<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>lengmonanhai</title>
  <link>http://lengmonanhai.blogbus.com</link>
  <description><![CDATA[lengmonanhai的博客大巴空间]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Thu, 01 Jan 1970 07:00:00 +0700</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/profile/4/0/7/4336704/avatar_4336704_96.jpg</url>
									<title>lengmonanhai</title>
									<link>http://lengmonanhai.blogbus.com</link>
								</image>  <item>
   <title>Perl脚本打造自己简单的XSS Proof of Concept</title>
   <description><![CDATA[刚学了几天Perl，最近在学校站点上逛，偶然发现freescale实验室网站的留言本有XSS漏洞（图1），于是就打算用它来练习写一个Perl的测试程序，介绍小菜入门的文章，高手略过。<br /><br />XSS大家都熟悉的很，细节就不赘述。经过手工测试成功后，开始为编写Perl测试工具做前期准备。<br />首先，通过查阅网页的HTML源代码中找到提交的变量名（图2）。<br /><br />特别要注意，这个留言本用于验证表单提交还有一个隐藏的参数。（图3）<br /><br />掌握了上述的资料...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div><div><a href="/logs/20687799.html">2006年100款最佳安全工具谱</a> 2008-05-11</div><div><a href="/logs/20687559.html">SQL Server应用程序中的高级SQL注入</a> 2008-05-11</div><div><a href="/logs/20687247.html">精妙Sql语句</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20741418.html&title=Perl%E8%84%9A%E6%9C%AC%E6%89%93%E9%80%A0%E8%87%AA%E5%B7%B1%E7%AE%80%E5%8D%95%E7%9A%84XSS+Proof+of+Concept">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20741418.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 22:52:25 +0800</pubDate>
  </item>
  <item>
   <title>php escapeshellcmd多字节编码漏洞解析及延伸</title>
   <description><![CDATA[漏洞公告在http://www.sektioneins.de/advisories/SE-2008-03.txt<br /><br />&nbsp;&nbsp;&nbsp;&nbsp;PHP 5 &lt;= 5.2.5<br />&nbsp;&nbsp;&nbsp;&nbsp;PHP 4 &lt;= 4.4.8<br /><br />&nbsp;&nbsp;&nbsp;&nbsp;一些允许如GBK，EUC-KR, SJIS等宽字节字符集的系统都可能受此影响，影响还是非常大的，国内的虚拟主机应该是通杀...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20688927.html">代码逆向乱谈之导引</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20688468.html">“机器狗”病毒驱动部分逆向分析注释（C代码）</a> 2008-05-11</div><div><a href="/logs/20686632.html">手工SQL标准注入语句</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20690499.html&title=php+escapeshellcmd%E5%A4%9A%E5%AD%97%E8%8A%82%E7%BC%96%E7%A0%81%E6%BC%8F%E6%B4%9E%E8%A7%A3%E6%9E%90%E5%8F%8A%E5%BB%B6%E4%BC%B8">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20690499.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 02:27:03 +0800</pubDate>
  </item>
  <item>
   <title>ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</title>
   <description><![CDATA[比较老的东西了，但好象知道的人还是不多，随便介绍一下<br /><br />来看ObOpenObjectByName，它会调用ObpLookupObjectByName来打开一个对象<br /><br />对象头(object_header)有一个object type结构<br />object type结构里有一个TypeInfo,结构是OBJECT_TYPE_INITIALIZER <br />typedef struct _OBJECT_TYPE_INITIALIZER {<br />USH...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20689164.html">程序从DOS/bios驻留内存到WINNT下监视读入内存数据</a> 2008-05-11</div><div><a href="/logs/20688927.html">代码逆向乱谈之导引</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div><div><a href="/logs/20685696.html">所有女孩看了都會哭的答案</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20689881.html&title=ObjectType+HOOK%E5%B9%B2%E6%B6%89%E6%B3%A8%E5%86%8C%E8%A1%A8%E6%93%8D%E4%BD%9C%28bypass+Icesword%2Cgmer%2CNIAP%2Cetc.%29">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20689881.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 02:18:14 +0800</pubDate>
