1、web安全 https://appsecwiki.com/
jwt https://appsecwiki.com/#/serversidesecurity?id=json-web-tokenjwt
https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/ 篡改算法为none/用对称算法替换非对称算法
json 劫持 https://appsecwiki.com/#/frontend?id=json-hijacking
react js https://appsecwiki.com/#/frontend?id=react-js
angular js https://appsecwiki.com/#/frontend?id=angular-js
postmessage https://appsecwiki.com/#/frontend?id=postmessage-vulnerabilities
2、物联网 iot安全 https://iotsecuritywiki.com/
iot分四块,嵌入式系统+云控制+网络+app
3、app安全 https://mobilesecuritywiki.com/
app安全包括 app本地安全+网络安全+业务服务安全,其他门槛较高的二进制分析+动态调试
4、其他
利用X-HTTP-Method-Override(用于代理中转http):put 上传shell http://www.sec-down.com/wordpress/?p=809
伪装phar文件成jpeg https://www.nc-lp.com/blog/disguise-phar-packages-as-images
phar是php归档文件,在头部的stub部分可以放置整个jpeg文件,然后接上__HALT_COMPILER(); ?>,接着为归档内容
<?php
class TestObject {}
$phar = new Phar("phar.phar");
$phar->startBuffering();
$phar->addFromString("test.txt","test");
$phar->setStub("\xFF\xD8\xFF\xFE\x13\xFA\x78\x74 __HALT_COMPILER(); ?>");
$o = new TestObject();
$phar->setMetadata($o);
$phar->stopBuffering();