eurekainc Goto Github PK
Name: Eurekainc
Type: User
Bio: Eurekainc
Name: Eurekainc
Type: User
Bio: Eurekainc
An MVC framework implemented in MySQL
Interactive UI component dev & test: React, React Native, Vue, Angular, Ember
Lightweight InfoPath alternative for SharePoint 2007,2010,2013,2016 and Office 365
Mirror of Apache Struts
An analytics dashboard and reporting tool for Mailgun transactional emails
[DEPRECATED] 一键清理 开源版,包括内存加速,缓存清理,自启管理,软件管理等。
super pratical css
*UNOFFICIAL* git-svn mirror of the (now dead) svn://svn.caucho.com/resin/ -- If you are looking for their modern repo, it lives on git://git.caucho.com/resin.git (see: http://resin.caucho.com/v5.0/manual/release-notes/5.0/5.0.0/ )
The content of swagger.io
Dynamic ES module loader
Example projects for Project Tango Java API
A little more fun for the pull-to-refresh interaction.
Free android xml template for Taxi App concept
TeamCity REST API (bundled in TeamCity distribution)
Software Engineering Technical Interview Prep
OutSystems Support Diagnostics Tool
TensorFlow Tutorial and Examples for Beginners with Latest APIs
Top10 Insufficient Transport Layer Protection(傳輸層保護不足) 對要連結的網站加入 basename() 語法,返回內部有的網站,不會導到其他網 站。 Top8 Unvalidated Redirects and Forwards(未驗證的導向) 導入扣款網站是使用 Get 來傳遞價格,簡單就可以改變。基本上用 Get 傳資料還 是很危險的… Fgetcsv() 解析 csv 格式檔案 file_put_contents(檔名, 內容) 寫入檔案 解決方法 1 確定是從購買網站進入,且比對 Session 才可以完成付費。 preg_match(正規表示條件, 要比對的字串) $_SERVER['HTTP_REFERER'] 前一個網頁的位置 解決方法 2 利用 sha1(microtime()) 以當前微秒加密後設定 token 變數與 session ,然後進 入購買網站後比對我傳入(get)的 token,與我的 session 比對。 <input type="hidden" name="token" value="<?php print($token);?> 設定 token if( $_SESSION['login'] != 'admin' || $_SESSION['token'] != $_GET['token'] ){ 比對 Top7 Failure to Restrict URL Access(限制 URL 存取失敗) 未經過登入畫面進入 admin.php 網頁 解決方法 登入後要設定 session 且要比對 session,若未設定 session 就進入 unsafe.php 網 頁。 $_SESSION[‘’] 此值是設定在伺服器上,可以防止權限不足而進入網站問題 Top5 預設密碼一定要改掉,下方網址有產品的預設帳號與密碼 http://www.defaultpassword.com/ Top4 直接修改 login 的使用者,即可進入受害者的網頁 owasp_lab2/member.php?login=user 解決方法 登入後要設定 session 且要比對 session,跟上方的 Top7 一樣 Top3 Cross-Site Scripting (XSS) 在留言板上傳入可執行的程式 解決方法 輸出內容改成 nl2br(htmlentities(內容)) nl2br() <br/>取代分行字元(\n) htmlentities() 將特殊字元轉為 html 實體參照 符號 轉換後 符號 轉換後 & & “ " ‘ ' < < > > Top2 Broken Authentication and Session Management 解決方法 設定 TimeOut 過期時間 start_session(600); 600 秒後過期 ID 不要當成 URL 傳遞 資料加密 Top1 Injection 只要在帳號打上 OR ‘’=’’ 帳號部分就一定可以成立 而#是 Sql 的註解語法,讓密碼可以不用判斷。所以密碼隨便打都可以進入。 解決方式 使用 PDO (PHP Data Object) 簡略說明,若有更多疑問請看老師的投影片!
Test'em 'Scripts! A test runner that makes Javascript unit testing fun.
Curated list of resources on testing distributed systems
An Android library that allows you to build text layouts more easily.
Udemy - The Complete Web Developer Course - Build 14 Websites by Rob Percival
Style your React Native components on one place
php restful-api风格接口 APP接口 APP接口权限 oauth2.0 接口版本管理 接口鉴权 tp5
Yet another prototype game project in Unity (5.6)
Material Design Music Player
Let us inspire you with all things TinyMCE can do
Micro-Transitions for Smooth Android To-Do List Animations
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.