你晓得这些名词的真正含义吗?
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">开源</span></strong><span style="color: black;">:开放源代码,指一种软件发布模式。开源<span style="color: black;">亦</span>有可能会有<span style="color: black;">必定</span>的限制,如现值阅读源代码的对象,限制衍生品等</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">黑客</span></strong><span style="color: black;">:源自英文hacker。骇客与黑客<span style="color: black;">区别</span>,最初指<span style="color: black;">热情</span>于计算机技术,水平高超的电脑<span style="color: black;">能手</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">骇客(黑帽子)</span></strong><span style="color: black;">:以个人意志为出发点,攻击网络或计算机</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">白帽子</span></strong><span style="color: black;">:专门<span style="color: black;">科研</span>或从事网络安全的人,是<span style="color: black;">加强</span>网络、系统安全水平的<span style="color: black;">重点</span>力量</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">灰帽子</span></strong><span style="color: black;">:介于两者之间</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">脚本</span></strong><span style="color: black;">:ASP即Active Server Pages,服务器端脚本环境,可用来创建动态交互式网页并<span style="color: black;">创立</span>强大的web应用程序</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">html</span></strong><span style="color: black;">(css、js、html)是标记语言不是编程语言</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">架构</span></strong><span style="color: black;">:C/S架构 即服务器-客户机结构。c/s结构<span style="color: black;">一般</span>采取两层结构,服务器负责数据管理,客户机负责完成与用户的交互任务</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">B/S架构 即浏览器-服务器结构。统一了客户端,将功能实现的核心部分放在了服务器上,简化了系统的<span style="color: black;">研发</span>,<span style="color: black;">守护</span>和<span style="color: black;">运用</span>。客户机上只<span style="color: black;">必须</span>装一个浏览器,服务器安装数据库,浏览器<span style="color: black;">经过</span>web服务器同数据库进行数据交互</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">CMS</span></strong><span style="color: black;">:内容管理系统</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">MD5</span></strong><span style="color: black;">:一种信息摘要算法,<span style="color: black;">能够</span>产生出一个128位(16字节)的散列值(hash value),用于<span style="color: black;">保证</span>信息传输完全一致。1996年后,该算法被证明存在弱点,<span style="color: black;">能够</span>被加以破解。2004年,证实MD5算法<span style="color: black;">没法</span>方式碰撞,不适用于安全性验证,如ssl公开密钥认证或是数字签名等用途</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">肉鸡</span></strong><span style="color: black;">:被黑客入侵并<span style="color: black;">长时间</span>空置的计算机或服务器</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">抓鸡</span></strong><span style="color: black;">:利用<span style="color: black;">运用</span>量大的程序漏洞,<span style="color: black;">运用</span>自动化的方式获取肉鸡的<span style="color: black;">行径</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">漏洞</span></strong><span style="color: black;">:软件、硬件、协议等等的可利用安全缺陷,可能被攻击者利用,对数据进行篡改,<span style="color: black;">掌控</span>等</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">Webshell</span></strong><span style="color: black;">:<span style="color: black;">经过</span>Web入侵的一种脚本工具,<span style="color: black;">能够</span><span style="color: black;">按照</span>此对网站服务进行<span style="color: black;">必定</span>程度上的<span style="color: black;">掌控</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">一句话木马</span></strong><span style="color: black;">:短小精悍,功能强大,隐蔽性非常好,在入侵中始终扮演者强大的<span style="color: black;">功效</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">提权</span></strong><span style="color: black;">:<span style="color: black;">加强</span>自己在服务器中的权限,就<span style="color: black;">例如</span>在windows中你本身登录用的用户<span style="color: black;">便是</span>guest,<span style="color: black;">而后</span><span style="color: black;">经过</span>提权之后,就变成超级管理员权限,<span style="color: black;">持有</span>了管理windows的所有权限。