- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
IdeaCMS系统总体防御文档(Overall defense documentation for the IdeaCMS system)
IdeaCMS系统总体防御文档(Overall defense documentation for the IdeaCMS system)
D0000D sent to the forum
No2 plate technical articles
D8888D post title
IdeaCMS system overall defense documentation
D8888D new content
Program vulnerability
1, cross site vulnerabilities. Guestbook.asp Resume.asp, the two files to add data, the parameters without any filtering, can cross site attack.
2, Cookie injection vulnerability. Or the above two files take full Request (parameter name) when taking parameters, so that even if there is a general anti injection system, it can also be bypassed by cookie injection to submit dangerous characters.
3, Session spoofing vulnerability. Background admin/chkuser.asp, verify login procedures exist session spoofing vulnerability.
4, the background of injection, cross site vulnerabilities. Daemon injection and cross site problems are not considered, without any treatment (this is a common problem for many programmers, including the old programmer, engaged in the work program for many years to remember: qianlizhidi, ulcer in the colony!)
5, upload file vulnerabilities. The website backstage management upload settings column, type can arbitrarily modify the upload file extension, the user can upload web Trojan of various types (say it is a bit odd to write this vulnerability programmer, they are set up, there will be detailed explanation).
6, backstage admin/Check_UserName.asp. Well, this document really does not know what people want to do written procedures, it is estimated that the debugger is convenient to see their own, and finally released forgot to delete, really should not be (by the leadership will be arrested wages).
7, verification code vulnerability. Background login does not have verification code and can be exploded.
Two, modify the program
1, adding parameter filtering function. According to the above 1, 4 is the filter parameters as a result of lax injection, cross site problems, write 1 characters of the filter function, each parameter w
您可能关注的文档
- 蒙题技巧~准确率大大提高~~~(The accuracy of skills is greatly improved).doc
- 蓝哥智洋,专为产品找寻出路!(LAN Gezhi ocean, specifically for the product and find a way!).doc
- 蒙牛企业文化(Mengniu enterprise culture).doc
- 蓝烨转投宏碁启幕裁员风波 方正员工人心惶惶(Blue Ye curtain at Acer founder staff layoffs storm jittery).doc
- 蓝染语录(Blue quotations).doc
- 蓝牙媒体---江苏蓝海传媒(Bluetooth media --- Jiangsu blue ocean media).doc
- 蓝白领薪酬倒挂 格子领人才走俏(Blue collar salary upside down grid collar talent popular).doc
- 蓝色警戒秘籍(Blue alert cheats).doc
- 蛋白质0010001(Protein 0010001).doc
- 虎杖中游离羟醛蒽醌(Free hydroxyl anthraquinone in Polygonum cuspidatum).doc
- IE 浏览器被篡改完全解决办法(IE browser is tampered with complete solution).doc
- IE7 IE8 IE9 IE10(重启IE生效)搜索加速器(IE7 IE8 Internet explorer 10 (restarts Internet explorer) to search for accelerators).doc
- IBM-T60开机优化(IBM - T60 startup optimization).doc
- IE主页被修改的解决方案(The IE home page is modified to the solution).doc
- iebook常见问题(Iebook FAQ).doc
- IE浏览器的妙用(Internet explorer).doc
- IE默认连接首页被修改(IE defaults to the home page).doc
- IE默认首页被修改的修复方法分类(Internet explorer defaults to the modified repair method classification).doc
- if引导的条件问句与虚拟语气(If guided conditional questions and subjunctive mood).doc
- III AutoCAD重要的编辑命令(III AutoCAD important edit command).doc
最近下载
- 第3课+追求人生理想+第一框+第3目【中职专用】2024-2025学年中职思想政治《哲学与人生》(高教版2023基础模块).pptx VIP
- 2011年考研英语二真题及答案解析.pdf VIP
- 《建筑施工企业碳排放统计核算标准》.pdf
- 面向教学评价的情感分类.pptx VIP
- 人教A版必修第一册高中数学2.1等式性质与不等式性质【教学课件】.pptx VIP
- 《中药材炮制加工方法图解》.pdf VIP
- 小学残疾儿童送教上门教案(40篇).pdf VIP
- 羊群效应——一个班级最可怕的存在!--高一上学期班级凝聚力主题班会课件.pptx VIP
- Apple 环保系统操作说明FMD_Portal_TRM_Training.pdf
- 厄瓜多尔介绍PPT.pptx
文档评论(0)