CN104519070B - 网站权限漏洞检测方法和系统 - Google Patents
网站权限漏洞检测方法和系统 Download PDFInfo
- Publication number
- CN104519070B CN104519070B CN201410854508.8A CN201410854508A CN104519070B CN 104519070 B CN104519070 B CN 104519070B CN 201410854508 A CN201410854508 A CN 201410854508A CN 104519070 B CN104519070 B CN 104519070B
- Authority
- CN
- China
- Prior art keywords
- parameter
- link
- access
- website
- value
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 19
- 238000012360 testing method Methods 0.000 claims abstract description 72
- 238000000034 method Methods 0.000 claims abstract description 16
- 230000008859 change Effects 0.000 claims description 24
- 230000004044 response Effects 0.000 claims description 24
- 238000004422 calculation algorithm Methods 0.000 claims description 20
- 230000015572 biosynthetic process Effects 0.000 claims description 8
- 230000005540 biological transmission Effects 0.000 claims description 5
- 238000004891 communication Methods 0.000 description 10
- 230000006854 communication Effects 0.000 description 10
- 230000004048 modification Effects 0.000 description 4
- 238000012986 modification Methods 0.000 description 4
- 230000008878 coupling Effects 0.000 description 3
- 238000010168 coupling process Methods 0.000 description 3
- 238000005859 coupling reaction Methods 0.000 description 3
- 238000010586 diagram Methods 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 230000008901 benefit Effects 0.000 description 2
- 238000004590 computer program Methods 0.000 description 2
- 238000010276 construction Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000008569 process Effects 0.000 description 2
- 230000007175 bidirectional communication Effects 0.000 description 1
- 238000004364 calculation method Methods 0.000 description 1
- 238000007689 inspection Methods 0.000 description 1
- 238000010295 mobile communication Methods 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000010200 validation analysis Methods 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
- 239000002699 waste material Substances 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410854508.8A CN104519070B (zh) | 2014-12-31 | 2014-12-31 | 网站权限漏洞检测方法和系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410854508.8A CN104519070B (zh) | 2014-12-31 | 2014-12-31 | 网站权限漏洞检测方法和系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN104519070A CN104519070A (zh) | 2015-04-15 |
CN104519070B true CN104519070B (zh) | 2018-03-13 |
Family
ID=52793792
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201410854508.8A Active CN104519070B (zh) | 2014-12-31 | 2014-12-31 | 网站权限漏洞检测方法和系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN104519070B (zh) |
Families Citing this family (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106302337B (zh) * | 2015-05-22 | 2020-12-04 | 腾讯科技(深圳)有限公司 | 漏洞检测方法和装置 |
CN106470132B (zh) * | 2015-08-19 | 2019-09-17 | 阿里巴巴集团控股有限公司 | 水平权限测试方法及装置 |
CN106548075B (zh) * | 2015-09-22 | 2020-03-27 | 阿里巴巴集团控股有限公司 | 漏洞检测方法和装置 |
CN105357195B (zh) * | 2015-10-30 | 2019-06-14 | 深信服科技股份有限公司 | web访问的越权漏洞检测方法及装置 |
CN107220262B (zh) * | 2016-03-22 | 2021-01-26 | 阿里巴巴集团控股有限公司 | 信息处理方法和装置 |
CN107294919A (zh) * | 2016-03-31 | 2017-10-24 | 阿里巴巴集团控股有限公司 | 一种水平权限漏洞的检测方法及装置 |
CN106027528B (zh) * | 2016-05-24 | 2019-07-12 | 微梦创科网络科技(中国)有限公司 | 一种web水平权限自动化识别的方法及装置 |
CN106101082A (zh) * | 2016-05-31 | 2016-11-09 | 乐视控股(北京)有限公司 | 权限漏洞检测方法及装置 |
CN106713347B (zh) * | 2017-01-18 | 2019-06-11 | 国网江苏省电力公司电力科学研究院 | 一种电力移动应用越权访问漏洞检测方法 |
CN108696490A (zh) * | 2017-04-11 | 2018-10-23 | 腾讯科技(深圳)有限公司 | 账号权限的识别方法及装置 |
CN109583210A (zh) * | 2017-09-29 | 2019-04-05 | 阿里巴巴集团控股有限公司 | 一种水平权限漏洞的识别方法、装置及其设备 |
CN110798385B (zh) * | 2019-11-07 | 2023-03-03 | 中天宽带技术有限公司 | 广域网访问设置功能的测试方法、装置、设备及介质 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101964025A (zh) * | 2009-07-23 | 2011-02-02 | 中联绿盟信息技术(北京)有限公司 | Xss检测方法和设备 |
