current location:Home > Technical Articles > Operation and Maintenance > Safety

  • What does sql injection mean?
    What does sql injection mean?
    SQL injection means that the user can submit a database query code and obtain certain data that needs to be known based on the results returned by the program. SQL injection attacks are one of the common means used by hackers to attack databases. We can achieve effective protection through database security protection technology.
    Safety 8408 2020-06-29 09:20:26
  • What are the CSRF defense methods?
    What are the CSRF defense methods?
    CSRF defense methods include: 1. Verify the HTTP Referer field; 2. Add token to the request address and verify it; 3. Customize attributes in the HTTP header and verify it. CSRF is an attack method that coerces users to perform unintended operations on the web application they are currently logged in to.
    Safety 22620 2020-06-29 09:08:44
  • What does cross-site request forgery mean?
    What does cross-site request forgery mean?
    Cross-site request forgery, often abbreviated as CSRF or XSRF, is an attack method that coerces users to perform unintentional operations on the web application they are currently logged in to. CSRF takes advantage of the website's trust in the user's web browser.
    Safety 5553 2020-06-28 17:05:14
  • What are the xss defense measures?
    What are the xss defense measures?
    XSS defense measures: 1. Do not insert untrusted data in allowed locations; 2. Decode HTML before inserting untrusted data into HTML element content; 3. Decode attributes before inserting untrusted data into common HTML attributes; 4. URL decoding before inserting untrusted data into HTML URL attributes.
    Safety 10958 2020-06-28 16:57:35
  • What are the three major types of cross-site scripting attacks?
    What are the three major types of cross-site scripting attacks?
    There are three major types of cross-site scripting attacks on XSS: 1. Persistent cross-site; 2. Non-persistent cross-site; 3. DOM cross-site. Persistent cross-site is the most direct type of hazard, and the cross-site code is stored on the server; non-persistent cross-site is a reflective cross-site scripting vulnerability, which is the most common type.
    Safety 13296 2020-06-28 16:48:56
  • What is a cross-site scripting attack?
    What is a cross-site scripting attack?
    Cross-site scripting attacks, also known as XSS, refer to exploiting website vulnerabilities to maliciously steal information from users. Cross-site scripting attacks are divided into three categories: 1. Persistent cross-site; 2. Non-persistent cross-site; 3. DOM cross-site. Among them, persistent cross-site is the most direct type of harm.
    Safety 6518 2020-06-28 16:34:59
  • What is a CSRF attack? How to prevent it?
    What is a CSRF attack? How to prevent it?
    CSRF attack refers to cross-site request forgery, which means that the attacker performs illegal operations as a legitimate user through site requests. Methods to prevent CSRF attacks: Perform token verification in HTTP requests. If there is no token in the request or the token content is incorrect, it will be considered a CSRF attack and the request will be rejected.
    Safety 4189 2020-06-19 17:31:00
  • XSS classification and defense measures
    XSS classification and defense measures
    Web server security: XSS is divided into three categories, namely: 1. Reflected XSS; 2. Storage XSS; 3. DOM XSS. XSS defense measures: 1. Filter and escape input and output; 2. Avoid using methods such as eval and new Function to execute strings.
    Safety 3433 2020-06-17 17:27:09
  • Quickly learn about HTTP and HTTPS protocols!
    Quickly learn about HTTP and HTTPS protocols!
    This article will give you a quick understanding of the HTTP and HTTPS protocols. It has certain reference value. Friends in need can refer to it. I hope it will be helpful to everyone.
    Safety 3106 2020-06-17 11:07:54
  • How does HTTPS ensure security? (detailed explanation)
    How does HTTPS ensure security? (detailed explanation)
    This article will take you through the problems of HTTP and introduce how HTTPS ensures security. It has certain reference value. Friends in need can refer to it. I hope it will be helpful to everyone.
    Safety 3031 2020-06-17 11:09:39
  • What is the main difference between HTTP and HTTPS
    What is the main difference between HTTP and HTTPS
    Web server security: The main differences between HTTP and HTTPS are: 1. The https protocol requires applying for a certificate; 2. http is a hypertext transfer protocol, and information is transmitted in plain text, while https is a secure SSL encrypted transmission protocol; 3. http The connection is simple and stateless.
    Safety 4940 2020-06-16 16:52:32
  • What is the principle of XSS attack
    What is the principle of XSS attack
    The principle of XSS attack is: the attacker enters malicious HTML code into a website with XSS vulnerabilities. When other users browse the website, the HTML code will be automatically executed to achieve the purpose of the attack, such as stealing the user's cookies. , destroy the page structure, redirect to other websites, etc.
    Safety 4878 2020-06-13 17:55:27
  • How to analyze database logs
    How to analyze database logs
    Common database attacks include weak passwords, SQL injection, privilege escalation, stolen backups, etc. By analyzing database logs, attack behaviors can be discovered, attack scenarios can be further restored, and attack sources can be traced.
    Safety 3501 2020-06-11 17:20:01
  • Sharing of several common webshell detection tools
    Sharing of several common webshell detection tools
    This article comes from the web server security column. It shares several common webshell detection tools with you. I hope it can help you. Webshell detection tools include: 1. Web Shell Detector; 2. CloudWalker.
    Safety 4752 2020-05-09 16:26:22
  • How to better defend against CC attacks under Linux
    How to better defend against CC attacks under Linux
    1. Install dependent packages: yum install perl-libwww-perl perl iptables 2. Download and install CSF: wget https://download.configserver.com/csf.tgz tar -xzf csf.tgz cd csf sh install.sh 3. Test CSF...
    Safety 754 2020-04-30 17:57:42

