<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[  冷漠 ' Blog]]></title> 
<link>http://www.lengmo.net/index.php</link> 
<description><![CDATA[不求盡如人意,但求無愧於心]]></description> 
<language>en-US</language> 
<copyright><![CDATA[  冷漠 ' Blog]]></copyright>
<item>
<link>http://www.lengmo.net/post/1051/</link>
<title><![CDATA[不要在我寂寞的时候说爱我 MTV]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Recreation]]></category>
<pubDate>Fri, 25 Jul 2008 18:07:26 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1051/</guid> 
<description>
<![CDATA[ 
	不要在我寂寞的时候说爱我 ，感觉不错的一首歌··是我喜欢的风格··<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/mtv/" rel="tag">mtv</a> , <a href="http://www.lengmo.net/tags/mv/" rel="tag">mv</a> , <a href="http://www.lengmo.net/tags/%25E9%259F%25B3%25E4%25B9%2590/" rel="tag">音乐</a> , <a href="http://www.lengmo.net/tags/%25E5%25A8%25B1%25E4%25B9%2590/" rel="tag">娱乐</a> , <a href="http://www.lengmo.net/tags/%25E4%25B8%258D%25E8%25A6%2581%25E5%259C%25A8%25E6%2588%2591%25E5%25AF%2582%25E5%25AF%259E%25E7%259A%2584%25E6%2597%25B6%25E5%2580%2599%25E8%25AF%25B4%25E7%2588%25B1%25E6%2588%2591/" rel="tag">不要在我寂寞的时候说爱我</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1050/</link>
<title><![CDATA[Kaminsky DNS Cache Poisoning Flaw Exploit for Domains]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Fri, 25 Jul 2008 01:44:28 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1050/</guid> 
<description>
<![CDATA[ 
	&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;____&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;____&nbsp;&nbsp;&nbsp;&nbsp; __&nbsp;&nbsp;&nbsp;&nbsp;__<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; /&nbsp;&nbsp;&nbsp;&nbsp;&#92;&nbsp;&nbsp;&nbsp;&nbsp;/&nbsp;&nbsp;&nbsp;&nbsp;&#92;&nbsp;&nbsp; &#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;----====####/&nbsp;&nbsp;/&#92;__&#92;##/&nbsp;&nbsp;/&#92;&nbsp;&nbsp;&#92;##&#124;&nbsp;&nbsp;&#124;##&#124;&nbsp;&nbsp;&#124;####====----<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;__&#124;&nbsp;&nbsp;&#124; &#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;___ &#124;&nbsp;&nbsp; __&nbsp;&nbsp; &#124; &#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;&nbsp;&nbsp;&#124;<br/>&nbsp;&nbsp;------======######&#92;&nbsp;&nbsp;&#92;/&nbsp;&nbsp;/#&#124;&nbsp;&nbsp;&#124;##&#124;&nbsp;&nbsp;&#124;#&#124;&nbsp;&nbsp;&#124;##&#124;&nbsp;&nbsp;&#124;######======------<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/dns/" rel="tag">dns</a> , <a href="http://www.lengmo.net/tags/cache_poisoning_flaw/" rel="tag">cache poisoning flaw</a> , <a href="http://www.lengmo.net/tags/exploit/" rel="tag">exploit</a> , <a href="http://www.lengmo.net/tags/bug/" rel="tag">bug</a> , <a href="http://www.lengmo.net/tags/exp/" rel="tag">exp</a> , <a href="http://www.lengmo.net/tags/%25E6%25BC%258F%25E6%25B4%259E/" rel="tag">漏洞</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1048/</link>
<title><![CDATA[wscan v3.0 (保证是你用过的最好的WEB扫描器)]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Tools]]></category>
<pubDate>Wed, 23 Jul 2008 04:42:08 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1048/</guid> 
<description>
<![CDATA[ 
