Embracing an Adversarial Mindset for Cpp SecurityMICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY1. Adversarial Scenarios 2. Vulnerability Trends 3. Exploits in the Wild 4. Strategies for Secure C++ DevelopmentWHOAMI 0x401006 Microsoft 0x40E04C Twitter # @malwareunicorn COMMUNITY 0x402023 JNE SIDE ACTIVITIESDay in the Life: Vulnerability Research ● Looking at code 75% ● Instrumenting fuzzing harnesses 5% ● Making POC when needed group CVE-2021-28310 CVE-2021-1732 • Used for privilege escalation • Out-of-bounds (OOB) write vulnerability in dwmcore.dll, which is part of Desktop Window Manager (dwm.exe) • Attacker grooms the heap0 码力 | 92 页 | 3.67 MB | 6 月前3
Guzzle PHP 6.5 DocumentationInstallation Bleeding edge License Contributing Guidelines Running the tests Reporting a security vulnerability Quickstart Making a Request Creating a Client Sending Requests Async Requests Concurrent requests handlers. Reporting a security vulnerability We want to ensure that Guzzle is a secure HTTP client library for everyone. If you've discovered a security vulnerability in Guzzle, we appreciate your help responsible manner [http://en.wikipedia.org/wiki/Responsible_disclosure]. Publicly disclosing a vulnerability can put the entire community at risk. If you've discovered a security concern, please email us0 码力 | 65 页 | 311.42 KB | 11 月前3
Guzzle PHP 7.0 DocumentationInstallation Bleeding edge License Contributing Guidelines Running the tests Reporting a security vulnerability Quickstart Making a Request Creating a Client Sending Requests Async Requests Concurrent requests handlers. Reporting a security vulnerability We want to ensure that Guzzle is a secure HTTP client library for everyone. If you've discovered a security vulnerability in Guzzle, we appreciate your help responsible manner [https://en.wikipedia.org/wiki/Responsible_disclosure]. Publicly disclosing a vulnerability can put the entire community at risk. If you've discovered a security concern, please email us0 码力 | 64 页 | 310.93 KB | 11 月前3
Guzzle PHP v5 DocumentationInstallation Bleeding edge License Contributing Guidelines Running the tests Reporting a security vulnerability Quickstart Making a Request Creating a Client Sending Requests Async Requests Concurrent requests handlers. Reporting a security vulnerability We want to ensure that Guzzle is a secure HTTP client library for everyone. If you've discovered a security vulnerability in Guzzle, we appreciate your help responsible manner [http://en.wikipedia.org/wiki/Responsible_disclosure]. Publicly disclosing a vulnerability can put the entire community at risk. If you've discovered a security concern, please email us0 码力 | 62 页 | 309.78 KB | 11 月前3
Guzzle PHP 5.3 Documentation}); User guide Overview Requirements Installation License Contributing Reporting a security vulnerability Quickstart Make a Request Using Responses Query String Parameters Uploading Data Cookies Redirects handlers. Reporting a security vulnerability We want to ensure that Guzzle is a secure HTTP client library for everyone. If you’ve discovered a security vulnerability in Guzzle, we appreciate your help responsible manner [http://en.wikipedia.org/wiki/Responsible_disclosure]. Publicly disclosing a vulnerability can put the entire community at risk. If you’ve discovered a security concern, please email us0 码力 | 72 页 | 312.62 KB | 11 月前3
Django CMS 3.9.x Documentationapply the new migrations. 3.7.4 release notes What’s new in 3.7.4 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.7.3 release notes What’s new in Jacob Rief Julz Angelo Dini 3.6.1 release notes What’s new in 3.6.1 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.6.0 release notes This release Chematronix Frank Jacob Rief Julz 3.5.4 release notes What’s new in 3.5.4 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.5.3 release notes What’s new in0 码力 | 417 页 | 1.68 MB | 6 月前3
Django CMS 3.8.x Documentationapply the new migrations. 3.7.4 release notes What’s new in 3.7.4 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.7.3 release notes What’s new in Jacob Rief Julz Angelo Dini 3.6.1 release notes What’s new in 3.6.1 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.6.0 release notes This release Chematronix Frank Jacob Rief Julz 3.5.4 release notes What’s new in 3.5.4 Bug Fixes Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.5.3 release notes What’s new in0 码力 | 413 页 | 1.67 MB | 6 月前3
Django CMS 4.0.x Documentationapply the new migrations. 3.7.4 release notes What’s new in 3.7.4 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 4.1. Django/Python compatibility table Rief • Julz • Angelo Dini 3.6.1 release notes What’s new in 3.6.1 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.6.0 release notes This release of Frank • Jacob Rief • Julz 3.5.4 release notes What’s new in 3.5.4 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.5.3 release notes What’s new in0 码力 | 296 页 | 1.79 MB | 6 月前3
Django CMS 3.9.x Documentationapply the new migrations. 3.7.4 release notes What’s new in 3.7.4 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.7.3 release notes What’s new in Documentation, Release 3.10.0 3.6.1 release notes What’s new in 3.6.1 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.6.0 release notes This release of Documentation, Release 3.10.0 3.5.4 release notes What’s new in 3.5.4 Bug Fixes • Fixed a security vulnerability in the plugin_type url parameter to insert JavaScript code. 3.5.3 release notes What’s new in0 码力 | 298 页 | 1.79 MB | 6 月前3
Guzzle PHP v5 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 1.1.5 Reporting a security vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 1.2 Quickstart . . . . . . . newer in order to perform integration tests on Guzzle’s HTTP handlers. Reporting a security vulnerability We want to ensure that Guzzle is a secure HTTP client library for everyone. If you’ve discovered we appreciate your help in disclosing it to us in a responsible manner. Publicly disclosing a vulnerability can put the entire community at risk. If you’ve discovered a security concern, please email us0 码力 | 49 页 | 231.08 KB | 11 月前3
共 39 条
- 1
- 2
- 3
- 4