Tool Recommendations

jQuery enterprise message form contact code

jQuery enterprise message form contact code is a simple and practical enterprise message form and contact us introduction page code.
form button
2024-02-29

HTML5 MP3 music box playback effects

HTML5 MP3 music box playback special effect is an mp3 music player based on HTML5 css3 to create cute music box emoticons and click the switch button.

HTML5 cool particle animation navigation menu special effects

HTML5 cool particle animation navigation menu special effect is a special effect that changes color when the navigation menu is hovered by the mouse.
Menu navigation
2024-02-29

jQuery visual form drag and drop editing code

jQuery visual form drag and drop editing code is a visual form based on jQuery and bootstrap framework.
form button
2024-02-29

Organic fruit and vegetable supplier web template Bootstrap5

An organic fruit and vegetable supplier web template-Bootstrap5
Bootstrap template
2023-02-03

Bootstrap3 multifunctional data information background management responsive web page template-Novus

Bootstrap3 multifunctional data information background management responsive web page template-Novus
backend template
2023-02-02

Real estate resource service platform web page template Bootstrap5

Real estate resource service platform web page template Bootstrap5
Bootstrap template
2023-02-02

Simple resume information web template Bootstrap4

Simple resume information web template Bootstrap4
Bootstrap template
2023-02-02

Cute summer elements vector material (EPS PNG)

This is a cute summer element vector material, including the sun, sun hat, coconut tree, bikini, airplane, watermelon, ice cream, ice cream, cold drink, swimming ring, flip-flops, pineapple, conch, shell, starfish, crab, Lemons, sunscreen, sunglasses, etc., the materials are provided in EPS and PNG formats, including JPG previews.
PNG material
2024-05-09

Four red 2023 graduation badges vector material (AI EPS PNG)

This is a red 2023 graduation badge vector material, four in total, available in AI, EPS and PNG formats, including JPG preview.
PNG material
2024-02-29

Singing bird and cart filled with flowers design spring banner vector material (AI EPS)

This is a spring banner vector material designed with singing birds and a cart full of flowers. It is available in AI and EPS formats, including JPG preview.
banner picture
2024-02-29

Golden graduation cap vector material (EPS PNG)

This is a golden graduation cap vector material, available in EPS and PNG formats, including JPG preview.
PNG material
2024-02-27

Home Decor Cleaning and Repair Service Company Website Template

Home Decoration Cleaning and Maintenance Service Company Website Template is a website template download suitable for promotional websites that provide home decoration, cleaning, maintenance and other service organizations. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-05-09

Fresh color personal resume guide page template

Fresh color matching personal job application resume guide page template is a personal job search resume work display guide page web template download suitable for fresh color matching style. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-29

Designer Creative Job Resume Web Template

Designer Creative Job Resume Web Template is a downloadable web template for personal job resume display suitable for various designer positions. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-28

Modern engineering construction company website template

The modern engineering and construction company website template is a downloadable website template suitable for promotion of the engineering and construction service industry. Tip: This template calls the Google font library, and the page may open slowly.
Front-end template
2024-02-28