	来源：C.R.S.T<br/>wscan V3.0 - Network Security Scanner (By cooldiyer Jul 22 2008)<br/>usage: wscan <-v> <-h Host> <-r RulesFile> <-p Port> <-m MaxThread><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <-t Timeout> <-l LogFile><br/>Example:<br/>&nbsp;&nbsp;> wscan -h <a href="http://www.baidu.com" target="_blank">www.baidu.com</a> -r cgi.txt -p 80 -m 10 -t 3<br/>............<br/>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1047/</link>
<title><![CDATA[网络信息风险评估的常用方法剖析]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[InformationSecurity]]></category>
<pubDate>Tue, 22 Jul 2008 01:09:12 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1047/</guid> 
<description>
<![CDATA[ 
	作者: Netlinking<br/>在风险评估过程中，可以采用多种操作方法，包括基于知识(Knowledge-based)的分析方法、基于模型(Model-based)的分析方法、定性(Qualitative)分析和定量(Quantitative)分析，无论何种方法，共同的目标都是找出组织信息资产面临的风险及其影响，以及目前安全水平与组织安全需求之间的差距。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/%25E9%25A3%258E%25E9%2599%25A9%25E8%25AF%2584%25E4%25BC%25B0/" rel="tag">风险评估</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%2589%25E5%2585%25A8%25E8%25AF%2584%25E4%25BC%25B0/" rel="tag">安全评估</a> , <a href="http://www.lengmo.net/tags/%25E4%25BF%25A1%25E6%2581%25AF%25E5%25AE%2589%25E5%2585%25A8/" rel="tag">信息安全</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%2589%25E5%2585%25A8%25E9%259C%2580%25E6%25B1%2582/" rel="tag">安全需求</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1046/</link>
<title><![CDATA[Z-blog又一严重跨站脚本攻击漏洞]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Mon, 21 Jul 2008 13:45:05 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1046/</guid> 
<description>
<![CDATA[ 
	来源：80 sec<br/><strong><a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">漏洞</a>说明：</strong>Z-<a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">Blog</a>是一款基于Asp平台的Blog博客(网志)程序，支持Wap，支持Firefox，Oprea等浏览器，在国内使用非常广泛，官方主页在<a href="http://www.rainbowsoft.org/" target="_blank">http://www.rainbowsoft.org/</a>。Z-blog代码严谨，前台功能简洁，后台功能强大，这为它的产品安全带来很大的优势，但是在上次的xss漏洞被公布后，80sec在产品中又发现一个严重的跨站脚本攻击漏洞，加上产品设计上的一些问题可能带来严重的后果。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/z-blog/" rel="tag">z-blog</a> , <a href="http://www.lengmo.net/tags/bug/" rel="tag">bug</a> , <a href="http://www.lengmo.net/tags/exploit/" rel="tag">exploit</a> , <a href="http://www.lengmo.net/tags/%25E8%25B7%25A8%25E7%25AB%2599/" rel="tag">跨站</a> , <a href="http://www.lengmo.net/tags/%25E8%2584%259A%25E6%259C%25AC/" rel="tag">脚本</a> , <a href="http://www.lengmo.net/tags/%25E6%25BC%258F%25E6%25B4%259E/" rel="tag">漏洞</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1045/</link>
<title><![CDATA[抵达廊坊]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[MyLife]]></category>
<pubDate>Sat, 19 Jul 2008 17:26:40 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1045/</guid> 
<description>
<![CDATA[ 
