption coding algorithm (6)

Wu Enda machine learning chapter 6-7
随机推荐
小迪网络安全-笔记(5)
邮资范围(数组 or +函数)
ARM服务器搭建 我的世界(MC) 1.18.2 版私服教程
ANAME
@resource is popular in idea
linxu下调试微信调一跳(Fedora 27)
Double code time scale network diagram
高并发day01(NIO、ConCurrent包)
Good partner of single chip microcomputer - CS Genesis SD NAND flash
How to make good use of cost compensation contract in government procurement
关于文件上传下载问题
Libevent report undefined reference to `getrandom‘
Learning about STM assembler design
How can the new generation of CS sdnand (also known as patch T card) make the old MCU youthful
Performance comparison between merge into and update in Oracle
Zuul路由的映射规则配置
Total price contract, cost compensation contract, labor contract
Tcp/ip protocol learning
【自动化测试】——robotframework实战(一)搭建环境
University