提权是黑客的专业名词,<span style="color: black;">通常</span>用于网站入侵和系统入侵中</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">水平越权</span></strong><span style="color: black;">:能看到统一权限下的其他用户的内容</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">垂直越权</span></strong><span style="color: black;">:向上获取更高层的权限</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">后门</span></strong><span style="color: black;">:在信息安全<span style="color: black;">行业</span>,后门时指绕过安全<span style="color: black;">掌控</span>而获取程序或系统<span style="color: black;">拜访</span>权的<span style="color: black;">办法</span>。后门的最<span style="color: black;">重点</span>的目的<span style="color: black;">便是</span>方便以后再次<span style="color: black;">奥密</span>进入<span style="color: black;">或</span><span style="color: black;">掌控</span>系统</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">端口</span></strong><span style="color: black;">:是英文“port”意译,<span style="color: black;">能够</span>认为是设备与外界通讯交流的出口。端口可分为虚拟端口和<span style="color: black;">理学</span>端口,其中虚拟端口指计算机内部或交换机路由器内的端口,不可见。例如计算机中的80、21、23端口。<span style="color: black;">理学</span>端口又<span style="color: black;">叫作</span>为接口,是可见端口,如RJ45端口。<span style="color: black;">tel</span><span style="color: black;">运用</span>的RJ11端口<span style="color: black;">亦</span>属于<span style="color: black;">理学</span>端口</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">网关</span></strong><span style="color: black;">:网关(Gateway)又<span style="color: black;">叫作</span>间接网见连接器、协议转换器。网关在网络层以上实现网络互联,是<span style="color: black;">繁杂</span>的网络互联设备,仅用于两个高层协议<span style="color: black;">区别</span>的网络互联。网关既<span style="color: black;">能够</span>用与广域网互联,<span style="color: black;">亦</span><span style="color: black;">能够</span>用于局域网互联</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">跳板</span></strong><span style="color: black;">(vps):为了<span style="color: black;">隐匿</span>自己的<span style="color: black;">位置</span>,<span style="color: black;">运用</span><span style="color: black;">已然</span>被<span style="color: black;">掌控</span>的<span style="color: black;">设备</span>来攻击其他<span style="color: black;">目的</span>,让别人<span style="color: black;">没法</span><span style="color: black;">查询</span>的自己的位置</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">旁站</span></strong><span style="color: black;">:即同服务器下的网站</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">旁站入侵</span></strong><span style="color: black;">:即同服务器下的网站入侵。入侵后<span style="color: black;">能够</span><span style="color: black;">经过</span>提权跨目录等手段拿到<span style="color: black;">目的</span>网站的权限</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">C段</span></strong><span style="color: black;">:IP<span style="color: black;">位置</span>是有分段的,<span style="color: black;">例如</span>1.1.1.1最后一个1是C段,如1.1.1.0--1.1.1.255这个C段为255个IP<span style="color: black;">位置</span>;B段<span style="color: black;">便是</span>1.1.0.0--1.1.255.255中间有65535个IP<span style="color: black;">位置</span>;A段为1.0.0.0--1.255.255.255</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">保存</span><span style="color: black;">位置</span></span></strong><span style="color: black;">:169.254.x.x</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">倘若</span>你的主机<span style="color: black;">运用</span>了DHCP功能自动<span style="color: black;">得到</span>一个IP<span style="color: black;">位置</span>,<span style="color: black;">那样</span>当你的DHCP服务器<span style="color: black;">出现</span>故障,或响应时间太长而超出了一个系统规定的时间,Wingdows系统会为你分配<span style="color: black;">这般</span>一个<span style="color: black;">位置</span>。<span style="color: black;">倘若</span>你<span style="color: black;">发掘</span>你的主机IP<span style="color: black;">位置</span>是一个诸如此类的<span style="color: black;">位置</span>,很不幸,十有八九是你的网络<span style="color: black;">不可</span>正常运行了。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">10.x.x.x、172.16.x.x~172.31.x.x、192.168.x.x</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">私有<span style="color: black;">位置</span>,这些<span style="color: black;">位置</span>被<span style="color: black;">海量</span>用于企业内部网络中。<span style="color: black;">有些</span>宽带路由器,<span style="color: black;">亦</span><span style="color: black;">常常</span><span style="color: black;">运用</span>192.168.1.1<span style="color: black;">做为</span>缺省<span style="color: black;">位置</span>。