	最近真是好累啊··昨天还在北京的，今天就已经到廊坊了··· 昨天在北京白天和客户沟通<a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">渗透测试</a>报告，每个应用系统的管理员一个个讲一遍，讲得我口干舌燥的，心里又着急的不得了··因为晚上 8 点多的火车来廊坊的··都 6 点了，还有好几个应用系统没有讲，真是不急都不行哈··一直到 7 点左右才算讲完了···<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/%25E5%2587%25BA%25E5%25B7%25AE/" rel="tag">出差</a> , <a href="http://www.lengmo.net/tags/%25E5%25BB%258A%25E5%259D%258A/" rel="tag">廊坊</a> , <a href="http://www.lengmo.net/tags/%25E9%2585%2592%25E5%25BA%2597/" rel="tag">酒店</a> , <a href="http://www.lengmo.net/tags/%25E7%2594%259F%25E6%25B4%25BB/" rel="tag">生活</a> , <a href="http://www.lengmo.net/tags/%25E6%2584%259F%25E5%258F%2597/" rel="tag">感受</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1044/</link>
<title><![CDATA[配置IIS蜜罐抵御黑客攻击]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Technology]]></category>
<pubDate>Sat, 19 Jul 2008 16:09:48 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1044/</guid> 
<description>
<![CDATA[ 
	来源：51CTO<br/>据有关资料显示，现在有大量的服务器仍在使用IIS提供Web服务，甚至有争夺占领Apache市场的趋势。在Web威胁日益严重的今天，我们当然要采用反病毒、防火墙、UTM、NAC等手段来加强网络安全。但是，有时正确地建设一个蜜罐也是对付<a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">黑客</a>的必需任务。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/iis/" rel="tag">iis</a> , <a href="http://www.lengmo.net/tags/%25E8%259C%259C%25E7%25BD%2590/" rel="tag">蜜罐</a> , <a href="http://www.lengmo.net/tags/honeypot/" rel="tag">honeypot</a> , <a href="http://www.lengmo.net/tags/%25E5%2585%25A5%25E4%25BE%25B5%25E6%25A3%2580%25E6%25B5%258B/" rel="tag">入侵检测</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1043/</link>
<title><![CDATA[Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Sat, 19 Jul 2008 15:30:33 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1043/</guid> 
<description>
<![CDATA[ 
	#!/usr/bin/python<br/>#<br/>#&nbsp;&nbsp; _____ _&nbsp;&nbsp; _ _____&nbsp;&nbsp;_____ _____ _____<br/>#&nbsp;&nbsp;/&nbsp;&nbsp;___&#124; &#124;_&#124; &#124;&nbsp;&nbsp;_&nbsp;&nbsp;&#92;&#124;&nbsp;&nbsp;_&nbsp;&nbsp;&#124;&nbsp;&nbsp;_&nbsp;&nbsp;&#124;_&nbsp;&nbsp; _&#124;<br/>#&nbsp;&nbsp;&#124; (___&#124;&nbsp;&nbsp;_&nbsp;&nbsp;&#124; [_)_/&#124; (_) &#124; (_) &#124; &#124; &#124;<br/>#&nbsp;&nbsp;&#92;_____&#124;_&#124; &#124;_&#124;_&#124; &#124;_&#124;&#124;_____&#124;_____&#124; &#124;_&#124;<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; C. H. R. O. O. T.&nbsp;&nbsp;SECURITY&nbsp;&nbsp;GROUP<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/apache/" rel="tag">apache</a> , <a href="http://www.lengmo.net/tags/mod_jk/" rel="tag">mod jk</a> , <a href="http://www.lengmo.net/tags/exploit/" rel="tag">exploit</a> , <a href="http://www.lengmo.net/tags/exp/" rel="tag">exp</a> , <a href="http://www.lengmo.net/tags/%25E6%25BC%258F%25E6%25B4%259E/" rel="tag">漏洞</a> , <a href="http://www.lengmo.net/tags/bug/" rel="tag">bug</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1042/</link>
<title><![CDATA[Oracle数据库安全性设计建议]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Technology]]></category>
<pubDate>Thu, 17 Jul 2008 04:40:04 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1042/</guid> 
<description>
<![CDATA[ 
	<strong>一、 什么是安全的系统</strong><br/><br/>安全性建设是一个长期并且卓绝的工作。作为一个符合标准的企业级系统，我们认为税务系统应该具备以下的安全性特点：<br/> 高可用性<br/> 对敏感数据的访问控制能力。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/oracle/" rel="tag">oracle</a> , <a href="http://www.lengmo.net/tags/%25E6%2595%25B0%25E6%258D%25AE%25E5%25BA%2593/" rel="tag">数据库</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%2589%25E5%2585%25A8%25E5%25AE%25A1%25E8%25AE%25A1/" rel="tag">安全审计</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%25A1%25E8%25AE%25A1/" rel="tag">审计</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%2589%25E5%2585%25A8%25E6%25A3%2580%25E6%259F%25A5/" rel="tag">安全检查</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1041/</link>
