Whether the link is initiated through your Gmail account or not, the malicious site can access your internal credentials.
不管该链接是否通过Gmail账户点开,该恶意网站都会得到你的内部资料。
The malicious site then, unbeknownst to you, can create an automatic filter that diverts your E-mail to a different E-mail account.
接着恶意网站会在你不知道的情况下建立自动过滤,将你的email转向其他的email账户。
This made it easier to trick users into thinking a malicious site was legitimate if it was designed to emulate a Web site you'd normally trust.
这使哄骗用户把一个模仿通常信任的网站设计的恶意站点认作合法网站变得更容易。
I have also seen incidents where someone has covered the entire page on a Microsoft controlled site with a transparent pixel, linking to a malicious site.
我也看到有人在微软控制的网站上覆盖整个页面的事件透明像素,链接到恶意网站。
Browser Guard now also monitors for changes to Internet Explorer start and default pages and if they are set to a malicious site, they are reset back to default Settings.
浏览器警卫同样也可以监控IE的开始和默认页面的变化,如果它们被篡改为恶意网站网页,则会自动恢复默认的设置。
CSRF attacks originate from malicious code from an intruder site that tricks a browser into transmitting unprovoked requests to a trusted site.
CSRF攻击由一个入侵站点的恶意代码发起,该代码欺骗浏览器,使其将无关的请求传输到一个受信任站点。
Guarantee that the pages in the Web site return user inputs only after validating them for any malicious code.
保证Web站点的页面只有在验证了用户输入没有恶意代码之后才返回用户输入。
As more malicious users target the site, the company will have to protect the user behaviors that give the site its value.
随着更多有恶意的用户将目标指向该网站,Twitter将要保护用户的行为以此让该网站有存在的意义。
XSS results from malicious scripts being injected into a Web site.
XSS由注入Web站点的恶意脚本而导致。
Firesheep grabs that cookie, allowing nosy or malicious users to, in essence, be you on the site and have full access to your account.
Firesheep钻了这个空子,让爱管闲事的恶意用户基本上可以用你的身份上网并且完全获取你的账号。
If the targeted Web site doesn't check for this type of malicious code, misuse of the user is probable.
如果目标Web站点不检查这类恶意代码,就可能造成恶意使用用户信息。
To exploit the security hole, hackers must trick users into visiting a Web site loaded with malicious code, Microsoft said.
微软说,为了利用这个安全漏洞,黑客必须欺骗用户访问一个装载了恶意代码的网站。
Let us assume an attacker succeeded in filling a page containing malicious script to the Web site for the subscribed members.
让我们假设攻击者成功地将一个包含恶意脚本的页面填入到订阅成员使用的网站上。
Cross-site scripting attacks allow hackers to embed a malicious script on your visitor's browser and then execute the script in order to gather data.
跨站点脚本攻击使黑客能够将恶意脚本嵌入到访问者的浏览器中,然后执行该脚本收集数据。
Attacks that exploit an apparently trustworthy intermediary to pass on malicious data are called "cross-site malicious content" attacks.
使用看起来可信任的中间媒介传输恶意数据的攻击被称为“交叉站点恶意内容”攻击。
Since attackers are usually trying to add malicious scripts, this particular variation is called a "cross-site scripting attack" (XSS attack).
由于攻击者通常是试图添加恶意的脚本,因些这种变化被称为“交叉站点脚本攻击” (XSS攻击)。
When an attacker introduces a malicious script to a dynamic form submitted by the user, a cross-site scripting (XSS) attack then occurs.
当攻击者向用户提交的动态表单引入恶意脚本时,就会产生跨站点脚本(XSS)攻击。
As Microsoft explains on its Web site, DEP is a set of hardware and software technologies that perform additional checks on memory to help prevent malicious code from running on a system.
据微软网站的说明,DEP是一系列硬件和软件技术,可以通过对内存区域的附加检查阻止恶意代码在系统上运行。
According to Microsoft, the vulnerability allows a malicious web site to run code on a client's machine.
根据微软所述,恶意站点可以利用该漏洞在用户机器上运行代码。
The malicious script introduced by the attacker is executed by the browser and the data is passed to the hacker's Web site.
于是浏览器会执行攻击者引入的恶意代码,数据将被传递到黑客的网站。
When the page is displayed, the malicious script runs, collects the users' cookies, and sends a request to the attacker's Web site with the cookies gathered.
显示该页面时,恶意脚本就运行,它收集用户的cookie,并向攻击者的网站发送包含收集到的 cookie 的请求。
Knowing that the cause is a malicious attack does take Twitter off the hook to some degree –it may have been assumed that the site was simply failing to scale properly, as had happened in the past.
当人们得知twitter宕机的原因是缘于恶意袭击,Twitter才得以从困境中缓过气来 -人们原本推测Twitter宕机的原因是twitter不能承受如此规模的服务器负担,而这种情况在以前就发生过的。
Usually the attacker will encode the malicious portion of the link to the site in HEX (or other encoding methods) so the request is less suspicious looking to the user when clicked on.
通常攻击者会把链接中的恶意内容编码成HEX(或其他编码方法),所以减少了用户点击时的怀疑。
One example is defacing a Web page, where the malicious user gets into your site and changes files.
例如,恶意用户进入您的站点并更改文件,从而使网页变得面目全非。
Malicious script that is embedded in input submitted to a Web site and later written back out to a client can appear to be originating from a trusted source.
嵌入到输入中的恶意脚本(提交到网站并且随后写回客户端)可以看起来像是来自受信任的源。
By keeping the code server side, you reduce the risk of any malicious activity through cross-site scripting, SQL injection, and so on.
通过将代码放在服务器端,减少了通过跨站点脚本、SQL注入等手段进行恶意活动的风险。
By keeping the code server side, you reduce the risk of any malicious activity through cross-site scripting, SQL injection, and so on.
通过将代码放在服务器端,减少了通过跨站点脚本、SQL注入等手段进行恶意活动的风险。
应用推荐