Google's new Jarlsberg server system: full of holes like 'cheese'
A new online solution from Google for web developers, including server systems with a lot of current security security holes ...
Network Administration - A new online solution from Google for web developers, including server systems with a wide range of security vulnerabilities available today, so they can search, discover, and claim. Waterfall and find ways to fix them.
This set of solutions consists of two main elements: a web application in the form of mini-blogs prepared in an unsafe situation - called Jarlsberg, named after a Norwegian country cheese, part The rest is a detailed step-by-step guide for detecting vulnerabilities in the web application.
The guidance information from Google Code University specifies cross-site scripting, path traversal, code execution and denial of service - DOS. After that, participants had to overcome a small challenge to find and exploit vulnerabilities on Jarlsberg server systems, with instructions, of course. For those 'students' who do not pass the challenge, each part will come with answers and suggestions to improve their skills.
This can be considered an online security course for Google, and Jarlsberg server system is available on Google's App Engine, or if you want, you can go home and run it locally. And analyzing the source code to find vulnerabilities is really unnecessary.
Not all vulnerabilities are found and exploited by a browser, for example to get a specific file through the direct path path traversal mechanism, students will need to use the command line tool. another is called curl. This may be due to the mechanism of pre-translating the paths of some browsers like http://jarlsberg.appspot.com/305378746796/./secret.txt to http://jarlsberg.appspot.com/secret.txt , and therefore cannot exploit the vulnerability.
You should read it
- How to scan websites for potential security vulnerabilities with Vega on Kali Linux
- IBM developed a new technology to patch security holes
- Google announced a serious vulnerability in the macOS kernel
- Intel's chip has eight new serious vulnerabilities
- Find security holes on every site with Nikto
- Detects many security vulnerabilities in Lenovo server infrastructure
- Warning of zero-day vulnerabilities in window manager on PC
- Chrome and Firefox have a serious security flaw, there is no way to fix it
- Security vulnerabilities - basic insights
- 9 misconceptions about security and how to resolve
- The NSA identifies 4 'critical' security vulnerabilities of cloud systems
- 5 common errors in managing security vulnerabilities
Maybe you are interested
Instructions to turn off the Spotify Canvas feature New achievement: TSP chip structure can run 1 million billion operations per second Fix error 'Unfortunately Google Allo has Stopped Error on Android' Which type of Omron nasal aspirator is best? 10 types of people you should avoid as far as possible in your life 8 types of people you should avoid as far as possible