はてなブックマークアプリ

サクサク読めて、
アプリ限定の機能も多数!

アプリで開く

はてなブックマーク

  • はてなブックマークって?
  • アプリ・拡張の紹介
  • ユーザー登録
  • ログイン
  • Hatena

はてなブックマーク

トップへ戻る

  • 総合
    • 人気
    • 新着
    • IT
    • 最新ガジェット
    • 自然科学
    • 経済・金融
    • おもしろ
    • マンガ
    • ゲーム
    • はてなブログ(総合)
  • 一般
    • 人気
    • 新着
    • 社会ニュース
    • 地域
    • 国際
    • 天気
    • グルメ
    • 映画・音楽
    • スポーツ
    • はてな匿名ダイアリー
    • はてなブログ(一般)
  • 世の中
    • 人気
    • 新着
    • 新型コロナウイルス
    • 働き方
    • 生き方
    • 地域
    • 医療・ヘルス
    • 教育
    • はてな匿名ダイアリー
    • はてなブログ(世の中)
  • 政治と経済
    • 人気
    • 新着
    • 政治
    • 経済・金融
    • 企業
    • 仕事・就職
    • マーケット
    • 国際
    • はてなブログ(政治と経済)
  • 暮らし
    • 人気
    • 新着
    • カルチャー・ライフスタイル
    • ファッション
    • 運動・エクササイズ
    • 結婚・子育て
    • 住まい
    • グルメ
    • 相続
    • はてなブログ(暮らし)
    • 掃除・整理整頓
    • 雑貨
    • 買ってよかったもの
    • 旅行
    • アウトドア
    • 趣味
  • 学び
    • 人気
    • 新着
    • 人文科学
    • 社会科学
    • 自然科学
    • 語学
    • ビジネス・経営学
    • デザイン
    • 法律
    • 本・書評
    • 将棋・囲碁
    • はてなブログ(学び)
  • テクノロジー
    • 人気
    • 新着
    • IT
    • セキュリティ技術
    • はてなブログ(テクノロジー)
    • AI・機械学習
    • プログラミング
    • エンジニア
  • おもしろ
    • 人気
    • 新着
    • まとめ
    • ネタ
    • おもしろ
    • これはすごい
    • かわいい
    • 雑学
    • 癒やし
    • はてなブログ(おもしろ)
  • エンタメ
    • 人気
    • 新着
    • スポーツ
    • 映画
    • 音楽
    • アイドル
    • 芸能
    • お笑い
    • サッカー
    • 話題の動画
    • はてなブログ(エンタメ)
  • アニメとゲーム
    • 人気
    • 新着
    • マンガ
    • Webマンガ
    • ゲーム
    • 任天堂
    • PlayStation
    • アニメ
    • バーチャルYouTuber
    • オタクカルチャー
    • はてなブログ(アニメとゲーム)
    • はてなブログ(ゲーム)
  • おすすめ

    Google I/O

『ha.ckers.org web application security lab』

  • 人気
  • 新着
  • すべて
  • Accuracy and Time Costs of Web Application Security Scanner Report ha.ckers.org web application security lab

    3 users

    ha.ckers.org

    Larry Suto is back with another report outlining the differences between some of the top web application scanners on the market. Before you get all uptight and start flaming me, I in NO WAY sponsored, encouraged or had anything to do with this test in any way. In fact, I only found out about it a few days ago. Not that I think that’ll stop the flame wars, but just direct your ire appropriately, pl

    • 世の中
    • 2010/02/04 11:29
    • memo
    • security
    • web
    • http://ha.ckers.org/weird/rfi-locations.dat

      3 users

      ha.ckers.org

      # Compiled by RSnake 01/29/2010 Mostly from milw0rm and other advisories. # Change XXpathXX to the path of your backdoor. Note that you may need to # try it against every directory on the target and because of how this was # culled you may need to add a question mark to your own XXpathXX URL: # Eg: XXpathXX => http://www.example.com/hax.txt? /2007/administrator/components/com_joomlaflashfun/admin.