CN103324890A (zh) * | 2013-07-03 | 2013-09-25 | 百度在线网络技术(北京)有限公司 | 对链接进行本地文件包含漏洞的检测方法和装置 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102281311B (zh) * | 2010-06-10 | 2014-06-04 | 阿里巴巴集团控股有限公司 | 一种基于开放应用编程接口实现网络业务的方法、系统及装置 |
-
2014
- 2014-12-31 CN CN201410854508.8A patent/CN104519070B/zh active Active
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101964025A (zh) * | 2009-07-23 | 2011-02-02 | 中联绿盟信息技术(北京)有限公司 | Xss检测方法和设备 |
CN103324890A (zh) * | 2013-07-03 | 2013-09-25 | 百度在线网络技术(北京)有限公司 | 对链接进行本地文件包含漏洞的检测方法和装置 |
Also Published As
Publication number | Publication date |
---|---|
CN104519070A (zh) | 2015-04-15 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN104519070B (zh) | 网站权限漏洞检测方法和系统 | |
CN104753730B (zh) | 一种漏洞检测的方法及装置 | |
CN103297394B (zh) | 网站安全检测方法和装置 | |
CN104881603B (zh) | 网页重定向漏洞检测方法及装置 | |
US11989247B2 (en) | Indexing access limited native applications | |
US9177058B2 (en) | Multi-step search result retrieval | |
CN104539605B (zh) | 网站xss漏洞检测方法和设备 | |
CN102567546B (zh) | 一种sql注入检测方法及装置 | |
CN108696490A (zh) | 账号权限的识别方法及装置 | |
CN104579830B (zh) | 服务监控方法及装置 | |
CN113342639B (zh) | 小程序安全风险评估方法和电子设备 | |
KR20110048670A (ko) | 악성 사이트 검출 장치, 방법 및 컴퓨터 프로그램이 기록된 기록매체 | |
US20190386909A1 (en) | Method and program product for a private performance network with geographical load simulation | |
CN106453436A (zh) | 一种网络安全的检测方法和装置 | |
CN102855418A (zh) | 发现Web内网代理漏洞的方法 | |
CN107392028A (zh) | 敏感信息的检测方法及其检测装置、存储介质、电子设备 | |
CN105404816B (zh) | 基于内容的漏洞检测方法及装置 | |
CN102710646A (zh) | 一种钓鱼网站的收集方法和系统 | |
CN103905372A (zh) | 一种钓鱼网站去误报的方法和装置 | |
CN103812906B (zh) | 一种网址推荐方法、装置和通信系统 | |
CN106126707A (zh) | 信息识别方法和信息识别装置 | |
CN104580197A (zh) | 密码检测方法和密码检测系统 | |
CN112600863A (zh) | 一种安全远程访问系统及方法 | |
CN107392027A (zh) | 一种网站漏洞测试方法、测试系统、电子设备及存储介质 | |
CN103618742B (zh) | 网站管理员权限验证方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C41 | Transfer of patent application or patent right or utility model | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20161128 Address after: 100015 Chaoyang District Road, Jiuxianqiao, No. 10, building No. 3, floor 15, floor 17, 1701-26, Applicant after: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. Address before: 100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park) Applicant before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Applicant before: Qizhi software (Beijing) Co.,Ltd. |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP03 | Change of name, title or address | ||
CP03 | Change of name, title or address |
Address after: Room 332, 3 / F, Building 102, 28 xinjiekouwei street, Xicheng District, Beijing 100088 Patentee after: QAX Technology Group Inc. Address before: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing. Patentee before: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20201230 Address after: 100044 2nd floor, building 1, yard 26, Xizhimenwai South Road, Xicheng District, Beijing Patentee after: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Patentee after: QAX Technology Group Inc. Address before: Room 332, 3 / F, Building 102, 28 xinjiekouwei street, Xicheng District, Beijing 100088 Patentee before: QAX Technology Group Inc. |
|
CP01 | Change in the name or title of a patent holder | ||
CP01 | Change in the name or title of a patent holder |
Address after: 100044 2nd floor, building 1, yard 26, Xizhimenwai South Road, Xicheng District, Beijing Patentee after: Qianxin Wangshen information technology (Beijing) Co.,Ltd. Patentee after: QAX Technology Group Inc. Address before: 100044 2nd floor, building 1, yard 26, Xizhimenwai South Road, Xicheng District, Beijing Patentee before: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Patentee before: QAX Technology Group Inc. |