a. Metasploit apache_tomcat_transfer_encoding module.
已知的
Nginx
漏洞
Nginx
是一个轻量级的
Web
服务器,用于将后端应用服务器(与
Apache
Coyote
类似)的连接代理入站。表
13-10
列出了早期的
Nginx
版本易受远程攻击。
表
13
-
10
:远程利用Nginx 漏洞
CVE
引用
影响的
Nginx
说明
CVE-2014-0088 1.5.11
及早期版本
Nginx
中执行的
SPDY
使得远程攻击者有可能利用
堆溢出运行任意代码
CVE-2013-4547 1.5.6
及早期版本
Nginx
允许攻击者利用非转义的空间字符绕过预
期的访问限制
CVE-2013-2028 1.3.9 and 1.4.0
通过分块的
Transfer-Encoding
请求
a
导致远程栈
溢出
CVE-2011-4963 1.2.0 and 1.3.0 Wi
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month, and much more.
O’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
I wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
I’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
I'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.