  </item>
  <item>
   <title>程序从DOS/bios驻留内存到WINNT下监视读入内存数据</title>
   <description><![CDATA[.586p&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;;########################################################################<br />...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20688468.html">“机器狗”病毒驱动部分逆向分析注释（C代码）</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div><div><a href="/logs/20687799.html">2006年100款最佳安全工具谱</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20689164.html&title=%E7%A8%8B%E5%BA%8F%E4%BB%8EDOS%2Fbios%E9%A9%BB%E7%95%99%E5%86%85%E5%AD%98%E5%88%B0WINNT%E4%B8%8B%E7%9B%91%E8%A7%86%E8%AF%BB%E5%85%A5%E5%86%85%E5%AD%98%E6%95%B0%E6%8D%AE">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20689164.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:50:45 +0800</pubDate>
  </item>
  <item>
   <title>代码逆向乱谈之导引</title>
   <description><![CDATA[早就想写点什么，自己都不知道一天在瞎忙什么，一直到最近才开始动手。。。我想通过这个乱谈系列跟大家分享一些心得。我打算在这个系列文章中讲点方法与思路，当然，很多方法并不是我的原创，只是我用这些方法和思路解决了我的实际问题。由于本人水平有限，很多说法只是我个人的理解，然后用我自己的语言表达出来，可能并不专业，所以在这里不负责任的乱谈一下，欢迎大家拍砖。<br /><br />什么是代码逆向<br /><br />代码逆向即是在没有源代码的情况下，对目标程序的行为、数据流、及编译器生成的代码进行分析，通过...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20690499.html">php escapeshellcmd多字节编码漏洞解析及延伸</a> 2008-05-11</div><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20688927.html&title=%E4%BB%A3%E7%A0%81%E9%80%86%E5%90%91%E4%B9%B1%E8%B0%88%E4%B9%8B%E5%AF%BC%E5%BC%95">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20688927.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:43:00 +0800</pubDate>
  </item>
  <item>
   <title>对抗启发式代码仿真检测技术分析</title>
   <description><![CDATA[&nbsp;最近在研究病毒的检测技术，虽然在这个木马、流氓件猖獗的年代，检测技术（除了考虑效率因素外）已经变得不是十分重要了。但俺仍然出于兴趣想从这里面寻找些思路。或许对抗技术的本身并不在于谁彻底打败了谁，而在于彼此间共同进步。在查阅资料中发现了这篇文章（Anti heuristic techniques&nbsp;&nbsp;author:Black Jack ），虽然是比较古老的，但还是可以从中获得很多新的思路。翻译的比较粗糙，如有不正确或不准确的地方还望大家指正，后面我会继续谈些对抗仿真技术的...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://moon-dong.blogbus.com/logs/50770466.html">2009-11-09</a> 2009-11-09</div><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20689164.html">程序从DOS/bios驻留内存到WINNT下监视读入内存数据</a> 2008-05-11</div><div><a href="/logs/20686632.html">手工SQL标准注入语句</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20688606.html&title=%E5%AF%B9%E6%8A%97%E5%90%AF%E5%8F%91%E5%BC%8F%E4%BB%A3%E7%A0%81%E4%BB%BF%E7%9C%9F%E6%A3%80%E6%B5%8B%E6%8A%80%E6%9C%AF%E5%88%86%E6%9E%90">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20688606.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:33:33 +0800</pubDate>
  </item>
  <item>
   <title>“机器狗”病毒驱动部分逆向分析注释（C代码）</title>
   <description><![CDATA[软件名称】: 机器狗（病毒）<br />【下载地址】: http://www.dream2fly.net 或 自己搜索下载<br />【加壳方式】: 未知壳<br />【编写语言】: MASM<br />【使用工具】: IDA<br />【操作平台】: win2003<br />【软件介绍】: 穿透冰点型带驱动病毒<br />【作者声明】: 只是感兴趣，没有其他目的。失误之处敬请诸位大侠赐教! <br /><br />*/<br />#include &lt;ntddk.h&gt;&nbsp;&nb...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div><div><a href="/logs/20687247.html">精妙Sql语句</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20688468.html&title=%E2%80%9C%E6%9C%BA%E5%99%A8%E7%8B%97%E2%80%9D%E7%97%85%E6%AF%92%E9%A9%B1%E5%8A%A8%E9%83%A8%E5%88%86%E9%80%86%E5%90%91%E5%88%86%E6%9E%90%E6%B3%A8%E9%87%8A%EF%BC%88C%E4%BB%A3%E7%A0%81%EF%BC%89">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20688468.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:25:18 +0800</pubDate>