私有网络<span style="color: black;">因为</span>不与<span style="color: black;">外边</span>互连,因而可能<span style="color: black;">运用</span>随意的IP<span style="color: black;">位置</span>。<span style="color: black;">保存</span><span style="color: black;">这般</span>的<span style="color: black;">位置</span>供其<span style="color: black;">运用</span>是为了避免以后接入公网时<span style="color: black;">导致</span><span style="color: black;">位置</span>混乱。<span style="color: black;">运用</span>私有<span style="color: black;">位置</span>的私有网络在接入Internet时,要<span style="color: black;">运用</span><span style="color: black;">位置</span>翻译(NAT),将私有<span style="color: black;">位置</span>翻译成公用合法<span style="color: black;">位置</span>。在Internet上,这类<span style="color: black;">位置</span>是<span style="color: black;">不可</span><span style="color: black;">显现</span>的。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">服务</span></strong><span style="color: black;">:指电脑中,<span style="color: black;">必须</span><span style="color: black;">各样</span>服务以支持<span style="color: black;">各样</span>功能,他在后台运行,<span style="color: black;">亦</span><span style="color: black;">能够</span>手动开启<span style="color: black;">或</span>关闭某些服务以达到管理相应功能的目的</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">权限:<span style="color: black;">指的是</span>某个特定的用户<span style="color: black;">拥有</span>特定的系统资源<span style="color: black;">运用</span>权力,像是文件夹,特定系统指令的<span style="color: black;">运用</span>或存储量的限制。<span style="color: black;">一般</span>,系统管理员,<span style="color: black;">或</span>在网络中的网络管理员,对某个特定资源的<span style="color: black;">运用</span>分配给用户<span style="color: black;">区别</span>的权限,系统软件则自动地强制执行这些权限</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">批处理文件</span></strong><span style="color: black;">:批处理,顾名思义<span style="color: black;">便是</span>进行批量的处理。批处理文件是扩展名为·bat 或·cmd的文本文件,<span style="color: black;">包括</span>一条或多条命令,由DOS或Windows系统内嵌的命令解释器来解释运行</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">渗透测试</span></strong><span style="color: black;">:渗透测试,是为了证明网络防御<span style="color: black;">根据</span>预期计划正常运行而<span style="color: black;">供给</span>的一种机制。不妨假设,你的<span style="color: black;">机构</span><span style="color: black;">定时</span>更新安全策略和程序,时时给系统打补丁,并采用了漏洞扫描器等工具,以<span style="color: black;">保证</span>所有补丁都已打上。<span style="color: black;">倘若</span>你早已做到了这些,<span style="color: black;">为何</span>还要请外方进行审查或渗透测试呢?<span style="color: black;">由于</span>,渗透测试能够独立地<span style="color: black;">检测</span>你的网络策略,换句话说,<span style="color: black;">便是</span>给你的系统安了一双眼睛。<span style="color: black;">况且</span>,进行这类测试的,都是寻找网络系统安全漏洞的专业人士</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">黑盒测试</span></strong><span style="color: black;">:在授权的<span style="color: black;">状况</span>下,模拟黑客的攻击<span style="color: black;">办法</span>和思维方式,来<span style="color: black;">评定</span>计算机网络系统可能存在的安全<span style="color: black;">危害</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">白盒测试</span></strong><span style="color: black;">:与黑盒测试恰恰相反,测试者<span style="color: black;">能够</span><span style="color: black;">经过</span>正常<span style="color: black;">途径</span>向被测单位取得<span style="color: black;">各样</span>资料,<span style="color: black;">包含</span>网络拓扑、员工资料<span style="color: black;">乃至</span>网站或其它程序的代码片段,<span style="color: black;">亦</span>能够与单位的其它员工(<span style="color: black;">营销</span>、程序员、管理者……)进行面对面的沟通。这类测试的目的是模拟企业内部雇员的越权操作</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">特点</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">充满挑战与刺激——不达目的不罢休</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">思路与经验的<span style="color: black;">累积</span><span style="color: black;">常常</span>决定成败</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">渗透测试是倾向于<span style="color: black;">守护</span>的</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">APT攻击:</span></strong><span style="color: black;">即高级可<span style="color: black;">连续</span>威胁攻击,<span style="color: black;">亦</span><span style="color: black;">叫作</span>为定向威胁攻击,指某组织对特定对象展开的<span style="color: black;">连续</span>有效的攻击活动。