<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[Sowhat的blog]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[secway.org]]></description>
<link>http://hi.baidu.com/secway</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[激情奥运]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/eb4a7cb3bfab1ba1d9335ad5.html]]></link>
        <description><![CDATA[
		
		这届奥运会到目前为止, 十分精彩!<br>
<br>
<br>
独得八金的外星人,菲尔普斯<br>
<div forimg="1"><img border="0" src="http://hiphotos.baidu.com/secway/pic/item/0e92ed51b9e65d3c42a75bed.jpg" small="0" class="blogimg"></div>
<br>
回头张臂捶胸<strong>减速</strong>冲刺9.69秒的百米飞人博尔特<br>
<div forimg="1"><img border="0" src="http://hiphotos.baidu.com/secway/pic/item/fecfc01c6459f39387d6b6e9.jpg" small="0" class="blogimg"></div>
<br>
最后十多秒以一个一本绝地逆转的佟文<br>
 <a href="http://hi.baidu.com/secway/blog/item/eb4a7cb3bfab1ba1d9335ad5.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Misc">Misc</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/eb4a7cb3bfab1ba1d9335ad5.html#comment">查看评论</a>]]></description>
        <pubDate>2008-08-17  16:04</pubDate>
        <category><![CDATA[Misc]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/eb4a7cb3bfab1ba1d9335ad5.html</guid>
</item>

<item>
        <title><![CDATA[Pwnie Awards 2008最终获奖名单]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/5d2f479b2f6410b3c9eaf4e5.html]]></link>
        <description><![CDATA[
		
		<a href="http://pwnie-awards.org/2008/index.html" target="_blank">Pwnie Awards 2008</a>的最终获奖名单:<br>
<br>
<strong>Best Server-Side Bug: </strong><br>
<ul>
    <li>
    <p class="work">Windows IGMP kernel vulnerability <span class="cve">(<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0069">CVE-2007-0069</a>)</span></p>
    <p class="author">Discovered by: Alex Wheeler and Ryan Smith</p>
    <p>Not only did Alex Wheeler and Ryan Smith lay claim to a lucky CVE</p></li></ul> <a href="http://hi.baidu.com/secway/blog/item/5d2f479b2f6410b3c9eaf4e5.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/5d2f479b2f6410b3c9eaf4e5.html#comment">查看评论</a>]]></description>
        <pubDate>2008-08-12  10:37</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/5d2f479b2f6410b3c9eaf4e5.html</guid>
</item>

<item>
        <title><![CDATA[Impressing Girls with Vista Memory Protection Bypasses]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/bde7b0ce69f9bf0592457e42.html]]></link>
        <description><![CDATA[
		
		<a href="http://hi.baidu.com/secway/blog/item/24265597d5cff46855fb9627.html" target="_blank">期待已经</a>的paper终于出来了.<br>
<br>
<br>
Mark Dowd &amp; Alex Sotirov<br>
<a href="http://taossa.com/archive/bh08sotirovdowd.pdf" target="_blank">Impressing Girls with Vista Memory Protection Bypasses</a><br>
拜读. 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/bde7b0ce69f9bf0592457e42.html#comment">查看评论</a>]]></description>
        <pubDate>2008-08-08  22:31</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/bde7b0ce69f9bf0592457e42.html</guid>
</item>

<item>
        <title><![CDATA[MAPP (Microsoft Active Protections Program)]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/e80d8efad702c9d8b48f3111.html]]></link>
        <description><![CDATA[
		
		微软要在Blackhat Vegas的时候宣布推出MAPP.<br>
这个计划就是在补丁推出之前向AV,IPS等安全厂商提供漏洞细节.<br>
主要是为了保护微软客户吧, 因为从推出补丁到exploit出来的时间越来越短了, 黑白红绿蓝客经常比安全厂商还要快.<br>
<br>
当然这个计划不会向哪些卖漏洞和exp的厂商开放,比如CANVAS和CoreImpact.<br>
<br>
参与这个计划的标准包括:<br>
&nbsp;&nbsp;&nbsp;    * Members must offer commercial protection features to Microsoft customers against network- or host-based attacks.<br>
&nbsp;&nbsp;&nbsp;    * Member <a href="http://hi.baidu.com/secway/blog/item/e80d8efad702c9d8b48f3111.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/e80d8efad702c9d8b48f3111.html#comment">查看评论</a>]]></description>
        <pubDate>2008-08-05  23:12</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/e80d8efad702c9d8b48f3111.html</guid>
</item>

<item>
        <title><![CDATA[F-Secure Reverse Engineering Challenge]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/c6c5ef824dc7e2b96c8119a5.html]]></link>
        <description><![CDATA[
		
