×¢²á | µÇ¼ Íü¼ÇÃÜÂ룿 51ctoÊ×Ò³ | ²©¿Í | ÂÛ̳ | ÕÐÆ¸
ÈȵãÎÄÕ ÅäÖÃÉóºËµÄʵʩ
¡¡°ïÖú
2008-07-15 07:53:07
©¶´ËµÃ÷£ºQQ MailÊÇTencent¹«Ë¾ÌṩµÄwebmail·þÎñ£¬Äã¿ÉÒÔʹÓÃÄãµÄQQÕÊ»§À´µÇ½ʹÓÃMail·þÎñ£¬¾ßÌåµÄÐÅÏ¢¿ÉÒÔ·ÃÎÊ
http://mail.qq.com/¡£µ«ÊÇ80secÍŶӳÉÔ±ÔÚQQ MailÀï·¢ÏÖ´æÔÚ¿çÕ¾½Å±¾Â©¶´£¬¶ñÒâÓû§¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÓʼþÀïαÔìµÇ½±í
µ¥ÇÔȡĿ±êÓû§µÄÃÜÂëÒÔ¼°ÍµÈ¡CookieÒÔÈ¡µÃÆäËûÓû§µÄÉí·Ý£¬»òÕßʹÓÃajaxµÈ¼¼Êõ¶ÁÈ¡Óû§µÄÃô¸ÐÐÅÏ¢¡£

©¶´³ÉÒò£ºQQ MailµÄJavascript Dom²¿·ÖÔÚ´¦ÀíÓʼþÄÚÈÝ£¬¶ÔÓʼþÄÚÈÝ×Ö·û´®µÄ´¦Àí·ÖΪstrºÍcodeÁ½¸öÁ÷³Ì£¬Í¨¹ý×éºÏµÄ±êÇ©ÄÚ
ÈÝ¿ÉÒÔÎóµ¼Javascript´¦ÀíͼƬÄÚÈݺÍÎÄ×ÖÁ´½Ó½øÈëstrÁ÷³Ì£¬..



2008-06-27 08:35:51
Ëæ×Å SQL INJECTION ¹¥»÷µÄÃ÷ÏÔÔö¶à£¬Î¢Èí½üÈÕ·¢²¼ÁËÈý¸öÃâ·Ñ¹¤¾ß£¬°ïÖúÍøÕ¾¹ÜÀíÔ±ºÍ¼ì²â´æÔڵķçÏÕ²¢¶Ô¿ÉÄܵĹ¥»÷½øÐÐÀ¹½Ø¡£

Scrawlr
ÏÂÔØµØÖ·£º
https://download.spidynamics.com/Products/scrawlr/

Õâ¸ö΢ÈíºÍ HPºÏ×÷¿ª·¢µÄ¹¤¾ß£¬»áÔÚÍøÕ¾ÖÐÅÀÐУ¬¶ÔËùÓÐÍøÒ³µÄ²éѯ×Ö·û´®½øÐзÖÎö²¢·¢ÏÖÆäÖÐµÄ SQL INJECTION ·çÏÕ¡£Scrawlr ʹÓÃÁ˲¿·Ö HP WebInspect ÏàͬµÄ¼¼Êõ£¬µ«Ö»¼ì²â SQL INJECTION ·çÏÕ¡£Scrawlr ´ÓÒ»¸öÆðʼ URL Èë¿Ú£¬ÅÀ±éÕû¸öÍøÕ¾£¬²¢¶ÔÕ¾µãÖÐËùÓÐÍøÒ³½øÐзÖÎöÒÔÕÒµ½¿ÉÄÜ´æÔڵĩ¶´¡£

Microsoft Source Code..



