Neglected Web Security thought

蓝知

蓝知更鸟 是种蓝背红胸的美丽小鸟。

首页 归档 关于 订阅

Neglected Web Security thought

Dec 2, 2017
  • take over your subdomain
    • DNS hijacking using cloud providers
  • DNS SPF Record Spoofing

    • paper
    • hackerone case
  • unicode vulnerability

    • Phishing Attack
  • Autobinding vulns

    • Spring MVC
    • case
  • cross-domain login detection code

    • X-Frame-Options (XFO) Detection from Javascript
    • old vector
  • QRLJacking

    • QRLJacking
  • abuse normal function

    • Steal Money by normal function
    • PRMitM attack
  • cross protocol script

    • Trying to hack Redis via HTTP requests
    • case ssrf + urllib injection+cross protocol script+python unserialize
  • CORS misconfiguration

  • 日志记录

  • Race Condition

    • 刷钱漏洞
  • IE Text/Plain

  • IE MIME Sniffing

SOME INTERESTING THINGS IN ELECTRON(Essays)VelocityServlet Expression-language Injection
最近文章
  • SOME INTERESTING THINGS IN ELECTRON(Essays)
  • Neglected Web Security thought
  • VelocityServlet Expression-language Injection
  • 一个xss的利用(location.pathname situation)
  • 百度v3登陆系统架构问题导致点我链接拿到你的bduss(巧用referer)
  • SOME攻击可导致点我链接蠕虫+关注
友情链接
Copyright © 2018 蓝知. Powered by Hexo. Theme by Cho.