      • 学び
      • 2010/01/30 22:30
      • http://ha.ckers.org/slowloris/slowloris.pl

        3 users

        ha.ckers.org

        #!/usr/bin/perl -w use strict; use IO::Socket::INET; use IO::Socket::SSL; use Getopt::Long; use Config; $SIG{'PIPE'} = 'IGNORE'; #Ignore broken pipe errors print \$shost, 'dns=s' => \$host, 'httpready' => \$httpready, 'num=i' => \$connections, 'cache' => \$cache, 'port=i' => \$port, 'https' => \$ssl, 'tcpto=i' => \$tcpto, 'test' => \$test, 'timeout=i' => \$timeout, 'version' => \$version, ); if ($

        • 暮らし
        • 2009/06/24 16:46
        • security
        • Slowloris HTTP DoS

          46 users

          ha.ckers.org

          Slowloris HTTP DoSCCCCCCCCCCOOCCOOOOO888@8@8888OOOOCCOOO888888888@@@@@@@@@8@8@@@@888OOCooocccc:::: CCCCCCCCCCCCCCCOO888@888888OOOCCCOOOO888888888888@88888@@@@@@@888@8OOCCoococc::: CCCCCCCCCCCCCCOO88@@888888OOOOOOOOOO8888888O88888888O8O8OOO8888@88@@8OOCOOOCoc:: CCCCooooooCCCO88@@8@88@888OOOOOOO88888888888OOOOOOOOOOCCCCCOOOO888@8888OOOCc:::: CooCoCoooCCCO8@88@8888888OOO888888888888888888OOOOCCCooooo

          • 暮らし
          • 2009/06/19 20:40
          • apache
          • security
          • DoS
          • tool
          • http
          • slowloris
          • セキュリティ
          • network
          • Hiding JS in Valid Images ha.ckers.org web application security lab

            4 users

            ha.ckers.org

            Matteo Carli wrote me today to discuss some RFI and JS stuff. We’ve been talking a lot about what uploaded images can do lately, but embedded JS is an interesting one for a few reasons. If you needed a drop for a payload, for instance. Here’s part of his email (edited slightly for formatting): So i created a simple php test like this: <?php include 'myimage.gif'; ?> and the result is like this. Im

            • 学び
            • 2009/04/14 17:00
            • *security
            • PHP
            • *javascript
            • セキュリティ
            • JavaScript
            • Clickjacking Details ha.ckers.org web applicati...

              12 users

              ha.ckers.org

              Today is the day we can finally start talking about clickjacking. This is just meant to be a quick post that you can use as a reference sheet. It is not a thorough advisory of every site/vendor/plugin that is vulnerable - there are far too many to count. Jeremiah and I got the final word today that it was fine to start talking about this due to the click jacking PoC against Flash that was released

              • 世の中
              • 2008/10/08 11:17
              • clickjack
              • security
              • Clickjacking
              • todo
              • browser
              • flash
              • セキュリティ
              • web
              • CSS History Hack

                7 users

                ha.ckers.org

                Originally found here but permanantly hosted on ha.ckers.org with Jeremiah's permission. Ha.ckers.org home || Jeremiah's blog Firefox Only! (1.5 - 2.0) tested on WinXP.

                • 学び
                • 2008/07/01 20:13
                • javascript
                • css
                • security
                • Web Application Scanning Depth Statistics ha.ckers.org web application security lab

                  3 users

                  ha.ckers.org

                  One of the most difficult aspects of web application security scanners is understanding how to evaluate them. Obviously the false positive false negative ratios are important, but it’s often difficult to measure, as it depends on the web application in question. However, Larry Suto came up with a very interesting concept on how to do unbiased measurements of web application scanners. One of the mo

                  • 学び
                  • 2007/10/26 16:38
                  • ha.ckers.org web application security lab - Archive » XSS Book Preview

                    5 users

                    ha.ckers.org

                    Well, we are finally done with the XSS book (XSS Attacks - Cross Site Scripting Attacks Exploits and Defense). It’s off at the presses, and should be on the shelves in a few week’s time. We were authorized to throw up a sample chapter and the table of contents from the book for anyone who would like to read it. You can download a zipped up version of Chapter 5 and the table of contents. Since it w

                    • 世の中
                    • 2007/04/24 17:07
                    • Security
                    • セキュリティ
                    • book
                    • SQL Injection Cheat sheet: Esp: for filter evasion - by RSnake

                      3 users

                      ha.ckers.org

                      SQL Injection Cheat sheet: Esp: for filter evasion - by RSnakeLoading... You must enable iframes to see this image. By RSnake Note from the author: If you don't know how SQL Injection works, this page probably won't help you. This page is for people who already understand the basics of SQL Injection attacks but want a deep understanding of the nuances regarding filter evasion. This page will also