		F-Secure Reverse Engineering Challenge<br>
<a href="http://www.khallenge.com/" target="_blank">http://www.khallenge.com/</a><br>
<br>
Level One:<br>
<a href="http://www.khallenge.com/c3d679cda24c6c4543e4ede3a65a0b64/FSC08_Level1.zip" target="_blank">http://www.khallenge.com/c3d679cda24c6c4543e4ede3a65a0b64/FSC08_Level1.zip</a> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/c6c5ef824dc7e2b96c8119a5.html#comment">查看评论</a>]]></description>
        <pubDate>2008-08-01  17:54</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/c6c5ef824dc7e2b96c8119a5.html</guid>
</item>

<item>
        <title><![CDATA[Sexy Hacking]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/b6e68f035a70f18ed43f7c33.html]]></link>
        <description><![CDATA[
		
		<a href="http://sexyhacking.com/videos/" target="_blank">http://sexyhacking.com/</a><br>
<br>
&quot;Sexy Hacking is a series of online videos where <font color="#ff0000">sexy girls teach hacking techniques</font>, tips, how-to's, tools, social engineering, security industry news and spoofs. Why read some boring news article or lame documentation when you can get the goods demonstrated by a sexy hacker girl? This is real information security - just sexier. &quot; 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/b6e68f035a70f18ed43f7c33.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-30  07:59</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/b6e68f035a70f18ed43f7c33.html</guid>
</item>

<item>
        <title><![CDATA[测试你的DNS]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/8318008da1981814b21bba75.html]]></link>
        <description><![CDATA[
		
		一个基于网页的工具, 测试一下你的DNS是不是容易被人搞<a href="https://www.dns-oarc.net/oarc/services/dnsentropy" target="_blank"><br>
https://www.dns-oarc.net/oarc/services/dnsentropy</a><br>
<br>
测了一下我家的,ft.<br>
<br>
<div forimg="1"><img border="0" src="http://hiphotos.baidu.com/secway/pic/item/297b47a8cc8ea0a6cb130ce0.jpg" small="0" class="blogimg"></div>
<br>
 <a href="http://hi.baidu.com/secway/blog/item/8318008da1981814b21bba75.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/8318008da1981814b21bba75.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-28  10:34</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/8318008da1981814b21bba75.html</guid>
</item>

<item>
        <title><![CDATA[漏洞: Flashblock绕过]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/39131d063a10117d020881c3.html]]></link>
        <description><![CDATA[
		
		一个多月前还向大家<a href="http://hi.baidu.com/secway/blog/item/c3e62166ba929c21ab184cc1.html" target="_blank">推荐</a>Flashblock这个工具, 今天偶然发现, Flashblock+firefox3可以被轻易<strong>绕过</strong>.<br>
<br>
使用Flashblock的同学可以打开下面这个页面测试一下:<br>
<a href="http://secway.org/pr14/flashblock.htm" target="_blank">http://secway.org/pr14/flashblock.htm</a><br>
<br>
如果打开之后就能看到那个姑娘,说明你的flashblock被绕过了. (被youtube? youtube可以, 黑白客就可以)<br>
<br>
开发者Phil <a href="http://hi.baidu.com/secway/blog/item/39131d063a10117d020881c3.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/39131d063a10117d020881c3.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-25  19:17</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/39131d063a10117d020881c3.html</guid>
</item>

<item>
        <title><![CDATA[Hacker in the stree]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/2bc4feb16c655352092302fc.html]]></link>
        <description><![CDATA[
		
		黑掉公路上的显示牌<br>
<br>
<a href="http://www.youtube.com/watch?v=s-gUCb_L4b4" target="_blank">http://www.youtube.com/watch?v=s-gUCb_L4b4</a><br>
<br> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/%CE%DE%CB%F9%B2%BB%BA%DA">无所不黑</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/2bc4feb16c655352092302fc.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-25  12:57</pubDate>
        <category><![CDATA[无所不黑]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/2bc4feb16c655352092302fc.html</guid>
</item>

<item>
        <title><![CDATA[Skype Backdoor?]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/b6e68f03474acc8ed43f7c55.html]]></link>
        <description><![CDATA[
		
		<a href="http://www.heise-online.co.uk/security/Speculation-over-back-door-in-Skype--/news/111170" target="_blank">Speculation over back door in Skype </a><br>
<p><font color="#333399">There has long been speculation that Skype may contain a back door.</font> Because the vendor has not revealed details of its proprietary Skype protocol or of how the client works, questions as to what else Skype is capable of and what risks are involved in deploying it in an enterprise environment remain op</p> <a href="http://hi.baidu.com/secway/blog/item/b6e68f03474acc8ed43f7c55.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/b6e68f03474acc8ed43f7c55.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-25  10:22</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/b6e68f03474acc8ed43f7c55.html</guid>
</item>

<item>
        <title><![CDATA[DNS欺骗漏洞代码已公布, 打补丁吧]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/a022c5005df92d81e950cd48.html]]></link>
        <description><![CDATA[
		
