<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>这个M &#187; 学习技术</title>
	<atom:link href="http://www.hb6.org/M/category/hacker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.hb6.org</link>
	<description>生命是一直这样无聊 还只是年轻时这样 ？——会越来越无聊的......</description>
	<lastBuildDate>Mon, 31 Oct 2011 15:04:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>&#8216;or&#8217;=&#039;or&#8217;万能密码漏洞修补与总结</title>
		<link>http://www.hb6.org/M/or-or-wan-neng-mi-ma.html</link>
		<comments>http://www.hb6.org/M/or-or-wan-neng-mi-ma.html#comments</comments>
		<pubDate>Fri, 30 Jul 2010 09:47:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[学习技术]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.hb6.org/?p=212</guid>
		<description><![CDATA[  说起这个万能密码,相信玩过黑的都认识吧.也就是 &#8216;or&#8217;='or&#8217;,这只最基础的一种,总结一下吧: 各种各样的万能密码 &#8216;or&#8217;='or&#8217; 1&#8242;or&#8217;1&#8242;=&#8217;1 admin&#8217;or&#8217;1&#8242;=&#8217;1&#8242;&#8211; &#8216;or’’=&#8217; ” or “a”=”a &#8216;) or (’a’=&#8217;a or 1=1&#8211; &#8216; or ’a’=&#8217;a &#8216;or”=&#8217; &#8216;or&#8217;1&#8242;=&#8217;1 “or=or” &#8216;or”=”or”=&#8217; &#8216;or&#8217;=&#8217;1&#8242; &#8216;or&#8217; &#8217;1&#8242;=&#8217;1 最短的:&#8217;or&#8217;1 修补方案: 在管理登录文件源码内找类似下面代码的代码  username=request.Form(“name”) pass=request.Form(“pass”) 改成: username=Replace(request.Form(“name”), “&#8216;”, “””) pass=Replace(request.Form(“pass”), “&#8216;”, “””) 如果找不到的话,看下管理登录页面源码内是否有调用的页面. 例如: &#60;form name=”form1&#8243; method=”post” action=”login_ok.asp”&#62; 则应检查login_ok.asp页面的源码. 来个例子吧: 原代码: thename=trim(request(“name”)) thepassword1=trim(request(“password”)) 修改为: thename=Replace(request.Form(“name”), “&#8216;”, “””) thepassword1=Replace(request.Form(“password”), “&#8216;”, [...]]]></description>
		<wfw:commentRss>http://www.hb6.org/M/or-or-wan-neng-mi-ma.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>upfile_soft.asp漏洞修补</title>
		<link>http://www.hb6.org/M/upfile_soft-asp.html</link>
		<comments>http://www.hb6.org/M/upfile_soft-asp.html#comments</comments>
		<pubDate>Thu, 29 Jul 2010 10:38:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[学习技术]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.hb6.org/?p=209</guid>
		<description><![CDATA[  很老的一个漏洞,最早学黑的时候利用过,当时只顾拿webshell也不会原理和修补,只知道用挖掘鸡扫,然后明小子动力上传.今天帮看朋友看一学校网站,居然还存在这样的漏洞,顺便研究了一下,修了此漏洞. 修改upfile_class.asp文件,大概在inc文件夹下. 原代码: oFileInfo.FileName = Mid (sFileName,InStrRev (sFileName, “\”)+1) oFileInfo.FilePath = Left (sFileName,InStrRev (sFileName, “\”)) oFileInfo.FileExt = Mid (sFileName,InStrRev (sFileName, “.”)+1) 修改为: oFileInfo.FileName = trim(Mid (sFileName,InStrRev (sFileName, “\”)+1)) oFileInfo.FilePath = trim(Left (sFileName,InStrRev (sFileName, “\”))) oFileInfo.FileExt = trim(Mid (sFileName,InStrRev (sFileName, “.”)+1))]]></description>
		<wfw:commentRss>http://www.hb6.org/M/upfile_soft-asp.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