2008-06-24 07:57:39
By dm

http://hi.baidu.com/int3/blog/item/201318c61bc9721e9c163d4d.html

 

 

Óв»ÉÙÅóÓÑÒ»Ö±ËËÓÁÎÒдÕâôһ¸öÂíºóÅÚ·ÖÎöµÄÎÄÕ£¬Ò²ÍÏÁ˺þã¬ÏÖÔڷųöÀ´ÁË¡£


Ê×ÏȸÐлMark Dowd·¢ÏÖÕâ¸ö©¶´²¢ÇÒ·ÖÏíÁËһЩ¹ØÓÚÕâ¸ö©¶´Í¨ÓÃÀûÓõķ½·¨¡£

ÔÙÔĶÁÕâÆªblog֮ǰ£¬ÇëÊì¶ÁMark Dowd¹ØÓÚFlash exploitµÄwhitepaperºÍFlash 9ÎÄ
¼þ¸ñʽÒÔ¼°Adobe¹ØÓÚAVM2µÄÏêϸÎĵµ¡£Ïȼòµ¥µÄ»Ø¹ËÒ»ÏÂflashÎļþ¸ñʽ£¬Ò»¸öSWFÎÄ
¼þÊÇÓÉSWF headerºÍÈô¸ÉtagÀ´×é³ÉµÄ¡£

SWF Header Format

 <[url]http://hiphotos.baidu.co..



2008-06-04 07:35:24
ÒÔÏÂÏûÏ¢À´×Ô»ÃÓ°ÂÛ̳[Ph4nt0m]Óʼþ×é
############################################################################
# MDaemon <== v9.6.5 Multiple Remote Buffer Overflow
#
# Vendor Site:
http://altn.com
#
# Risk : Highly Critical
# hehe funny bugs here .. the worldclient use the port 3000 for a webmail
like (it use also an admin webmail
# located at
# port 1000 [by default both are opened])
# this file unfortunatly contain multiple buffer overflows , If you send a
message to a u..



2008-06-03 07:36:40
×÷ÕßblogÉϵķÖÎöÓÐÅŰæÎÊÌ⣬ËùÒÔתµÄÊÇpediyÉϵġ£
-------------------------

±ê Ìâ: ¡¾Ô­´´¡¿flash©¶´ËùÓÃshellcodeµÄ·ÖÎö
×÷ Õß: ÐùԯС´Ï
ʱ ¼ä: 2008-06-02,19:29
Á´ ½Ó:
http://bbs.pediy.com/showthread.php?t=65907

×÷ÕßÖ÷Ò³: http://hi.baidu.com/yicong2007
Ä¿ µÄ: ´¿Êôѧϰ£¬ÇëÎðÓÃÓÚ¶ñÒâÓÃ;

×î½ü¼¸Ììflash©¶´µÄÍøÂí·Ç³£Á÷ÐУ¬ÓÚÊÇÎÒÏë·ÖÎöÒ»ÏÂshellcodeÊÇÔõôÅܵġ£

µ«ÊÇÄÜÁ¦ËùÏÞ£¬»¹ÄÑÒÔÏñ´óÅ£ÃÇÒ»Ñù¶¨Î»µ½ÓЩ¶´µÄ´úÂë¼°¹Û²ìÕû¸öÒç³ö¹ý³Ì¡£ÓÚ
ÊÇ£¬ÎÒÖ»ÄÜ×öºóÃæÒ»²¿·Ö¹¤×÷£¬¼´¿´¿´ÄǸö»ûÐ..



2008-05-28 07:44:48



2008-05-18 19:57:39



2008-05-13 08:31:02



2008-05-09 08:15:17
ph4nt0m£¬ÄãºÃ
À´×Ô£º
www.csna.net
×÷Õߣºrobur
 
ǰÁ½ÌìÂòµÄ¹ýÆÚÔÓÖ¾ÉÏ¿´µ½µÄÒ»¿îÈí¼þ£¬¸Õ¿ªÊ¼»¹Ã»×¢Ò⣬ºóÀ´¾ÍºÞ×Ô¼ºÔÓÖ¾ÂòÍíÁË¡££¨½ñÄê3Ô·ݵġ¶ºÚ¿Í·ÀÏß¡·£©
ÄǸöÉñÆæµÄÈí¼þ£¬¾ÍÏñÎÒ±êÌâÉÏ˵µÄ£¬½ÐSSClone£¬½âÊÍÆðÀ´¾ÍÊÇ£ºSwitch Session Clone£¬Ò²¾ÍÊÇ"½»»»»ú»á»°¿Ë¡"£¨´¿×ÖÃæ·­Ò룬´¿µÄ¡« £©¡£