  </item>
  <item>
   <title>最酷的windows后门</title>
   <description><![CDATA[在windows 2000/xp/vista下，按shift键5次，可以打开粘置，会运行sethc.exe，而且，在登录界面里也可以打开。这就让人联想到WINDOWS的屏保，将程序替换成cmd.exe后，就可以打开shell了。<br /><br />参考McafeeAvertLabs：<br />http://feeds.feedburner.com/~r/McafeeAvertLabsBlog/~3/101149799/<br /><br />XP：<br />将安装源光盘弹出（或将硬盘上的安装...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20689881.html">ObjectType HOOK干涉注册表操作(bypass Icesword,gmer,NIAP,etc.)</a> 2008-05-11</div><div><a href="/logs/20688606.html">对抗启发式代码仿真检测技术分析</a> 2008-05-11</div><div><a href="/logs/20687559.html">SQL Server应用程序中的高级SQL注入</a> 2008-05-11</div><div><a href="/logs/20685696.html">所有女孩看了都會哭的答案</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20687937.html&title=%E6%9C%80%E9%85%B7%E7%9A%84windows%E5%90%8E%E9%97%A8">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20687937.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:15:35 +0800</pubDate>
  </item>
  <item>
   <title>2006年100款最佳安全工具谱</title>
   <description><![CDATA[在2000和2003年非常成功的推出了安全工具调查后，Insecure.Org 非常高兴为大家带来2006年度的安全工具调查。我-Fyodor对nmap-hackers 邮件列表中的用户进行了调查，让大家来分享他们最喜欢用的工具，结果有3243名用户提供了反馈信息。我从反馈信息中选取了大家最喜欢的前100种工具，并将它们进行了分类。建议安全界人士仔细阅读这份列表，并对不熟悉或未听说过的工具进行研究，相信会有很大帮助。我自己就从中发现了很多以前没有使用过但非常好用的工具。当很多菜鸟问我&ldquo;我...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20689164.html">程序从DOS/bios驻留内存到WINNT下监视读入内存数据</a> 2008-05-11</div><div><a href="/logs/20687937.html">最酷的windows后门</a> 2008-05-11</div><div><a href="/logs/20686632.html">手工SQL标准注入语句</a> 2008-05-11</div><div><a href="/logs/20685696.html">所有女孩看了都會哭的答案</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20687799.html&title=2006%E5%B9%B4100%E6%AC%BE%E6%9C%80%E4%BD%B3%E5%AE%89%E5%85%A8%E5%B7%A5%E5%85%B7%E8%B0%B1">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20687799.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:13:53 +0800</pubDate>
  </item>
  <item>
   <title>SQL Server应用程序中的高级SQL注入</title>
   <description><![CDATA[第一次翻译，水平有限，难免有错，请不吝指正。转载请保留信息完整。<br /><br />摘要：<br />这份文档是详细讨论SQL注入技术，它适应于比较流行的IIS+ASP+SQLSERVER平台。它讨论了哪些SQL语句能通过各种各样的方法注入到应用程序中，并且记录与攻击相关的数据确认和数据库锁定。<br /><br />这份文档的预期读者为与数据库通信的WEB程序的开发者和那些扮演审核WEB应用程序的安全专家。<br /><br />介绍：<br />&nbsp;&nbsp;&nbsp;&nbsp...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/20741418.html">Perl脚本打造自己简单的XSS Proof of Concept</a> 2008-05-11</div><div><a href="/logs/20689164.html">程序从DOS/bios驻留内存到WINNT下监视读入内存数据</a> 2008-05-11</div><div><a href="/logs/20688927.html">代码逆向乱谈之导引</a> 2008-05-11</div><div><a href="/logs/20687247.html">精妙Sql语句</a> 2008-05-11</div><div><a href="/logs/20686632.html">手工SQL标准注入语句</a> 2008-05-11</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Flengmonanhai.blogbus.com%2Flogs%2F20687559.html&title=SQL+Server%E5%BA%94%E7%94%A8%E7%A8%8B%E5%BA%8F%E4%B8%AD%E7%9A%84%E9%AB%98%E7%BA%A7SQL%E6%B3%A8%E5%85%A5">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://lengmonanhai.blogbus.com/logs/20687559.html</link>
   <author>Inspiration</author>
   <pubDate>Sun, 11 May 2008 01:03:19 +0800</pubDate>
  </item>
 </channel>
</rss>
