惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
D
Docker
Stack Overflow Blog
Stack Overflow Blog
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence
H
Help Net Security
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
L
LangChain Blog
MongoDB | Blog
MongoDB | Blog
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
SegmentFault 最新的问题
博客园 - 司徒正美
C
Check Point Blog
B
Blog
Y
Y Combinator Blog
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
F
Fortinet All Blogs
美团技术团队
D
DataBreaches.Net

Attack and Defense Labs

Cracking hashes in the JavaScript cloud with Ravan Performing DDoS attacks with HTML5 Cross Origin Requests & WebWorkers Port Scanning with HTML5 and JS-Recon RSnake, Web Security and a few beers HTML5 goodness at BlackHat Abu Dhabi this week Re-visiting JAVA De-serialization: It can't get any simpler than this !! XSSing client-side dynamic HTML includes by hiding HTML inside images and more Stealing entire Auto-Complete data in Google Chrome Shell of the Future – Reverse Web Shell Handler for XSS Exploitation Chrome and Safari users open to stealth HTML5 AppCache attack HTML5 Security Articles and Live Demos Stroke triggered XSS and StrokeJacking New technique to be released for Attacking JAVA Serialized Communication at Black Hat Europe 2010 Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution Imposter and Whitepapers released The Goan NullCon Hangover The ClubHack 2009 hangover Stealing Databases and Setting Backdoors on Google Gears Breaking the Browser Sandbox and stealing some files Browser Phishing Explained The SecurityByte and OWASP AppSec Asia 2009 hangover Lust 2.0 talk @ SecurityByte and OWASP AppSec Asia 2009
Attacking JAVA Serialized Communication: BH EU 2010
Manish S. · 2010-04-18 · via Attack and Defense Labs
JAVA Object Serialization has been in use in many applications for a long time now. I find many enterprise ap…