这种攻击活动<span style="color: black;">拥有</span>极强的隐蔽性和针对性,<span style="color: black;">一般</span>会运用受感染的<span style="color: black;">各样</span>介质(usb接口)、供应链(给<span style="color: black;">目的</span>单位做服务)和社会工程学等多种手段实施先进的、持久的且有效的威胁和攻击,极强的隐蔽性,<span style="color: black;">隐藏</span>期长,<span style="color: black;">连续</span>性强,<span style="color: black;">目的</span>性强</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">静态网站:</span></strong><span style="color: black;"><span style="color: black;">指的是</span><span style="color: black;">所有</span>由HTML(标准通用标记语言的子集)代码格式页面<span style="color: black;">构成</span>的网站,所有的内容<span style="color: black;">包括</span>在网页文件中。网页上<span style="color: black;">亦</span><span style="color: black;">能够</span><span style="color: black;">显现</span><span style="color: black;">各样</span>视觉动态效果,如GIF动画、FLASH动画、滚动字幕等,而网站<span style="color: black;">重点</span>是静态化的页面和代码<span style="color: black;">构成</span>,<span style="color: black;">通常</span>文件名均以htm、html、shtml等为后缀</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">动态网站:</span></strong><span style="color: black;">动态网站并不<span style="color: black;">指的是</span><span style="color: black;">拥有</span>动画功能的网站,而<span style="color: black;">指的是</span>网站内容可<span style="color: black;">按照</span><span style="color: black;">区别</span><span style="color: black;">状况</span>动态变更的网站,<span style="color: black;">通常</span><span style="color: black;">状况</span>下动态网站<span style="color: black;">经过</span>数据库进行架构。动态网站除了要设计网页外,还要<span style="color: black;">经过</span>数据库和编程序来使网站<span style="color: black;">拥有</span><span style="color: black;">更加多</span>自动的和高级的功能。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">动态网站<span style="color: black;">表现</span>在网页<span style="color: black;">通常</span>是以asp,jsp,php,aspx等技术,而静态网页<span style="color: black;">通常</span>是HTML(标准通用标记语言的子集)结尾,动态网站服务器空间配置要比静态的网页<span style="color: black;">需求</span>高,<span style="color: black;">花费</span><span style="color: black;">亦</span>相应的高,<span style="color: black;">不外</span>动态网页利于网站内容的更新,适合企业建站。动态是相<span style="color: black;">针对</span>静态网站而言的</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">伪静态网站</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">伪静态是相对真实静态来讲的,<span style="color: black;">一般</span><span style="color: black;">咱们</span>为了<span style="color: black;">加强</span>搜索引擎的友好面,都将<span style="color: black;">文案</span>内容生成静态页面,<span style="color: black;">然则</span>有的<span style="color: black;">伴侣</span>为了实时的<span style="color: black;">表示</span><span style="color: black;">有些</span>信息。<span style="color: black;">或</span>还想运用动态脚本<span style="color: black;">处理</span><span style="color: black;">有些</span>问题。<span style="color: black;">不可</span>用静态的方式来展示网站内容。<span style="color: black;">然则</span>这就损失了对搜索引擎的友好面。怎么样在两者之间找个中间<span style="color: black;">办法</span>呢,这就产生了伪静态技术。伪静态技术<span style="color: black;">指的是</span>展示出来的是以html一类的静态页面形式,但其实是用ASP一类的动态脚本来处理的</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">伪静态:URL重写方式,写的看起来是个静态页面。并不是真的静态。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">Location</span></strong><span style="color: black;">:重定向用户到另一个页面,可识别身份认证后<span style="color: black;">准许</span><span style="color: black;">拜访</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">Cookie</span></strong><span style="color: black;">:客户端发回给服务器证明用户状态的信息(头:值成对<span style="color: black;">显现</span>)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">Referer</span></strong><span style="color: black;">:发起新请求之前用户<span style="color: black;">位置于</span>哪个页面,服务器基于此头的安全限制很容易被修改绕过</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">Host</span></strong><span style="color: black;">:被<span style="color: black;">拜访</span>的的完整URL中的主机名<span style="color: black;">叫作</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">状态码</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">状态码的职责是当客户端向服务器发送请求时,描述返回的请求结果。借助状态码,用户<span style="color: black;">能够</span><span style="color: black;">晓得</span>服务器端是正常处理了请求还是<span style="color: black;">显现</span>了错误。