The fuzzy tale of an x/crypto vulnerability## The fuzzy tale of an x/crypto vulnerability Michael McLoughlin Gophercon 2019 Lightning Talks Uber Advanced Technologies Group ## 8 ,140 lines of amd64 assembly in crypto ## 10 ,474 lines of amd64 amd64 assembly in golang.org/x/crypto   ## Fuzzing 0 ✓ crypto/aes (GCM mode) ✓ crypto/elliptic (P256) ✓ crypto/sha1 ✓ crypto/sha256 ✓ crypto/sha512 ✓ x/crypto/chacha20poly1305 ✓ x/crypto/sha3 ✓ x/crypto/blake2b ✓ x/crypto/blake2s ✓ x/crypto/argon20 码力 | 74 页 | 2.99 MB | 2 年前3
The Tale of Smokey and the Crypto Bandits## The Tale of Smokey and the Crypto Bandits How Okteto uses Falco to keep users happy and our platform healthy eBPF Summit Ramiro Berrelleza ## Hey everyone! • Co-founder of Okteto ● Former architect Cloud SupportHi Ramiro, Open Source to the rescue! ## X Falco Attempt #1 - We were young and naive • Installed Falco in the clusters - Configured it with Automatically respond to malicious actions without requiring human intervention ## The Tale of Smokey and the Crypto Bandits eBPF Summit Ramiro Berrelleza0 码力 | 14 页 | 926.57 KB | 2 年前3
常见Redis未授权访问漏洞总结常见的未授权访问漏洞: Redis 未授权访问漏洞 MongoDB 未授权访问漏洞 Jenkins 未授权访问漏洞 Memcached 未授权访问漏洞 JBOSS 未授权访问漏洞 VNC 未授权访问漏洞 Docker 未授权访问漏洞 ZooKeeper 未授权访问漏洞 Rsync 未授权访问漏洞 Atlassian Crowd 未授权访问漏洞 CouchDB 未授权访问漏洞 Elasticsearch Elasticsearch 未授权访问漏洞 Hadoop 未授权访问漏洞 Jupyter Notebook 未授权访问漏洞 ## Redis未授权访问漏洞 ## 漏洞简介以及危害 Redis 默认情况下,会绑定在 0.0.0.0:6379,如果没有进行采用相关的策略,比如添加防火墙规则避免其他非信任来源 ip 访问等,这样将会将 Redis 服务暴露到公网上,如果在没有设置密码认证(一般为空) 公钥写入目标服务器的 /root/.ssh 文件夹的 authotrized_keys 文件中,进而可以使用对应私钥直接使用 ssh 服务登录目标服务器、添加计划任务、写入 Webshell 等操作。 ## 漏洞利用 环境介绍 攻击机:windows10 目标靶机:Centos7 ip地址:192.168.18.138 连接工具:xshell ## 环境搭建 wget http://download0 码力 | 44 页 | 19.34 MB | 2 年前3
Typescript
SDK Version
1.x.x## Typescript SDK Version 1.x.x ## Table of contents 1. Overview.....3 a. Environmental Setup 2. Configurations.....4 3. Token Persistence.....7 a. Implementing OAuth Persistence0 码力 | 56 页 | 1.29 MB | 2 年前3
Django CMS 3.0.x Documentationfollow the Tutorials. ## Requirements • Python 2.6, 2.7, 3.3 or 3.4. • Django 1.4.5, 1.5.x, 1.6.x or 1.7.x • South 1.0.1 or higher (Only required up to Django 1.6) • Django-classy-tags 0.5 or higher ## Revision management • Django-reversion 1.8.X (with Django 1.6.X and Django 1.7.X) to support versioning of your content. Note: As of Django CMS 3.0.x, only the most recent 10 published revisions are this document. See Databases below for more information and related links. ## I nstalling on Mac OS X If you are using the system provided Python (2.6 or later), ensure you have pip installed. sudo easy_install0 码力 | 180 页 | 1.56 MB | 1 年前3
Django 4.0.x DocumentationPython is installed by typing `python` from your shell; you should see something like: Python 3.x.y [GCC 4.x] on linux Type "help", "copyright", "credits" or "license" for you click on it, a new slot will be added. If you want to remove the added slot, you can click on the X to the top right of the added slot. This image shows an added slot: 