		Dan Kaminsky报的<a href="http://www.kb.cert.org/vuls/id/800113" target="_blank">DNS欺骗漏洞</a>, 最近几个几个礼拜以来一直是焦点.<br>
故事的发展也很有戏剧性.<br>
<br>
在Microsoft, Cisco, Bind等各方联合发布补丁之后, 首先是质疑声一片, 很多人怀疑这个漏洞的威力,比如<a href="http://www.matasano.com/log/ " target="_blank"> matasano</a>.  但是后来他们和Dan电话交流过之后, 立马被折服, 承认这个漏洞很牛x.<br>
<br>
Dan同学打算去Blackhat Vegas做一个关于此漏洞的演讲, 所以细节也一直没有披露, 以为最起码能包到8 <a href="http://hi.baidu.com/secway/blog/item/a022c5005df92d81e950cd48.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/a022c5005df92d81e950cd48.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-24  08:55</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/a022c5005df92d81e950cd48.html</guid>
</item>

<item>
        <title><![CDATA[买电视]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/43ca5c2e2a9589564fc226ab.html]]></link>
        <description><![CDATA[
		
		奥运快来了, 没买到门票, 只能指望电视了.<br>
<br>
昨天跑去苏宁电器买电视, 放眼望去, 都是高清、LCD、平板、49寸。。。少说五六千，稍微nx点的，都在一万多两万。<br>
<br>
没钱，就想买个一千多块的。找了半天没找到，一千块似乎连21寸的纯屏都买不到。<br>
就在我累到快要绝望的时候，大老远看到一个nb闪闪放光芒的LCD电视，左上角贴个标签，&ldquo;1085元&rdquo;！<br>
wk，赶紧冲过去，难得啊，外型也很cool，才一千出头，这哪家厂商这么好啊。。。<br>
<br>
跑到跟前，刚想摸一下那电视，发现&ldquo;1085元&rdquo;左边还有两个 <a href="http://hi.baidu.com/secway/blog/item/43ca5c2e2a9589564fc226ab.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Misc">Misc</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/43ca5c2e2a9589564fc226ab.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-22  16:51</pubDate>
        <category><![CDATA[Misc]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/43ca5c2e2a9589564fc226ab.html</guid>
</item>

<item>
        <title><![CDATA[2008 Pwnie Award nominees announced]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/8704cd093c3de7226b60fbe4.html]]></link>
        <description><![CDATA[
		
		<a href="http://pwnie-awards.org/awards.html" target="_blank">Pwnie Award nominees</a><br>
<br>
wushi大牛的flash漏洞被提名Best Client-Side Bug. 这个要支持!<br>
<br>
Pwnie for Best Client-Side Bug<br>
<br>
<ul>
    <li>
    <p class="work">Adobe Flash DefineSceneAndFrameLabelData vulnerability <span class="cve">(<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0071">CVE-2007-0071</a>)</span></p>
    <p class="author">Discovered by: Mark Dowd and </p></li></ul> <a href="http://hi.baidu.com/secway/blog/item/8704cd093c3de7226b60fbe4.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/8704cd093c3de7226b60fbe4.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-22  08:28</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/8704cd093c3de7226b60fbe4.html</guid>
</item>

<item>
        <title><![CDATA[暴风影音0DAY]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/688e797b35d276f20ad18798.html]]></link>
        <description><![CDATA[
		
		dummy@pst公布了<a href="http://hi.baidu.com/dummy24/blog/item/dfc576dc2768b3a7cc116603.html" target="_blank">一个暴风影音的0day</a>, 挂马的同学又可以添新装备了, 因为这个漏洞可以通过浏览器远程触发.<br>
<br>
至于dummy说的&quot;<em><span style="font-size: 10.5pt;"><font face="宋体">因为此端口</font></span><span style="font-size: 10.5pt;"><font face="宋体">绑定的地址不是localhost, 从而导致此溢出</font></span><span style="font-size: 10.5pt;"><font face="宋体">可以</font></span></em> <a href="http://hi.baidu.com/secway/blog/item/688e797b35d276f20ad18798.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/688e797b35d276f20ad18798.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-20  20:59</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/688e797b35d276f20ad18798.html</guid>
</item>

<item>
        <title><![CDATA[How to parse the .doc file format [SWI]]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/3a5153a412f600f19052ee93.html]]></link>
        <description><![CDATA[
		
		天朝DOC圈day横行,学习一下怎么parse doc很有必要.<br>
<br>
How to parse the .doc file format<br>
<a href="http://blogs.technet.com/swi/archive/2008/07/18/how-to-parse-doc-file-format.aspx" target="_blank">http://blogs.technet.com/swi/archive/2008/07/18/how-to-parse-doc-file-format.aspx</a><br> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/3a5153a412f600f19052ee93.html#comment">查看评论</a>]]></description>
        <pubDate>2008-07-19  10:58</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/3a5153a412f600f19052ee93.html</guid>
</item>


</channel>
</rss>