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">状态码的类别:</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">类别 <span style="color: black;">原由</span>短语</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">1XX Informational(信息性状态码) 接受的请求正在处理</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">2XX Success(成功状态码) 请求正常处理完毕</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">3XX Redirection(重定向状态码) <span style="color: black;">必须</span>进行附加操作以完成请求</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">4XX Client Error(客户端错误状态码) 服务器<span style="color: black;">没法</span>处理请求</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">5XX Server Error(服务器错误状态码) 服务器处理请求出错</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">2XX——<span style="color: black;">显示</span>请求被正常处理了</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">1、200 OK:请求已正常处理。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">2、204 No Content:请求处理成功,但<span style="color: black;">无</span>任何资源<span style="color: black;">能够</span>返回给客户端,<span style="color: black;">通常</span>在只<span style="color: black;">必须</span>从客户端往服务器发送信息,而对客户端不<span style="color: black;">必须</span>发送新信息内容的<span style="color: black;">状况</span>下<span style="color: black;">运用</span>。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">3、206 Partial Content:是对资源某一部分的请求,该状态码<span style="color: black;">暗示</span>客户端进行了范围请求,而服务器成功执行了这部分的GET请求。响应报文中<span style="color: black;">包括</span>由Content-Range指定范围的实<span style="color: black;">身体</span>容。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">3XX——<span style="color: black;">显示</span>浏览器<span style="color: black;">必须</span>执行某些特殊的处理以正确处理请求</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">4、301 Moved Permanently:资源的uri已更新,你<span style="color: black;">亦</span>更新下你的书签引用吧。永久性重定向,请求的资源<span style="color: black;">已然</span>被分配了新的URI,以后应<span style="color: black;">运用</span>资源<span style="color: black;">此刻</span>所指的URI。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">5、302 Found:资源的URI已临时定位到其他位置了,姑且算你<span style="color: black;">已然</span><span style="color: black;">晓得</span>了这个<span style="color: black;">状况</span>了。临时性重定向。和301<span style="color: black;">类似</span>,但302<span style="color: black;">表率</span>的资源不是永久性移动,只是临时性性质的。换句话说,已移动的资源对应的URI将来还有可能<span style="color: black;">出现</span>改变。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">6、303 See Other:资源的URI已更新,你<span style="color: black;">是不是</span>能临时按新的URI<span style="color: black;">拜访</span>。该状态码<span style="color: black;">暗示</span><span style="color: black;">因为</span>请求对应的资源存在着另一个URL,应<span style="color: black;">运用</span>GET<span style="color: black;">办法</span>定向获取请求的资源。303状态码和302状态码有着相同的功能,但303状态码<span style="color: black;">知道</span><span style="color: black;">暗示</span>客户端应当采用GET<span style="color: black;">办法</span>获取资源,这点与302状态码有区别。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">当301,302,303响应状态码返回时,几乎所有的浏览器都会把POST改成GET,并删除请求报文内的主体,之后请求会自动再次发送。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">7、304 Not Modified:资源已找到,但未符合<span style="color: black;">要求</span>请求。该状态码<span style="color: black;">暗示</span>客户端发送附带<span style="color: black;">要求</span>的请求时(采用GET<span style="color: black;">办法</span>的请求报文中<span style="color: black;">包括</span>If-Match,If-Modified-Since,If-None-Match,If-Range,If-Unmodified-Since中任一首部)服务端<span style="color: black;">准许</span>请求<span style="color: black;">拜访</span>资源,但因<span style="color: black;">出现</span>请求未满足<span style="color: black;">要求</span>的<span style="color: black;">状况</span>后,直接返回304.。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">8、307 Temporary Redirect:临时重定向。与302有相同的含义。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">4XX——<span style="color: black;">显示</span>客户端是<span style="color: black;">出现</span>错误的<span style="color: black;">原由</span>所在。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">9、400 Bad Request:服务器端<span style="color: black;">没法</span>理解客户端发送的请求,请求报文中可能存在语法错误。