Õâ¸öÈí¼þÓÐʲôÓã¿ÆäÌØµã¾ÍÊÇ¿ÉÒÔ²»Í¨¹ý´«Í³µÄARPÆÛÆ­·½·¨£¬À´ÊµÏÖ¾ÖÓòÍøÄڵĻỰ¼àÌý¡¢½Ù³Ö¡¢¸´ÖƵȲÙ×÷¡££¨ÆäʵÕâ¸öÈí¼þ±¾ÉíÊÇÓÃÀ´»á»°¸´ÖƵģ¬Ò²¾ÍÊÇÀ¹½Ø¿Í»§»ú·¢Ë͸øÍø¹ØµÄÊý¾Ý°ü£¬Èç¹ûÀ¹½ØÍø¹Ø·¢Ë͸ø¿Í»§»..



2008-05-09 08:07:39



2008-05-08 07:52:11
ÒÔÏÂÏûÏ¢À´×Ô»ÃÓ°ÂÛ̳[Ph4nt0m]Óʼþ×é
 
Adobe Acrobat Professional Javascript For PDF Security Feature Bypass and Memory Corruption Vulnerabilities
 
by cocoruder(frankruder_at_hotmail.com)
http://ruder.cdut.net

Summary:
    Two critical vulnerabilities exist in the javascript API of Adobe Acrobat Professional 7. A remote attacker who successfully exploits these vulnerabilities can execute restricted functions and arbitrary codes on the affected syste..



2008-05-07 09:43:43
ÒÔÏÂÏûÏ¢À´×Ô»ÃÓ°ÂÛ̳[Ph4nt0m]Óʼþ×é
 
Ô­PAPERµØÖ·£º
http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf

 
          author : kj021320
          team :  I.S.T.O
 
            ×î½ü氡æ°¡µÄ£¬½ñÌìÖÕÓÚÓеãµãʱ¼ä³é³öÀ´¿´¿´¼¼ÊõÎÄÕÂÁË£¬×î½ü¹úÍâÓÖ³öÁ˹ØÓÚÐÂÐÍORA×¢Èë¼¼ÊõµÄPAPER£¬¸Ï½ô²âÊÔ£¬Ö÷ÒªÊdzöÏÖÔÚSQLÓï..



2008-05-07 09:41:31



2008-05-04 08:23:13



2008-04-25 08:24:37
ÒÔÏÂÏûÏ¢À´×Ô»ÃÓ°ÂÛ̳[Ph4nt0m]Óʼþ×é

˵ʵ»°flashget2.0Ò»µãÒ²²»ºÃÓÃ
ÔÚmsÍÏwin 2k3¶¼ÍÏÁ˼¸Ìì
×îºóһŭ֮ÏÂ×°Á˸ö1¡£7¼¸µÄ°æ±¾²»µ½Ò»¸öÉÏÎç¸ã¶¨
а汾¼È²»Îȶ¨Ëã·¨ÓֲÈÃÈËÄÑÒÔ½ÓÊÜ


2008/4/23 remax <
remax.z@gmail.com>:

Ò²¾ÍÖ»ÄÜd.o.sÁ˰É..




On 4ÔÂ23ÈÕ, ÏÂÎç9ʱ53·Ö, "kook1991" <wek...@163.com> wrote:
> FlashGet 2.0 Õýʽ°æµÄ0day ÔçÔÚ2.0bate°æ¾ÍÓÐÕâ¸öBUG µ±Ê±·¢ÏÖÁ˵«ÊDZȽÏæ¾ÍÈÓÏÂÁË
>
> ½ñÌì¿´¼û³öÕýʽ°æÁË ÏÂÔØ»ØÀ´ÊÔÁËһϠÈí¼þ¸üРBUGÓÌÔÚ ÓÚÊǺõ°ÑPOC·Å³öÀ..



 <<   1   2   3   >>   Ò³Êý ( 1/3 )