×¢²á | µÇ¼ Íü¼ÇÃÜÂ룿 51ctoÊ×Ò³ | ²©¿Í | ÂÛ̳ | ÕÐÆ¸
ÈȵãÎÄÕ ÓÃÁËÊ®ÄêµÄQQºÅ£¬µÚ¶þ´Î±»..
¡¡°ïÖú
2008-09-02 08:14:10
  _____

·¢¼þÈË: SecuriTeam [mailto:
support@securiteam.com]
·¢ËÍʱ¼ä: 2008Äê8ÔÂ31ÈÕ 15:04
ÊÕ¼þÈË: html-list@securiteam.com
Ö÷Ìâ: [EXPL] Sun Solaris snoop SMB Exploit

 

The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com

- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
[ur..



2008-08-15 08:21:06
-----ÓʼþÔ­¼þ-----
·¢¼þÈË:
listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
´ú±í Andy Davis
·¢ËÍʱ¼ä: 2008Äê8ÔÂ13ÈÕ 5:14
ÊÕ¼þÈË: vuln-dev@securityfocus.com

Ö÷Ìâ: Step-by-step instructions for debugging Cisco IOS using gdb

Step-by-step instructions for debugging IOS using gdb - Andy Davis,
2008 (iosftpexploit "at" googlemail <dot> com):

I have been asked by many people for a simple step-by-step guide for
setting up an IOS..



2008-07-29 08:05:31
±ê Ìâ: ¡¾Ô­´´¡¿Ñ¸À×ЭÒé·ÖÎö
×÷ Õß: theOcrat
ʱ ¼ä: 2007-08-16,11:56
Á´ ½Ó:
http://bbs.pediy.com/showthread.php?t=49767

¡¾ÎÄÕ±êÌâ¡¿: Ñ¸À×ЭÒé·ÖÎö
¡¾ÎÄÕÂ×÷Õß¡¿: the0crat
¡¾ÓʼþµØÖ·¡¿: the0crat.cn_at_gmail.com
¡¾×÷ÕßÖ÷Ò³¡¿: http://the0crat.spaces.live.com
¡¾Éú²úÈÕÆÚ¡¿: 20070526
¡¾Èí¼þÃû³Æ¡¿: Thunder 5.5.6.274
¡¾Ê¹Óù¤¾ß¡¿: OD+Ethereal
¡¾×÷ÕßÉùÃ÷¡¿: ±¾ÎĽö¹©Ñо¿Ñ§Ï°£¬±¾È˶ÔÒòÕâÆªÎÄÕ¶øµ¼ÖµÄÒ»Çкó¹û£¬²»³Ðµ£Èκη¨ÂÉÔðÈΡ£±¾ÎÄÖеÄ..



2008-07-15 07:53:07
©¶´ËµÃ÷£ºQQ MailÊÇTencent¹«Ë¾ÌṩµÄwebmail·þÎñ£¬Äã¿ÉÒÔʹÓÃÄãµÄQQÕÊ»§À´µÇ½ʹÓÃMail·þÎñ£¬¾ßÌåµÄÐÅÏ¢¿ÉÒÔ·ÃÎÊ
http://mail.qq.com/¡£µ«ÊÇ80secÍŶӳÉÔ±ÔÚQQ MailÀï·¢ÏÖ´æÔÚ¿çÕ¾½Å±¾Â©¶´£¬¶ñÒâÓû§¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÓʼþÀïαÔìµÇ½±í
µ¥ÇÔȡĿ±êÓû§µÄÃÜÂëÒÔ¼°ÍµÈ¡CookieÒÔÈ¡µÃÆäËûÓû§µÄÉí·Ý£¬»òÕßʹÓÃajaxµÈ¼¼Êõ¶ÁÈ¡Óû§µÄÃô¸ÐÐÅÏ¢¡£

©¶´³ÉÒò£ºQQ MailµÄJavascript Dom²¿·ÖÔÚ´¦ÀíÓʼþÄÚÈÝ£¬¶ÔÓʼþÄÚÈÝ×Ö·û´®µÄ´¦Àí·ÖΪstrºÍcodeÁ½¸öÁ÷³Ì£¬Í¨¹ý×éºÏµÄ±êÇ©ÄÚ
ÈÝ¿ÉÒÔÎóµ¼Javascript´¦ÀíͼƬÄÚÈݺÍÎÄ×ÖÁ´½Ó½øÈëstrÁ÷³Ì£¬..



