current location:Home > Technical Articles > Operation and Maintenance > Safety

  • Will Chrome block all types of non-HTTPS mixed content downloads?
    Will Chrome block all types of non-HTTPS mixed content downloads?
    This article introduces the relevant content that the new version of Chrome will block the downloading of all types of non-HTTPS mixed content. It has certain reference value and I hope it can help everyone.
    Safety 2898 2020-11-26 16:03:38
  • 27 recommended information security books
    27 recommended information security books
    This article shares information security-related books with everyone, which has certain reference value. I hope it can help everyone.
    Safety 4628 2020-09-17 17:47:26
  • Introduction to Linux local privilege escalation vulnerability
    Introduction to Linux local privilege escalation vulnerability
    Website security tutorial: This article introduces you to the issues related to Linux local privilege escalation vulnerabilities. It has certain reference value and I hope it can help everyone.
    Safety 2211 2020-09-01 16:49:34
  • What are the methods of port scanning?
    What are the methods of port scanning?
    Web server security: Port scanning methods include: 1. nmap detection port; 2. masscan detection port; 3. socket detection port; 4. telnet detection port; 5. nc detection port.
    Safety 13529 2020-08-10 17:19:55
  • What are the three ways of sql injection?
    What are the three ways of sql injection?
    There are three ways of sql injection: 1. Numeric injection; when the input parameter is an integer, there may be a numeric injection vulnerability. 2. Character injection; when the input parameter is a string, a character injection vulnerability may exist. 3. Other types (for example: search injection, cookie injection, POST injection, etc.).
    Safety 21382 2020-07-20 16:46:31
  • What does pseudo-random number mean?
    What does pseudo-random number mean?
    Pseudo-random numbers are random number sequences calculated from the "[0,1]" uniform distribution using a deterministic algorithm. Pseudo-random numbers are not truly random numbers, but have statistical characteristics similar to random numbers, such as uniformity, independence, etc. Methods for generating pseudo-random numbers include: 1. Direct method, which is generated based on the physical meaning of the distribution function; 2. Reversal method; 3. Acceptance-rejection method.
    Safety 9059 2022-04-07 18:37:34
  • What harm can be caused by file inclusion vulnerabilities?
    What harm can be caused by file inclusion vulnerabilities?
    The possible harms caused by file containing vulnerabilities are: 1. The files of the web server are browsed by the outside world, resulting in information leakage; 2. The script is arbitrarily executed, resulting in the website being tampered with. File inclusion vulnerabilities are a common vulnerability affecting web applications that rely on scripts to run.
    Safety 11155 2020-06-29 09:51:01
  • What are the methods of SQL injection defense?
    What are the methods of SQL injection defense?
    SQL injection defense methods include: 1. PreparedStatement; 2. Use regular expressions to filter incoming parameters; 3. String filtering. Among them, using a precompiled statement set is a simple and effective method because it has built-in ability to handle SQL injection.
    Safety 10361 2020-06-29 09:34:24
  • What does sql injection mean?
    What does sql injection mean?
    SQL injection means that the user can submit a database query code and obtain certain data that needs to be known based on the results returned by the program. SQL injection attacks are one of the common means used by hackers to attack databases. We can achieve effective protection through database security protection technology.
    Safety 8256 2020-06-29 09:20:26
  • What are the CSRF defense methods?
    What are the CSRF defense methods?
    CSRF defense methods include: 1. Verify the HTTP Referer field; 2. Add token to the request address and verify it; 3. Customize attributes in the HTTP header and verify it. CSRF is an attack method that coerces users to perform unintended operations on the web application they are currently logged in to.
    Safety 22329 2020-06-29 09:08:44
  • What does cross-site request forgery mean?
    What does cross-site request forgery mean?
    Cross-site request forgery, often abbreviated as CSRF or XSRF, is an attack method that coerces users to perform unintentional operations on the web application they are currently logged in to. CSRF takes advantage of the website's trust in the user's web browser.
    Safety 5402 2020-06-28 17:05:14
  • What are the xss defense measures?
    What are the xss defense measures?
    XSS defense measures: 1. Do not insert untrusted data in allowed locations; 2. Decode HTML before inserting untrusted data into HTML element content; 3. Decode attributes before inserting untrusted data into common HTML attributes; 4. URL decoding before inserting untrusted data into HTML URL attributes.
    Safety 10814 2020-06-28 16:57:35
  • What are the three major types of cross-site scripting attacks?
    What are the three major types of cross-site scripting attacks?
    There are three major types of cross-site scripting attacks on XSS: 1. Persistent cross-site; 2. Non-persistent cross-site; 3. DOM cross-site. Persistent cross-site is the most direct type of hazard, and the cross-site code is stored on the server; non-persistent cross-site is a reflective cross-site scripting vulnerability, which is the most common type.
    Safety 13138 2020-06-28 16:48:56
  • What is a cross-site scripting attack?
    What is a cross-site scripting attack?
    Cross-site scripting attacks, also known as XSS, refer to exploiting website vulnerabilities to maliciously steal information from users. Cross-site scripting attacks are divided into three categories: 1. Persistent cross-site; 2. Non-persistent cross-site; 3. DOM cross-site. Among them, persistent cross-site is the most direct type of harm.
    Safety 6336 2020-06-28 16:34:59
  • What is a CSRF attack? How to prevent it?
    What is a CSRF attack? How to prevent it?
    CSRF attack refers to cross-site request forgery, which means that the attacker performs illegal operations as a legitimate user through site requests. Methods to prevent CSRF attacks: Perform token verification in HTTP requests. If there is no token in the request or the token content is incorrect, it will be considered a CSRF attack and the request will be rejected.
    Safety 4042 2020-06-19 17:31:00