<title><![CDATA[MYSQL Injection IDS]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Tools]]></category>
<pubDate>Wed, 16 Jul 2008 01:31:08 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1041/</guid> 
<description>
<![CDATA[ 
	出处:80sec<br/>函数严格限制SQL文里出现<br/><br/>　　###########################################<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/mysql/" rel="tag">mysql</a> , <a href="http://www.lengmo.net/tags/injection/" rel="tag">injection</a> , <a href="http://www.lengmo.net/tags/ids/" rel="tag">ids</a> , <a href="http://www.lengmo.net/tags/%25E6%25B3%25A8%25E5%2585%25A5/" rel="tag">注入</a> , <a href="http://www.lengmo.net/tags/%25E5%2585%25A5%25E4%25BE%25B5%25E6%25A3%2580%25E6%25B5%258B/" rel="tag">入侵检测</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1040/</link>
<title><![CDATA[Microsoft Office Snapshot Viewer ActiveX Exploit (可执行版) ]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Tue, 15 Jul 2008 01:26:05 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1040/</guid> 
<description>
<![CDATA[ 
	来源：baicker <br/>网上的都是放启动项，这个可以自动执行<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/office/" rel="tag">office</a> , <a href="http://www.lengmo.net/tags/snapshot_viewer/" rel="tag">snapshot viewer</a> , <a href="http://www.lengmo.net/tags/activex/" rel="tag">activex</a> , <a href="http://www.lengmo.net/tags/exploit/" rel="tag">exploit</a> , <a href="http://www.lengmo.net/tags/exp/" rel="tag">exp</a> , <a href="http://www.lengmo.net/tags/%25E6%25BC%258F%25E6%25B4%259E/" rel="tag">漏洞</a> , <a href="http://www.lengmo.net/tags/bug/" rel="tag">bug</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1039/</link>
<title><![CDATA[浅析企业信息安全管理体系建设]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[InformationSecurity]]></category>
<pubDate>Mon, 14 Jul 2008 09:35:14 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1039/</guid> 
<description>
<![CDATA[ 
	来源：IT 专家网<br/>时至今日，“信息”作为一种商业资产，其所拥有的价值对于一个企业而言毋庸置疑，重要性也是与日俱增。信息安全，按照国际标准化组织提出的ISO/IEC 27000中的概念，需要保证信息的“保密性”、“完整性”和“可用性”。通俗地讲，就是要保护信息免受来自各方面的威胁，从而确保一个企业或机构可持续发展。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/%25E4%25BF%25A1%25E6%2581%25AF%25E5%25AE%2589%25E5%2585%25A8/" rel="tag">信息安全</a> , <a href="http://www.lengmo.net/tags/%25E4%25BD%2593%25E7%25B3%25BB%25E6%259E%25B6%25E6%259E%2584/" rel="tag">体系架构</a> , <a href="http://www.lengmo.net/tags/%25E8%25A7%25A3%25E5%2586%25B3%25E6%2596%25B9%25E6%25A1%2588/" rel="tag">解决方案</a> , <a href="http://www.lengmo.net/tags/%25E9%259C%2580%25E6%25B1%2582%25E5%2588%2586%25E6%259E%2590/" rel="tag">需求分析</a> , <a href="http://www.lengmo.net/tags/%25E5%25A8%2581%25E8%2583%2581%25E5%2588%2586%25E6%259E%2590/" rel="tag">威胁分析</a> , <a href="http://www.lengmo.net/tags/%25E5%25AE%2589%25E5%2585%25A8%25E7%25AD%2596%25E7%2595%25A5/" rel="tag">安全策略</a> , <a href="http://www.lengmo.net/tags/%25E7%258E%25B0%25E7%258A%25B6%25E5%2588%2586%25E6%259E%2590/" rel="tag">现状分析</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1038/</link>