2008-06-27 08:35:51
Ëæ×Å SQL INJECTION ¹¥»÷µÄÃ÷ÏÔÔö¶à£¬Î¢Èí½üÈÕ·¢²¼ÁËÈý¸öÃâ·Ñ¹¤¾ß£¬°ïÖúÍøÕ¾¹ÜÀíÔ±ºÍ¼ì²â´æÔڵķçÏÕ²¢¶Ô¿ÉÄܵĹ¥»÷½øÐÐÀ¹½Ø¡£

Scrawlr
ÏÂÔØµØÖ·£º
https://download.spidynamics.com/Products/scrawlr/

Õâ¸ö΢ÈíºÍ HPºÏ×÷¿ª·¢µÄ¹¤¾ß£¬»áÔÚÍøÕ¾ÖÐÅÀÐУ¬¶ÔËùÓÐÍøÒ³µÄ²éѯ×Ö·û´®½øÐзÖÎö²¢·¢ÏÖÆäÖÐµÄ SQL INJECTION ·çÏÕ¡£Scrawlr ʹÓÃÁ˲¿·Ö HP WebInspect ÏàͬµÄ¼¼Êõ£¬µ«Ö»¼ì²â SQL INJECTION ·çÏÕ¡£Scrawlr ´ÓÒ»¸öÆðʼ URL Èë¿Ú£¬ÅÀ±éÕû¸öÍøÕ¾£¬²¢¶ÔÕ¾µãÖÐËùÓÐÍøÒ³½øÐзÖÎöÒÔÕÒµ½¿ÉÄÜ´æÔڵĩ¶´¡£

Microsoft Source Code..



2008-06-24 07:57:39
By dm

http://hi.baidu.com/int3/blog/item/201318c61bc9721e9c163d4d.html

 

 

Óв»ÉÙÅóÓÑÒ»Ö±ËËÓÁÎÒдÕâôһ¸öÂíºóÅÚ·ÖÎöµÄÎÄÕ£¬Ò²ÍÏÁ˺þã¬ÏÖÔڷųöÀ´ÁË¡£


Ê×ÏȸÐлMark Dowd·¢ÏÖÕâ¸ö©¶´²¢ÇÒ·ÖÏíÁËһЩ¹ØÓÚÕâ¸ö©¶´Í¨ÓÃÀûÓõķ½·¨¡£

ÔÙÔĶÁÕâÆªblog֮ǰ£¬ÇëÊì¶ÁMark Dowd¹ØÓÚFlash exploitµÄwhitepaperºÍFlash 9ÎÄ
¼þ¸ñʽÒÔ¼°Adobe¹ØÓÚAVM2µÄÏêϸÎĵµ¡£Ïȼòµ¥µÄ»Ø¹ËÒ»ÏÂflashÎļþ¸ñʽ£¬Ò»¸öSWFÎÄ
¼þÊÇÓÉSWF headerºÍÈô¸ÉtagÀ´×é³ÉµÄ¡£

SWF Header Format

 <[url]http://hiphotos.baidu.co..



2008-06-18 07:55:46
Author: wzt
EMail:
wzt@xsec.org
Site: http://www.xsec.org
Date: 2008-6-13

 

Ò». Ð÷ ÂÛ
¶þ. X86µÄÓ²¼þѰַ·½·¨
Èý. Äں˶ÔÒ³±íµÄÉèÖÃ
ËÄ. ʵÀý·ÖÎöÓ³Éä»úÖÆ


Ò». Ð÷ ÂÛ
ÎÒÃǾ­³£ÔÚ³ÌÐòµÄ·´»ã±à´úÂëÖп´µ½Ò»Ð©ÀàËÆ0x32118965ÕâÑùµÄµØÖ·£¬²Ù×÷ϵͳÖгÆÎª
ÏßÐÔµØÖ·£¬»òÐéÄâµØÖ·¡£ÐéÄâµØÖ·ÓÐʲôÓã¿ÐéÄâµØÖ·

ÓÖÊÇÈçºÎת»»ÎªÎïÀíÄÚ´æµØÖ·µÄÄØ£¿±¾Õ½«¶Ô´Ë×÷Ò»¸ö¼òÒª²ûÊö¡£
1.1 LinuxÄÚ´æÑ°Ö·¸ÅÊö
ÏÖ´úÒâÒåÉϵIJÙ×÷ϵͳ¶¼´¦ÓÚ32λ±£»¤Ä£Ê½Ï¡£Ã¿¸ö½ø³ÌÒ»°ã¶¼ÄÜѰַ4GµÄÎïÀí¿Õ¼ä¡£
µ«ÊÇÎÒÃǵÄÎïÀíÄÚ´..



2008-06-04 07:35:24
ÒÔÏÂÏûÏ¢À´×Ô»ÃÓ°ÂÛ̳[Ph4nt0m]Óʼþ×é
############################################################################
# MDaemon <== v9.6.5 Multiple Remote Buffer Overflow
#
# Vendor Site:
http://altn.com
#
# Risk : Highly Critical
# hehe funny bugs here .. the worldclient use the port 3000 for a webmail
like (it use also an admin webmail
# located at
# port 1000 [by default both are opened])
# this file unfortunatly contain multiple buffer overflows , If you send a
message to a u..



