pengkobe / blog Goto Github PK
View Code? Open in Web Editor NEWsource code of my blog. build with express && mongodb
License: MIT License
source code of my blog. build with express && mongodb
License: MIT License
只有文字太单调了...
内空!
现在主要是为了个人使用,需要整理出一个大家都可使用的版本,同时有重整架构的想法!
顿时感觉身体被掏空。
阿里云前两天才发的漏洞:MongoDB数据库未授权访问漏洞及加固,本打算这个周末补补的,结果今早打开博客一看,只剩一个空壳子了,我想,这是至今为止,互联网给我上的最惨痛的一堂课了吧。
开启MongoDB服务时不添加任何参数时,默认是没有权限验证的,登录的用户可以通过默认端口无需密码对数据库任意操作(增删改高危动作)而且可以远程访问数据库。
在刚安装完毕的时候 MongoDB 都默认有一个 admin 数据库,此时admin数据库是空的,没有记录权限相关的信息!当admin.system.users一个用户都没有时,即使 mongod 启动时添加了 —auth 参数,如果没有在 admin 数据库中添加用户,此时不进行任何认证还是可以做任何操作(不管是否是以 —auth 参数启动),直到在 admin.system.users 中添加了一个用户。加固的核心是只有在 admin.system.users 中添加用户之后, mongodb 的认证,授权服务才能生效。
这种风格简约大气,让人一目了然,博客风格可以借鉴。
pv/err/clicks...
样式错乱
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.