Tool Recommendations

jQuery enterprise message form contact code

jQuery enterprise message form contact code is a simple and practical enterprise message form and contact us introduction page code.
form button
2024-02-29

HTML5 MP3 music box playback effects

HTML5 MP3 music box playback special effect is an mp3 music player based on HTML5 css3 to create cute music box emoticons and click the switch button.

HTML5 cool particle animation navigation menu special effects

HTML5 cool particle animation navigation menu special effect is a special effect that changes color when the navigation menu is hovered by the mouse.
Menu navigation
2024-02-29

jQuery visual form drag and drop editing code

jQuery visual form drag and drop editing code is a visual form based on jQuery and bootstrap framework.
form button
2024-02-29

Organic fruit and vegetable supplier web template Bootstrap5

An organic fruit and vegetable supplier web template-Bootstrap5
Bootstrap template
2023-02-03

Bootstrap3 multifunctional data information background management responsive web page template-Novus

Bootstrap3 multifunctional data information background management responsive web page template-Novus
backend template
2023-02-02

Real estate resource service platform web page template Bootstrap5

Real estate resource service platform web page template Bootstrap5
Bootstrap template
2023-02-02

Simple resume information web template Bootstrap4

Simple resume information web template Bootstrap4
Bootstrap template
2023-02-02

Cute summer elements vector material (EPS PNG)

This is a cute summer element vector material, including the sun, sun hat, coconut tree, bikini, airplane, watermelon, ice cream, ice cream, cold drink, swimming ring, flip-flops, pineapple, conch, shell, starfish, crab, Lemons, sunscreen, sunglasses, etc., the materials are provided in EPS and PNG formats, including JPG previews.
PNG material
2024-05-09

Four red 2023 graduation badges vector material (AI EPS PNG)

This is a red 2023 graduation badge vector material, four in total, available in AI, EPS and PNG formats, including JPG preview.
PNG material
2024-02-29

Singing bird and cart filled with flowers design spring banner vector material (AI EPS)

This is a spring banner vector material designed with singing birds and a cart full of flowers. It is available in AI and EPS formats, including JPG preview.
banner picture
2024-02-29

Golden graduation cap vector material (EPS PNG)

This is a golden graduation cap vector material, available in EPS and PNG formats, including JPG preview.
PNG material
2024-02-27

Home Decor Cleaning and Repair Service Company Website Template

Home Decoration Cleaning and Maintenance Service Company Website Template is a website template download suitable for promotional websites that provide home decoration, cleaning, maintenance and other service organizations. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-05-09

Fresh color personal resume guide page template

Fresh color matching personal job application resume guide page template is a personal job search resume work display guide page web template download suitable for fresh color matching style. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-29

Designer Creative Job Resume Web Template

Designer Creative Job Resume Web Template is a downloadable web template for personal job resume display suitable for various designer positions. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-28

Modern engineering construction company website template

The modern engineering and construction company website template is a downloadable website template suitable for promotion of the engineering and construction service industry. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-28