2008-06-03 07:36:40
×÷ÕßblogÉϵķÖÎöÓÐÅŰæÎÊÌ⣬ËùÒÔתµÄÊÇpediyÉϵġ£
-------------------------

±ê Ìâ: ¡¾Ô­´´¡¿flash©¶´ËùÓÃshellcodeµÄ·ÖÎö
×÷ Õß: ÐùԯС´Ï
ʱ ¼ä: 2008-06-02,19:29
Á´ ½Ó:
http://bbs.pediy.com/showthread.php?t=65907

×÷ÕßÖ÷Ò³: http://hi.baidu.com/yicong2007
Ä¿ µÄ: ´¿Êôѧϰ£¬ÇëÎðÓÃÓÚ¶ñÒâÓÃ;

×î½ü¼¸Ììflash©¶´µÄÍøÂí·Ç³£Á÷ÐУ¬ÓÚÊÇÎÒÏë·ÖÎöÒ»ÏÂshellcodeÊÇÔõôÅܵġ£

µ«ÊÇÄÜÁ¦ËùÏÞ£¬»¹ÄÑÒÔÏñ´óÅ£ÃÇÒ»Ñù¶¨Î»µ½ÓЩ¶´µÄ´úÂë¼°¹Û²ìÕû¸öÒç³ö¹ý³Ì¡£ÓÚ
ÊÇ£¬ÎÒÖ»ÄÜ×öºóÃæÒ»²¿·Ö¹¤×÷£¬¼´¿´¿´ÄǸö»ûÐ..



2008-06-02 07:33:22
http://www.80sec.com/release/phpwind-exploit.txt

©¶´·¢²¼£ºhttp://www.80sec.com/

©¶´×÷Õߣºjianxin@80sec.com

©¶´³§ÉÌ£º http://www.phpwind.com/
    PHPWind ÂÛ̳ϵͳ ÊÇÒ»ÌײÉÓà php+mysql Êý¾Ý¿â ·½Ê½ÔËÐв¢¿ÉÉú³É html Ò³ÃæµÄÈ«ÐÂÇÒÍêÉÆµÄÇ¿´óϵͳ¡£Òò¾ßÓзǷ²µÄ·ÃÎÊ
ËٶȺÍ׿ԽµÄ¸ºÔØÄÜÁ¦¶øÉîÊܹúÄÚÍâÅóÓѵÄϲ°®¡£
    ±¾Â©¶´Ó°ÏìphpwindËùÓа汾

©¶´Î£º¦£º¸ß

©¶´ËµÃ÷£ºphpwindÊǹúÄÚʹÓ÷dz£¹ã·ºµÄÒ»¿î³ÌÐò£¬ÓÉÓÚÔÚ³ÌÐ..



2008-05-28 07:44:48



2008-05-18 19:57:39



2008-05-13 16:48:56



2008-05-13 08:31:02



2008-05-09 08:15:17
ph4nt0m£¬ÄãºÃ
À´×Ô£º
www.csna.net
×÷Õߣºrobur
 
ǰÁ½ÌìÂòµÄ¹ýÆÚÔÓÖ¾ÉÏ¿´µ½µÄÒ»¿îÈí¼þ£¬¸Õ¿ªÊ¼»¹Ã»×¢Ò⣬ºóÀ´¾ÍºÞ×Ô¼ºÔÓÖ¾ÂòÍíÁË¡££¨½ñÄê3Ô·ݵġ¶ºÚ¿Í·ÀÏß¡·£©
ÄǸöÉñÆæµÄÈí¼þ£¬¾ÍÏñÎÒ±êÌâÉÏ˵µÄ£¬½ÐSSClone£¬½âÊÍÆðÀ´¾ÍÊÇ£ºSwitch Session Clone£¬Ò²¾ÍÊÇ"½»»»»ú»á»°¿Ë¡"£¨´¿×ÖÃæ·­Ò룬´¿µÄ¡« £©¡£

Õâ¸öÈí¼þÓÐʲôÓã¿ÆäÌØµã¾ÍÊÇ¿ÉÒÔ²»Í¨¹ý´«Í³µÄARPÆÛÆ­·½·¨£¬À´ÊµÏÖ¾ÖÓòÍøÄڵĻỰ¼àÌý¡¢½Ù³Ö¡¢¸´ÖƵȲÙ×÷¡££¨ÆäʵÕâ¸öÈí¼þ±¾ÉíÊÇÓÃÀ´»á»°¸´ÖƵģ¬Ò²¾ÍÊÇÀ¹½Ø¿Í»§»ú·¢Ë͸øÍø¹ØµÄÊý¾Ý°ü£¬Èç¹ûÀ¹½ØÍø¹Ø·¢Ë͸ø¿Í»§»..



 <<   1   2   3   4   >>   Ò³Êý ( 1/4 )