<title><![CDATA[百度的JS数据流注入型跨站]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Sun, 13 Jul 2008 14:02:59 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1038/</guid> 
<description>
<![CDATA[ 
	来源：0×37 Security<br/><br/>今天看到的百度贴吧XSS有属于这种类型的，不过仅在FF下有效，原因是在GBK字符集及其子集（或更高级的双字节字符集）编码环境下构造类似于包含%c1′这样的双字节字符串时，提交给服务端，返回。在这整个处理过程的任何一环节，FF都会单独处理这两个字节（%c1与’），而服务端却认为这是一个完整的双字节字符，这导致了单引号这样的特殊字符可以侥幸在FF下残留下来。IE不行，那是因为它也认为这两个字节构成了一个双字节字符。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/baidu/" rel="tag">baidu</a> , <a href="http://www.lengmo.net/tags/%25E7%2599%25BE%25E5%25BA%25A6/" rel="tag">百度</a> , <a href="http://www.lengmo.net/tags/%25E8%25B7%25A8%25E7%25AB%2599/" rel="tag">跨站</a> , <a href="http://www.lengmo.net/tags/js_%25E6%25B3%25A8%25E5%2585%25A5/" rel="tag">js 注入</a> , <a href="http://www.lengmo.net/tags/injection/" rel="tag">injection</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1037/</link>
<title><![CDATA[PHP 168 SQL注射漏洞]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Bug&amp;Exp]]></category>
<pubDate>Sat, 12 Jul 2008 11:24:02 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1037/</guid> 
<description>
<![CDATA[ 
	来源：80 sec<br/><strong><a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">漏洞</a>说明：</strong>历经数年开发与完善的”PHP168整站系统”是国内最早的多功能模块化网站管理<a href="http://www.lengmo.net" target="_blank" title="http://www.lengmo.net" class="mykeyword">软件</a>系统；不仅适合于建设一般的企业、政府、学校、个人等小型网站，同时也适合于建设地区门户、行业门户、收费网站等大中型网站，80sec在其产品中发现了一个严重的SQL注射漏洞，可能被恶意用户查询数据库的敏感信息，如管理员密码，加密key等等，从而控制整个网站。<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/php_168/" rel="tag">php 168</a> , <a href="http://www.lengmo.net/tags/%25E6%25B3%25A8%25E5%2585%25A5/" rel="tag">注入</a> , <a href="http://www.lengmo.net/tags/%25E6%25BC%258F%25E6%25B4%259E/" rel="tag">漏洞</a> , <a href="http://www.lengmo.net/tags/sql_injection/" rel="tag">sql injection</a> , <a href="http://www.lengmo.net/tags/sql_%25E6%25B3%25A8%25E5%2585%25A5/" rel="tag">sql 注入</a> , <a href="http://www.lengmo.net/tags/bug/" rel="tag">bug</a> , <a href="http://www.lengmo.net/tags/exp/" rel="tag">exp</a> , <a href="http://www.lengmo.net/tags/exploit/" rel="tag">exploit</a>
]]>
</description>
</item><item>
<link>http://www.lengmo.net/post/1036/</link>
<title><![CDATA[ Microsoft SQL Server SA权限最新入侵方法]]></title> 
<author>!4p47hy &lt;l3n6m0@gmail.com&gt;</author>
<category><![CDATA[Technology]]></category>
<pubDate>Fri, 11 Jul 2008 05:30:43 +0000</pubDate> 
<guid>http://www.lengmo.net/post/1036/</guid> 
<description>
<![CDATA[ 
	作者: 王岗 出处:51CTO.com<br/><br/>在获得SA密码后，往往因为服务器管理者或”前人”将net.exe和net1.exe被限制使用，无法添加管理员账号。我们知道VBS在活动目录(ADSI)部分有一个winnt对象，用来管理本地资源，利用它可以不依靠CMD等命令就能添加一个管理员，具体代码如下：<br/>............<br/><br/>Tags - <a href="http://www.lengmo.net/tags/sql_server/" rel="tag">sql server</a> , <a href="http://www.lengmo.net/tags/sa/" rel="tag">sa</a> , <a href="http://www.lengmo.net/tags/%25E6%258F%2590%25E6%259D%2583/" rel="tag">提权</a> , <a href="http://www.lengmo.net/tags/%25E5%2585%25A5%25E4%25BE%25B5/" rel="tag">入侵</a>
]]>
</description>
</item>
</channel>
</rss>