摘要: Bcrypt把算法版本、计算次数和salt都放到hash值里面去了 Stored in the database, a bcrypt "hash" might look something like this: $2a$10$vI8aWBnW3fID.ZQ4/zo1G.q1lRps.9cGLcZEi 阅读全文
posted @ 2016-10-09 19:44 小小leo 阅读(1895) 评论(0) 推荐(0) 编辑
摘要: 两个exp: https://github.com/AppSecConsulting/Pentest-Tools/blob/master/jetty-bleed.py https://github.com/GDSSecurity/Jetleak-Testing-Script 阅读全文
posted @ 2016-10-09 14:19 小小leo 阅读(9715) 评论(0) 推荐(0) 编辑