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">10、401 Unauthorized:该状态码<span style="color: black;">暗示</span>发送的请求<span style="color: black;">必须</span>有<span style="color: black;">经过</span>HTTP认证(BASIC认证,DIGEST认证)的认证信息。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">11、403 Forbidden:不<span style="color: black;">准许</span><span style="color: black;">拜访</span>那个资源。该状态码<span style="color: black;">显示</span>对请求资源的<span style="color: black;">拜访</span>被服务器拒绝了。(权限,未授权IP等)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">12、404 Not Found:服务器上<span style="color: black;">无</span>请求的资源。路径错误等。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">5XX——服务器本身<span style="color: black;">出现</span>错误</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">13、500 Internal Server Error:貌似内部资源出故障了。该状态码<span style="color: black;">显示</span>服务器端在执行请求时<span style="color: black;">出现</span>了错误。<span style="color: black;">亦</span>有可能是web应用存在bug或某些临时故障。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">14、503 Service Unavailable:抱歉,我<span style="color: black;">此刻</span>正在忙着。该状态码<span style="color: black;">显示</span>服务器暂时<span style="color: black;">处在</span>超负载或正在停机<span style="color: black;">守护</span>,<span style="color: black;">此刻</span><span style="color: black;">没法</span>处理请求</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">渗透测试流程</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">知道</span><span style="color: black;">目的</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">确定范围</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">确定规则</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">确定需求</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">信息收集(<span style="color: black;">名人</span>画像)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">基本</span>信息(<span style="color: black;">机构</span>法人,高级人员姓名,人员关系)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">系统信息(服务器的系统,版本信息,开源框架)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">应用信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">版本信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">服务信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">人员信息(通讯录,<span style="color: black;">机构</span>架构)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">防护信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">漏洞探测(goby)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">系统漏洞</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">应用漏洞</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">端口服务漏洞</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">漏洞验证</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">自动化验证</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">手工验证</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">登录猜解(登录认证、401认证)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">业务漏洞验证</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">公开资源的利用</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">信息分析</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">精细</span>打击</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">绕过防御检测机制</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">poc检测 ping vps——跳板机</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">exp(中文意思是“漏洞利用”)攻击 whoami</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">ipconfig</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">指定攻击路径</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">实施攻击</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">获取内部信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">信息整理</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">形成报告</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">漏洞数量</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">漏洞<span style="color: black;">害处</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">修复<span style="color: black;">意见</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">静态网站</span></span></p>
你的话深深触动了我,仿佛说出了我心里的声音。 楼主发的这篇帖子,我觉得非常有道理。 你的见解真是独到,让我受益匪浅。 对于这个问题,我有不同的看法... 论坛的成功是建立在我们诚恳、务实、高效、创新和团结合作基础上,我们要把这种精神传递下去。
页:
[1]