                      • 学び
                      • 2007/02/26 12:07
                      • sql
                      • security
                      • Detecting FireFox Extentions ha.ckers.org web application security lab

                        3 users

                        ha.ckers.org

                        In the same vein as the IE specific res:// URLs that can help you detect Internet Explorer, I’ve taken that detection one step further in Firefox. After discovering the issue with IETab where a user can be maliciously forced into the Internet Explorer rendering engine it got me thinking about ways to even detect that that is possible. How do you know your target is running what, and how to do you

                        • 世の中
                        • 2006/09/05 19:24
                        • security
                        • mozilla
                        • extension
                        • firefox
                        • http://ha.ckers.org/weird/firefox-extentions.html

                          6 users

                          ha.ckers.org

                          Return to the homepage Note: This will not work if you don't have Firefox and JavaScript enabled. This works by asking the browser to render the chrome that has been registered by each browser extention. Once they load up properly it uses an onload event handler to write to a span tag. Using this you can detect what is installed on a extention by extention basis. You are not using Search Status

                          • 学び
                          • 2006/09/05 14:21
                          • firefox
                          • addon
                          • extension
                          • Googleパーソナライズド ホームページにクロスサイトスクリプティングの脆弱性

                            7 users

                            ha.ckers.org

                            Google is vulnerable to cross site scripting. While surfing around the personalization section of Google I ran accross the RSS feed addition tool which is vulnerable to XSS. The employees at Google were aware of XSS as they protected against it as an error condition, however if you input a valid URL (like my RSS feed) it will return with a JavaScript function containing the URL. If you append the

                            • 暮らし
                            • 2006/07/06 09:30
                            • xss
                            • security
                            • google
                            • Ajax
                            • セキュリティ
                            • JavaScript
                            • ha.ckers.org web application security lab

                              19 users

                              ha.ckers.org

                              I’m already back in the airport after a long day over at the world OWASP conference in New York. Among other things that were noteworthy was some extremely tacky marketing schwag from the ISC2 folks that says, “I fill the holes in your SLC”. I feel dirty having even typed that. I wish I were kidding. Ridiculous pictures of Dave Aitel wearing said schwag may or may not end up online in the near fut

                              • 学び
                              • 2006/07/05 19:00
                              • security
                              • *security
                              • Hack
                              • programming
                              • あとで読む
                              • XSS (Cross Site Scripting) Cheat Sheet

                                624 users

                                ha.ckers.org

                                XSS (Cross Site Scripting) Cheat Sheet Esp: for filter evasion By RSnake Note from the author: XSS is Cross Site Scripting. If you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to

                                • 暮らし
                                • 2005/07/26 05:06
                                • xss
                                • security
                                • cheatsheet
                                • セキュリティ
                                • javascript
                                • web
                                • cheat sheet
                                • programming
                                • チートシート
                                • hack

                                このページはまだ
                                ブックマークされていません

                                このページを最初にブックマークしてみませんか?

                                『ha.ckers.org web application security lab』の新着エントリーを見る

                                キーボードショートカット一覧

                                j次のブックマーク

                                k前のブックマーク

                                lあとで読む

                                eコメント一覧を開く

                                oページを開く

                                はてなブックマーク

                                • 総合
                                • 一般
                                • 世の中
                                • 政治と経済
                                • 暮らし
                                • 学び
                                • テクノロジー
                                • エンタメ
                                • アニメとゲーム
                                • おもしろ
                                • アプリ・拡張機能
                                • 開発ブログ
                                • ヘルプ
                                • お問い合わせ
                                • ガイドライン
                                • 利用規約
                                • プライバシーポリシー
                                • 利用者情報の外部送信について
                                • ガイドライン
                                • 利用規約
                                • プライバシーポリシー
                                • 利用者情報の外部送信について

                                公式Twitter

                                • 公式アカウント
                                • ホットエントリー

                                はてなのサービス

                                • はてなブログ
                                • はてなブログPro
                                • 人力検索はてな
                                • はてなブログ タグ
                                • はてなニュース
                                • ソレドコ
                                • App Storeからダウンロード
                                • Google Playで手に入れよう
                                Copyright © 2005-2025 Hatena. All Rights Reserved.
                                設定を変更しましたx