Google's new Jarlsberg server system: full of holes like 'cheese'
Network Administration - A new online solution from Google for web developers, including server systems with a wide range of security vulnerabilities available today, so they can search, discover, and claim. Waterfall and find ways to fix them.
This set of solutions consists of two main elements: a web application in the form of mini-blogs prepared in an unsafe situation - called Jarlsberg, named after a Norwegian country cheese, part The rest is a detailed step-by-step guide for detecting vulnerabilities in the web application.
The guidance information from Google Code University specifies cross-site scripting, path traversal, code execution and denial of service - DOS. After that, participants had to overcome a small challenge to find and exploit vulnerabilities on Jarlsberg server systems, with instructions, of course. For those 'students' who do not pass the challenge, each part will come with answers and suggestions to improve their skills.
This can be considered an online security course for Google, and Jarlsberg server system is available on Google's App Engine, or if you want, you can go home and run it locally. And analyzing the source code to find vulnerabilities is really unnecessary.
Not all vulnerabilities are found and exploited by a browser, for example to get a specific file through the direct path path traversal mechanism, students will need to use the command line tool. another is called curl. This may be due to the mechanism of pre-translating the paths of some browsers like http://jarlsberg.appspot.com/305378746796/./secret.txt to http://jarlsberg.appspot.com/secret.txt , and therefore cannot exploit the vulnerability.
You should read it
- Google announced a serious vulnerability in the macOS kernel
- Intel's chip has eight new serious vulnerabilities
- Find security holes on every site with Nikto
- Detects many security vulnerabilities in Lenovo server infrastructure
- Warning of zero-day vulnerabilities in window manager on PC
- Chrome and Firefox have a serious security flaw, there is no way to fix it
- Security vulnerabilities - basic insights
- 9 misconceptions about security and how to resolve
May be interested
- A new discovery about the strange interaction between cosmic black holes and lightsurely many of us have heard of 'anecdotes' without anything in the universe able to escape the gravity of black holes, not even light.
- Microsoft launched Windows Server 2012 operating systemon september 5, the associated press reported, microsoft corp. has released windows server 2012 operating system, marking the first time they have released an important update for server platforms since 2009.
- How to turn an Android device into a web serverdo you need a low power device to run the website? want to regain space your web server is taking up? want to share some information with everyone, be it friends or public, but don't have the financial to run a full-scale web server?
- SYSTEM_USER function in SQL Serverthe system_user statement returns the username of the current user in the sql server database.
- 12 best Linux server operating systemsalthough linux operating systems provide a great desktop environment, linux can also successfully complete the task of a server. linux often provides advanced permissions, increasing flexibility and stability.
- Microsoft silently updated Windows 10 to patch 2 serious security holesaccording to microsoft, the two newly patched security holes affect hundreds of millions of regular windows 10 users and even windows 10 server.
- The discovery of a giant black hole, 70 times the mass of the Sun in the Milky Way, challenges every theorythe existence of this giant black hole shocked researchers because it contradicted previous cosmological theories.
- The old Windows Server can still protect itself against hackersmany businesses are still using windows server 2003 and even microsoft no longer supports it.
- Create VPN Server on Windows 8no need to install any additional applications, you can easily 'turn' your computer into a vpn server if you're using windows 8. in this way, you can share data from the computer. as a simple lan system in the form of remote access. & a
- How to install DNS Server on Windows Server 2019from microsoft, the domain name system (dns) is one of the industry standard protocol sets that includes tcp / ip, along with dns client and dns server that provide name resolution services that map names to the ip addresses of computers. .