gpt4 book ai didi

java - 网站安全: what does it mean to infect people with silent java drive?

转载 作者:行者123 更新时间:2023-11-29 19:46:35 24 4
gpt4 key购买 nike

有人通过我的网站提交了匿名联系请求,声称他们发现了漏洞并询问了漏洞赏金计划。

他们分享说他们已经找到了一种方法来感染带有静默 java 驱动器的人。

那是什么样的漏洞?
有哪些基本方法可以避免这种情况?

最佳答案

这是一个非常古老的...称为九 (9) 球攻击。

If a Web visitor is new, the victim is pushed through a few more re-directions to land at the site www.nine2rack.in, which may sound like a site in India, but is in Ukraine, Websense believes. The URL inspired Websense to name the attack method Nine Ball.

The final stop for a Web victim includes a drive-by download attempt after the malware checks for vulnerabilities in the browser, Adobe or Quicktime software on the user’s desktop. If it succeeds, the attack will download a Trojan with a keylogger component that many anti-virus software packages do not yet identify, according to Websense.

Source

避免攻击。

  • 首先要过滤您从最终用户那里收到的所有数据。
  • 为您的 cPanel 或 FTP/SFTP 设置一个强密码

关于java - 网站安全: what does it mean to infect people with silent java drive?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/19096466/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com