七月份文章收藏

HTML縮小的潛在XSS漏洞html

https://hackerone.com/reports/24684node

 

node.js 目錄遍歷nginx

https://hackerone.com/reports/358645git

--path-as-is    Do not squash .. sequences in URL pathgithub

curl 中 --path-as-is 選項的意思是在不要壓縮URL路徑中的 .. 符號npm

serve包介紹:https://www.npmjs.com/package/servecookie

 

內容注入curl

https://hackerone.com/reports/144104xss

用戶或攻擊者可以將其文本注入錯誤頁面,而且能夠捕獲用戶訪問惡意站點。url

 

 

圖片xss

https://hackerone.com/reports/72526

"><img src="x" onerror=alert(cookie)>.png

 

 

header頭攻擊

https://hackerone.com/reports/137181

 

 

NGINX alias錯誤配置可任意讀取

https://hackerone.com/reports/317201

https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md

https://www.leavesongs.com/PENETRATION/nginx-insecure-configuration.html

相關文章
相關標籤/搜索