- Jan 2023
-
Local file Local file
-
revolutionary
革命性
-
performance degradation,
性能下降
-
legacy formats
传统形式
-
Executive Summary
报告摘要
-
- Sep 2022
-
sonraisecurity.com sonraisecurity.com
-
Posture
态势
-
Evolution
演变
-
-
blog.lightspin.io blog.lightspin.io
-
demonstrate
证明
-
ongoing
持续
-
Compliance
遵守
-
-
www.chrisfarris.com www.chrisfarris.com
-
evasion
逃避
-
Inventory
清单
-
exfil
绕过
-
flaws
缺陷
-
dimensionally
尺寸
-
telemetry
遥测
-
panic
惊恐
-
-
www.chrisfarris.com www.chrisfarris.com
-
a bunch of
一堆
-
- Aug 2022
-
wiz.io wiz.io
-
tenant isolation
租户隔离
-
remediation
修复
-
Given the success of our research
鉴于我们研究的成果
-
reveals
揭露
-
undisclosed
未公开的
-
cross-tenant vulnerabilities
跨租户漏洞
-
initial foothold
初始立足点
-
vendors
供应商
-
isolation
隔离
-
- Feb 2022
-
portswigger.net portswigger.net
-
it's all too easy to think you know it all already
人们很容易认为自己已经知道了所有内容
-
glibly
流利的
-
inconsistency
不一致
-
nominations
提名
-
dominated
控制,占主导地位
-
particular
特别的
-
countdown
倒数
-
frankly exceptional
坦率的,非同寻常的出类拔萃
-
they're affiliated with.
他们有关联的
-
panellists
小组成员
-
nominated
提名
-
Since kicking off the selection process in January,
自从1月开始选择
-
-
securitylab.github.com securitylab.github.com
-
craft
制作
-
Prevent
阻止
-
nested objects
嵌套对象
-
In addition to
除了..之外
-
hey are transitively imported by other dependencies.
他们被其他依赖传递的导入
-
get around
绕过
-
opt-in
选择性加入
-
addressed
解决
-
mitigations
减轻,缓和
-
compromise and run arbitrary system commands
妥协并执行系统命令
-
Multiple
多个
-
are not applicable to the vector reported.
对报道的向量不适用
-
has a mechanism to control
有一个机制控制
-
claims
声称
-
Some issues were addressed
一些问题被解决
-
-
dubbo.apache.org dubbo.apache.org
-
POJOs
对象
-
-
checkmarx.com checkmarx.com
-
it was mitigated by the vendor.
供应商缓解了这个问题
-
- Jan 2022
-
jolokia.org jolokia.org
-
A fine grained security mechanism
一个细粒度的安全机制
-
Bulk requests allow for multiple JMX operations with a single remote server roundtrip
批量请求允许在一个单独的请求中,使用多个JMX操作,
-
This opens a whole new world for different
这打开了一个全新的世界
-
but uses the much more open HTTP for its transport business where the data payload is serialized in JSON.
但是对外传输业务使用更开放的HTTP, 数据载荷使用反序列化的JSON
-
side by side
肩并肩 living side by side with JSR-160
-
It is an agent based approach
这是一个基于代理的方法
-
not usable outside the Java world.
在java世界之外不可用
-
underlying
基本
-
Add-on standards like JSR-77 didn't received the adoption level they deserved
像JSR-77这样的附加标准,并没有得到应有的采用级别
-
Especially the various levels of sophistications for implementing MBeans
特别是实现mbeans的各种复杂程度
-
impressive
Especially the various levels of sophistications for implementing MBeans, starting with dead simple Standard MBeans and ending in very flexible Open MBeans and MXBeans, are impressive. 令人影响深刻
-
Even more than ten years after its incubation
在他孵化十年后
-
crafted specification
I love JMX. It is a well crafted specification, #card
- 设计精心的规范
-
failed spectacularly
壮观的失败
Tags
Annotators
URL
-
-
www.ietf.org www.ietf.orgrfc23964
-
unlimited
无限的
-
specifies
指定,具体说明
-
an Internet standards track protocol
一个因特网标准协议
-
Memo
备忘录
-
-
Local file Local file
-
combination
组合
-
Prior to that
在那之前
-
period
句号
-
available
可获得的
-
backward compatibility
后向兼容
-
inconsistencies
不一致
-
complicated
复杂的,难懂的
-
FINDINGS
调查结果
-
这个PDF, 介绍了两种常见情况, 导致解析漏洞
- 使用了多个不同的URL解析器
- 实现标准之之间的冲突 然后举了log4j的例子
-
As it turns out,
结果是
-
irregular
不规律的
-
remedy
改正
-
countermeasures
对抗措施
-
originates
起源, 缘起
-
gist
要点, 大意
-
evaluated
对…作评价;【数】求…的值
-
affected
影响, 加载
-
primitives
原语
-
innovative research.
创新性的研究
-
Specification
标准
-
Incompatibility
不相容
-
Multiple
多重.多个
-
largely occurred
大部分发生, 基本上
-
inconsistencies
不一致,矛盾
-
joint research
联合研究
-
it is plausible
这是合理的
-
accurately
精确的
-
integral
不可缺少
-
-
github.com github.com
-
(I've heard there are problems here.)
我听说这里有问题
-
German
德国
-
lacking
不足
-
specifications
规范
-
presume
假设
-
a decimal number
十进制数
-
partial dot-addresses ("127.0")
部分点地址
-
accept backslashes instead of slashes
接受反斜线替代斜线
-
possibly a few using even more.
或者部分人使用的更多
-
'file' URLs are notoriously often malformed.
file协议声名狼藉的畸形
-
producer
生成器
-
zero to an infinite amount of slashes
0到无穷大数量的斜杠
-
hierarchical
分层, 使用所有网络使用的分层方案
-
Put simply,
简单的说
-
chances are
有可能, 后面接一个宾语从句
-
best-effort
尽力而为
-
Specification
规范
-
WHATWG
超文本应用技术工作组
-
Interop
URl相互操作, 冲突
Tags
Annotators
URL
-
-
hypothes.is hypothes.is
-
这个是这个页面的note
-
d running. It's time to start annotating some documents.
这个是一个测试评论
Tags
Annotators
URL
-